--------------- QuickDiag | g3n-h@ckm@n | 2_29.06.2016.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 22/07/2016 18:16:44 Updated 29/06/2016 | 12.50 by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+04:00) Port Louis [theo (Administrator)] - [THEO-HP] (S-1-5-21-2532391380-2442022221-794288624-1001) System: Microsoft Windows 10 Famille - - (10.0.10586) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Famille|C:\WINDOWS|\Device\Harddisk0\Partition2 Boot : Normal boot PC: HP Pavilion dv7 Notebook PC - Hewlett-Packard - IdNumber: 2CE224121Q - UUID: E08F2370-39B7-E111-BD7E-C98E44EBCD5F Processor : X64 - 2494 Mhz - Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz InsydeH2O Version 03.71.51F.0A - en|US|iso8859-1 - Insyde - S/N: 2CE224121Q - F.0A - HPQOEM - 1 CoreTemp : 30 Celsius ----------| Extended ---------- | SoundDevice IDT High Definition Audio CODEC - Status: OK - Manufacturer: IDT - PNPDeviceID: HDAUDIO\FUNC_01&VEN_111D&DEV_76E0&SUBSYS_103C181D&REV_1001\4&1DDD38FB&0&0001 Son Intel(R) pour écrans - Status: OK - Manufacturer: Intel(R) Corporation - PNPDeviceID: HDAUDIO\FUNC_01&VEN_8086&DEV_2806&SUBSYS_103C1818&REV_1000\4&1DDD38FB&0&0301 ---------- | Video Intel(R) HD Graphics 4000 - Resolution: 1600x900 - Colors: 4294967296 - RefreshRate: 39 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: igdumdim64.dll,igd10iumd64.dll,igd10iumd64.dll,igdumdim32,igd10iumd32,igd10iumd32 - PNPDeviceID: PCI\VEN_8086&DEV_0166&SUBSYS_181D103C&REV_09\3&11583659&0&10 - AdapterCompatibility: Intel Corporation - RAM: -2133168128 NVIDIA GeForce GT 630M - Resolution: x - Colors: - RefreshRate: - Bits Per Pixel - DeviceID: VideoController2 - Drivers: nvd3dumx.dll,nvwgf2umx.dll,nvwgf2umx.dll,nvwgf2umx.dll,nvd3dum,nvwgf2um,nvwgf2um,nvwgf2um - PNPDeviceID: PCI\VEN_10DE&DEV_0DE9&SUBSYS_181D103C&REV_A1\4&438082C&0&0008 - AdapterCompatibility: NVIDIA - RAM: 1073741824 Inegrated Video Chipset DeviceName: Intel(R) HD Graphics 4000 - DriverVersion: 10.18.10.4358 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 27136 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 87040 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34632 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42936 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35696 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25344 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 53760 - Manufacturer: Microsoft Corporation - Status: OK ---------- | CPU CPU #1 value:33 % CPU #2 value:20 % CPU #3 value:27 % CPU #4 value:27 % Total Overall CPU Usage value:27 % ---------- | Network Realtek PCIe GBE Family Controller : SENT:0 bytes/sec / RECVD:0 bytes/sec Carte Wi-Fi 802.11b_g_n [projet] 1x1 4313GN Broadcom : SENT:62,916 bytes/sec / RECVD:62,916 bytes/sec Overall -> SEND Maxium:27 bytes/sec, / RECEIVE Maximum:62,916 bytes/sec Microsoft Kernel Debug Network Adapter - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000 Carte Wi-Fi 802.11b/g/n (projet) 1x1 4313GN Broadcom - Ethernet 802.3 - Broadcom - Status: - PnPID : PCI\VEN_14E4&DEV_4727&SUBSYS_1795103C&REV_01\4&31D34B42&0&00E3 Realtek PCIe GBE Family Controller - Ethernet 802.3 - Realtek - Status: - PnPID : PCI\VEN_10EC&DEV_8168&SUBSYS_1818103C&REV_07\4&1A2E8246&0&00E5 Microsoft Hosted Network Virtual Adapter - Ethernet 802.3 - Microsoft - Status: - PnPID : {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_SAP\5&1D068BBA&0&01 Bluetooth Device (Personal Area Network) - Ethernet 802.3 - Microsoft - Status: - PnPID : BTH\MS_BTHPAN\7&ADF794B&1&2 Bluetooth Device (RFCOMM Protocol TDI) - - Microsoft - Status: - PnPID : BTH\MS_RFCOMM\7&ADF794B&1&0 WAN Miniport (SSTP) - - - Status: - PnPID : WAN Miniport (IKEv2) - - - Status: - PnPID : WAN Miniport (L2TP) - - - Status: - PnPID : WAN Miniport (PPTP) - - - Status: - PnPID : WAN Miniport (PPPOE) - - - Status: - PnPID : WAN Miniport (IP) - - - Status: - PnPID : WAN Miniport (IPv6) - - - Status: - PnPID : WAN Miniport (Network Monitor) - - - Status: - PnPID : ---------- | Memory RAM = Total (MB) : 4091 | Free (MB) : 1276 Pagefile = Total (MB) : 8285 | Free (MB) : 4804 Virtual = Total (MB) : 4194 | Free (MB) : 3952 Physical Memory 1 : Capacity: 4294967296 - Bottom-Slot 2(under) - Posit.: 2 - Manufacturer: Samsung - PartNumber: M471B5273DH0-CK0 - S/N: 00C6B0D4 ---------- | SID Users Administrateur : [S-1-5-21-2532391380-2442022221-794288624-500] DefaultAccount : [S-1-5-21-2532391380-2442022221-794288624-503] HomeGroupUser$ : [S-1-5-21-2532391380-2442022221-794288624-1003] Invité : [S-1-5-21-2532391380-2442022221-794288624-501] theo : [S-1-5-21-2532391380-2442022221-794288624-1001] UpdatusUser : [S-1-5-21-2532391380-2442022221-794288624-1000] Administrateurs : [S-1-5-32-544] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] HomeUsers : [S-1-5-21-2532391380-2442022221-794288624-1002] ---------- | Drives D:\ -> [Fixed] | [Recovery] | Total : 21.91 Go | Free : 2.32 Go -> NTFS [RAID] C:\ -> [Fixed] | [] | Total : 573.97 Go | Free : 237.06 Go -> NTFS [RAID] Disk Usage Information [2 total Physical Disks] Physical Drive #0 [C:, D:] : Read:1,341,721 bytes/sec, Written:0 bytes/sec Max Read:1,341,721 bytes/sec, Max Write:0 bytes/sec Physical Drive #\ [THEO-HP\Disque, physique(1)\Écritures, disque,, octets/s] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Overall - Read Maximum:1,341,721 bytes/sec, Write Maximum:0 bytes/sec DeviceID: \\.\PHYSICALDRIVE1 - Status: OK - USB - External hard disk media - 3 Part. - PnPID : USBSTOR\DISK&VEN_SAMSUNG&PROD_M2_PORTABLE&REV_\00000011E093105000B0&0 DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - SCSI - Fixed hard disk media - 4 Part. - PnPID : SCSI\DISK&VEN_HITACHI&PROD_HTS547564A9E384\4&2593752F&0&000000 ---------- | Windows updates No detected update !!! Microsoft : + Windows Is Activated ---------- | Browsers IE : 11.0.10586.494 (© Microsoft Corporation. Tous droits réservés.) FF : 46.0.1.5966 (©Firefox and Mozilla Developers; available under the MPL 2 license.) GC : 35.0.1916.153 (Copyright 2012 Google Inc.) Default : "C:\Program Files (x86)\Firefox\firefox.exe" "%1" ---------- | FlashPlayer FlashPlayer ActiveX : 22.0.0.209 FlashPlayer Plugin : 22.0.0.209 ---------- | Security AV : avast! Antivirus Enabled AS : avast! Antivirus Enabled AM : Malwarebytes' Anti-Malware ( 2.3.173.0) [Update : 15/11/2015 20:41:08] FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Manual(3)] = Running AS: Windows Defender [Manual(3)] = stopped WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 360 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.10586.0) = C:\Windows\System32\smss.exe CPU Usage:0 % 600 | [Owner : | Parent : 492() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.10586.306) = C:\Windows\System32\wininit.exe CPU Usage:0 % 676 | [Owner : | Parent : 600(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.10586.71) = C:\Windows\System32\services.exe CPU Usage:0 % 684 | [Owner : | Parent : 600(wininit.exe) | ?????] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.10586.0) = C:\Windows\System32\lsass.exe CPU Usage:0 % 764 | [Owner : | Parent : 592() | ?????] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.10586.306) = C:\Windows\System32\winlogon.exe CPU Usage:0 % 824 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 880 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 1000 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 92 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 304 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 444 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:4 % 1032 | [Owner : | Parent : 676(services.exe) | ?????] - (.HP - HP Service.) - (6.0.100.276) = C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe CPU Usage:0 % 1148 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 1196 | [Owner : | Parent : 676(services.exe) | ?????] - (.Intel Corporation - IntelCpHeciSvc Executable.) - (9.0.20.9000) = C:\Windows\SysWOW64\IntelCpHeciSvc.exe CPU Usage:0 % 1352 | [Owner : | Parent : 676(services.exe) | ?????] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.62.) - (8.17.13.5362) = C:\Windows\System32\nvvsvc.exe CPU Usage:0 % 1376 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 1400 | [Owner : | Parent : 1352(nvvsvc.exe) | ?????] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.5362) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe CPU Usage:0 % 1408 | [Owner : | Parent : 1352(nvvsvc.exe) | ?????] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.62.) - (8.17.13.5362) = C:\Windows\System32\nvvsvc.exe CPU Usage:0 % 1500 | [Owner : | Parent : 676(services.exe) | ?????] - (.Intel Corporation - igfxCUIService Module.) - (6.15.10.4358) = C:\Windows\System32\igfxCUIService.exe CPU Usage:0 % 1544 | [Owner : | Parent : 676(services.exe) | ?????] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6418.0) = C:\Program Files\IDT\WDM\stacsv64.exe CPU Usage:0 % 1660 | [Owner : | Parent : 676(services.exe) | ?????] - (.Hewlett-Packard Company - HpService.) - (4.2.9.1) = C:\Windows\System32\hpservice.exe CPU Usage:0 % 1816 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 1864 | [Owner : | Parent : 676(services.exe) | ?????] - (.AVAST Software - avast! Service.) - (12.1.3076.0) = C:\Program Files\AVAST Software\Avast\AvastSvc.exe CPU Usage:0 % 1884 | [Owner : | Parent : 1000(svchost.exe) | ?????] - (.Microsoft Corporation - Infrastructure d’extensibilité pour les services réseau Windows sans fil 802.11.) - (10.0.10586.0) = C:\Windows\System32\wlanext.exe CPU Usage:0 % 1892 | [Owner : | Parent : 1884(wlanext.exe) | ?????] - (.Microsoft Corporation - Console Window Host.) - (10.0.10586.0) = C:\Windows\System32\conhost.exe CPU Usage:0 % 1788 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 2132 | [Owner : theo | Parent : 444(svchost.exe) | 21 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.10586.0) = C:\Windows\System32\sihost.exe CPU Usage:0 % 2160 | [Owner : | Parent : 444(svchost.exe) | ?????] - (.Microsoft Corporation - Moteur du Planificateur de tâches.) - (10.0.10586.494) = C:\Windows\System32\taskeng.exe CPU Usage:0 % 2192 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.8693) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe CPU Usage:0 % 2228 | [Owner : | Parent : 2160(taskeng.exe) | ?????] - (.Google Inc. - Programme d'installation de Google.) - (1.2.183.21) = C:\Program Files (x86)\Google\Update\GoogleUpdate.exe CPU Usage:0 % 2548 | [Owner : theo | Parent : 2516() | 86.69 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.10586.494) = C:\Windows\explorer.exe CPU Usage:0 % 2652 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.10586.122) = C:\Windows\System32\spoolsv.exe CPU Usage:0 % 2936 | [Owner : | Parent : 676(services.exe) | ?????] - (.Autodesk Inc. - Autodesk Application Manager.) - (4.0.69.0) = C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe CPU Usage:0 % 2964 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 2980 | [Owner : | Parent : 676(services.exe) | ?????] - (.Hewlett-Packard Company - HP Client Services.) - (1.1.0.3539) = C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe CPU Usage:0 % 2988 | [Owner : | Parent : 676(services.exe) | ?????] - (.-.) - (0.0.0.0) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe CPU Usage:0 % 2996 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 3004 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 3016 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Message Queuing Service.) - (10.0.10586.0) = C:\Windows\System32\mqsvc.exe CPU Usage:0 % 3024 | [Owner : | Parent : 676(services.exe) | ?????] - (.- DCSHOST.) - (2.0.0.49) = C:\ProgramData\DatacardService\HWDeviceService64.exe CPU Usage:0 % 3060 | [Owner : | Parent : 676(services.exe) | ?????] - (.Broadcom Corporation. - Bluetooth Radio Management Support.) - (12.0.0.8048) = C:\Windows\System32\BtwRSupportService.exe CPU Usage:0 % 3068 | [Owner : | Parent : 676(services.exe) | ?????] - (.EasyBits Software AS - Shared EasyBits services for Windows.) - (5.0.0.101) = C:\Windows\SysWOW64\ezSharedSvcHost.exe CPU Usage:0 % 2016 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Phone Number Recognition (PNR) module.) - (8.3.0.9150) = C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe CPU Usage:0 % 2172 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Updates Skype Click to Call.) - (8.3.0.9150) = C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe CPU Usage:0 % 2156 | [Owner : | Parent : 676(services.exe) | ?????] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - (1.7.2.0) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe CPU Usage:0 % 1756 | [Owner : | Parent : 676(services.exe) | ?????] - (.Hewlett-Packard Development Company, L.P. - HP Quick Launch WMI Service.) - (2.7.1.0) = C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe CPU Usage:0 % 1748 | [Owner : | Parent : 676(services.exe) | ?????] - (.Apple Inc. - Bonjour Service.) - (3.0.0.10) = C:\Program Files\Bonjour\mDNSResponder.exe CPU Usage:0 % 1736 | [Owner : | Parent : 676(services.exe) | ?????] - (.Apple Inc. - YSLoader.exe.) - (17.344.0.68) = C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe CPU Usage:0 % 3156 | [Owner : | Parent : 676(services.exe) | ?????] - (.Hewlett-Packard - HP Usage Improvement Tracking.) - (1.0.12935.3667) = C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe CPU Usage:0 % 3276 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 3292 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 3316 | [Owner : | Parent : 676(services.exe) | ?????] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - (19.0.12.98) = C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe CPU Usage:0 % 3324 | [Owner : | Parent : 676(services.exe) | ?????] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Interface.) - (1.23.216.0) = C:\Program Files\Intel\iCLS Client\HeciServer.exe CPU Usage:0 % 3444 | [Owner : | Parent : 676(services.exe) | ?????] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host Interface.) - (8.0.0.1351) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe CPU Usage:0 % 3532 | [Owner : | Parent : 676(services.exe) | ?????] - (.TData.com - TData.com.) - (1.0.0.42) = C:\Program Files (x86)\TData\TData.exe CPU Usage:0 % 3656 | [Owner : theo | Parent : 3024(HWDeviceService64.exe) | 8.27 Mo] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) - (2.0.0.49) = C:\ProgramData\DatacardService\DCSHelper.exe CPU Usage:0 % 3700 | [Owner : theo | Parent : 3316(SynTPEnhService.exe) | 17.21 Mo] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) - (19.0.12.98) = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe CPU Usage:2 % 3936 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 4308 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - SMSvcHost.exe.) - (4.6.1038.0) = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe CPU Usage:0 % 4668 | [Owner : theo | Parent : 4228() | 4.09 Mo] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (19.0.12.98) = C:\Program Files\Synaptics\SynTP\SynTPHelper.exe CPU Usage:0 % 5272 | [Owner : theo | Parent : 824(svchost.exe) | 7.47 Mo] - (.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) - (10.0.10586.0) = C:\Windows\System32\wbem\unsecapp.exe CPU Usage:0 % 5524 | [Owner : theo | Parent : 5380() | 11.77 Mo] - (.Intel Corporation - igfxEM Module.) - (6.15.10.4358) = C:\Windows\System32\igfxEM.exe CPU Usage:0 % 5532 | [Owner : theo | Parent : 5380() | 8.69 Mo] - (.Intel Corporation - igfxHK Module.) - (6.15.10.4358) = C:\Windows\System32\igfxHK.exe CPU Usage:0 % 5552 | [Owner : theo | Parent : 5380() | 10.26 Mo] - (.Intel Corporation - igfxTray Module.) - (6.15.10.4358) = C:\Windows\System32\igfxTray.exe CPU Usage:0 % 5920 | [Owner : theo | Parent : 1400(nvxdsync.exe) | 12.4 Mo] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.5362) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe CPU Usage:0 % 5360 | [Owner : theo | Parent : 5920(nvtray.exe) | 11.2 Mo] - (.NVIDIA Corporation - NVIDIA Update Backend.) - (10.4.0.5) = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe CPU Usage:0 % 2296 | [Owner : theo | Parent : 2392() | 24.77 Mo] - (.- IEWebSiteLogon.) - (6.0.100.276) = C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe CPU Usage:0 % 944 | [Owner : theo | Parent : 444(svchost.exe) | 13.8 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.10586.0) = C:\Windows\System32\taskhostw.exe CPU Usage:0 % 4588 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.10586.494) = C:\Windows\System32\SearchIndexer.exe CPU Usage:0 % 2288 | [Owner : theo | Parent : 444(svchost.exe) | 3.37 Mo] - (.CyberLink - YouCam Mirage.) - (1.0.0.526) = C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe CPU Usage:0 % 4728 | [Owner : theo | Parent : 2548(explorer.exe) | 16.32 Mo] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6418.0) = C:\Program Files\IDT\WDM\sttray64.exe CPU Usage:0 % 2544 | [Owner : theo | Parent : 1576() | 11.9 Mo] - (.- HP Taskbar Process HP.) - (1.1.4.0) = C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe CPU Usage:0 % 1540 | [Owner : theo | Parent : 1576() | 12.72 Mo] - (.Hewlett-Packard Development Company, L.P. - HP Taskbar Process TP.) - (1.1.4.0) = C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe CPU Usage:0 % 6684 | [Owner : theo | Parent : 2548(explorer.exe) | 627.96 Mo] - (.Mozilla Corporation - Firefox.) - (47.0.0.6025) = C:\Program Files (x86)\Firefox\Firefox.exe CPU Usage:26 % 6732 | [Owner : theo | Parent : 2548(explorer.exe) | 15.13 Mo] - (.Comfort Software Group - Free Alarm Clock.) - (4.0.1.0) = C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe CPU Usage:0 % 6896 | [Owner : theo | Parent : 2548(explorer.exe) | 88.96 Mo] - (.Skype Technologies S.A. - Skype.) - (7.25.0.106) = C:\Program Files (x86)\Skype\Phone\Skype.exe CPU Usage:0 % 6956 | [Owner : | Parent : 676(services.exe) | ?????] - (.Disc Soft Ltd - Disc Soft Bus Service.) - (10.3.0.152) = C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe CPU Usage:0 % 5748 | [Owner : theo | Parent : 2548(explorer.exe) | 14.19 Mo] - (.© 2015 Microsoft Corporation - Microsoft Bing Service.) - (1.0.6.0) = C:\Users\theo\AppData\Local\Microsoft\BingSvc\BingSvc.exe CPU Usage:0 % 5568 | [Owner : theo | Parent : 2548(explorer.exe) | 20.95 Mo] - (.Microsoft Corporation - Microsoft OneDrive.) - (17.3.6390.509) = C:\Users\theo\AppData\Local\Microsoft\OneDrive\OneDrive.exe CPU Usage:0 % 5968 | [Owner : theo | Parent : 6352() | 6.98 Mo] - (.Intel Corporation - Intel(R) USB 3.0 Monitor.) - (1.0.0.120) = C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe CPU Usage:0 % 6384 | [Owner : theo | Parent : 6352() | 16.75 Mo] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) - (1.7.2.0) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe CPU Usage:0 % 6268 | [Owner : theo | Parent : 6352() | 11.42 Mo] - (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) - (1.3.5.0) = C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe CPU Usage:0 % 4584 | [Owner : theo | Parent : 6352() | 10.36 Mo] - (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) - (2.1.0.51) = C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe CPU Usage:0 % 6628 | [Owner : | Parent : 676(services.exe) | ?????] - (.Hewlett-Packard Company - HP Software Framework WMI Service.) - (6.5.6.1) = C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe CPU Usage:0 % 6488 | [Owner : theo | Parent : 6352() | 9.64 Mo] - (.Research In Motion Limited - Launch Agent Service.) - (4.2.0.35) = C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe CPU Usage:0 % 6448 | [Owner : theo | Parent : 6352() | 13.94 Mo] - (.Hewlett-Packard Development Company, L.P. - HP Message Service.) - (2.7.2.0) = C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe CPU Usage:0 % 6484 | [Owner : | Parent : 676(services.exe) | ?????] - (.Research In Motion Limited - BlackBerry Device Manager.) - (4.2.0.33) = C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe CPU Usage:0 % 2408 | [Owner : theo | Parent : 6352() | 14.3 Mo] - (.Apple Inc. - iTunesHelper.) - (11.4.0.18) = C:\Program Files (x86)\iTunes\iTunesHelper.exe CPU Usage:0 % 640 | [Owner : theo | Parent : 6352() | 38.44 Mo] - (.AVAST Software - avast! Antivirus.) - (12.1.3076.6) = C:\Program Files\AVAST Software\Avast\AvastUI.exe CPU Usage:0 % 3624 | [Owner : theo | Parent : 6352() | 10.86 Mo] - (.Oracle Corporation - Java Update Scheduler.) - (2.8.60.27) = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe CPU Usage:0 % 6728 | [Owner : theo | Parent : 6352() | 66.54 Mo] - (.Dropbox, Inc. - Dropbox.) - (6.4.14.0) = C:\Program Files (x86)\Dropbox\Client\Dropbox.exe CPU Usage:0 % 6856 | [Owner : | Parent : 676(services.exe) | ?????] - (.Apple Inc. - iPodService Module (64-bit).) - (11.4.0.18) = C:\Program Files\iPod\bin\iPodService.exe CPU Usage:0 % 7552 | [Owner : theo | Parent : 676(services.exe) | 11.86 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 6164 | [Owner : theo | Parent : 1616() | 40.08 Mo] - (.Autodesk Inc. - Autodesk Application Manager.) - (4.0.69.0) = C:\Users\theo\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe CPU Usage:0 % 7188 | [Owner : | Parent : 676(services.exe) | ?????] - (.- Firefox.) - (1.0.0.1) = C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe CPU Usage:0 % 7664 | [Owner : | Parent : 676(services.exe) | ?????] - (.Hewlett-Packard Company - HP Support Solutions Framework Service.) - (8.2.18.7) = C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe CPU Usage:0 % 7800 | [Owner : | Parent : 676(services.exe) | ?????] - (.Intel Corporation - Local Manageability Service.) - (8.0.0.1351) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe CPU Usage:0 % 8052 | [Owner : | Parent : 676(services.exe) | ?????] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - (1.7.12.0) = C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe CPU Usage:0 % 5580 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 3772 | [Owner : | Parent : 676(services.exe) | ?????] - (.Intel Corporation - User Notification Service.) - (8.0.0.1351) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe CPU Usage:0 % 5868 | [Owner : theo | Parent : 3624(jusched.exe) | 13.59 Mo] - (.Oracle Corporation - Java Update Checker.) - (2.8.60.27) = C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe CPU Usage:0 % 8788 | [Owner : theo | Parent : 824(svchost.exe) | 20.76 Mo] - (.Microsoft Corporation - Application Frame Host.) - (10.0.10586.0) = C:\Windows\System32\ApplicationFrameHost.exe CPU Usage:0 % 9100 | [Owner : theo | Parent : 824(svchost.exe) | 36.33 Mo] - (.Microsoft Corporation - Paramètres.) - (10.0.10586.11) = C:\Windows\ImmersiveControlPanel\SystemSettings.exe CPU Usage:0 % 7216 | [Owner : theo | Parent : 6684(Firefox.exe) | 14.59 Mo] - (.Mozilla Corporation - Plugin Container for Firefox.) - (47.0.0.6025) = C:\Program Files (x86)\Firefox\plugin-container.exe CPU Usage:0 % 4544 | [Owner : theo | Parent : 7216(plugin-container.exe) | 9.44 Mo] - (.Adobe Systems, Inc. - Adobe Flash Player 22.0 r0.) - (22.0.0.209) = C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_22_0_0_209.exe CPU Usage:0 % 4928 | [Owner : theo | Parent : 4544(FlashPlayerPlugin_22_0_0_209.exe) | 19.47 Mo] - (.Adobe Systems, Inc. - Adobe Flash Player 22.0 r0.) - (22.0.0.209) = C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_22_0_0_209.exe CPU Usage:2 % 9200 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 7868 | [Owner : | Parent : 1376(svchost.exe) | ?????] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (10.0.10586.218) = C:\Windows\System32\audiodg.exe CPU Usage:0 % 5860 | [Owner : theo | Parent : 824(svchost.exe) | 14.5 Mo] - (.Microsoft Corporation - InstallAgent.) - (10.0.10586.420) = C:\Windows\System32\InstallAgent.exe CPU Usage:0 % 3680 | [Owner : theo | Parent : 1032(TrueSuiteService.exe) | 31.97 Mo] - (.AuthenTec Inc. - TouchControl.) - (6.0.100.276) = C:\Program Files (x86)\HP SimplePass\TouchControl.exe CPU Usage:0 % 8548 | [Owner : | Parent : 444(svchost.exe) | ?????] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) - (10.0.14361.1000) = C:\Windows\System32\CompatTelRunner.exe CPU Usage:0 % 2852 | [Owner : | Parent : 8548(CompatTelRunner.exe) | ?????] - (.Microsoft Corporation - Console Window Host.) - (10.0.10586.0) = C:\Windows\System32\conhost.exe CPU Usage:0 % 9712 | [Owner : | Parent : 8548(CompatTelRunner.exe) | ?????] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) - (10.0.14361.1000) = C:\Windows\System32\CompatTelRunner.exe CPU Usage:2 % 9944 | [Owner : | Parent : 4708() | ?????] - (.Microsoft Corporation - Programme d’installation pour les modules Windows.) - (10.0.10586.0) = C:\Windows\servicing\TrustedInstaller.exe CPU Usage:0 % 7272 | [Owner : | Parent : 676(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe CPU Usage:0 % 1936 | [Owner : theo | Parent : 2548(explorer.exe) | 29.58 Mo] - (.SosVirus - QuickDiag.) - (29.6.2016.1) = C:\Users\theo\Desktop\QuickDiag.exe CPU Usage:0 % ---------- | MD5 [MD5.E396258CFD8F84E8F2C24930E6D88C67] - [13/07/2016 20:55:14] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4409.43 Ko] - (10.0.10586.494) : C:\WINDOWS\Explorer.exe [MD5.41E25E514D90E9C8BC570484DBAFF62B] - [30/10/2015 11:17:49] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [228.5 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\cmd.exe [MD5.3E7CCD0F507877C50078205667CE8133] - [30/10/2015 11:18:03] - (.© Microsoft Corporation. Tous droits réservés. - Processus d’exécution client-serveur.) - [17.72 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\csrss.exe [MD5.9513834DAC717444F04169EA5D120885] - [30/10/2015 11:17:51] - (.© Microsoft Corporation. - COM Surrogate.) - [18.34 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\dllhost.exe [MD5.1C9C6933A94C594DE7366124B4DD6075] - [30/10/2015 11:17:46] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [689.05 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Kernel32.dll [MD5.889459F1FDDC5EC58B437AA6C436F33F] - [30/10/2015 11:18:03] - (.© Microsoft Corporation. - Local Security Authority Process.) - [56.55 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\lsass.exe [MD5.B339861C6A2A86FBCA67C2006B461473] - [30/10/2015 11:17:51] - (.© Microsoft Corporation. - Distributed COM Services.) - [883.5 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\rpcss.dll [MD5.0DCB89B1F3689BC6262FF30BBD603171] - [30/10/2015 11:18:14] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [58 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\rundll32.exe [MD5.6FF8248F3A9D69A095C7F3F42BC29CB2] - [27/04/2016 09:16:35] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [429.84 Ko] - (10.0.10586.71) : C:\WINDOWS\System32\services.exe [MD5.8497852ED44AFF902D502015792D315D] - [30/10/2015 11:17:49] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [42.91 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\svchost.exe [MD5.F5F7CE3E32536F1A37FB3972F27A814F] - [11/06/2016 12:50:59] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de l’API uilisateur de Windows multi-utilisateurs.) - [1366.43 Ko] - (10.0.10586.306) : C:\WINDOWS\System32\user32.dll [MD5.8F3ECCB5DC878FA14887B43CD148CBA9] - [30/10/2015 11:17:53] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Userinit.) - [30 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\userinit.exe [MD5.C1C81AAF533552B3C4D9F11A5FF97700] - [11/06/2016 12:50:51] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [284.53 Ko] - (10.0.10586.306) : C:\WINDOWS\System32\Wininit.exe [MD5.5C156EC4E44E30331BCC865A3B61D839] - [11/06/2016 12:51:10] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Windows.) - [572 Ko] - (10.0.10586.306) : C:\WINDOWS\System32\Winlogon.exe [MD5.70148EFA9A562E7185B75BBE7D376BF7] - [27/04/2016 09:16:39] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de fonction connexe pour WinSock.) - [565.34 Ko] - (10.0.10586.3) : C:\WINDOWS\System32\Drivers\afd.sys [MD5.492B99D2E3D5D7BFD5F0AE1BE7BD37DD] - [30/10/2015 11:17:23] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [27.84 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\atapi.sys [MD5.B6664965BF346322BBDF286174851476] - [30/10/2015 11:17:23] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [188.34 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\ataport.sys [MD5.7F9C7226D743B232907ED2537B8A574F] - [30/10/2015 11:18:09] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [90.5 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\cdfs.sys [MD5.82D97776BF982AA143BDC7DFB5054EA8] - [30/10/2015 11:17:22] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [169.5 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\cdrom.sys [MD5.935823F79CBEDB91637B63D37E3A5A36] - [11/06/2016 12:50:56] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [145 Ko] - (10.0.10586.212) : C:\WINDOWS\System32\Drivers\dfsc.sys [MD5.84BC034B6BB763733C1949B7B9BAF976] - [30/10/2015 11:17:18] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [78 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\hdaudbus.sys [MD5.53FDD9E69189E546DE4740F8C4D8AB2F] - [30/10/2015 11:17:23] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [112 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\i8042prt.sys [MD5.9E5E8F2A1996F23B7E9687846AA81B01] - [30/10/2015 11:17:43] - (.© Microsoft Corporation. - IP Network Address Translator.) - [140 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\ipnat.sys [MD5.0B3B0C1D86050355676640488FA897D3] - [27/04/2016 09:16:38] - (.© Microsoft Corporation. Tous droits réservés. - Minirdr SMB Windows NT.) - [420.84 Ko] - (10.0.10586.122) : C:\WINDOWS\System32\Drivers\mrxsmb.sys [MD5.E582DA849A58524E645545FB68B6625D] - [11/06/2016 12:50:50] - (.© Microsoft Corporation. Tous droits réservés. - NDIS (Network Driver Interface Specification).) - [1125.84 Ko] - (10.0.10586.212) : C:\WINDOWS\System32\Drivers\ndis.sys [MD5.C03E926B0E7D66D68994067231DC3246] - [15/06/2016 21:49:13] - (.© Microsoft Corporation. - MBT Transport driver.) - [272 Ko] - (10.0.10586.420) : C:\WINDOWS\System32\Drivers\netbt.sys [MD5.19BD8A88AAC580592668B070AC0727D9] - [11/06/2016 12:51:48] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [2101.84 Ko] - (10.0.10586.212) : C:\WINDOWS\System32\Drivers\ntfs.sys [MD5.7D0FC96264C0F8F2C1321E33E8EB646C] - [30/10/2015 11:17:23] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [94.5 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\parport.sys [MD5.E3C82823B22463BC38AA4F8ADA852624] - [27/04/2016 09:16:36] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [102.5 Ko] - (10.0.10586.122) : C:\WINDOWS\System32\Drivers\rasl2tp.sys [MD5.1DC2CC74B51E4DC4CD5A20C1021E4010] - [30/10/2015 11:19:42] - (.© Microsoft Corporation. Tous droits réservés. - Redirecteur de périphérique de Microsoft RDP.) - [169 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\rdpdr.sys [MD5.CF63BF6AAEDF721E37F9E216FD321B8E] - [13/07/2016 20:51:47] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [2346.84 Ko] - (10.0.10586.494) : C:\WINDOWS\System32\Drivers\tcpip.sys [MD5.91D3F2A6253EF83EFBD7903028F58C4D] - [27/04/2016 09:16:42] - (.© Microsoft Corporation. - TDI Translation Driver.) - [115.84 Ko] - (10.0.10586.3) : C:\WINDOWS\System32\Drivers\tdx.sys [MD5.E1F91A727A04C9F8199D04FF3BBBF63C] - [30/10/2015 11:17:22] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de cliché instantané du volume.) - [404.84 Ko] - (10.0.10586.0) : C:\WINDOWS\System32\Drivers\volsnap.sys ---------- | Locked Applications ---------- | Explorer.exe component call (Microsoft Files Whitelisted) (.NVIDIA Corporation.-.NVIDIA shim initialization dll, Version 353.62.) - (10.18.13.5362) -- C:\Windows\system32\nvinitx.dll (.Hewlett-Packard Company.-.Hewlett-Packard Company DeskBand.) - (8.0.0.2) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFTaskbar.dll (..-..) - (0.0.0.0) -- C:\WINDOWS\System32\CoreUIComponents.dll (.NVIDIA Corporation.-.NVIDIA D3D Shim Driver, Version 353.62.) - (10.18.13.5362) -- C:\WINDOWS\SYSTEM32\nvumdshimx.dll (.Intel Corporation.-.User Mode Driver for Intel(R) Graphics Technology.) - (10.18.10.4358) -- C:\WINDOWS\system32\igd10iumd64.dll (.Intel Corporation.-.Unified Shader Compiler for Intel(R) Graphics Accelerator.) - (10.18.10.4358) -- C:\WINDOWS\SYSTEM32\igdusc64.dll (.Dropbox, Inc..-.Dropbox Shell Extension.) - (1.0.0.34) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll (..-..) - (1.2.502.0) -- C:\Users\theo\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll (.Malwarebytes.-.Malwarebytes Anti-Malware.) - (3.1.1.0) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll (.AVAST Software.-.avast! Shell Extension.) - (12.1.3076.0) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll (.Autodesk.-.AutoCAD Dwg common shell extension handler.) - (20.0.51.0) -- C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll (.NVIDIA Corporation.-.NVIDIA Shell Extensions.) - (8.17.13.5362) -- C:\WINDOWS\system32\nv3dappshext.dll (.NVIDIA Corporation.-.NVIDIA NVAPI Library, Version 353.62.) - (10.18.13.5362) -- C:\WINDOWS\system32\nvapi64.dll (.NVIDIA Corporation.-.NVIDIA French language resource library.) - (8.17.13.5362) -- C:\WINDOWS\SYSTEM32\Nv3DAppShExtR.dll ---------- | Svchost.exe component call (Microsoft Files Whitelisted) (.NVIDIA Corporation.-.NVIDIA shim initialization dll, Version 353.62.) - (10.18.13.5362) -- C:\Windows\system32\nvinitx.dll (.Apple Inc..-.Bonjour Namespace Provider.) - (3.0.0.10) -- C:\Program Files\Bonjour\mdnsNSP.dll (.NVIDIA Corporation.-.NVIDIA D3D Shim Driver, Version 353.62.) - (10.18.13.5362) -- C:\WINDOWS\system32\nvumdshimx.dll (.NVIDIA Corporation.-.NVIDIA D3D10 Driver, Version 353.62.) - (10.18.13.5362) -- C:\WINDOWS\system32\nvwgf2umx.dll (.Intel Corporation.-.User Mode Driver for Intel(R) Graphics Technology.) - (10.18.10.4358) -- C:\WINDOWS\system32\igd10iumd64.dll (.SRS Labs, Inc..-.Audio Processing Object for Windows Vista.) - (2.3.13.0) -- C:\WINDOWS\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll (.Validity Sensors, Inc..-.Validity WBF Engine Adapter.) - (4.3.301.0) -- C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\VCSWBFENGINEADAPTER.DLL ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\...\Run]) - User: AUTORITE NT\SERVICE LOCAL OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\...\Run]) - User: AUTORITE NT\SERVICE RÉSEAU OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\...\Run]) - User: theo-HP\UpdatusUser Sidebar - (%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\...\Run]) - User: theo-HP\UpdatusUser Facebook Update - ("C:\Users\theo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo Akamai NetSession Interface - ("C:\Users\theo\AppData\Local\Akamai\netsession_win.exe" [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo FreeAC - (C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe -autorun [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo DAEMON Tools Lite Automount - ("C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo Skype - ("C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo BingSvc - (C:\Users\theo\AppData\Local\Microsoft\BingSvc\BingSvc.exe [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo Mobile Partner - (C:\Program Files (x86)\Wi-Fi Modem\Wi-Fi Modem [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo OneDrive - ("C:\Users\theo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\...\Run]) - User: theo-HP\theo SysTrayApp - (C:\Program Files\IDT\WDM\sttray64.exe [HKLM\...\Run]) - User: Public SetDefault - (C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [HKLM\...\Run]) - User: Public BCSSync - ("C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [HKLM\...\Run]) - User: Public NvBackend - ("C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [HKLM\...\Run]) - User: Public SynTPEnh - (%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [HKLM\...\Run]) - User: Public [HKU\S-1-5-18\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="C:\Users\theo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver "Akamai NetSession Interface"="C:\Users\theo\AppData\Local\Akamai\netsession_win.exe" "FreeAC"=C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe -autorun "DAEMON Tools Lite Automount"="C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun "BingSvc"=C:\Users\theo\AppData\Local\Microsoft\BingSvc\BingSvc.exe [16/05/2016 18:43:18] "Mobile Partner"=C:\Program Files (x86)\Wi-Fi Modem\Wi-Fi Modem "OneDrive"="C:\Users\theo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"=C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup "Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WAB Migrate"=%ProgramFiles%\Windows Mail\wab.exe /Upgrade [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"=C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"=C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [10/10/2013 19:44:51] "SetDefault"=C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [20/12/2011 01:34:06] "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "SynTPEnh"=%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [HKLM\Software\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "SysTrayApp"=0x040000000000000000000000 "SynTPEnh"=0x040000000000000000000000 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "USB3MON"="C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" "Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [15/09/2011 14:00:00] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [19/08/2011 17:48:44] "HP CoolSense"=C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey "RIMBBLaunchAgent.exe"=C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [27/06/2013 12:59:20] "HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [05/03/2012 15:38:38] "Magic Desktop for HP notification"="C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe" ""= "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "ADSKAppManager"="C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "Dropbox"="C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 ---------- | Startings up registry ¦ Folder ---------- | Other keys [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "InstanceID"=be335648-9a8e-42fc-becc-5e8ebce "GlassSessionId"=1 [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "ResourceTimeoutCount"=648000 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "PendingFileRenameOperations"=\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\cleanup.old \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.old [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=UsoSvc gpsvc trustedinstaller "WaitToKillServiceTimeout"=200 "SystemStartOptions"= NOEXECUTE=OPTIN "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(2) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=3 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Authentication Packages"=msv1_0 "SecureBoot"=1 "ProductType"=3 "disabledomaincreds"=0 "forceguest"=0 "restrictanonymous"=0 "restrictanonymoussam"=1 "everyoneincludesanonymous"=0 "fullprivilegeauditing"=0x00 "LsaPid"=684 "Notification Packages"=scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll "Security Packages"=kerberos msv1_0 schannel wdigest tspkg pku2u livessp ---------- | .LNK C:\Google Chrome.lnk () aWA\2���HF0 chrome.exeBヨHw��Hw�*Mchrome.exe`- C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk (shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk (shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk (shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk (shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk (/0) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk (::{7007ACC7-3202-11D1-AAD2-00805FC1270E}) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk (/name Microsoft.DeviceManager) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk (/name Microsoft.System) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk (/name Microsoft.PowerOptions) C:\Users\Administrateur\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk (/name Microsoft.ProgramsAndFeatures) C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\SendTo\Destinataire de télécopie.lnk (/SendTo) C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk (shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group2\1 - Run.lnk (shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group2\2 - Search.lnk (shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk (shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk (/0) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk (::{7007ACC7-3202-11D1-AAD2-00805FC1270E}) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk (/name Microsoft.DeviceManager) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group3\06 - System.lnk (/name Microsoft.System) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk (/name Microsoft.PowerOptions) C:\Users\Administrateur\Local Settings\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk (/name Microsoft.ProgramsAndFeatures) C:\Users\Administrateur\Menu Démarrer\Programmes\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Administrateur\Menu Démarrer\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Administrateur\SendTo\Destinataire de télécopie.lnk (/SendTo) C:\Users\Administrateur\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\Public\Desktop\AutoCAD 2015 - Français (French).lnk ( /product ACAD /language "fr-FR") C:\Users\Public\Desktop\HP+.lnk (http://redirect.hp.com/svs/rdr?bd=all&tp=dticon&locale=fr_fr&pf=cnnb&c=122&s=hp_plus&TYPE=4) C:\Users\Public\Desktop\rara Music.lnk (http://redirect.hp.com/svs/rdr?locale=fr_fr&bd=pavilion&tp=dticon&pf=cnnb&c=121&s=RaRa&TYPE=4) C:\Users\Public\Desktop\WildTangent Games App - hp.lnk ("C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe" /src desktopoem /dp hpcnb1c12) C:\Users\theo\AppData\Local\Microsoft\Windows\GameExplorer\{3266d333-42e6-4cb3-a50a-a87067dede95}\PlayTasks\0\Torchlight.lnk ("C:\Program Files (x86)\HP Games\Torchlight\torchlight-WT.exe" /launchgc /src gameexploreroem) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk (shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk (shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk (shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk (shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk (/0) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk (::{7007ACC7-3202-11D1-AAD2-00805FC1270E}) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk (/name Microsoft.DeviceManager) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk (/name Microsoft.System) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk (/name Microsoft.PowerOptions) C:\Users\theo\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk (/name Microsoft.ProgramsAndFeatures) C:\Users\theo\AppData\Local\Popcorn Time\Popcorn Time.lnk (.) C:\Users\theo\AppData\Roaming\Autodesk\AutoCAD 2015\R20.0\fra\Plotters\Assistant Ajouter un traceur.lnk (/LANGUAGE fr-FR) C:\Users\theo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Photos Snapfish.lnk (http://www.snapfish.com/hp_taskbaricon_notebook_2012_fr) C:\Users\theo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk (/prefetch:1) C:\Users\theo\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\theo\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk (/sendto:) C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\Autodesk\Installer Autodesk® AutoCAD® 2015 maintenant.lnk (/URL "http://edutrial.autodesk.com/SWDLDNET4/2015/ACD/WI/AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup.exe" /skipPI /SN 900-60361971 /PK 001G1 /akamai) C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\Popcorn Time\Popcorn Time.lnk (.) C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk\Installer Autodesk® AutoCAD® 2015 maintenant.lnk (/URL "http://edutrial.autodesk.com/SWDLDNET4/2015/ACD/WI/AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup.exe" /skipPI /SN 900-60361971 /PK 001G1 /akamai) C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time\Popcorn Time.lnk (.) C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\theo\AppData\Roaming\Microsoft\Word\Identifiant305308490887090645\Identifiant.docx.lnk (0) C:\Users\theo\Desktop\AdsFix_Donate.lnk (https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=S3AQ8V3XRWWYN) C:\Users\theo\Desktop\BlackBerry Device Manager.lnk (/RunServer) C:\Users\theo\Desktop\HP Support Assistant.lnk (/p 2) C:\Users\theo\Desktop\Installer Autodesk® AutoCAD® 2015 maintenant.lnk (/URL "http://edutrial.autodesk.com/SWDLDNET4/2015/ACD/WI/AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup.exe" /skipPI /SN 900-60361971 /PK 001G1 /akamai) C:\Users\theo\Desktop\Popcorn Time.lnk (.) C:\Users\theo\Local Settings\Microsoft\Windows\GameExplorer\{3266d333-42e6-4cb3-a50a-a87067dede95}\PlayTasks\0\Torchlight.lnk ("C:\Program Files (x86)\HP Games\Torchlight\torchlight-WT.exe" /launchgc /src gameexploreroem) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk (shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group2\1 - Run.lnk (shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group2\2 - Search.lnk (shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk (shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk (/0) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk (::{7007ACC7-3202-11D1-AAD2-00805FC1270E}) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk (/name Microsoft.DeviceManager) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group3\06 - System.lnk (/name Microsoft.System) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk (/name Microsoft.PowerOptions) C:\Users\theo\Local Settings\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk (/name Microsoft.ProgramsAndFeatures) C:\Users\theo\Local Settings\Popcorn Time\Popcorn Time.lnk (.) C:\Users\theo\Menu Démarrer\Programmes\Autodesk\Installer Autodesk® AutoCAD® 2015 maintenant.lnk (/URL "http://edutrial.autodesk.com/SWDLDNET4/2015/ACD/WI/AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup.exe" /skipPI /SN 900-60361971 /PK 001G1 /akamai) C:\Users\theo\Menu Démarrer\Programmes\Popcorn Time\Popcorn Time.lnk (.) C:\Users\theo\Menu Démarrer\Programmes\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\theo\Menu Démarrer\Programs\Autodesk\Installer Autodesk® AutoCAD® 2015 maintenant.lnk (/URL "http://edutrial.autodesk.com/SWDLDNET4/2015/ACD/WI/AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup.exe" /skipPI /SN 900-60361971 /PK 001G1 /akamai) C:\Users\theo\Menu Démarrer\Programs\Popcorn Time\Popcorn Time.lnk (.) C:\Users\theo\Menu Démarrer\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\theo\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\theo\SendTo\Skype.lnk (/sendto:) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk (shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk (shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk (shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk (shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk (/0) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk (::{7007ACC7-3202-11D1-AAD2-00805FC1270E}) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk (/name Microsoft.DeviceManager) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk (/name Microsoft.System) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk (/name Microsoft.PowerOptions) C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk (/name Microsoft.ProgramsAndFeatures) C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk (shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group2\1 - Run.lnk (shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group2\2 - Search.lnk (shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk (shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk (/0) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk (::{7007ACC7-3202-11D1-AAD2-00805FC1270E}) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk (/name Microsoft.DeviceManager) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group3\06 - System.lnk (/name Microsoft.System) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk (/name Microsoft.PowerOptions) C:\Users\UpdatusUser\Local Settings\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk (/name Microsoft.ProgramsAndFeatures) C:\Users\UpdatusUser\Menu Démarrer\Programmes\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\UpdatusUser\Menu Démarrer\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\UpdatusUser\SendTo\Fax Recipient.lnk (/SendTo) C:\ProgramData\Bureau\AutoCAD 2015 - Français (French).lnk ( /product ACAD /language "fr-FR") C:\ProgramData\Bureau\HP+.lnk (http://redirect.hp.com/svs/rdr?bd=all&tp=dticon&locale=fr_fr&pf=cnnb&c=122&s=hp_plus&TYPE=4) C:\ProgramData\Bureau\rara Music.lnk (http://redirect.hp.com/svs/rdr?locale=fr_fr&bd=pavilion&tp=dticon&pf=cnnb&c=121&s=RaRa&TYPE=4) C:\ProgramData\Bureau\WildTangent Games App - hp.lnk ("C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe" /src desktopoem /dp hpcnb1c12) C:\ProgramData\Hewlett-Packard\HP Setup\launchreg.lnk (MODE=REGISTRATION URL=ReminderPage.html) C:\ProgramData\Hewlett-Packard\HP Setup\NativeClient\launchreg.lnk (MODE=REGISTRATION) C:\ProgramData\Menu Démarrer\Programmes\Search.lnk (-sta {C90FB8CA-3295-4462-A721-2935E83694BA}) C:\ProgramData\Menu Démarrer\Programmes\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Menu Démarrer\Programmes\Accessibility\Speech Recognition.lnk (-SpeechUX) C:\ProgramData\Menu Démarrer\Programmes\Accessories\Mobility Center.lnk (/open) C:\ProgramData\Menu Démarrer\Programmes\Accessories\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Menu Démarrer\Programmes\Administrative Tools\Computer Management.lnk (/s) C:\ProgramData\Menu Démarrer\Programmes\Administrative Tools\Event Viewer.lnk (/s) C:\ProgramData\Menu Démarrer\Programmes\Administrative Tools\Performance Monitor.lnk (/s) C:\ProgramData\Menu Démarrer\Programmes\Administrative Tools\Resource Monitor.lnk (/res) C:\ProgramData\Menu Démarrer\Programmes\Administrative Tools\Task Scheduler.lnk (/s) C:\ProgramData\Menu Démarrer\Programmes\Autodesk\AutoCAD 2015 - Français (French)\AutoCAD 2015 - Français (French).lnk ( /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programmes\Autodesk\AutoCAD 2015 - Français (French)\Restaurer les paramètres par défaut.lnk (/reset /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programmes\Autodesk\AutoCAD 2015 - Français (French)\Utilitaire de transfert de licence - AutoCAD 2015.lnk (001G1 2015.0.0.F -d SA -l fr-FR) C:\ProgramData\Menu Démarrer\Programmes\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Exporter les paramètres d'AutoCAD 2015.lnk (/e /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programmes\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Importer les paramètres d'AutoCAD 2015.lnk (/i /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programmes\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Migrer à partir d'une version précédente.lnk (/product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programmes\BlackBerry\BlackBerry Device Manager.lnk (/RunServer) C:\ProgramData\Menu Démarrer\Programmes\Communication and Chat\getonline.lnk (MODE=GETONLINE URL=ReminderPage.html) C:\ProgramData\Menu Démarrer\Programmes\Dropbox\Dropbox.lnk (/home) C:\ProgramData\Menu Démarrer\Programmes\Games\Aller aux jeux familiaux.lnk (/id=d58eecb0-0816-11de-8c30-0800200c9a66 /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Aller aux jeux généraux.lnk (/id=000d96f5-8034-4b74-a429-b6f0b04c75f4 /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Aller aux jeux Multi-joueurs.lnk (/id=c3c636e0-1b04-11de-8c30-0800200c9a66 /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Aller aux jeux pour enfants.lnk (/id=3eda1e54-8889-41f5-a649-5a306789b7ef /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Bejeweled 3.lnk ("C:\Program Files (x86)\HP Games\Bejeweled 3\bejeweled3-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Chuzzle Deluxe.lnk ("C:\Program Files (x86)\HP Games\Chuzzle Deluxe\Chuzzle Deluxe-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Farm Frenzy.lnk ("C:\Program Files (x86)\HP Games\Farm Frenzy\Farm Frenzy-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\FATE.lnk ("C:\Program Files (x86)\HP Games\FATE\Fate-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Mahjongg Artifacts.lnk ("C:\Program Files (x86)\HP Games\Mahjongg Artifacts\Mahjongg Artifacts-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Plants vs. Zombies - Game of the Year.lnk ("C:\Program Files (x86)\HP Games\Plants vs Zombies - Game of the Year\plantsvszombies-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Plus de jeux de HP Games.lnk (/id=977b5905-4d14-47f1-bbbf-7b92f596695d /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\Polar Bowler.lnk ("C:\Program Files (x86)\HP Games\Polar Bowler\Polar-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\Games\WildTangent Games App - hp.lnk ("C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe" /src gamesmenuoem /dp hpcnb1c12) C:\ProgramData\Menu Démarrer\Programmes\Games\Zuma's Revenge.lnk ("C:\Program Files (x86)\HP Games\Zumas Revenge\zumasrevenge-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programmes\HP Help and Support\HP Support Assistant.lnk (/p 1) C:\ProgramData\Menu Démarrer\Programmes\Java\A propos de Java.lnk (-tab about) C:\ProgramData\Menu Démarrer\Programmes\Java\Rechercher les mises à jour.lnk (-tab update) C:\ProgramData\Menu Démarrer\Programmes\Microsoft Office\Microsoft InfoPath Designer 2010.lnk ( /design) C:\ProgramData\Menu Démarrer\Programmes\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Project Server 2010 Accounts.lnk (-ProjectProfiles) C:\ProgramData\Menu Démarrer\Programmes\Music, Photos and Videos\Photos Snapfish.lnk (http://www.snapfish.com/hp_taskbaricon_notebook_2012_fr) C:\ProgramData\Menu Démarrer\Programmes\Music, Photos and Videos\rara Music.lnk (http://redirect.hp.com/svs/rdr?locale=fr_fr&bd=pavilion&tp=onlinesvs&pf=cnnb&c=121&s=RaRa&TYPE=4) C:\ProgramData\Menu Démarrer\Programmes\Security and Protection\HP Recovery Manager\HP Recovery Media Creation.lnk (\CRM) C:\ProgramData\Menu Démarrer\Programmes\Shopping and Services\eBay.lnk (http://redirect.hp.com/svs/rdr?TYPE=4&tp=onlinesvs&s=ebay&pf=cnnb&locale=fr_fr&bd=all&c=122) C:\ProgramData\Menu Démarrer\Programmes\System Tools\Default Programs.lnk (/name Microsoft.DefaultPrograms) C:\ProgramData\Menu Démarrer\Programmes\System Tools\Task Manager.lnk (/7) C:\ProgramData\Menu Démarrer\Programmes\VideoLAN\Reset VLC media player preferences and cache files.lnk (--reset-config --reset-plugins-cache vlc://quit) C:\ProgramData\Menu Démarrer\Programmes\VideoLAN\VLC media player skinned.lnk (-Iskins) C:\ProgramData\Menu Démarrer\Programs\Search.lnk (-sta {C90FB8CA-3295-4462-A721-2935E83694BA}) C:\ProgramData\Menu Démarrer\Programs\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Menu Démarrer\Programs\Accessibility\Speech Recognition.lnk (-SpeechUX) C:\ProgramData\Menu Démarrer\Programs\Accessories\Mobility Center.lnk (/open) C:\ProgramData\Menu Démarrer\Programs\Accessories\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Menu Démarrer\Programs\Administrative Tools\Computer Management.lnk (/s) C:\ProgramData\Menu Démarrer\Programs\Administrative Tools\Event Viewer.lnk (/s) C:\ProgramData\Menu Démarrer\Programs\Administrative Tools\Performance Monitor.lnk (/s) C:\ProgramData\Menu Démarrer\Programs\Administrative Tools\Resource Monitor.lnk (/res) C:\ProgramData\Menu Démarrer\Programs\Administrative Tools\Task Scheduler.lnk (/s) C:\ProgramData\Menu Démarrer\Programs\Autodesk\AutoCAD 2015 - Français (French)\AutoCAD 2015 - Français (French).lnk ( /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programs\Autodesk\AutoCAD 2015 - Français (French)\Restaurer les paramètres par défaut.lnk (/reset /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programs\Autodesk\AutoCAD 2015 - Français (French)\Utilitaire de transfert de licence - AutoCAD 2015.lnk (001G1 2015.0.0.F -d SA -l fr-FR) C:\ProgramData\Menu Démarrer\Programs\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Exporter les paramètres d'AutoCAD 2015.lnk (/e /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programs\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Importer les paramètres d'AutoCAD 2015.lnk (/i /product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programs\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Migrer à partir d'une version précédente.lnk (/product ACAD /language "fr-FR") C:\ProgramData\Menu Démarrer\Programs\BlackBerry\BlackBerry Device Manager.lnk (/RunServer) C:\ProgramData\Menu Démarrer\Programs\Communication and Chat\getonline.lnk (MODE=GETONLINE URL=ReminderPage.html) C:\ProgramData\Menu Démarrer\Programs\Dropbox\Dropbox.lnk (/home) C:\ProgramData\Menu Démarrer\Programs\Games\Aller aux jeux familiaux.lnk (/id=d58eecb0-0816-11de-8c30-0800200c9a66 /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Aller aux jeux généraux.lnk (/id=000d96f5-8034-4b74-a429-b6f0b04c75f4 /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Aller aux jeux Multi-joueurs.lnk (/id=c3c636e0-1b04-11de-8c30-0800200c9a66 /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Aller aux jeux pour enfants.lnk (/id=3eda1e54-8889-41f5-a649-5a306789b7ef /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Bejeweled 3.lnk ("C:\Program Files (x86)\HP Games\Bejeweled 3\bejeweled3-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Chuzzle Deluxe.lnk ("C:\Program Files (x86)\HP Games\Chuzzle Deluxe\Chuzzle Deluxe-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Farm Frenzy.lnk ("C:\Program Files (x86)\HP Games\Farm Frenzy\Farm Frenzy-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\FATE.lnk ("C:\Program Files (x86)\HP Games\FATE\Fate-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Mahjongg Artifacts.lnk ("C:\Program Files (x86)\HP Games\Mahjongg Artifacts\Mahjongg Artifacts-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Plants vs. Zombies - Game of the Year.lnk ("C:\Program Files (x86)\HP Games\Plants vs Zombies - Game of the Year\plantsvszombies-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Plus de jeux de HP Games.lnk (/id=977b5905-4d14-47f1-bbbf-7b92f596695d /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\Polar Bowler.lnk ("C:\Program Files (x86)\HP Games\Polar Bowler\Polar-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\Games\WildTangent Games App - hp.lnk ("C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe" /src gamesmenuoem /dp hpcnb1c12) C:\ProgramData\Menu Démarrer\Programs\Games\Zuma's Revenge.lnk ("C:\Program Files (x86)\HP Games\Zumas Revenge\zumasrevenge-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Menu Démarrer\Programs\HP Help and Support\HP Support Assistant.lnk (/p 1) C:\ProgramData\Menu Démarrer\Programs\Java\A propos de Java.lnk (-tab about) C:\ProgramData\Menu Démarrer\Programs\Java\Rechercher les mises à jour.lnk (-tab update) C:\ProgramData\Menu Démarrer\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk ( /design) C:\ProgramData\Menu Démarrer\Programs\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Project Server 2010 Accounts.lnk (-ProjectProfiles) C:\ProgramData\Menu Démarrer\Programs\Music, Photos and Videos\Photos Snapfish.lnk (http://www.snapfish.com/hp_taskbaricon_notebook_2012_fr) C:\ProgramData\Menu Démarrer\Programs\Music, Photos and Videos\rara Music.lnk (http://redirect.hp.com/svs/rdr?locale=fr_fr&bd=pavilion&tp=onlinesvs&pf=cnnb&c=121&s=RaRa&TYPE=4) C:\ProgramData\Menu Démarrer\Programs\Security and Protection\HP Recovery Manager\HP Recovery Media Creation.lnk (\CRM) C:\ProgramData\Menu Démarrer\Programs\Shopping and Services\eBay.lnk (http://redirect.hp.com/svs/rdr?TYPE=4&tp=onlinesvs&s=ebay&pf=cnnb&locale=fr_fr&bd=all&c=122) C:\ProgramData\Menu Démarrer\Programs\System Tools\Default Programs.lnk (/name Microsoft.DefaultPrograms) C:\ProgramData\Menu Démarrer\Programs\System Tools\Task Manager.lnk (/7) C:\ProgramData\Menu Démarrer\Programs\VideoLAN\Reset VLC media player preferences and cache files.lnk (--reset-config --reset-plugins-cache vlc://quit) C:\ProgramData\Menu Démarrer\Programs\VideoLAN\VLC media player skinned.lnk (-Iskins) C:\ProgramData\Microsoft\Windows\GameExplorer\{000d96f5-8034-4b74-a429-b6f0b04c75f4}\PlayTasks\0\provider.lnk (/id=000d96f5-8034-4b74-a429-b6f0b04c75f4 /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{0334682e-f04f-4f03-8b56-d518fdcb7661}\PlayTasks\0\Zuma's Revenge.lnk ("C:\Program Files (x86)\HP Games\Zumas Revenge\zumasrevenge-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{227680FF-28CE-48EE-AADF-8D009B2813A9}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Dark Orbit\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{22A975C0-D22F-482C-A387-637EEC15870F}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - World of Warcraft\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{25bcd516-b0c6-4f76-98b1-b22b35615883}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Salon Street\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{26352374-af55-4b53-b07b-6b0288ed97df}\PlayTasks\0\provider.lnk (/id=26352374-af55-4b53-b07b-6b0288ed97df /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{29556c6b-abba-4173-8102-4642846d5b4f}\PlayTasks\0\Wedding Dash.lnk ("C:\Program Files (x86)\HP Games\Wedding Dash\Wedding Dash-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{2D080D0F-37EF-433E-90F1-CE36EB0205F6}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Seafight\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{3266d333-42e6-4cb3-a50a-a87067dede95}\PlayTasks\0\Torchlight.lnk ("C:\Program Files (x86)\HP Games\Torchlight\torchlight-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{3eda1e54-8889-41f5-a649-5a306789b7ef}\PlayTasks\0\provider.lnk (/id=3eda1e54-8889-41f5-a649-5a306789b7ef /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{471351f0-4e8a-47bf-a6b3-3de3c99ae340}\PlayTasks\0\Jewel Match 3.lnk ("C:\Program Files (x86)\HP Games\Jewel Match 3\jewelmatch3-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{49bddb7b-1943-4156-a1a3-d00b5789d29c}\PlayTasks\0\Fishdom (TM) 2.lnk ("C:\Program Files (x86)\HP Games\Fishdom (TM) 2\Fishdom2-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{4e625a41-ccdd-4571-bf53-12288f43c73e}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Build-A-Lot Metropolis\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{502CF397-846F-459B-AB59-9826E34B7ECE}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Club Penguin\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{5ae0d760-ddcf-4247-85df-eacefd518e86}\PlayTasks\0\Plants vs. Zombies - Game of the Year.lnk ("C:\Program Files (x86)\HP Games\Plants vs Zombies - Game of the Year\plantsvszombies-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{5d1b040e-e496-4a7b-ae4e-9b17eb28a7e2}\PlayTasks\0\Final Drive Fury.lnk ("C:\Program Files (x86)\HP Games\Final Drive Fury\Racing-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{5f828e7a-066c-4d4a-ada6-8b2494b859db}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Polar Bowler Strike!\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{677247CF-4120-46DC-A3DF-71588CC9CB7E}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Shaiya\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{6BDF3201-10E6-46ED-9A87-7FD18C418CFD}\PlayTasks\0\FATE.lnk ("C:\Program Files (x86)\HP Games\FATE\Fate-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{6E7DD52D-205E-4D6D-AF6A-0C34703DFA61}\PlayTasks\0\Chuzzle Deluxe.lnk ("C:\Program Files (x86)\HP Games\Chuzzle Deluxe\Chuzzle Deluxe-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{82cff345-989a-4f4d-94de-db6de238eb5f}\PlayTasks\0\Mystery of Mortlake Mansion.lnk ("C:\Program Files (x86)\HP Games\Mystery of Mortlake Mansion\mysteryofmortlakemansion-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{8d1038f5-9e51-4c97-b363-e0d7a6725e9a}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Organized Crime\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{951226E3-26FC-40BC-8085-3677B1128F59}\PlayTasks\0\Polar Bowler.lnk ("C:\Program Files (x86)\HP Games\Polar Bowler\Polar-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{977b5905-4d14-47f1-bbbf-7b92f596695d}\PlayTasks\0\provider.lnk (/id=977b5905-4d14-47f1-bbbf-7b92f596695d /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{992f66c3-df2c-43d7-96c0-67d0f46b56f8}\PlayTasks\0\Jewel Quest II.lnk ("C:\Program Files (x86)\HP Games\Jewel Quest II\Jewel Quest II-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{A4B598D2-9BFF-456F-A667-D3B8A0849286}\PlayTasks\0\Insaniquarium Deluxe.lnk ("C:\Program Files (x86)\HP Games\Insaniquarium Deluxe\Insaniquarium Deluxe-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{af7a9bad-f0f1-4fe3-87a1-676657bed867}\PlayTasks\0\Cake Mania.lnk ("C:\Program Files (x86)\HP Games\Cake Mania\Cake Mania-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{b34a9d7b-bf0b-479e-bf97-82986009f633}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Odd Manor\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{b87f2bde-5d44-4e86-bd37-a71616b35ea6}\PlayTasks\0\Bejeweled 3.lnk ("C:\Program Files (x86)\HP Games\Bejeweled 3\bejeweled3-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{bba80652-58a7-4320-a64f-475fdbda4363}\PlayTasks\0\Virtual Families.lnk ("C:\Program Files (x86)\HP Games\Virtual Families\virtualfamilies-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{bf3485ba-306e-4774-bf8e-403bf8535439}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Battlestar Galactica Online\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{c3c636e0-1b04-11de-8c30-0800200c9a66}\PlayTasks\0\provider.lnk (/id=c3c636e0-1b04-11de-8c30-0800200c9a66 /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{c8c605c6-cd2a-4242-9b27-b8b27bdf6684}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Gun Bros\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{c8f4bd34-d7cd-40fd-a437-35cb021410e8}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Penguin World\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{ca4ed303-5737-4b13-9aff-3f92aa8e364d}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - It Girl!\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{d0dc6569-7b4e-4707-b589-ea594b6d8d31}\PlayTasks\0\Mahjongg Artifacts.lnk ("C:\Program Files (x86)\HP Games\Mahjongg Artifacts\Mahjongg Artifacts-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{d58eecb0-0816-11de-8c30-0800200c9a66}\PlayTasks\0\provider.lnk (/id=d58eecb0-0816-11de-8c30-0800200c9a66 /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{d8addf57-a369-460f-8a5c-2f240d8e33b7}\PlayTasks\0\Virtual Villagers 4 - The Tree of Life.lnk ("C:\Program Files (x86)\HP Games\Virtual Villagers 4 - The Tree of Life\virtualvillagers4thetreeoflife-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{e923cba5-ed90-4670-bf07-064d14a1cd55}\PlayTasks\0\web.lnk ("C:\Program Files (x86)\HP Games\Web Link - Mahjongg Dark Dimensions\launcher.exe" /src gameexploreroemoem) C:\ProgramData\Microsoft\Windows\GameExplorer\{ed7e4b33-7f4e-48c9-947d-dfff27b576b6}\PlayTasks\0\Cradle of Rome 2.lnk ("C:\Program Files (x86)\HP Games\Cradle of Rome 2\cradleofrome2-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{f10f89f1-9c08-4d85-9169-a28ba1fc6ab0}\PlayTasks\0\Farm Frenzy.lnk ("C:\Program Files (x86)\HP Games\Farm Frenzy\Farm Frenzy-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{fb65380e-3812-44f7-bbec-128e82369adf}\PlayTasks\0\Jewel Quest Solitaire 2.lnk ("C:\Program Files (x86)\HP Games\Jewel Quest Solitaire 2\jewelquestsolitaire2-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{fcedd1a0-cbd2-4697-8c5d-107bfeb05ff5}\PlayTasks\0\Farmscapes.lnk ("C:\Program Files (x86)\HP Games\Farmscapes\farmscapes-WT.exe" /launchgc /src gameexploreroem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk (-sta {C90FB8CA-3295-4462-A721-2935E83694BA}) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk (-SpeechUX) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk (/open) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk (/res) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2015 - Français (French)\AutoCAD 2015 - Français (French).lnk ( /product ACAD /language "fr-FR") C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2015 - Français (French)\Restaurer les paramètres par défaut.lnk (/reset /product ACAD /language "fr-FR") C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2015 - Français (French)\Utilitaire de transfert de licence - AutoCAD 2015.lnk (001G1 2015.0.0.F -d SA -l fr-FR) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Exporter les paramètres d'AutoCAD 2015.lnk (/e /product ACAD /language "fr-FR") C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Importer les paramètres d'AutoCAD 2015.lnk (/i /product ACAD /language "fr-FR") C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2015 - Français (French)\Migrer les paramètres personnalisés\Migrer à partir d'une version précédente.lnk (/product ACAD /language "fr-FR") C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry\BlackBerry Device Manager.lnk (/RunServer) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat\getonline.lnk (MODE=GETONLINE URL=ReminderPage.html) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk (/home) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Aller aux jeux familiaux.lnk (/id=d58eecb0-0816-11de-8c30-0800200c9a66 /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Aller aux jeux généraux.lnk (/id=000d96f5-8034-4b74-a429-b6f0b04c75f4 /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Aller aux jeux Multi-joueurs.lnk (/id=c3c636e0-1b04-11de-8c30-0800200c9a66 /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Aller aux jeux pour enfants.lnk (/id=3eda1e54-8889-41f5-a649-5a306789b7ef /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Bejeweled 3.lnk ("C:\Program Files (x86)\HP Games\Bejeweled 3\bejeweled3-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chuzzle Deluxe.lnk ("C:\Program Files (x86)\HP Games\Chuzzle Deluxe\Chuzzle Deluxe-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Farm Frenzy.lnk ("C:\Program Files (x86)\HP Games\Farm Frenzy\Farm Frenzy-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\FATE.lnk ("C:\Program Files (x86)\HP Games\FATE\Fate-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjongg Artifacts.lnk ("C:\Program Files (x86)\HP Games\Mahjongg Artifacts\Mahjongg Artifacts-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Plants vs. Zombies - Game of the Year.lnk ("C:\Program Files (x86)\HP Games\Plants vs Zombies - Game of the Year\plantsvszombies-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Plus de jeux de HP Games.lnk (/id=977b5905-4d14-47f1-bbbf-7b92f596695d /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Polar Bowler.lnk ("C:\Program Files (x86)\HP Games\Polar Bowler\Polar-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\WildTangent Games App - hp.lnk ("C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe" /src gamesmenuoem /dp hpcnb1c12) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Zuma's Revenge.lnk ("C:\Program Files (x86)\HP Games\Zumas Revenge\zumasrevenge-WT.exe" /launchgc /src gamesmenuoem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP Support Assistant.lnk (/p 1) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\A propos de Java.lnk (-tab about) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Rechercher les mises à jour.lnk (-tab update) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk ( /design) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Project Server 2010 Accounts.lnk (-ProjectProfiles) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos\Photos Snapfish.lnk (http://www.snapfish.com/hp_taskbaricon_notebook_2012_fr) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos\rara Music.lnk (http://redirect.hp.com/svs/rdr?locale=fr_fr&bd=pavilion&tp=onlinesvs&pf=cnnb&c=121&s=RaRa&TYPE=4) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection\HP Recovery Manager\HP Recovery Media Creation.lnk (\CRM) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services\eBay.lnk (http://redirect.hp.com/svs/rdr?TYPE=4&tp=onlinesvs&s=ebay&pf=cnnb&locale=fr_fr&bd=all&c=122) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk (/name Microsoft.DefaultPrograms) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk (/7) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Reset VLC media player preferences and cache files.lnk (--reset-config --reset-plugins-cache vlc://quit) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk (-Iskins) ---------- | AppCertDlls | AppInit_DLLs [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_Dlls"=C:\Windows\system32\nvinitx.dll, C:\WINDOWS\system32\nvinitx.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_Dlls"=C:\WINDOWS\SysWOW64\nvinit.dll ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-18\Control Panel\Desktop] "DragFullWindows"=1 "FontSmoothing"=2 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "UserPreferencesMask"=0x9E3E038012000000 "LockScreenAutoLockActive"=0 [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer] "TelemetrySalt"=0 "ShellState"=0x240000003028000000000000000000000000000001000000130000000000000062000000 "SlowContextMenuEntries"=0x5D54A9A2C2A0B4429708A0B2BADD77C8330200004E3AAA90BA1C3342B8BB535773D484491D0300003673466C8182604E8204430CED96822D7A030000BD0E0C47735D584D9CEDE91E22E232826B030000B083204722C5CF11876300608CC02F2477010000 [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "EnableStartMenu"=0 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=0 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "ScreenSaveActive"=1 "UserPreferencesMask"=0x9E3E078012000000 ""= "Wallpaper"=C:\Users\theo\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg [05/05/2015 21:21:43] "Win8DpiScaling"=0 "DpiScalingVer"=4096 "MaxVirtualDesktopDimension"=1600 "MaxMonitorDimension"=1600 "TranscodedImageCount"=2 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC3010089840F0040060000840300007B82EBF45787D00143003A005C00550073006500720073005C007400680065006F005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00570069006E0064006F007700730020004C006900760065002000500068006F0074006F002000470061006C006C006500720079005C00570069006E0064006F007700730020004C006900760065002000500068006F0074006F002000470061006C006C006500720079002000570061006C006C00700061007000650072002E006A007000670000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "PreferredUILanguages"=fr-FR "WaitToKillAppTimeout"=200 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] ""= [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{59031A47-3F72-44A7-89C5-5595FE6B30EE}"=1 "{E31EA727-12ED-4702-820C-4B6445F28E1A}"=1 "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{59031A47-3F72-44A7-89C5-5595FE6B30EE}"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "ShellState"=0x240000003A28000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "TelemetrySalt"=7 "SlowContextMenuEntries"=0x3673466C8182604E8204430CED96822DA93200006024B221EA3A6910A2DC08002B30309D8F170000CEC429A936FD7042B4F534ECAC5BD63CF31600000114020000000000C0000000000000468E1F0000B083204722C5CF11876300608CC02F249B150000 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "LastClockSize"=0x270000000F000000460000000F000000410000000F000000 "GlobalAssocChangedCounter"=133 "AppReadinessLogonComplete"=1 "FirstRunTelemetryComplete"=1 "link"=0x15000000 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=2 "ShowCompColor"=1 "HideFileExt"=0 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "SuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StartMenuInit"=11 "ShowSuperHidden"=0 ""=0 "ShowStatusBar"=1 "StoreAppsOnTaskbar"=1 "EnableStartMenu"=1 "ReindexedProfile"=1 "ShowTaskViewButton"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery] "MRUListEx"=0x070000000800000006000000050000000400000003000000020000000100000000000000FFFFFFFF "0"=0x7500730062000000 "1"=0x73006B007900700061000000 "2"=0x73006B007900700065000000 "3"=0x630061006C00630075006C006100740072006900630065000000 "4"=0x43006F0072006200650069006C006C0065000000 "5"=0x61006B00610069006D000000 "6"=0x61006B0061006D00610069000000 "8"=0x7000610069000000 "7"=0x7000610069006E0074000000 [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "ScreenSaveActive"=1 "Wallpaper"= [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 [HKU\S-1-5-20\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "ScreenSaveActive"=1 [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 [HKU\S-1-5-19\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "ScreenSaveActive"=1 [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=0 "SoftwareSASGeneration"=1 "EnableSecureUIAPath"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 "EnableShellExecuteHooks"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=4 "SmartScreenEnabled"=RequireAdmin [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=0 "SoftwareSASGeneration"=1 "EnableSecureUIAPath"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 "EnableShellExecuteHooks"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=61 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=10586 "FirstLogon"=0 "PUUActive"=0x53A5712D0400000003001200BC2F00008732000096670100D0000000170019006FAB8F9F674F0800817A0100BD130000041000000A0400000000000033790100005900002F0000003103FF1123E4D101 "ParseAutoexec"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=10586 [HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders [HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "Userinit"=C:\Windows\system32\userinit.exe, "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "scremoveoption"=0 "ShutdownStartTime"=131135017657893406 "UserSessionShutdownStopTime"=131135017856986714 "ShutdownFlags"=7 "AutoAdminLogon"=0 "DefaultUserName"=theo "ShutdownWithoutLogon"=0 "DisableCad"=1 "EnableFirstLogonAnimation"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "EnableSIHostIntegration"=1 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "Userinit"=C:\WINDOWS\system32\userinit.exe, ---------- | Associations [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Classes\.scr] ""=AutoCADScriptFile [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Clients\StartMenuInternet\FirefoxHTML\Shell\open\Command] ""=C:\Program Files (x86)\Firefox\firefox.exe [30/06/2016 20:13:59] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Clients\StartMenuInternet\FirefoxHTML\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Firefox\firefox.exe" "-ReinstallCommand" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Internet Explorer\iexplore.exe" [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command] ""="C:\Program Files (x86)\AVAST Software\SZBrowser\Launcher.exe" [HKLM\Software\Clients\StartMenuInternet\SafeZoneStable\InstallInfo] "ReinstallCommand"="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Internet Explorer\iexplore.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command] ""="C:\Program Files (x86)\AVAST Software\SZBrowser\Launcher.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\InstallInfo] "ReinstallCommand"="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser ---------- | AppcompatFlags [HKU\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Windows\Temp\{B31770D1-C43D-4DDE-A043-EB054F0C9458}\InstallFlashPlayer.exe"=0x5341435001000000000000000700000028000000C0EC460016A5470001000000000000000000000A0021000059193B14E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000040120000000000000100000001000000 "C:\Users\theo\AppData\Local\Temp\ist17D0.tmp\tools\fflike.exe"=0x534143500100000000000000070000002800000080F30800AE9709000100000000000000000001060001000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000BE0A0000000000000100000001000000 "C:\Windows\SysWOW64\Macromed\Temp\{53D78FD8-B22F-4411-B3E8-4869E5F6AF4C}\InstallFlashPlayer.exe"=0x5341435001000000000000000700000028000000C0522A00A23E2B0001000000000000000000000A0021000059193B14E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000005B250000000000000100000001000000 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Program Files (x86)\Hewlett-Packard\HP Setup\NativeClient\hptcs.exe"=1 "C:\Users\theo\Pas important\Downloads\710_b042_multilanguage.exe"=1 "C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe"=1 "C:\Users\theo\Pas important\Downloads\Windows8FirewallControlPlus-Setup.exe"=1 "C:\swsetup\sp57966\setup.exe"=1 "C:\Users\theo\Pas important\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_fr.exe"=1 "C:\Users\theo\Pas important\Downloads\gedit-setup-2.30.1-1.exe"=1 "C:\Users\theo\Pas important\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_fr(1).exe"=1 "C:\Program Files (x86)\HP Games\onplay\onplay.exe"=512 "SIGN.MEDIA=3ED784F1 TGE.EXE"=1 "C:\Users\theo\Pas important\Downloads\jxpiinstall(2).exe"=1 "C:\Users\theo\Pas important\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe"=1 "C:\Users\theo\Pas important\Downloads\Firefox Setup 29.0.1.exe"=1 "C:\Users\theo\Pas important\Downloads\Firefox Setup 29.0.1 (1).exe"=1 "C:\Users\theo\Pas important\Downloads\SkypeSetup.exe"=1 "C:\Users\theo\Pas important\Downloads\Install_DetMinero_v1.2.exe"=1 "C:\DETMINERO\unins000.exe"=1 "C:\Program Files (x86)\OpenOffice 4\program\soffice.exe"=512 "C:\Users\theo\Pas important\Downloads\AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup_webinstall.exe"=1 "C:\Users\theo\Pas important\Downloads\AutoCAD_2015_French_Win_32-64bit_R1_wi_fr-FR_Setup_webinstall (1).exe"=1 "C:\Users\theo\Pas important\Downloads\AutoCAD_2016_French_Win_32_64bit_wi_fr-FR_Setup.exe"=1 "C:\Program Files (x86)\gedit\unins000.exe"=1 "C:\Users\theo\Desktop\mbam-setup-2.2.0.1024.exe"=1 "C:\Users\theo\Pas important\Downloads\JavaSetup8u60.exe"=1 "C:\Users\theo\Pas important\Downloads\JavaSetup8u60 (1).exe"=1 "C:\Users\theo\Pas important\Downloads\SumatraPDF-3.0-install.exe"=1 "C:\Users\theo\Cycle Ingé\Project 32bit\setup.exe"=1 "SIGN.MEDIA=8705FBE Doc sup\languagepack2010sp1-kb2460043-x86-fullfile-fr-fr.exe"=1 "C:\Users\theo\Pas important\Downloads\ccsetup511.exe"=1 "C:\Users\theo\Pas important\Downloads\DropboxInstaller.exe"=1 "C:\Users\theo\Pas important\Downloads\FreeAlarmClockSetup.exe"=1 "C:\Users\theo\Pas important\Downloads\DTLiteInstaller.exe"=1 "SIGN.MEDIA=176B9722 setup.exe"=1 "C:\Program Files (x86)\Parametres SFR 3G\AutoRun\AutoRunSetup.exe"=1 "SIGN.MEDIA=7056BBA8 csetup.exe"=1 "C:\Windows\uncsetup.exe"=33 "C:\Users\theo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MB7DEIDK\Firefox Setup Stub 46.0.1.exe"=1 "C:\Users\theo\Pas important\Downloads\HP-CNB.3.5.5822.22213__YUC120820-01_Normal.exe"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Users\theo\AppData\Local\Temp\RarSFX0\installer_msi_win.msi"=0x534143500100000000000000070000002800000000E400006BAB01000100000000000000000001050010000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000C4510100000000003200000032000000 "C:\Program Files\AVAST Software\Avast\avastui.exe"=0x534143500100000000000000070000002800000050405D00A8FE5D0001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000897CB214000000000500000005000000 "C:\Program Files (x86)\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000C8FB050036C5060001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\theo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C03802000BA5020001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\theo\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000C8F0890013408A0001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\theo\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8BA020001D3020001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\theo\AppData\Local\Microsoft\BingSvc\BSvcProcessor.exe"=0x534143500100000000000000070000002800000098101100C837110001000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000005BC90000000000005F0400005F040000 "C:\Program Files (x86)\HP SimplePass\DownloadAD.exe"=0x534143500100000000000000070000002800000028E7030018000400010000000000000000000206F122000019B4C529E312D101000000000000000002000000280000000000000000000000001000000000000000000000000000006A320000000000000500000005000000 "C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe"=0x534143500100000000000000070000002800000000F000006C2401000100000000000000000000067122000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000D6430200000000000200000002000000 "C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"=0x5341435001000000000000000700000028000000B85603008D7803000100000000000000000003060001000059193B14E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000F699411E000000001100000011000000 "C:\Users\theo\Pas important\Downloads\UsbFix_2016_8.248.exe"=0x53414350010000000000000007000000280000002CAD2F00000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000010980200000000000100000001000000 "C:\UsbFix\UsbFix.exe"=0x534143500100000000000000070000002800000000101C0066881C0001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000DC231200000000000400000004000000 "C:\Users\theo\Pas important\Downloads\SkypeSetup.exe"=0x5341435001000000000000000700000028000000689A190024441A000100000000000000000002060001000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000008930000000000000100000001000000 "C:\Program Files (x86)\WinZipper\winzipersvc.exe"=0x5341435001000000000000000700000028000000786A11004497110001000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000008F170000000000000100000001000000 "C:\Program Files (x86)\WinZipper\winziper.exe"=0x534143500100000000000000070000002800000078BE15003FEC150001000000000000000000000A7122000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000FA000000000000000100000001000000 "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe"=0x5341435001000000000000000700000028000000D8D61500800116000100000000000000000001060001000019B4C529E312D1010000000100000000 "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"=0x5341435001000000000000000700000028000000B0700E007B760E000100000000000000000001067102000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000030657C09000000000400000004000000 "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE"=0x5341435001000000000000000700000028000000C02AA601081EA7010100000000000000000001060001000059193B14E312D1010000000100000000 "C:\Program Files (x86)\WinZipper\wzdl.exe"=0x534143500100000000000000070000002800000078D00400EBB0050001000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000007B470600000000000400000004000000 "C:\Program Files (x86)\Skype\Phone\Skype.exe"=0x534143500100000000000000070000002800000080349301D45E930101000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000219D4D10000000000200000002000000 "C:\Users\theo\AppData\Local\Akamai\uninstall.exe"=0x534143500100000000000000070000002800000090A724009A9225000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000EB270000000000000100000001000000 "C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe"=0x534143500100000000000000070000002800000050D50A0045DF0A000100000000000000000001067322000059193B14E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000035530B0F000000000100000001000000 "C:\ProgramData\qwinpq\WFini.exe"=0x5341435001000000000000000700000028000000E83403004A2B040001000000000000000000000A7122000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000000B060000000000000100000001000000 "C:\Users\theo\Pas important\Downloads\QuickDiag.exe"=0x5341435001000000000000000700000028000000108A2000C3EE200001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000C50C2A00000000000100000001000000 "C:\Program Files\Internet Explorer\iexplore.exe"=0x5341435001000000000000000700000028000000C0740C00BD6F0D0001000000010000000000000A0021000059193B14E312D1010000000000000000 "C:\Users\theo\Desktop\QuickDiag.exe"=0x5341435001000000000000000700000028000000108A2000C3EE200001000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000019EB1A04000000000200000002000000 "C:\ProgramData\lwinpl\WFini.exe"=0x5341435001000000000000000700000028000000E83403004A2B040001000000000000000000000A7122000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000F9080000000000000100000001000000 "C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe"=0x5341435001000000000000000700000028000000A8FD5C005D5E5D0001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000B2F72904000000000A0000000A000000 "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe"=0x534143500100000000000000070000002800000000A80100E5D601000100000000000000000001067122000019B4C529E312D10100000000000000000200000028000000000000000000001000000000000000000000000000000000B96FAC04000000001200000012000000 "C:\Program Files (x86)\Internet Explorer\iexplore.exe"=0x5341435001000000000000000700000028000000C0840C00DDCA0C0001000000010000000000000A0021000019B4C529E312D1010000000000000000 "C:\Program Files (x86)\FreeAlarmClock\CsBringWindow.exe"=0x5341435001000000000000000700000028000000A06B00002F68010001000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000006E000000000000000100000001000000 "C:\Windows\uncsetup.exe"=0x534143500100000000000000070000002800000000604100000000000300000000000000000001057120000019B4C529E312D10100000000000000000500000010000000000000000000000000020105000800000200000028000000000201050008002000008000000000000000800000000000243B0000000000000200000002000000 "C:\Program Files (x86)\HP SimplePass\CheckUpdate.exe"=0x534143500100000000000000070000002800000028450A00AC830A00010000000000000000000206F122000019B4C529E312D1010000008000000000020000002800000000000000000000000000000000000000000000000000000094670000000000000100000001000000 "C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE"=0x5341435001000000000000000700000028000000B004210076B221000100000000000000000001060001000059193B14E312D1010000000100000000 "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE"=0x5341435001000000000000000700000028000000C0DE15001A2116000100000000000000000001060001000059193B14E312D1010000000100000000 "C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe"=0x5341435001000000000000000700000028000000A8B75F001890600001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000AD573C04000000000200000002000000 "C:\Users\theo\Desktop\mbam-setup-2.2.1.1043.exe"=0x534143500100000000000000070000002800000090AF5C017A9F5D0101000000000000000000000A0021000019B4C529E312D10100000000000000000200000050000000000000000000004000000000000000000000000000000000BC866A04000000000100000001000000000000000000000000000000000000000000000000000000265A0000000000000100000000000000 "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"=0x5341435001000000000000000700000028000000E0759700E487970001000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000005EF60500000000000100000001000000 "C:\Program Files (x86)\Firefox\Firefox.exe"=0x534143500100000000000000070000002800000080DB0500B000060001000000000000000000000A0021000019B4C529E312D1010000000100000000 [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe"=32 ---------- | IFEO ---------- | Mountpoints2 ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKU\S-1-5-20\SOFTWARE\Microsoft\Windows Defender] "CachedProxyAccessType "=1 "CachedProxy"= "CachedProxyBypass"= "LastKnownGoodProxy"=1 [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=131062095539121844 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "ProductType"=2 "ManagedDefenderProductType"=0 "ProductStatus"=0 "InstallTime"=0xD1D27C3B35C3D101 "DisableAntiSpyware"=1 "DisableAntiVirus"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts 127.0.0.1 localhost ::1 localhost ---------- | @ [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet settings] "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "IE5_UA_Backup_Flag"=5.0 "ZonesSecurityUpgrade"=0x3BCD177C47A0D101 "EnableNegotiate"=1 "ProxyEnable"=0 "EnableHttp1_1"=1 "ProxyHttp1.1"=1 "AutoConfigProxy"=wininet.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Save_Session_History_On_Exit"=no "Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "FormSuggest Passwords"=no "Enable Browser Extensions"=yes "Start Page"=http://google.fr/ "Default_Page_URL"=http://www.nuesearch.com/?type=hp&ts=1467646762&z=f6a7083ab45109899c25dedg7zeq5mbq5zaq6maq7o&from=wpm0616&uid=HitachiXHTS547564A9E384_J2180053EE9ULCEE9ULCX "Cache_Update_Frequency"=Once_Per_Session "Local Page"=C:\Windows\system32\blank.htm "NoUpdateCheck"=1 "Play_Background_Sounds"=yes "Play_Animations"=yes "CompatibilityFlags"=0 "IE9TourNoShow"=1 "IconCache"=u60a31a "FullScreen"=no "Window_Placement"=0x2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF1A00000000000000220500001F030000 "IE9RunOnceLastShown"=1 "IE9RunOnceLastShown_TIMESTAMP"=0xD626018A5D8BCD01 "Use FormSuggest"=no "IE9RunOncePerInstallCompleted"=1 "IE9RunOnceCompletionTime"=0xE8FAB89FA68DCD01 "DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFB0010000970000003004000077020000 "OperationalData"=13 "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0xD9870DD0BDC8D101 "IE10TourShown"=1 "IE10TourShownTime"=0x19B6CF51FA87CF01 "ImageStoreRandomFolder"=wc0wb4f "Search Bar"=https://www.google.com/ "IE10RunOnceLastShown"=1 "IE10RunOnceLastShown_TIMESTAMP"=0x375D5893E0CECF01 "ApplicationTileImmersiveActivation"=0 "AssociationActivationMode"=2 "DoNotTrack"=1 "IE10TourNoShow"=1 "DefSpellLang"=fr-FR "Start Page_TIMESTAMP"=0x17702AE246D9D101 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"= "Start Page Redirect Cache_TIMESTAMP"=0x107002C557A5D101 "Start Page Redirect Cache AcceptLangs"=fr-FR "AutoSearch"=1 "EdgeSwitchingOSBuildNumber"=10586.th2_release_sec.160527-1834 "Default_Search_URL"=https://www.google.com/ie [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=0 "SecureProtocols"=2688 "CertificateRevocation"=1 "EnableNegotiate"=1 "MigrateProxy"=1 "ProxyEnable"=0 "ProxyOverride"=*.local "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EmailName"=User@ "PrivDiscUiShown"=1 "EnableHttp1_1"=1 "WarnOnIntranet"=0 "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "AutoConfigProxy"=wininet.dll "UseSchannelDirectly"=0x01000000 "WarnOnPost"=0x01000000 "UrlEncoding"=0 "ZonesSecurityUpgrade"=0x2600A78F2AC3D101 "WarnonZoneCrossing"=0 "EnableAutodial"=0 "NoNetAutodial"=0 "GlobalUserOffline"=0 "ProxyHttp1.1"=1 "WarNonBadCertReceving"=1 "WarNonHTTPSToHTTPRedirect"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Cache_Update_Frequency"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=%11%\blank.htm "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "CertificateRevocation"=1 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EmailName"=User@ "PrivDiscUiShown"=1 "EnableHttp1_1"=1 "WarnOnIntranet"=1 "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "AutoConfigProxy"=wininet.dll "UseSchannelDirectly"=0x01000000 [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Cache_Update_Frequency"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=C:\WINDOWS\System32\blank.htm "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "User Agent"=Mozilla/5.0 (compatible; MSIE 9.0; Win32) "CertificateRevocation"=1 [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Cache_Update_Frequency"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=C:\WINDOWS\System32\blank.htm "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "User Agent"=Mozilla/5.0 (compatible; MSIE 9.0; Win32) "CertificateRevocation"=1 [HKLM\Software\Microsoft\Internet Explorer\Main] "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://www.nuesearch.com/?type=hp&ts=1467646762&z=f6a7083ab45109899c25dedg7zeq5mbq5zaq6maq7o&from=wpm0616&uid=HitachiXHTS547564A9E384_J2180053EE9ULCEE9ULCX "Default_Search_URL"=https://www.google.com/ie "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "Security Risk Page"=about:SecurityRisk "Start Page"=https://www.google.com/ "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://www.nuesearch.com/?type=hp&ts=1467646762&z=f6a7083ab45109899c25dedg7zeq5mbq5zaq6maq7o&from=wpm0616&uid=HitachiXHTS547564A9E384_J2180053EE9ULCEE9ULCX "Default_Search_URL"=https://www.google.com/ie "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\WINDOWS\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "Security Risk Page"=about:SecurityRisk "Start Page"=https://www.google.com/ "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | SSODL | SEH | URLSH | STS [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=Groove GFS Stub Execution Hook ---------- | Toolbar [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=0 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser] "ITBar7Layout"=0x13000000000000000000000030000000100004003300000001000000000700005E010000080000000101000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000011D7AF1FF9AB6A4F81305166C7371427000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ITBar7Height"=21 [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={2EACE1DC-6B18-444D-810F-F75DFB8DB01D} "Version"=5 "UpgradeTime"=0xD9870DD0BDC8D101 "KnownProvidersUpgradeTime"=0xD9870DD0BDC8D101 "DefaultPackCorrection"=1 "ShowSearchSuggestionsInAddressGlobal"=1 "DefaultPackNTCorrection"=1 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} ---------- | Extensions [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{25510184-5A38-4A99-B273-DCA8EEF6CD08}] : (@C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (Se&nd to OneNote) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (OneNote Lin&ked Notes) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] : () - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}] : (@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{25510184-5A38-4A99-B273-DCA8EEF6CD08}] : (@C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (Se&nd to OneNote) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (OneNote Lin&ked Notes) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] : () - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{A95fe080-8f5d-11d2-a20b-00aa003c157a}] : (@C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101) - [] ---------- | SearchScopes [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2EACE1DC-6B18-444D-810F-F75DFB8DB01D}] - (Google) - https://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} : ---------- | ElevationPolicy [HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458}] - (C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration) - wtapp_ProtocolHandler.exe : C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\wtapp_PresenceDetector.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\2323B5B8-9D8F-4063-B1F8-B32017C24844] - (C:\Users\theo\AppData\Local\Facebook\Video\Skype\) - : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA}] - (C:\Users\theo\AppData\Local\Facebook\Video\Skype\) - FacebookVideoCalling.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{127F0913-71BE-44EB-95C-566AA3824A67}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14CD64FB-E383-4EF4-94E1-5586C774304D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{174EC1BF-AA3C-413A-81D4-3F11A01FD2B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19B4B99F-1CB5-4BEB-A611-D02C572B71C4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1C5B41D8-7178-41A1-A339-3D881A18D3C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1D6E1B85-C210-4882-9CA8-F4AA35EC9CD4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F751C67-748A-4E27-BE85-B6F44D89B42}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{20DDB288-6DEC-48AF-BC90-57CD4E0223D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2292234B-3EF7-4042-886D-B62C871576D5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{240705A2-E51D-44DC-8818-1C9225B9F0F6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{24E0418-268F-49E0-972D-9E2427AEC72D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26D87E86-193C-4197-B04-7F2C22591CB4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28AB90AA-AA0-424B-943F-DFC11F19B16}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2A6D8BF7-9B4B-4C02-9F89-DB8A61237}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B811B9A-D28C-4007-99CD-652549271FA8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2C681EEB-11B7-4512-8D99-F94453DFDD7E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E3D9A22-AE2F-4D14-A2AC-7A64E91C9EB5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2F298D17-899E-418D-ADE3-1CB0F2EB7AED}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30737CF0-EE98-4FEE-8C5E-20FF0732D37}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{316E5D5B-F3EB-40E1-9A89-6433CA6B8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{32DA65-4F8C-4DDA-8096-9270A4B6A52A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34807CC1-FBC3-4428-BE38-A612756170C2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{35B716CB-A732-49EE-82A4-3BEFB2D0049}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36AEEFCE-8648-47A1-8CB7-9519F6C5B1E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{375A9D6F-9D8-4260-ACDF-267C7CAE131B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{382DF764-B1B7-4179-B859-5E41D6C4582}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39077938-7792-4DAC-A943-9BF649D8816}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39A90D91-4602-4FA4-8838-D55C8139942}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3A61B658-94A-40F1-AF88-2080A1AE955}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AE4D4D4-EE4E-459B-8D83-04ACEF3F560}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B537C7A-200-405E-8170-1C3214E19E7D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3C23DFDA-5D1F-494A-9D49-D2EF8EEB692}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3CC21876-C84E-49DD-8284-148813279DAE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D878A28-AC6-459D-9633-4063C1C546F3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3E784637-4F2C-46A5-AFC5-634E8F1772}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3F7A9BAE-4913-4BF2-AC2-76C554C36DF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3FE9DCC9-5075-400B-82FD-C1A6CB277253}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{405901B1-4667-4AD8-9A4B-8A1A7AC0DB2C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41C31943-1403-45BB-A47F-75218D79E7C4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42BF9539-B1C5-4A60-BC40-589D82DB7622}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{431C0A8F-9626-421D-ACD5-E1C8578AAB7C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43EC7F18-3E00-4AFD-9DEF-2DC7E4C2D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4472710-F2A2-42BC-8183-4A545889F1DF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44AB926C-4D9-4DFE-B9C3-6417AEAFF93A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{45645AB9-CE0B-4F44-85DA-2E16B38E286}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{45D7DD-3B21-46FB-A54-54C6C815456F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{465CCFC7-B4F-4BAD-8619-6D79DC47A0F6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{46FBFEAF-32DA-4DC0-96E3-63AA844B1261}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4769C75E-458D-4982-9A2B-7A2F765490F4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4831192B-678-4013-A071-5D406D96234E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48BC210D-F2A5-4DF4-8CDB-3672C348EEFB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49505DA5-ADF6-461D-9622-CD3F25195FC4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49D54076-6FB5-4464-A112-C51E5ADAB8A0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4A642B77-3256-4AE3-94DC-3BAFC03FE2B1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4AEE2C48-4C3C-495C-BD8D-C0F6A9BA516}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4BA6199F-F255-4206-BC17-965E96DC8DAC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4C03E579-E73F-4CF8-A99-ECCDFAC76FDD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4D159305-9DA0-4B37-85D0-3FB8FF8C62E0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4DF87DC0-BBCD-4C13-8AA8-B523DA7C7255}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E720D96-731F-4200-8EBF-E32EF1DCA2C9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4F13E754-3FA5-41D4-B80-E4E5A6C82F90}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FD43E07-509B-4B77-A9B7-1C3EA7556EBE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50255AD0-15A2-47C0-99C7-2D33D3182A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50A0E2E4-1A56-45BD-A53E-6726A77DD6AF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{513AB4B6-29E3-4F78-9A46-F04D9978766}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51B12F2E-6A03-476C-A13F-F68537BF679}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5269E569-4E7-4830-A06A-71C1E7FDCCC3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{536ED510-9F97-4F70-A3CB-82166C6C618A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5411C31C-4A3B-4C48-9E69-3BA5EDA9BDB0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54BD15-7E01-4924-894E-E6C9207E8146}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5538F239-B7B-42C2-97BC-213DBB5F7E9E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{557E3FA7-C856-4464-B832-FF7F691DD6DE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{564A00BA-146C-433C-A6AF-214575D1C49D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56EEE2BD-B804-47C3-9FBB-1F3CDF72547}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{576F3FB1-7ED1-483A-91BA-F953C6F4AD3A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5800230-FC58-42DC-A6C-470FFBA923B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59020A50-CEBE-4557-8164-307862639DAB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{598B4021-137D-4D5D-B0DD-8A6C70EA80BF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59D8599A-2E1B-4BD3-AB6F-44D33942E177}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5A7C1DFD-F22-4110-A4CF-F2D96DAAAB5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5B62679F-9381-458E-AF52-12155E3289F3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C2B2B03-2DF-4006-BA4A-FB902DD6D32}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5CE2CE4C-3539-4930-9F64-F8C7D82BA1DC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D5F3206-BF19-412A-963C-7087A84E742E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E362C45-A3F-46BF-92A1-1F9A43EC7719}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5EC944FC-619C-4FF4-B0DF-9DA94CC47FDF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5FDBCEEA-F333-4CC3-A5BE-A76CAFBBE56}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60631E67-22CE-4FA5-A2D-65F285EAD7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60D6F3A4-420E-4955-95C3-52F486F1E639}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61B6CF52-A740-4C32-A64E-2BE08523A716}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62453E0A-CEE5-40E1-8D7B-57D0C8CEE6A2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6322F77D-C095-4744-8E72-4F3AFAFD0A4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6391CBA3-A5DE-43FD-A8C7-D813AA411D11}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6426E580-A475-4E49-B070-7423EEE6BAE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{64AFE45A-D8AD-4617-8C83-42722A25E67}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6590CCF7-11EF-4C60-8214-B5145B4570BB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{663FAC0-CE9B-4962-A173-9C46391E75B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{670ACE1F-D5E4-48E8-B4CF-676E8143A21B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{67C66066-FA9E-4031-84FA-66DB0B3E8E9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{683BAAEA-660A-43D4-9D4A-AE59B96E15}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68F8F9FC-D8AD-40EA-A0A-EA254B99C0DA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69B14FA5-EE49-4A0A-B323-DA3CF796AAE3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A4AAEE6-5854-4A30-94A6-55CBB211D3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6AD8A6AE-C472-40B5-932E-76E29EB7BE0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BA805E4-66A4-4FFB-B753-5ED1D826DA22}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BFD4DDE-A5E7-49A6-A3B2-DD3D55A256E2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6D032DF1-6719-437B-96A-BB12AC4BD433}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6D83BE0B-C0EF-4296-AE26-DE90C2E6D216}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E1ADA6D-B866-4B8A-ACFC-2CA67B9E6870}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6EF0AF75-AD7E-4E3B-8411-C02223893DB1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6FC4E6F-2195-492A-9910-D72FD2F7661A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7055190-6C6C-4B5E-938C-66BB93DE7870}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70CBE17E-52C-4387-A0AB-EF3CDCEE7AD8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{71984B7D-1C7-435A-AD61-E5F46D7633F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72386B8-8745-4840-ABDC-F0EA50F84196}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72A2329C-CBA2-42D3-8A7F-8A68BBDCE559}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7355DC5C-65EB-49C2-8011-102A8E58CF3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74377E5B-D0EA-4860-9ECA-EEE5D613CB5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75490355-8642-4A2F-9535-FC6C41319298}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75E5C961-115F-42FA-8314-725BD2F240}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{765039D5-8795-4A47-BDAD-FA1876B3529E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{76AD7C1B-5F6A-44EB-9991-C6145FF4CC3D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7763132C-7662-4785-A1BC-C598952331EC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78787CE0-A17D-4E22-8E4F-CB38D40A2A0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79579E0F-DFDA-4908-BD35-14677661FCD8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79F8856C-5B67-4C2D-91AB-E598D39B1CFA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A2D9E9-8E79-46F5-A2CC-20544245E84}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7AB48D56-C027-4C5B-9161-C52A066335B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7B447FAD-52C6-4BB2-9055-5D93473495A4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7B9E2A4-4C1A-49C8-B9D4-70ECE293F2F7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C20DA89-6EF6-4D20-B2F9-E0BA21B6913}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7D3888DF-3189-45B3-8ADB-5E17745BEDB0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E1A506-1155-47C6-B2AF-DEAF22C6E89D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7ED0C81F-8302-4930-BAAC-E512E9999E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7FA783DB-DC0F-4018-8D28-EC14B3621860}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{801EF8E0-973A-4FD5-8F3D-91EE2B2F4930}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8099A6A2-737-4987-BE52-AEB2DC557BEF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8182BE69-72D1-439E-8975-19B8E612CCF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{820F1191-7AC5-4F39-8C75-B26F011629}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82DE2997-8CB4-4985-AFA7-C5E1EC7372D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8358842B-FF2B-4C7F-A09C-5E49C2F492F3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{842ABAC-8D21-49EE-BAD9-D8E28D937CF2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{84CDBA31-87F-4E21-A113-22158DD9121}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{859D3D1-C21A-4869-BD89-4B69DD7BBD56}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{86538604-89C4-460A-A238-A495CCD6D10}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{86D543AE-51B0-42B8-913-941B587D22CE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{876F6282-88CE-4C22-B78-D3114E775488}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{885A6DC2-91B4-4BDD-866C-B3D61EDAAEA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8908AD3E-A1BC-44A5-973D-82D4392F17}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{896A05A0-A34B-40A0-BC87-51C0EECD11A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A04B24F-794D-4792-8422-97FBA2BDD9E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8AE896B8-2699-44EC-9C90-DF29BCB08C3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C026D37-4DDF-4ED2-9656-4E63BCBF612F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8CC0153E-2C7B-40D0-AB46-6F2EAE1A9C1B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8D2AEEE0-8AE2-4E49-B986-38798FE86D52}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E2422E4-762D-461F-AAD6-66B9C6C67C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EC7D614-F0C-4E9D-B4A0-7CBB3510B34A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8FE84CBA-E431-4CC4-B243-8BDAB8862E20}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{907C7776-2241-4785-A8ED-293D567581B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{91151137-6E-4294-9371-2188E65D604B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{918D88AE-BB63-4744-885A-29509DC6891}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{91F67764-1287-4D7C-8CF9-E89466FC7C11}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{927D94AB-7CAD-4EBE-AFBB-7E4654A8D9E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{92CC29B1-8EA4-4ED0-90CA-2384E1EC9A6E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{92EDBB4E-D3F8-450A-8B60-34DFDE9513B8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9354A9E6-239F-4DBF-9734-122E6C8DBEFE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93D9199A-5BF7-49BD-9E20-26864EF18ABD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93ECD2EF-500-475C-956E-5DC5691501D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{940D90B0-E470-4895-82D9-63FC953DF0D7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9425A2E4-A1E-4229-BA14-C0CCC617712}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{94537C1C-E8-4079-B990-CFE17C0E6BD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9496EDD2-417E-4DA2-81C-DDE09B2F8945}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{94B95747-DEB4-4F93-BBB6-C5693B23F8D9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{94E3EF6E-DEDF-4DAC-9B67-E69BAEDB347}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9515FE0-CDAE-4C91-9436-23D088FDAC6C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9574A373-E75C-48D1-ABEF-36E1ACBC8623}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{957BCD63-948C-4865-857E-55F7ADBFDEB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95AFAAB5-4BAB-46EF-889-A39F37493142}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95BD2DD6-859B-43AC-B3B8-3A74C6991BC0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95E7E8F-C842-42A3-9090-6EF8E91B587}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95ED238B-C867-41A5-B489-15A4613757F3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{962A9B1B-81F4-4048-8738-817B3EE00D2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9647747-42D6-4F21-81BB-B515DC5F3EB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9671100E-E1C6-4C97-A576-9591B797ACF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{96A6D89B-6B4-49A6-9060-40FEDB8D2FED}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{96F4D1F6-E126-4BD5-A0C6-8E4CA127C4AA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{970D3C46-F50D-449C-8763-F64186B88C8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{972F5F62-CE26-4E39-AC38-F41CF61CAD70}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9777F813-4CF7-4AD1-AAA6-95C361EC3CE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{97818E0-AA5F-490D-8EA0-6E531C7FA1B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{979C091A-2826-446D-8CB6-F79CE9CFB50}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{97D7AFA8-C736-477F-9936-F6C69A5B4DA6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{97EA7BA1-A62D-405F-809F-2FE1CFE9D19}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9803D423-13BD-4521-BDAA-5F822DB0562}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9824FD8F-E53D-43BE-96B3-B17974251E59}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9842ABAD-537A-4793-A1F4-52FEB836DDE9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98983F43-187E-4135-9A40-6524ECEF70B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98B0294D-DF0B-42FD-9712-B877D91B58B4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98C26925-E053-49D2-BC99-813AA7647295}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98D93446-EF7C-4377-859C-4C5B505778CB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{990F1579-4D2D-4274-8F4E-8221B7F41D8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9928B251-697B-4C0C-ADE8-B3628A3198C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{992F1601-3967-4D2A-A760-61B12377D30}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{995DA723-D8E2-4B86-BD8A-F9A783914541}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9972954C-DCB1-4291-984D-D44A4A55D0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{999E3B31-2ED2-4F1F-A959-E5FD6E9E953D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99D3C248-58BD-475B-9B89-59516EA261C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99E5F7A0-E1F-4710-8BE-A5FE24CF9CFB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A10B60F-1FE7-49DD-BEC5-97C44523373}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A515EB0-CA72-498F-B4FC-AFCE43BF6C9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A6540F-87E3-43A1-B3BA-D6D376771F8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A748C8B-11B0-48D2-9361-C15CAC7B2FE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9AF19751-A8DB-48B8-82D3-D7FF511E3C94}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9B11A5A3-59F2-40A1-A931-5F72BF771E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9B312099-8269-42DC-BE50-8F24552DE63}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9B591AD3-9100-475C-AA58-56B7734B9161}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9B7F6522-BD89-4D0A-ADC8-CACAD2B7DB5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BA2AE34-D9B4-4F81-AB14-34F1B853C379}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BAF8CBB-8314-48E1-89C9-282E3746074}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BCEB16D-70EE-4413-B74B-C9217BA2FF8D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BD5040A-A707-44D5-A936-FA5A8121AD2D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C156744-BB10-47C0-A59-7D4696565750}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C3D0F93-FFE-4763-B6AE-BAA17A84158}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C4C16CC-73A9-4255-9A68-EEDB4FD218AA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C690D32-B6DD-4E0D-8910-C520A0C70E1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C983530-DBDA-4258-9C9A-37F012EDEB3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CDA99B9-BECB-4475-8389-17E62BC8225F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CECCA5B-343D-4A86-93F5-2949201083}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF83EF6-D852-4F16-A69F-2E657BF2B7CB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9D422DEB-794C-4AEE-A142-E5C2DFC14F9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9D4CDDFE-F39B-4DBA-B5DF-F2912FB31F5A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9D58DA02-8E63-4B42-BFB1-EBA07A88C03A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9D7E6743-2DDB-4831-A443-10334ED171C2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9DA81FD5-A276-4F06-912-EDB8BEF98C18}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9DBF365B-EF15-4D8D-8A91-9E77FBC7CC3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9DE63B0A-A66-4CBA-828F-91C07C159D2F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9E16DF3B-E2AD-4D46-A599-8CC183CE53C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9E46C619-4B3C-443D-AC34-C487325F30}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9E903C50-6E3F-4C0A-BDBE-1829F23763B3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EAE8D74-E908-4A97-B1F6-389F1C2B359A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB59926-CE79-4081-A79F-918498B5951E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EC27DF3-4C93-4BDA-9EB3-86ECF29A998}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EE59E6-FDFC-470D-8A91-CC5A234FD32}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F0F57A6-4D98-4AAF-B0AD-2CD9BACC6C9A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F36CEF5-6736-4709-B0D1-96DCBC2DD24D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F61EAFB-EC4-4975-999F-67FB7FDA0C5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F858EBC-3CA3-43FA-B563-14D0373EFA80}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FA628CF-EBCA-41F0-BFE7-30E0361A5E1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FAD4783-FE8F-4E30-995F-F7FB74598119}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FBB9A73-2C58-4753-AC3D-F792A8FDDC17}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A0023892-C540-44CB-AE65-C3E0D5EA1B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A03A2F45-D324-47A7-922C-8AB43186D9F6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A06F6982-A5EA-4074-A58B-CE29493678AA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A0B49E28-AD0D-4A7B-B2FE-A8A9D0F510D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A0CFCF48-E7A-440A-81B0-6CDF4912FF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A0F0E230-AC4E-4D6C-B9AB-C692A319D12}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A0F83EBE-9B12-4C46-82DE-EDF893C41D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A153017C-26B3-4275-B2F8-1A1F55991F8C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A15ED97B-FB20-4A8D-92F1-33A84D96BD9D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D5C52-BB78-47AD-BF9B-217A77EFB7E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A1D11633-F35C-4B27-A3A2-FC5970C6FEE1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A245929F-1656-409A-AB32-2CD3BF367D6F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A262AA04-D1B9-4FCA-BE9-F18CD9528D50}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2659EF1-2F2B-488C-8DE-F123D52AAA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A29B95-1447-4872-8F64-14DB58A4DF1A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2B0C170-4E9F-40C6-B199-2B10AB4C981}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2C605BF-349A-4D49-BDE6-7A48F1A2338}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2DB78ED-177-4F4C-B35E-A91451C2613}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A30BE37A-5DF2-4238-B071-BDB372E47A75}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A33934B4-BA6D-4AF0-9DCD-E415CE31A21}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A35E5610-69BD-4FCA-9BC-967754506768}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A373B853-7ED4-4233-AB7-50E1F88E22B9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A3A14A4C-AA07-417D-907B-D8ADD5A1090}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A3C6A4C7-E5A5-4DD9-ACC2-9A32C196F92}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A3F2B6BB-AD92-46F2-90E1-413173B3780}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A41F901A-649A-41DC-9438-8968D426D1F8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A437FC5-B65B-4296-B41-99CE7C2E78C6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4A596C9-4CE-41A7-9935-6062B58522F9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4C7B25B-D8CF-48B9-8EA1-EF66E3BEFE5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4F600E8-4C26-4287-92FB-0263053866}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A51CD10B-C2C6-4EAA-A7E2-C588BDD238A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A52E6E22-6C09-4E69-91C-84B69325685}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A54FA0CE-EB98-4077-AD65-B887F5D85BBA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A580C501-43B8-4954-BA56-D9875BD388EB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A58C4A09-3287-4E16-9919-CAF8F5DC177}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5B803C9-AF81-4665-B6DC-85ADD8ABD5EA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5FED867-2E76-4EEF-80E0-9EDE6F18AD36}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A61C1E66-84DA-4132-B488-1B544BD6489}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A65360E0-30A7-4F61-A77E-E34E7B5F67D3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A6688CDC-B374-41C7-A91E-8BD26665C779}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A6770557-4BF7-4259-9168-F9BA8B1E97E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A6A8EAE2-6A67-4C21-AFCE-6A83E1562567}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A7192247-5E2A-4E3C-A535-5E769EBC94AF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A72A270-4D98-4BDD-856B-C369D61F641F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A75DD3F-9F1D-4060-9BF2-FEA614B0BBF3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A769E336-A3A4-426D-BA5E-63FA17C9C313}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A77E57F-3362-4998-8A53-A823072CC9F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A79C3779-F06-4A94-9694-DD34C3CC8D5F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A7A83BFE-B565-427B-92E6-6761E779EB4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A7BF7356-B5F3-4F49-9E84-84FE1590B1B8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A842B457-311E-4B93-8B2E-DC8BC3FA1BB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A87B8272-5138-4CBF-A2BA-5095310AAFB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8BA26FC-20B0-40BB-BDE9-4A2413530CD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8D0297C-22BA-4164-A02C-5AA4FC3E93D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8F552BE-3BF-41B5-B3C3-BE183024AAF7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A945621-716-4A00-80D-7490AD8CA52F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A97EBCB0-64B9-44C1-94B5-B5556B3DA3D1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A9A16579-81CA-496A-B413-16C113129FB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A9EF0336-F1AB-445C-81C7-615D6C0C420}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AA26F15-AFFF-4623-8D3B-34545FB3BA12}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AA4DBCD7-E88F-485C-B3A4-646F327557D0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AA99C909-F725-4AEE-A82A-B8BDE4723514}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAAEB6D-ADC2-4F90-BBF5-162440AA4D50}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAC96141-1DD7-4F85-A60-36FAB259A195}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAFF643C-462-4F09-B71-CA260909E5F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AB2B4C56-BB4B-4E72-B9D0-1A44E9B98DB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AB40E004-873F-4AED-A1DF-2C4A350738}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AB6A0033-9CAF-400F-A8E1-EBAB1A2C480}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AB6E62A3-2131-4E4A-8E3-57336D7D22DE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ABD6EEDF-A98B-4BB3-837F-97CC953885}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ABE56D81-8D3E-4DD5-B715-7AC6162C72}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC0C31D2-7035-4A4B-8892-D8E1B77243D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC4636EA-F6E2-4390-89CE-67F1A26F4DF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ACB0E8E5-F983-45A6-8887-67C6309D378}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AD413154-9361-4379-8F7-1F91B85CFA23}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AD519899-FE5B-4223-BDA7-6EA4F6994390}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AD67B0E1-C0-4672-B1BB-5B2DE18D5A9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AD74AB6E-72-47F5-82E5-1251E1101ED5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ADE8911B-1EF2-4E56-9FB2-CA5C8D15C442}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE026611-F24-4CD6-88DD-83F1AFEF1FAC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE093305-68BF-45A0-88CC-FAB9DC79A83C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE606424-2C3C-488A-8022-3858E2DA3711}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE6426FA-386C-4494-8DDB-EB193D6DA11}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE831C37-4E39-45B9-9F17-DA8F9B9FC142}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE912B9A-489F-4E12-8458-EE9A1681C85B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AEBDE8E-429-4D2D-802D-6D9EFDE6D88}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AEF5313D-F341-45B3-81F-CDA15B73CFA5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF1E21EF-76E9-46F4-915E-AB22E8795}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF48B5F8-9C97-40D4-925A-86AA3FF9997}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFA1188D-7DBF-432D-B116-9AAAFA726381}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFC788ED-3A3C-4FDD-B485-63D815038DF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B00E3B8E-2518-449E-8A2F-1D2FC7B4644E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B054004D-7781-4253-880-9CAC71A7F17}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B0B0838C-2D58-4BC2-9DE3-28983093AFBD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B0C701DA-2B40-4ACC-A520-EBA8C1FA64EA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1092D9C-228C-4AA0-BCF1-C93436E359B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1332B74-9530-4498-A5F6-489DE74144E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B14623DA-E0CD-4B76-94E0-D61E60E3A6B4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B16B7E37-773F-4793-8615-CDF8945D30F0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1AA3D86-FD53-4A47-918E-D54241505E61}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1CF71DA-E9BF-4BF0-8F31-19A68D284E77}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1FB9D53-CC9F-4482-A1D6-C224528F482}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B249F602-2DA3-4339-ABFD-3F102CC4918A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B251F6D5-D801-4353-A3ED-A36BB481C18D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2887D45-70B5-41C2-84C6-E2704B304E24}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2AA7607-81E-401C-B498-8BA7E69F9C34}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BE7C8B-8139-413A-A448-4C256E532A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2DA8B37-8F45-400E-92D9-2EA41B4436D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2FC000C-3876-4A1E-986-939D25569CC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B325ACCC-7614-4074-ADD2-48E759E08040}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B33ECEAE-60A1-4257-B943-8965648F82B3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3582973-568F-471C-8140-35BA8CDDC8B5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B38E4A0-368F-47C2-9A4E-9FE399794238}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3BBB3D-4CE1-4EB2-B8D-B9E444549F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3EA2CB4-8CDB-4776-8F4-13611611DDD2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B41E0B87-7528-47C4-B05-C1252F309FBB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B44AD8CD-E982-4D67-B63A-35B87D438BB3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B49CF930-FADA-49BC-A11-3C89AEDFE92}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B4C6D891-5E3C-46D8-A281-38D5365B4CE2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B4ED951D-EF1-4C7A-B5DC-E857FDDB29E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5011965-690-429F-B9D-EA60C0413A5D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B511280D-7CB6-4DA3-92CD-869341535F9A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B51A9D32-CCED-4283-89EA-843FB4E76C35}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5242C36-BB0F-4625-B344-B68FE271BD2F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5545955-CD0D-4525-B165-747839787B9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B59B6DF1-CD7-433E-9E82-A83DDE99CE9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5AEDD3-46BD-4830-B8FE-EE86A26FD71}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5FA74E5-77AF-4A67-82DE-B2EDA34249D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B608B723-DC94-4944-952-A4C2931BDDE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B62BD950-DF9A-47C0-824F-879BE4F5524}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B631EB77-31C0-48CF-8840-B13BE123A7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B63D16BC-6479-4915-814-1032B2598287}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B640ED44-FB32-40FE-89AF-8A456EAA2644}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B66101E5-ED93-4423-A981-9FD652CE744F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B6B7CD5-A6F3-45B0-B144-699F7917772B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B6C9D1EA-31B8-46CC-BC93-225662D5A3E0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B6DE5C2B-2977-45BB-A47A-75E22C133EA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B6FD415A-7F72-44A1-880-5D7B25D535AD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B705E60D-1C4A-412E-998E-BEB895DB81A3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B727DAF5-E0A8-4195-8ECE-6A42A7F3F93}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B7444B3A-38B8-45B3-AA83-B5492425905A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B75CF258-B6DF-46DE-877F-EB4D7DB06632}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B7AEA2A7-9AF3-485C-B677-C4EA38BC55BD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B800C295-8C5F-4FD2-9440-A1566D9486C9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B8213A98-439C-46FA-A652-26D8E69044B6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B83C41E7-80C7-4CAA-A8A9-38A6FE43DF8D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B84996DB-90E-46A1-9D40-85AD4ABB4BC6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B86365F0-F62A-4F2C-95D8-7A24B4AA88AE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B87D9FAC-EBB3-4E9C-937D-CC439359EF7B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9196F77-6974-4D7A-BC68-F8E7CA81BC3D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B938E4E0-7CF9-47B6-BFCE-265BCA1D58E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9602E71-5DCE-4BF9-BBCA-3AAEEF57F930}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B967383D-F13D-41A3-A55C-EE1A7B83995}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9713CF8-A5ED-4F5E-80D4-24213371F24E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9A392B9-3672-42E0-A87-A66437B59D47}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9EAF4B5-4434-481F-BE1-25D1537F7E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA2979D0-2C62-4143-80A4-67156A8B4D0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA3E60DD-6B61-42F0-82DF-9DD4CAF354}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAB118BB-6A01-49E4-BE94-4C51E1FC21D5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BB23EF5F-87F-47E3-816F-4118981164E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BB5F69DE-5E93-4140-BF98-A786E57588}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BB6E3D8F-B04F-4040-BCD-E87F8267CB8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BBA9C593-BA79-491D-8CDE-8916CCC5B582}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BBE0F00F-A7F-4F19-BBFD-E04923477BA6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC0A847F-97F0-4342-8B50-57E24A1CEC6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC19E84A-CCD9-48FA-A2CD-72CF84BA7BD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC7490E4-6DB0-4CB8-B715-2AFCCB83954D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC9B8A41-868D-4025-9752-AA583B8E3C8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BCCB3C5E-1B8C-4B3D-980-C0B544B3C751}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BCF6F6E7-3E04-47FD-B7BA-54A91A8283E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD2120EC-76BB-4C14-BF2D-FD364F03720}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD2E53A9-5B57-401D-ACE2-EB3C3E68DEE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD40B6E3-7DF-48AD-86DD-9AA9204B262C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD776261-1B0F-4268-8030-61A24655126}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD9D4B1-5C10-4D9A-83EF-C52E96CB406D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BDCCBEFA-2835-4BE3-8081-4747853A180}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE00F51D-A789-463B-8AE7-1C8A90F1F614}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE573B1D-8A1-4E2C-8CFC-3B18E8ED415}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE6B6D9D-846F-4B7D-BD6A-7B68B777FF65}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE882241-D66D-4BEC-A9C2-AAA69A49617}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEA26495-3C35-413C-9A6-F69C4E182083}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEB4B878-74FB-42EE-9979-FE14AC7E8761}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEF991F3-2380-4687-81C3-5D92D315550}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF74365-CAE3-4D91-8CD7-CBBE70C884A0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF93999F-4639-4FF1-9EB7-BC1BB2B843B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFFBA3AF-94EA-44A7-96F3-FBBF50512A4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C02D02DF-2848-4C2A-B618-749A3E10B7AB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C049246A-E329-4047-8DAB-ACCDBEBBB5F3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0516A1A-C9A2-4C40-BF38-F8BED7D290B5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C072273B-8F33-4F8C-87B2-4B477842B77}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C096ADB6-73F5-41AB-8D75-7C4DECA569AF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0AAD528-643-4683-8CF1-A1FF2DEA8AD2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0C91A92-E1C6-4F90-8DD-B2899F6BFB8E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0F68F02-AA77-41DB-B556-A40A9EDE741}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C10D8E1C-6BA9-4C5B-9B4F-D8796D9663C7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C15F8F87-A0B1-4A17-82D-BDD4AC75ED1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1A21D80-729C-4AB2-8412-9E431B59E83A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1BFF9C9-32F2-43E6-BDFF-50B497F7C52D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C20195C7-1C04-4941-897D-4382F3B869}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C20E88A3-FB3D-49F7-BD14-C6EED27F47B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C236DB6F-10ED-4016-9636-5CCB9C4539CE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2449AEF-5678-4635-B8F3-A357881181}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2702530-CAC3-4B41-B886-E77A7771AE56}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2B203DE-B9F0-4DB1-8933-C9C7120A438}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C323F26E-200A-4802-AB9-86FC8F452C91}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C34A2F73-DDF2-43E4-AAF9-9BADDBD13ADC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3760D60-7C19-4805-A2FD-D6B8C9F2FF8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3B991A-E563-4277-925A-8CCBCB6A74AD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3E47ED5-B352-44BC-99A9-779227D9099}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FFE5AF-91F0-4475-B3BD-6CA560E44DEC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4049A7D-809-4E64-B04B-5BEDA68DA1AA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C449A696-5B08-4A55-87B6-7F323382906C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C453B3BF-3FA8-4262-B1D2-CFF271CE897C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C47392ED-B4D3-4F3E-821F-BA4CB175D2C4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4A7E076-3CC-478C-98F0-25CFA1B5B0D8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4C1B998-57F8-4132-A329-7B1858FD11DE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4E8322F-72A8-4581-82F2-BA98D7399FA1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5039D96-BA1-445D-AF5D-6AAC865D686}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5243FCC-6B1-4286-97B8-43EACFF05B48}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C55E4FE3-D40-4437-8C4C-E83313CB4511}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C58BA544-8CB4-4433-84C-9B8A94C985F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5E844CE-3A5F-4FD6-8CBC-085E6F54A8C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C609185C-14B8-452D-9178-158029DBEFB3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C61DCA19-E495-416F-8B1C-9AFD93A16A8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C666F5E-99B5-4438-9999-74F929F91D6A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C67880C6-3913-4541-BED2-455350B46975}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C6AEA0B3-4AC1-431B-B484-358F1ACA8625}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C6BCCCE9-8B05-4D2B-AA50-387C545B1EC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C6DC2910-AE9F-4379-B8D8-2EF59A98C4F8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7126869-E463-49BB-AC6F-576FE262E42}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C756DB39-C3ED-4665-A71A-1F869F59D8AA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C779CF1D-A723-4BF7-8F4F-112BE68AE4A3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C788AB27-2252-4237-9E54-D0C741A248AA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C79D1F1A-4E2-462B-AF27-924F9F887B9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7AB74D0-ECB8-4634-B546-56322DF5B5B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7E8BE3D-ECDC-490D-9742-C340D9A76D8E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C84CE972-BECD-428E-81C-F8372126E7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C883D16E-D63E-43C7-93A1-38F3D403641}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C88FD7A0-8981-4C8B-BFD1-659A4993BBD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8F9A88B-6152-429A-B89F-BF1F2CD9CCCC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C908919B-FD41-4168-AC47-8523ABDBAB1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C90D3DF4-CD4C-438D-B525-E8B1D0BF5E21}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C93462CC-A929-45E4-9D95-7F6E42CD79A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C989590F-D4B7-468D-9857-CD81C39E16D9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9A7C653-6B6E-4DD5-B88F-609B0351019}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9C0268F-5C37-4261-A031-C1EC3BCB8DB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9F79C7B-354E-4683-B657-F0C9CC419421}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA0936F7-E495-44A0-837A-1A132F1A2BF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA5798E1-8AC7-42F3-BFBE-E7873B18F9C1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAB34EF-84EA-4C20-85BE-75E2EA1C8BD0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAEA243B-7304-478D-A38E-807724DB9ABA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB044F7E-84E2-409C-A72-3491EBBB1A5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB383AF3-B26E-4790-8525-F4F3A99FDD35}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB75C5F1-F58B-4F88-A891-A0264D641EE8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB88A179-4E10-4BBA-959-FE57A79411D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CBC9A88B-CC35-438C-9EE0-4B1C68CED9D7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CBD613D-536F-4D42-AA16-E6968434434}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CBFF6652-93D2-47B3-8AAC-CEDAE6DAC5FB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CC1A2EB7-A4F8-413A-BBFF-DFA595014}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CC4D30C2-728C-427F-A0A3-BE4222B3BCE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCD48FBC-7467-4017-929C-C6A9E9DAD9F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCE37342-56DF-44C2-A97F-A05AFCF43E7D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CD0F19B6-2067-42A6-95EF-E31D6EE33DE1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CD63DD27-F046-4D5D-AE55-B2B963698DA4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CDAAA5CB-35D-4CE8-BB63-2F54C6D9F1E0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CDC3DD17-326E-4AC4-971A-BF46FE141FB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CDEAF3B1-4C33-48C7-8959-F99E8B5A119}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CE174B6B-C897-42BD-B3EE-17B6AD2A38}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CE338F8C-E4E8-4766-AA95-B24E86385C13}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CE6D4B0-F221-43F3-B2EB-AD56BD31418}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CE76843A-3815-4741-8736-E2BB64C3608B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CEA402E3-7335-4025-874-F455D35DB6EE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CEADB7C1-341-41DE-BFF1-D7B590D5BB19}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CED5E9D-1E21-4069-B54F-462159C6309A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CED6B670-110B-48D5-86F4-A8764A8BCEA4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CEDDACC0-1DA8-4C30-8293-FDEA65AC563}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CEF4829-A1E9-4A7F-81ED-ABDBF565736}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF080443-C1E0-4302-A01B-AF0EF4A59E3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF17691A-26D2-441E-810-EDDEBD6CF5BB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF5F2B6B-17D3-48DC-9DAA-82228A92B54}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF94C633-270F-41C4-80D0-208475EE1396}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFEBF49E-4075-4CC5-BF2B-694DFDD6122}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFFAFF97-18AB-48C4-BA43-74C1EB2779EA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D053833E-EE83-4248-B62B-B5C99A62C1B5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D06DC5DF-2044-4092-8A2B-798C4568EBE0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D082ABCE-A3FD-4408-B133-8289A2FEDD4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D094A491-17C1-4583-9A7C-40B60694BD8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D0FD3D48-D7E1-41C5-BD2C-A7EA9F3691BD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1055E44-CF67-47A2-ABEC-A7651AB33C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1608015-55C2-4643-B116-1FCA464ADA5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D173570-B728-4B63-8050-FAE75DADFDCB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1967A88-8735-42A1-805D-45F7AA3A31DA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1AC0C2A-7238-4B59-95DA-929A99EBCD88}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1D39DD5-6F1-4912-96D5-1076DA9B578D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1DC22A1-8783-4925-86ED-A8972232CA33}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1EC97C7-111B-4DC1-8D50-B967F61150}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D20A8236-6C6D-43B9-AB59-70EF74D74E0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D27A88CC-DEA0-4DF0-B226-62CA5CAA95C9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2A41706-1871-4A01-895E-11EC5B408CE8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2B0B6B5-EF22-47EE-919D-6F5E94805514}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2D387AB-785D-4F0F-B1D-7B47F31E5ECE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2DED9E6-8096-4696-BB86-83CD2D99E64}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D31BD91E-8B66-4B05-AC9A-87673BD3F8B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D35D916E-7B97-43BC-AE3C-63F238519DF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D36AF46E-D36D-43C9-B7D6-394EE2EA1439}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3F43C67-DEC8-4555-8172-53C815162D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D43AC1B-ADB3-4097-938D-D38DFA449D6B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D443CF26-7D82-4A62-8BC5-E5E2CCE6628E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D4590D48-DD2A-4E93-8DC9-67A22936154}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D46CDC2A-E34E-4EDF-948D-7647D0BC592}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D47C39B1-7253-4827-B885-EDC1356AD76F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D486992A-908-48E5-AB56-26B1362FDD68}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D49B2E4F-697E-442A-BEAE-25DE51DAE09C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5052A90-510D-4C6A-98D7-11B74E31B564}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D51A57B8-D601-47E7-8A5D-87FEB8A914CE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D53E7084-69F8-45A9-BF3F-D0D48EEAFEFE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D558E25-E0E8-4733-BFE9-BE3E99E62FAD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5677589-370-45F8-9581-448C296079BF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D573CCA3-263E-4496-A192-86875252B042}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5D1BC94-C8E7-4EAB-B649-5FD416CE1DA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5E2AEB8-FEDB-4A00-BC4F-E7B486CFFB14}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6081EDF-CC4B-42BC-A919-8CE70FA715E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6315834-F0F2-4604-AB20-2691AB9AE5C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D67A6E6F-E32F-4FFF-A4B6-3FF77B32ED}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6947BB4-244D-4EE4-AFEE-61278E2B1D59}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BCC23C-52C5-48A8-A38B-B13A3A7F71E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6E6E7AF-2231-4E0E-A676-FEF26029319}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D71C5121-855A-403A-AB52-81B0BF795982}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D774B091-931-4800-9578-B0186D41D7A2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D799D954-E1F7-40F9-B89F-6DBE7923309}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D80F3EA5-F2B0-4098-A7CE-EF48AF264DE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D869C95-30DC-47FC-9AC8-2E821672A3EC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D88273CC-3FD-404E-B04-E0848F68295}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8ACE902-7994-4FDA-BEB1-B5D79435A4EE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8BDFA61-8917-4577-8AC-2C342F67E112}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8F1CD95-4C35-442F-8756-D256C5C4C5CC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D90B07C5-F778-4A94-954F-2CD828CFFA9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D92A0A5A-87C9-4B72-A2C-8FA944A453D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D94234CB-205D-4C72-9B7-28CA3E79F7DE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D9CA31A3-7120-47FB-8BB4-7E94A26A3BBC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA2E274C-C30E-4BEE-8F37-E82EE6DEA170}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA3D00C9-6CC5-4A98-A2C8-6CC6D61514CC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA3F94CF-D5F1-4494-BEB4-EBD33A70623F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA763A81-DA65-47F1-9FCF-93A2A12A91D4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAA6287C-B9F-42DA-B3F9-EECD7D1573D6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAF01EB9-A39-4D8C-8D27-7FDD6D758A9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB24CDDF-C4C2-4907-B1D-49F57AE9675}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB5FBF45-6553-44DD-B5F0-73AACC8F639D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB6B257C-C2D2-4B12-A71A-EF25FAEE367E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBA1A3AC-6EB0-4DA6-A7CC-F47275244483}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBB1DDA3-F362-4491-847D-7B72EBF7892}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC1DF93A-E14-4253-8A14-1C99D0EDC07F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC4950BA-36B1-46BA-848F-B44067BA5158}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC81BF75-1B4A-4F07-A0DF-BBDE2EBEA1C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DCD71730-879C-486E-BB9B-4D32BCA25B5B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DCEED8EF-3E3-4AD7-9089-2D1F336D426}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD0AEDAA-44D2-4AD9-8D5A-F52110B8EB74}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD17E6CA-2982-4CDC-917E-2ABC6A6E86B8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD349186-486A-4059-98EF-94213AF66A0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD722971-77A0-479B-AAA2-649396E7423D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD7B82AB-F19E-4C9A-B3CD-9832AC62E7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDBFD918-F16-4C9D-94FF-6C90EA4E5D1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDCC591C-993C-464F-8853-61BEFB2F6DC3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE0E82C9-FD97-423B-9F5E-D261748EC9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE2DEAB8-BD09-4CAD-B216-8CADBD6BBC29}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE7C3AE2-7E7C-490F-BE29-CE09942437F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE7FE8D-7720-4627-A4BE-29FDF0303C3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE93DC3F-9C59-42D5-A6F3-BE95718E66F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DEA7F1B8-9FB7-4F4C-BD3A-D0C969C3F3FF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DEC97F2C-E72E-4D29-8A2A-CDF2CEF092F5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DF136420-8CF3-4E33-80CF-F7FACDD59289}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DF3154A9-E247-4227-BC7B-669FBD27D8D3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DF4F67BF-8D0A-4587-9399-7F7A4DFE2C9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFF07527-4841-4A92-9913-7EAD4214F7A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFFC7C53-FFD-4BCD-90C-4CCF60425BE9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0211CEA-1807-45D2-ACBE-29616E26D77}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E03727A7-4C4D-474A-A54-85CBA45782}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0665FB6-70E7-45BA-8F90-9FA135C826D8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0E0B0D9-EB15-43B3-B081-F063F0FDFCE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1194CD9-7725-41B7-9961-D5E0CF9AF527}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1259932-A904-44FE-96AA-1AA5706DB2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E16BCC5F-28CC-4AD5-AF8D-BB9A4AA0E5EB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E18FB81A-A48A-4920-BED7-619127C2AB89}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1A60E71-7AD3-4A69-9587-379E2E63CB7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1B8CFB6-53EF-4E3C-AD67-FF9C638F8E0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1CB4A66-429B-498A-A257-83EA689E50D6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1E0587E-3A4A-4A05-998B-995A8B5B6AB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1FC5756-39ED-49E8-A5B7-563E777CF0BF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E21683B2-F65A-4DF0-B83D-8378EB9D5432}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E21D0969-EC2C-434A-8DD2-89F82D12BEE4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E24EE55D-FDB-41A6-82AE-F1A904CDCF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E2A695C7-D618-4021-8E98-2922D2EE1FE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E2E423E3-DFC5-41F1-999-8667B2C9851}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3305273-4F14-4E62-A4F5-CE136A56C0F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E33E496E-C353-48CE-A76-EF8EA0D96F18}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E346F0CB-53F4-4ABC-9B1C-E3364ADC5030}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E365D1FC-BE20-408B-8BEE-B7232C22C48}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3953979-ECD8-4549-8FCB-A1B25E8C721}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E39E98A2-B6FC-4232-A4DA-AA98B7C4E9BE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3AEFCB4-E008-4396-A4C1-A9F8C662677B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3B8893-62DC-48A3-80BE-C9DA7052EFCF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3E76B3C-468-4900-9E2E-F86E1153B34}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3F025AE-AB18-4CB0-A2E-A05DF5BDF5A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E4499142-7859-4976-BA3B-E13FB7D3EB15}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E46B9BFC-E646-4946-910-531E1647AA8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E4C910E2-558F-4515-BFEC-D2F563D4DA1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E4E76A50-3583-455B-8BE8-0E0FF9E8EAF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E504DEAB-9F8A-4B8A-B399-7A58BFA1D580}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5112065-F6D6-4C74-ACD7-18D59E22BF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5197763-F229-4661-9EE7-A1CC357EA6C1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E60CB089-94D7-4FAD-A59B-E7350362F56}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E613B3D-3E1B-425A-96EE-AB8956CFA86}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E62BA365-4F50-4711-9C2C-6BF64D07B46}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E67DC1C3-4D8B-4CAB-89C-11C818403AE7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6C29196-B759-42E1-902E-D63D582574D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E72075D-A144-459D-A18D-A8EE7B58E19}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E759E546-F76C-4186-8EDE-505E03A4C71}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E77E8AEC-DBE9-490A-8C21-238CBEF573}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7AFA8-AF79-4A64-8158-436189A4640}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7E30970-1CEB-4F9D-A3C5-EBA6A518B923}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7FE8DF5-7A06-4552-AD92-36A120B59CC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E802114F-52D4-446C-822F-70304635980}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E82C8CA0-CE85-4EB1-A8B1-E7413A4F548}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E85E563B-FCC7-4BBF-8950-EA6DB0D58435}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E87F684E-6E-45C6-A281-685738A3CF35}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8C0F1E2-435E-46CD-A160-895290DB118F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8D0F775-5B05-4464-B11B-DF9A395B73A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8E607DF-30D0-4ABB-B187-B2FC48E03B9E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9114B1D-DD16-4683-AB5A-F7EC82273C55}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E92CAE9E-D094-4CBE-B689-E26FA2240C4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9417E32-A46-4965-83C9-E02CF82B38E8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E97B9B57-9947-4AE4-ACC7-2EAD49ADF549}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9908BF7-803A-403A-9BC7-8F2B173124}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9A62065-F4F7-4E36-9DE5-F539ACBBC621}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9E7EB4B-3A8F-4CA9-83FF-2779C4F95F0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA16FC6C-F38D-42C7-B955-95227A9FB8A0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA5C64DD-11B3-4CA6-9D36-E18054A6E022}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA6A3E1F-5751-46C5-814A-3A9D1D791ACA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EAA6F905-4CE1-46BD-91DF-629D4BE9D8F1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EABAB21B-5AF-4BAB-B7A4-44E09DC81}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EACC45FD-AE0-471E-B4D4-727F7A2C9D7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EAF4788B-2CD5-4356-9DBC-5FFA7679780}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB10D8EE-DB79-4193-A6FA-893AAC46677}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB2E61F-2B01-42AB-B032-D1E61A4CF8AE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB4D2750-1643-40C1-8CAA-5F2B1F3E074}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB57A152-1830-4EE4-85CF-F9C7AD2E60F8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB6E60DC-91DC-4C1D-AA5F-C477ABE513F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB792009-7F4A-4DDF-BE4D-212DC8F344F6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBAA84D2-CF75-48A9-A7E7-A7953E1CC45}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBBE134A-95C4-4C79-89ED-DF87D7F7693F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBC76078-FBFD-4044-98D5-435C97A70D4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBE95F40-42EF-464A-A16-C0CCBEFE3F3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC2DE24C-BD23-4B5D-9E75-8449D112642}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC33ECF2-67D8-4A9C-A65C-EB16CEC82D27}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC87FE73-F3E-4DF0-9882-A3ACB4C925D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC94C6B7-A352-48A0-A3BA-F7AE43A94B1A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECCD2C82-8777-4A7B-B1A5-FF46BAB1728F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED319BF3-6BA-4DA6-8366-4943DFCD6F70}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED9DE169-8E6F-4C0A-AC9-644E5777159}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDA610EF-EBB6-4C4F-863-E99A2923EA54}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDB56F0E-7583-48C1-8CD6-2A8272842CF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDF9307D-B2E6-406E-95DF-FCA68ADB2F50}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE3CCCCC-2792-4CB7-ADA1-FDD9DB7AF0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE5528B2-B807-488D-97B-D7F6173ED52}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE762734-15C-4815-821D-C79799D4483}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE9334C3-82D2-4EAC-92AD-FC176BB2FD1B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEC6AC74-3079-48B6-98C-15BF4467A02D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EED62D19-D77-4813-8F2F-D4F3DE83C3E7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EED911E6-3886-4D34-B4BE-959BB487E2C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF0ADFCB-6CCD-4D29-A483-2C99DC596161}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF196D4D-628E-4D71-8C57-44D8EAE74728}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFA26371-2664-4190-AB67-CBE96AC40E2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFAF28EB-FF62-4F42-92A8-43F1E5089F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFD42460-4637-44DB-8B43-39ED2120EB3E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFE4311A-56C-45B3-940-C8E740B27EE}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F03E7E54-489E-450B-B59C-0DDBCF256DA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0799056-ABE1-4DA4-B6E0-24312516C468}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0BB6757-2A52-4ECC-961F-6C9E9BCD4879}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0FA7B8E-5BE-47F4-95B0-3A273576553F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1183D43-D59-48A5-9F55-B1F2D6E388F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F15080D1-D854-4DCA-87FA-A512724F7ED6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F18547B1-67B0-4A9C-9850-1A42BE5B615C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1AB4AC-78E3-42CD-AF95-95166BB8AD9B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1C048A6-68F8-480A-B62-DFA13A2DF0C4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1EE4C44-90E6-4A43-A4AD-A7B51AC98218}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F233A28D-176D-477E-AB6-E22A3D285B87}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F26EB90-6745-4D3A-997E-13BA41E9951}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F294B9E9-9760-4650-9C5A-7262747146F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F29D84C3-6047-4CC9-9B1D-FCFED5C6A82}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F2BC49E6-3CD4-4BD3-8AA8-F8F378E343D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F2C1B14A-956E-4023-8F76-8E5818C017}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F30D9A6F-DD3D-4A07-827E-9985C8BF5EF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F31D33CD-9781-4746-8F4-EBD75F28E24}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F32FC030-23B6-405A-A9DA-EA3E563DB07}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34DDDD2-BA71-4642-AE1E-FAB612E99AD3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F35C4E5-9E29-4AF4-BFB3-A52D20E9DB2F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F3BD5130-B7A1-4632-BD2-A30E6AF0DD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F3D0248-43B7-4C1A-BD22-B17340DF217D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F3FE1A85-2BCA-4F4B-A38A-AA11D1C3FA4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4529524-794B-46B0-AC32-8779ECBD6A20}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F465FDCD-6AE-4772-BE91-795CECE08FB7}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F48A4F8E-8E1-4E1B-8B97-E8EEE17744A9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4C9E026-3274-4724-9973-338EC011CA8A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5250EDD-38F9-4165-8C19-EAAE668195B4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F55B3C90-2163-4606-97A4-A11EB48F9D1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F580CFC5-E717-4AD5-95EA-3078EDFDD22}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F59AB7E0-BAD-42DB-B626-16F298F14762}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5CCF3B9-5716-4636-A7C5-BC48746BEEA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5DC38F9-8C0D-44C5-8DDD-BCB576C9F038}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6216CB4-BA07-47C6-8AA4-39BA2A6438}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F63D5B22-9667-461A-B566-B324988B1D}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F67AEAA8-9724-4EFA-B6BB-38A2B4975CB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6A4DCF2-76EE-4C5A-BBA-5E7A4F637BC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6B4988E-82F0-44A0-AD12-58B46EC4A37C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6DBD9FA-C65E-4F1D-88BA-A3AAACCF847}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F745B5F4-CDD4-455E-96F-F990DD861D94}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F76CCAD6-A0-4013-A2D0-10F558AF821A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7B63F8E-EED-4BA2-AE11-41F5B0531825}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7D555FA-4A0E-43D8-9AF2-CE0F5496225}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7DC27D7-B90B-4787-B0F7-588C24282CA2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F81F1EF-3CB8-49AA-832D-8ACD153980A4}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8315240-4953-4678-9BBE-915A6B23DC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8366246-C9A9-4E4F-ACEC-7532DA597C59}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F853B1C-C719-49B9-84A6-A0AC44E29CD6}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F87EDEFD-F40E-4A47-A65E-B292AA1C9E3B}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8AA6906-27B4-453E-9447-F27836B84C66}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8F1A6F8-5FBF-4050-A949-6E55F02CC576}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9095226-C7AB-4577-BD1-F03765D13B20}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F935FAFB-7075-4445-BC23-FA563085645F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F947CA9D-909-467D-8C4D-2379BBF0E3A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F95E1682-59A1-4DED-95EA-98E470EAC9C5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F97FCF69-B382-4F82-A1F7-FB758427758}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F98ADB30-4E16-4E60-87C9-203C2A341CED}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9975D93-7087-4619-9818-6718F75348B5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9AF8681-F547-4C82-955B-67FD3DEFF8EF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9CE54C7-5EB5-4413-9E5-471643E48772}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9FFB7D-3A26-4E0E-9A69-622D559BBE78}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA2FC272-38E-4CD5-8FAB-F74A5D12C2}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA44D52E-83D1-4580-926C-69323671AFBD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA709D16-B1F-4CD9-ACB8-378BD2912AB1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA818B99-99E8-4A06-9626-1453DAB8DFB5}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA91996F-14F8-4A64-A565-9D319AFBE30}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA959C7E-EDD3-4014-B7D-B2E87E21CCC0}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB1368A-4C66-420D-9E67-79E3B6FB915C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB1F2E29-5E85-4467-BA74-C58BE8C7AA8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FBB1824F-2B7-4538-8333-EE9977C2401C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FBD92313-BBB7-4D9A-8C50-FD7B13BD2F15}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FBFA42C1-DFE3-40DD-BD1A-FE66BA491D1A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC1354A2-EAF5-4129-83B0-8E11E12FAB5E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC289862-D693-4CCC-B1FF-CD6C34761D8}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC7901C0-8B92-4473-98AA-181DD2E5ABD}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FCA911C1-BD62-42DB-9E58-53F8B73F1A3}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD08E6ED-5D40-45EB-A112-4B895C38648}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD296132-946D-4A47-8DA3-9D8CF2701BCB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD774D36-699C-43E7-896B-3D4CE1A273A1}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDB3DFD1-50B6-4E0F-AD76-7C1174A11F3A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDC1FD0-5C74-4B76-BE85-51EA23313FA}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDD1AF2B-D7BE-4BCB-9562-437713F33BB}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDFDF5F8-DCEF-4007-A39B-B0A3DCAA35F9}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE4CFDF-6CAA-49E0-8BA9-DEDC6D79A0DF}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE5E7C35-493-4B0D-B4FF-2F1BD4D589BC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE8133E0-1CB3-4C79-A7B8-4167349A653A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE9DB234-B5C6-459A-9AB2-52DEFEC8A1F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FECFF8D4-FAA8-4B28-90F9-A9696FBF43F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FEE93099-D7D-4BD9-BF36-6EB0D948C61C}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF0466F0-AD12-4E5A-8C52-8392EFD82953}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF182715-A644-4C35-9E3E-4FA3E183F6A}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-codedownloader.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF1AC921-BADA-4361-9471-1DD97E0FA7F}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-buttonutil64.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF2FFB64-2F26-4A3A-8413-F7185E2A5E}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF74D3C1-BCB9-43FC-B076-837AA53039BC}] - (C:\Program Files (x86)\Plus-HD-4.9) - Plus-HD-4.9-enabler.exe-helper.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\4DDD5300-D063-473A-9D82-96B009619DA5] - (C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions) - HPSAObjectMetrics.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{000209FF-0000-0000-C000-000000000046}] - (C:\Program Files\Microsoft Office\Office14) - winword.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{003B91A6-61E3-4591-891D-01E94C8CB11E}] - (c:\Program Files\Microsoft Silverlight\5.1.50428.0\) - Silverlight.Configuration.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03288CB3-3893-46D1-8D58-B2F8BB6FF5BF}] - (C:\Program Files\Microsoft Office\Office14) - MSACCESS.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] - (C:\Program Files\Common Files\Microsoft Shared\Ink) - tabtip.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{061BD2D3-1C9C-4697-B895-22A6D45A5901}] - (C:\Program Files (x86)\HP SimplePass\) - Splash.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] - (C:\Windows\System32) - wpcer.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}] - (C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28) - symerr.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] - (C:\Windows\System32) - wuapp.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138c8a3-54f7-4e7f-afbb-d995fb5a7171}] - (C:\Windows\system32\spool\DRIVERS\x64\3) - E_YARNHTE.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{130c40f0-1bcb-4852-8b63-291cf90a600b}] - (C:\Windows\System32) - msdt.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1753B788-C64C-4D57-B6BC-95C48992C4A7}] - (C:\Windows\System32) - msspellcheckingfacility.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework64\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0935-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework64\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1ec76a37-1762-46ff-9b14-765b3e6793be}] - (c:\Program Files\Microsoft Silverlight\5.1.50428.0\) - agcp.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{230ab713-0883-4182-8d89-b04c9a5cdf53}] - (C:\Windows\system32\spool\DRIVERS\x64\3) - E_YPREHTE.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2391d819-9d17-44ec-9ac1-f6aa07549469}] - (%systemroot%\system32) - wermgr.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] - (C:\Program Files\Internet Explorer) - ieinstal.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BBE903C-2776-4574-9855-EC1597ABE3D6}] - (C:\Program Files\Microsoft Office\Office14) - excel.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2dec4925-1312-4d7f-a6f5-89272d848dcf}] - (%WINDIR%\system32\IME\IMEJP\) - IMJPUEX.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{357FBE87-6C8E-490D-A059-4746C864AE6F}] - (C:\Program Files\Common Files\Microsoft Shared\Ink) - InputPersonalization.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38f2c092-34df-4c12-9d9e-c9679bf0ab31}] - (C:\Windows\SysWOW64) - presentationhost.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49E561B1-1091-4E65-98A0-AFCA4996CD1D}] - (C:\Windows\System32) - RuntimeBroker.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8381C-2705-4DC2-ADF3-347D4D619350}] - (%WINDIR%\system32\IME\shared) - imecfmui.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5FBAF6E6-C64B-49DB-AB1B-F93C607EBC71}] - (C:\Program Files\Microsoft Office\Office14\) - onenote.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61bd7005-d55e-4693-a191-0caa33601426}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{643CDDDA-BB87-4B3D-BB82-E8BF99DBF2C6}] - (C:\Program Files\Microsoft Office\Office14) - excel.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{674287D8-FA5D-42c9-9DF0-014BE8F893FD}] - (%windir%\System32\GWX) - GWX.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{681f008a-b1c3-412d-9d95-e7a68837a6ce}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A7C9604-8A57-4B28-821B-BDEDF0E04788}] - (C:\Program Files\Microsoft Office\Office14) - winproj.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] - (%ProgramFiles%\Windows Media Player) - wmplayer.exe : %SystemRoot%\system32\wmp.dll [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] - (%ProgramFiles(x86)%\Windows Media Player) - wmplayer.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] - (C:\Program Files\Internet Explorer) - iedw.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{734A9EB3-A34D-4fb7-9DB4-549C28F7EF97}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] - (C:\Windows\system32\) - CertEnrollCtrl.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] - (C:\Windows\System32) - verclsid.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f7bd411-f034-4ac0-9424-224bd7ab4e4e}] - (%WINDIR%\system32\IME\SHARED\) - IMEPADSV.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{812954F9-FAA2-4aee-A9E7-3C4FDE2166A6}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] - (C:\Windows\System32) - ctfmon.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{877467C0-F9E4-4561-84F0-65AA7539833C}] - (C:\Windows\System32) - CredentialUIBroker.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C1BF1CF-EEED-4f17-A0BC-27EED069F49B}] - (C:\Program Files\Common Files\AuthenTec\) - TrueService.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] - (C:\Windows) - helppane.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8D13E03F-8289-4c15-A84F-7A8F655C830A}] - (C:\Program Files\Microsoft Office\Office14) - NAMECONTROLSERVER.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{989F13EE-B25B-4FAB-9AED-C4336C8CCF0C}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98E3C2D3-E92F-469F-87EB-76054F640517}] - (C:\Windows\System32\IME\SHARED\) - imesearch.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a1ad1bbb-3b33-4260-a74c-5fd8bc1479fc}] - (C:\Windows) - splwow64.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a4fbcbc6-4be5-4c3d-8ab5-8b873357a23e}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5054EC7-B9CB-4ad5-9F95-D8171A6D6BFA}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] - (C:\Windows\SysWOW64\xpsviewer) - xpsviewer.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5B020FD-E04B-4e67-B65A-E7DEED25B2CF}] - (%SystemRoot%\System32) - wisptis.exe : %SystemRoot%\System32\wisp.dll [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A73D8D09-594A-431F-AB27-72AF4FCF25CF}] - (C:\Program Files\Microsoft Office\Office14) - MSACCESS.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{afe26134-8a16-4149-b798-242574f3f4a9}] - (%SystemRoot%\system32\IME\IMETC\) - IMTCPROP.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] - (C:\Windows\System32) - cmd.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] - (%systemroot%\system32) - TSWbPrxy.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD18A03F-31CC-4CC0-B52D-9E199122923D}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c14f6fd9-2ef6-4726-8153-60f98a4ce945}] - (C:\Windows\system32\spool\DRIVERS\x64\3) - E_YJACHTE.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AED-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA1750F5-7ECC-4DAA-AA46-CFC6EE89A953}] - (C:\Program Files\Microsoft Office\Office14) - winword.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] - (C:\Windows\System32) - notepad.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD993BDC-06E0-4131-B889-DD3B9AEBE253}] - (C:\Program Files\Microsoft Office\Office14\) - IEContentService.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E10C9D6E-22A3-45FA-BFCA-4BA0E26014FA}] - (C:\Program Files (x86)\HP SimplePass\) - BioMonitor.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea109b0c-6a97-45f0-9eb4-5907dd99b995}] - (%WINDIR%\system32\IME\SHARED\) - imedictupdateui.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] - (C:\Windows\System32) - presentationhost.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f5d04f46-b4b2-4202-a191-f780421b4200}] - (%WINDIR%\system32\IME\IMEJP\) - imjpdct.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6A6CA96-B08E-4429-BA30-39232494F292}] - (C:\Program Files\Microsoft Office\Office14) - MSPUB.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7629763-7562-4d3a-8468-6CA5563852B2}] - (C:\Program Files\Microsoft Office\Office14) - INFOPATH.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa6f0991-f729-4899-b095-d3fbca253cf6}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] - (C:\Windows\System32\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] - (C:\Windows\System32\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC88B53C-9B2A-1A25-5867-C8612E79DBF6}] - (C:\Program Files\Microsoft Office\Office14) - POWERPNT.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\4DDD5300-D063-473A-9D82-96B009619DA5] - (C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions) - HPSAObjectMetrics.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{000209FF-0000-0000-C000-000000000046}] - (C:\Program Files\Microsoft Office\Office14) - winword.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{003B91A6-61E3-4591-891D-01E94C8CB11E}] - (c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\) - Silverlight.Configuration.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03288CB3-3893-46D1-8D58-B2F8BB6FF5BF}] - (C:\Program Files\Microsoft Office\Office14) - MSACCESS.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] - (C:\Program Files (x86)\Common Files\Microsoft Shared\Ink) - tabtip.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{061BD2D3-1C9C-4697-B895-22A6D45A5901}] - (C:\Program Files (x86)\HP SimplePass\) - Splash.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] - (C:\Windows\SysWOW64) - wpcer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}] - (C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat Elements) - Acrobat Elements.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}] - (C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28) - symerr.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA}] - (C:\Users\theo\AppData\Local\Facebook\Video\Skype\) - FacebookVideoCalling.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] - (C:\Windows\SysWOW64) - wuapp.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{130c40f0-1bcb-4852-8b63-291cf90a600b}] - (C:\Windows\SysWOW64) - msdt.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{15B3FB63-66F4-4EFC-B717-BB283B85E79B}] - (C:\Program Files (x86)\Adobe\Reader 10.0\Reader\) - AcroBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1753B788-C64C-4D57-B6BC-95C48992C4A7}] - (C:\Windows\SysWOW64) - msspellcheckingfacility.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1ec76a37-1762-46ff-9b14-765b3e6793be}] - (c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\) - agcp.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2391d819-9d17-44ec-9ac1-f6aa07549469}] - (%systemroot%\system32) - wermgr.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] - (C:\Program Files (x86)\Internet Explorer) - ieinstal.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BBE903C-2776-4574-9855-EC1597ABE3D6}] - (C:\Program Files\Microsoft Office\Office14) - excel.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2dec4925-1312-4d7f-a6f5-89272d848dcf}] - (%WINDIR%\system32\IME\IMEJP\) - IMJPUEX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{357FBE87-6C8E-490D-A059-4746C864AE6F}] - (C:\Program Files (x86)\Common Files\Microsoft Shared\Ink) - InputPersonalization.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{358E6F10-DE8A-4602-8424-179CA217F8EE}] - (C:\Program Files (x86)\Adobe\Reader 10.0\Reader) - AcroRd32Info.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{380689D0-AFAA-47E6-B80E-A33436FE314B}] - (C:\Program Files (x86)\Windows Live\Contacts\) - wlcomm.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39A895E9-93DD-4ffa-A4A3-2C14608B5B61}] - (C:\Windows\SysWOW64\Adobe\Shockwave 11) - SwHelper_1163633.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43ABBB95-C0E9-497B-8BB9-B5FA08861705}] - (C:\Program Files (x86)\Windows Live\Mail\) - wlmail.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44D1B085-E495-4b5f-9EE6-34795C46E7E7}] - (C:\Program Files (x86)\Java\jre1.8.0_60\bin) - jp2launcher.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49E561B1-1091-4E65-98A0-AFCA4996CD1D}] - (C:\Windows\SysWOW64) - RuntimeBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}] - (C:\Program Files (x86)\adobe\acrobat 7.0\reader) - acrord32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8381C-2705-4DC2-ADF3-347D4D619350}] - (%WINDIR%\system32\IME\shared) - imecfmui.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5852F5ED-8BF4-11D4-A245-0080C6F74284}] - (C:\Program Files (x86)\Java\jre1.8.0_60\bin) - javaws.exe : C:\Program Files (x86)\Java\jre1.8.0_60\bin\wsdetect.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5FBAF6E6-C64B-49DB-AB1B-F93C607EBC71}] - (C:\Program Files\Microsoft Office\Office14\) - onenote.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61bd7005-d55e-4693-a191-0caa33601426}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{643CDDDA-BB87-4B3D-BB82-E8BF99DBF2C6}] - (C:\Program Files\Microsoft Office\Office14) - excel.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{674287D8-FA5D-42c9-9DF0-014BE8F893FD}] - (%windir%\Syswow64\GWX) - GWX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{681f008a-b1c3-412d-9d95-e7a68837a6ce}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68934FDE-CDB1-42CC-A38B-A44B43B0785C}] - (C:\Windows\SysWOW64\Adobe\Director) - SWDNLD.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A7C9604-8A57-4B28-821B-BDEDF0E04788}] - (C:\Program Files\Microsoft Office\Office14) - winproj.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] - (%ProgramFiles%\Windows Media Player) - wmplayer.exe : %SystemRoot%\system32\wmp.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] - (%ProgramFiles(x86)%\Windows Media Player) - wmplayer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] - (C:\Program Files (x86)\Internet Explorer) - iedw.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{734A9EB3-A34D-4fb7-9DB4-549C28F7EF97}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{76E2369A-75BA-41F9-8B9E-16059E5CF9A6}] - (C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\) - AdobeARM.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] - (C:\Windows\SysWOW64\) - CertEnrollCtrl.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] - (C:\Windows\SysWOW64) - verclsid.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f7bd411-f034-4ac0-9424-224bd7ab4e4e}] - (%WINDIR%\sysnative\IME\SHARED\) - IMEPADSV.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{812954F9-FAA2-4aee-A9E7-3C4FDE2166A6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82821E4E-4B46-430D-8BB8-8B480FC9D8A5}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] - (C:\Windows\SysWOW64) - ctfmon.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{877467C0-F9E4-4561-84F0-65AA7539833C}] - (C:\Windows\SysWOW64) - CredentialUIBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C1BF1CF-EEED-4f17-A0BC-27EED069F49B}] - (C:\Program Files\Common Files\AuthenTec\) - TrueService.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] - (C:\Windows) - helppane.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8D13E03F-8289-4c15-A84F-7A8F655C830A}] - (C:\Program Files\Microsoft Office\Office14) - NAMECONTROLSERVER.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E1F80F4-953F-41E7-8460-E64AE5BE4ED3}] - (C:\Program Files (x86)\Adobe\Reader 10.0\Reader) - AdobeCollabSync.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9019d14b-638d-4383-bb95-441b7f57eafb}] - (C:\Program Files (x86)\Windows Live\Installer\) - wlstartup.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}] - (C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat) - acrobat.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{989F13EE-B25B-4FAB-9AED-C4336C8CCF0C}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98E3C2D3-E92F-469F-87EB-76054F640517}] - (C:\Windows\SysWOW64\IME\SHARED\) - imesearch.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C6A861C-B233-4994-AFB1-C158EE4FC578}] - (C:\Program Files (x86)\Adobe\Reader 10.0\Reader) - AcroRd32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}] - (C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements) - Acrobat Elements.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a00068b1-1e4e-41c7-afa9-baeb9697e2b9}] - (%CommonProgramFiles%\Research In Motion\AppLoader) - Loader.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a1ad1bbb-3b33-4260-a74c-5fd8bc1479fc}] - (C:\Windows) - splwow64.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a4fbcbc6-4be5-4c3d-8ab5-8b873357a23e}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5054EC7-B9CB-4ad5-9F95-D8171A6D6BFA}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] - (C:\Windows\SysWOW64\xpsviewer) - xpsviewer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A73D8D09-594A-431F-AB27-72AF4FCF25CF}] - (C:\Program Files\Microsoft Office\Office14) - MSACCESS.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{afe26134-8a16-4149-b798-242574f3f4a9}] - (%SystemRoot%\system32\IME\IMETC\) - IMTCPROP.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] - (C:\Windows\SysWOW64) - cmd.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] - (%systemroot%\system32) - TSWbPrxy.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD18A03F-31CC-4CC0-B52D-9E199122923D}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}] - (C:\Program Files (x86)\Google\Update\1.3.24.7) - GoogleUpdateBroker.exe : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C442AC41-9200-4770-8CC0-7CDB4F245C55}] - (C:\Program Files (x86)\Google\Update) - GoogleUpdate.exe : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AED-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8FE2181-CAE7-49EE-9B04-DB7EB4DA544A}] - (C:\Program Files (x86)\Java\jre1.8.0_60\bin) - ssvagent.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA1750F5-7ECC-4DAA-AA46-CFC6EE89A953}] - (C:\Program Files\Microsoft Office\Office14) - winword.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D133B285-8A43-4EC7-93BE-9B909C2370F5}] - (C:\Program Files (x86)\Windows Live\Messenger\) - msnmsgr.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d8a5d001-3352-40db-9d1c-ed46683193b5}] - (C:\Program Files (x86)\Windows Live\Writer\) - WindowsLiveWriter.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB9524B3-24F4-48fa-91C5-B8EEF1C0A14F}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] - (C:\Windows\SysWOW64) - notepad.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD993BDC-06E0-4131-B889-DD3B9AEBE253}] - (C:\Program Files\Microsoft Office\Office14\) - IEContentService.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E10C9D6E-22A3-45FA-BFCA-4BA0E26014FB}] - (C:\Program Files (x86)\HP SimplePass\) - BioMonitor.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e5f90a07-7db7-4dcb-bd6d-d3fecd376ca3}] - (C:\Program Files (x86)\adobe\acrobat 6.0\reader) - acrord32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6E51F7A-27CE-4ba0-9951-4912E40EF4A3}] - (C:\Program Files (x86)\Adobe\Reader 10.0\Reader) - arh.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea109b0c-6a97-45f0-9eb4-5907dd99b995}] - (%WINDIR%\sysnative\IME\SHARED\) - imedictupdateui.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] - (C:\Windows\SysWOW64) - presentationhost.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f5d04f46-b4b2-4202-a191-f780421b4200}] - (%WINDIR%\system32\IME\IMEJP\) - imjpdct.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6A6CA96-B08E-4429-BA30-39232494F292}] - (C:\Program Files\Microsoft Office\Office14) - MSPUB.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7629763-7562-4d3a-8468-6CA5563852B2}] - (C:\Program Files\Microsoft Office\Office14) - INFOPATH.EXE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa6f0991-f729-4899-b095-d3fbca253cf6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] - (C:\Windows\SysWOW64\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] - (C:\Windows\SysWOW64\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}] - (C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat) - acrobat.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC88B53C-9B2A-1A25-5867-C8612E79DBF6}] - (C:\Program Files\Microsoft Office\Office14) - POWERPNT.EXE : ---------- | Ext\Settings [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] : : C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}] : : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] : : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] : : C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] : : C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] : : C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000}] : : C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435B-BC74-9C25C1C588A9}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] : : C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll ---------- | Ext\Stats [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BCC737-B171-4746-94C9-0D8A0B2C0089}] : : C:\PROGRA~2\MICROS~1\Office14\IEAWSDC.DLL [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] : : C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{219C3416-8CB2-491A-A3C7-D9FCDDC9D600}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{233C1507-6A77-46A4-9443-F871F945D258}] : : C:\Windows\SysWow64\Adobe\Director\SwDir.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25336920-03F9-11CF-8FD0-00AA00686F13}] : : C:\Windows\SysWOW64\mshtml.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25510184-5A38-4A99-B273-DCA8EEF6CD08}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2933BF90-7B36-11D2-B20E-00C04F983E60}] : : %SystemRoot%\System32\msxml3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2933BF94-7B36-11D2-B20E-00C04F983E60}] : : %SystemRoot%\System32\msxml3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{312B9567-734D-4A21-A8AA-F319BD1AAA6F}] : : C:\Program Files (x86)\Windows Live\Messenger\msgsc.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55136805-B2DE-11D1-B9F2-00A0C98BC547}] : : C:\Windows\SysWOW64\ieframe.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5852F5ED-8BF4-11D4-A245-0080C6F74284}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\wsdetect.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6BF52A52-394A-11D3-B153-00C04F79FAA6}] : : %SystemRoot%\system32\wmp.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] : : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8856F961-340A-11D0-A96B-00C04FD705A2}] : : C:\Windows\SysWOW64\ieframe.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{88D96A05-F192-11D4-A65F-0040963251E5}] : : C:\Windows\SysWOW64\msxml6.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{88D96A0A-F192-11D4-A65F-0040963251E5}] : : C:\Windows\SysWOW64\msxml6.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8AD9C840-044E-11D1-B3E9-00805F499D93}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2iexp.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A95FE080-8F5D-11D2-A20B-00AA003C157A}] : : [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] : : C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] : : C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}] : : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA8A9780-280D-11CF-A24D-444553540000}] : : C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CAFEEFAC-DEC7-0000-0001-ABCDEFFEDCBA}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\deployJava1.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}] : : C:\Users\theo\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2517915-48CE-4286-970F-921E881B8C5C}] : : C:\Windows\SysWOW64\WindowsLiveLogin.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}] : : C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}] : : C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEAF541-F3E1-4C24-ACAC-99C30715084A}] : : c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] : : C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ED8C108E-4349-11D2-91A4-00C04F7969E8}] : : %SystemRoot%\System32\msxml3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F5078F32-C551-11D3-89B9-0000F81FE221}] : : %SystemRoot%\System32\msxml3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F5078F35-C551-11D3-89B9-0000F81FE221}] : : %SystemRoot%\System32\msxml3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}] : : %SystemRoot%\System32\msxml3.dll [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}] : : %SystemRoot%\System32\msxml3.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}] : : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}] : : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] -> (Groove GFS Browser Helper) : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 03:41:02] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] -> (Skype Click to Call for Internet Explorer) : C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [25/05/2016 10:30:38] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] -> (Office Document Cache Handler) : C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [06/03/2013 10:37:48] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] -> (HP Network Check Helper) : C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [06/05/2015 04:32:58] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] -> (Adobe PDF Link Helper) : C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [18/12/2012 18:28:18] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] -> (Groove GFS Browser Helper) : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 03:41:02] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> (Java(tm) Plug-In SSV Helper) : C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [17/11/2015 00:35:44] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] -> (Skype Click to Call for Internet Explorer) : C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [25/05/2016 10:30:38] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] -> (Office Document Cache Handler) : C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [06/03/2013 10:37:48] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> (Java(tm) Plug-In 2 SSV Helper) : C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [17/11/2015 00:35:44] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] -> (HP Network Check Helper) : C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [06/05/2015 04:32:58] ---------- | Chrome C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\aohghmighlieiainnegkcijnfilokake = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\apdfllckaahabafndbhieahigkjlhalf = : Google & co - https://drive.google.com/?usp=chrome_app - Google & co - [http://docs.google.com/http://drive.google.com/https://docs.google.com/https://drive.google.com/] - https://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co - http://www.youtube.com - http://www.youtube.com - Google & co - http://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\coobgpohoikkiipiblmjeljniedjpjpf = : Google & co - http://www.google.com/webhp?source=search_app - Google & co - [*://www.google.com/search*://www.google.com/webhp*://www.google.com/imgres] - http://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\gighmmpiobklfepjocnamgkkbiglidom = : __MSG_description2__ - AdBlock - https://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\kanflfepiobnpjbljmngfgegijhdpljm = : HP SimplePass Website Logon Extension. - Website Logon C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl = : Quickly access Skype for Web and Share on Skype through your browser - Skype - https://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\npdicihegicnhaangkdmcgbjceoemeoo = : __MSG_newtab_chrome_extension_description__ - __MSG_newtab_chrome_extension_name__ - https://clients2.google.com/service/update2/crx C:\Users\theo\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co - https://mail.google.com/mail/ca - Google & co - [*://mail.google.com/mail/ca] - http://clients2.google.com/service/update2/crx [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\kanflfepiobnpjbljmngfgegijhdpljm] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\npdicihegicnhaangkdmcgbjceoemeoo] ---------- | Opera ---------- | Firefox [HKLM\Software\mozilla\Firefox\Extensions] "wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF "sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF [HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions] "wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF "sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin] - (Facebook Video Calling Plugin) : C:\Users\theo\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 22.0.0.209 Plugin) : C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] - (Office Authorization plug-in for NPAPI browsers) : C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 22.0.0.209 Plugin) : C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] - (Adobe Shockwave Player) : C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@Apple.com/iTunes,version=] - (Module iTunes Detector) : [HKLM\Software\WOW6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0] - () : C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@authentec.com/ffwloplugin] - () : C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52] - (Intel IPT WebApi plugin) : C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater] - (This plugin updates Intel WebAPI component) : C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.60.2] - (Java™ Deployment Toolkit) : C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2] - (Oracle® Next Generation Java™ Plug-In) : C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] - (Office Authorization plug-in for NPAPI browsers) : C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0] - (BlackBerry Web Software Loading Helper Plug-In for Mozilla browsers) : C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (WildTangent Games App Presence Detector Plugin) : C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [HKLM\Software\WOW6432Node\MozillaPlugins\Adobe Reader] - (Handles PDFs in-place in Firefox) : C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll C:\Users\theo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Prefs.js user_pref("browser.newtab.url", "https://www.google.com"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "google"); user_pref("browser.search.defaultenginename.US", "data:text/plain,browser.search.defaultenginename.US=yessearches"); user_pref("browser.search.selectedEngine", "yessearches"); user_pref("browser.startup.homepage", "https://www.google.com"); user_pref("browser.startup.homepage_override.buildID", "20160502172042"); user_pref("browser.startup.homepage_override.mstone", "46.0.1"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.InstallationThankYouPage", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.InstallationTime", 1385316094); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.active", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.addressbar", "NA"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.addressbarenhanced", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncdb_dbWasSet", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncdb_dbWasSet_FF25_FIX", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncinternaldb_dbWasSet", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncinternaldb_dbWasSet_FF25_FIX", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.backgroundver", 2); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.certdomaininstaller", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.changeprevious", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.InstallationTime.value", "1385316094"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_aoi.value", "%221388082914%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_parent_zoneid.value", "%22471395%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.iframe-exists.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.iframe-exists.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.jw_token.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.jw_token.value", "%221f3a3b11-c748-78b9-df85-60b111f6ffb7%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.load_balancer.expiration", "Sun Jan 05 2014 16:19:28 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%5C%22%3A%20%5C%22http%3A//api28.thetrafficstat.net%5C%22%20%7D%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.previous_page.value", "%22https%3A//www.google.fr/search%3Fq%3Dads+by+plusHD.9+%253F%26ie%3Dutf-8%26oe%3Dutf-8%26rls%3Dorg.mozilla%3Afr%3Aofficial%26client%3Dfirefox-a%26gws_rd%3Dcr%26ei%3DpDrJUr2EAdGU0QXN2YDYBA%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.user_id.value", "%221428b460e842d79ed93ef945a1d04940%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.description", "Turn YouTube videos to High Definition by default"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.domain", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.enablesearch", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.homepage", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.iframe", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22000680%22%2C%22sub_id%22%3A%220%22%2C%22uzid%22%3A%220%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_appVer.value", "54"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_lastVersion.value", "1"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_meta.value", "%7B%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_nextCheck.expiration", "Sun Jan 05 2014 16:19:08 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_nextCheck.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_queue.value", "%7B%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.__194_lastCheck__.expiration", "Sun Jan 05 2014 11:59:48 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.__194_lastCheck__.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb._country_code_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb._country_code_.value", "%22FR%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D%2C%22version%22%3A%221.30.153.0%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.lastDailyReport", "1388898872839"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.lastUpdate", "1388913548870"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.manifesturl", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.newtab", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.opensearch", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.pluginsurl", "https://w9u6a2p6.ssl.hwcdn.net/plugin/apps/45918/plugins/093/ff/plugins.json"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.pluginsversion", 48); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.publisher", "Plus HD"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.searchstatus", 0); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.setnewtab", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.thankyou", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.updateinterval", 360); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.ver", 54); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.apps", "45918"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.bic", "1428b460e842d79ed93ef945a1d04940"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.cid", 45918); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.firstrun", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.hadappinstalled", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.installationdate", 1385316094); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.modetype", "production"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.reportInstall", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.statsDailyCounter", 47); user_pref("extensions.adblockplus.currentVersion", "1.8"); user_pref("extensions.adblockplus.fastcollapse", true); user_pref("extensions.adblockplus.lastRuleUpdate", 1375302878); user_pref("extensions.autoDisableScopes", 10); user_pref("extensions.avastwrc.settings", "{\"current\":{\"callerId\":2018,\"userId\":\"209063266f3a28cca0078852ea17ba75\",\"edition\":0,\"lastApplicationEventSent\":1466871948716},\"features\":{\"phishing\":true,\"dnt\":true,\"dntSocial\":false,\"dntAdTracking\":false,\"dntWebAnalytics\":false,\"dntOthers\":false,\"siteCorrect\":true,\"siteCorrectAuto\":false,\"safeZone\":false,\"communityIQ\":true,\"serp\":true,\"serpPopup\":true},\"siteCorrect\":{\"declined\":{}},\"safeZone\":{\"declined\":{}},\"phishing\":{\"trusted\":{}}}"); user_pref("extensions.avastwrc.whiteList", "{\"trk\":{\"apps.facebook.com\":{\"703\":false},\"avast.com\":{\"779\":false}}}"); user_pref("extensions.blocklist.pingCountTotal", 227); user_pref("extensions.blocklist.pingCountVersion", 30); user_pref("extensions.bootstrappedAddons", "{\"@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924\":{\"version\":\"1.08.8.66\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\theo\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\41A66E7E5EE1\\\\extensions\\\\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":false},\"e10srollout@mozilla.org\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\e10srollout@mozilla.org.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":true},\"firefox@getpocket.com\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\firefox@getpocket.com.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":true},\"loop@mozilla.org\":{\"version\":\"1.2.6\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\loop@mozilla.org.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":true},\"wrc@avast.com\":{\"version\":\"10.3.3.13\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"multiprocessCompatible\":false,\"runInSafeMode\":false}}"); user_pref("extensions.checkCompatibility.", false); user_pref("extensions.databaseSchema", 17); user_pref("extensions.e10sBlockedByAddons", true); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:46.0.1"); user_pref("extensions.getAddons.cache.lastUpdate", 1467131611); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20140319.01"); user_pref("extensions.lastAppVersion", "46.0.1"); user_pref("extensions.lastPlatformVersion", "46.0.1"); user_pref("extensions.mywebsearch.prevKwdEnabled", true); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0\"},{\"b\":224520318,\"c\":\"mindspark.full\",\"p\":\"L.0.1\"},{\"b\":224520322,\"c\":\"mindspark.imagesearch\",\"p\":\"L.0.2\"},{\"b\":224520325,\"c\":\"mindspark.advanced\",\"p\":\"L.0.3\"},{\"b\":224520328,\"c\":\"mindspark.directorysearch\",\"p\":\"L.0.4\"},{\"b\":224520265,\"c\":\"mindspark.search\",\"p\":\"L.1\"},{\"b\":224520267,\"c\":\"mindspark.ask\",\"p\":\"R.0\"},{\"b\":224520332,\"c\":\"mindspark.wrench\",\"p\":\"R.1\"}]"); user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "46.0"); user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986"); user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=782a8460"); user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", true); user_pref("extensions.toolbar.mindspark._brMembers_.hp.guardType", "HPR"); user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true); user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016052320"); user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true); user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1467303331920"); user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986"); user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"ja\",\"en\"],\"defaultLocale\":\"en\",\"supportedLocale\":\"en\",\"previousLocale\":\"en\"}"); user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false); user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false); user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true); user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false); user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en"); user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar"); user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "http://www.yessearches.com/chrome.php?uid=CBD5DCBBF51CDE119B2F62F2E996E82C&ptid=dam&ts=AHEpBnQtBn4mBE..&v=20160301&mode=ffexttoolbar&q="); user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false); user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"filesToDelete\":[\"C:\\\\Users\\\\theo\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\41A66E7E5EE1\\\\YourGSearchFinder_br\\\\STUB.sqlite\",\"C:\\\\Users\\\\theo\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\41A66E7E5EE1\\\\YourGSearchFinder_br\"]}"); user_pref("extensions.toolbar.mindspark.hp.enabled", true); user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "yourGSearchfinder@GSearch.com"); user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com"); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/plugin"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.wrc.SearchRules.google.com.url", "^http(s)?\\:\\/\\/((.)+\\.)?google\\.(com|[a-z\\.]{2,})\\/(.)*"); user_pref("extensions.wrc.SearchRules.public.avast.com.url", "^http(s)?\\:\\/\\/public\\.avast\\.com\\/(.)*"); user_pref("extensions.wrc.SearchRules.seznam.cz.url", "^http(s)?\\:\\/\\/search\\.seznam\\.cz\\/(.)*"); user_pref("extensions.wrc@avast.com.sdk.baseURI", "resource://wrc-at-avast-dot-com/"); user_pref("extensions.wrc@avast.com.sdk.domain", "wrc-at-avast-dot-com"); user_pref("extensions.wrc@avast.com.sdk.load.reason", "startup"); user_pref("extensions.wrc@avast.com.sdk.rootURI", "file:///C:/Program%20Files/AVAST%20Software/Avast/WebRep/FF/"); user_pref("extensions.wrc@avast.com.sdk.version", "10.3.3.13"); user_pref("extensions.xpiState", "{\"app-profile\":{\"@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924\":{\"d\":\"C:\\\\Users\\\\theo\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\41A66E7E5EE1\\\\extensions\\\\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi\",\"e\":true,\"v\":\"1.08.8.66\",\"st\":1456810647000},\"cacaoweb@cacaoweb.org\":{\"d\":\"C:\\\\Users\\\\theo\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\41A66E7E5EE1\\\\extensions\\\\cacaoweb@cacaoweb.org\",\"e\":false,\"v\":\"1.0.34\",\"st\":1457797514511,\"mt\":1457797514511}},\"app-system-defaults\":{\"e10srollout@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\e10srollout@mozilla.org.xpi\",\"e\":true,\"v\":\"1.0\",\"st\":1462255340479},\"firefox@getpocket.com\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\firefox@getpocket.com.xpi\",\"e\":true,\"v\":\"1.0\",\"st\":1462255340528},\"loop@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\loop@mozilla.org.xpi\",\"e\":true,\"v\":\"1.2.6\",\"st\":1462255340684}},\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi\",\"e\":true,\"v\":\"46.0.1\",\"st\":1462255340478}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"e\":true,\"v\":\"10.3.3.13\",\"st\":1450016766771,\"mt\":1450016685045}}}"); C:\Users\theo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\Prefs.js user_pref("browser.newtab.url", "https://www.google.com"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "google"); user_pref("browser.search.selectedEngine", "yessearches"); user_pref("browser.startup.homepage", "https://www.google.com"); user_pref("browser.startup.homepage_override.buildID", "20140506152807"); user_pref("browser.startup.homepage_override.mstone", "29.0.1"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.InstallationThankYouPage", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.InstallationTime", 1385316094); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.active", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.addressbar", "NA"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.addressbarenhanced", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncdb_dbWasSet", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncdb_dbWasSet_FF25_FIX", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncinternaldb_dbWasSet", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncinternaldb_dbWasSet_FF25_FIX", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.backgroundver", 2); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.certdomaininstaller", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.changeprevious", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.InstallationTime.value", "1385316094"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_aoi.value", "%221388082914%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_parent_zoneid.value", "%22471395%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.iframe-exists.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.iframe-exists.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.jw_token.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.jw_token.value", "%221f3a3b11-c748-78b9-df85-60b111f6ffb7%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.load_balancer.expiration", "Sun Jan 05 2014 16:19:28 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%5C%22%3A%20%5C%22http%3A//api28.thetrafficstat.net%5C%22%20%7D%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.previous_page.value", "%22https%3A//www.google.fr/search%3Fq%3Dads+by+plusHD.9+%253F%26ie%3Dutf-8%26oe%3Dutf-8%26rls%3Dorg.mozilla%3Afr%3Aofficial%26client%3Dfirefox-a%26gws_rd%3Dcr%26ei%3DpDrJUr2EAdGU0QXN2YDYBA%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.user_id.value", "%221428b460e842d79ed93ef945a1d04940%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.description", "Turn YouTube videos to High Definition by default"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.domain", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.enablesearch", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.homepage", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.iframe", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22000680%22%2C%22sub_id%22%3A%220%22%2C%22uzid%22%3A%220%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_appVer.value", "54"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_lastVersion.value", "1"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_meta.value", "%7B%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_nextCheck.expiration", "Sun Jan 05 2014 16:19:08 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_nextCheck.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_queue.value", "%7B%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.__194_lastCheck__.expiration", "Sun Jan 05 2014 11:59:48 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.__194_lastCheck__.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb._country_code_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb._country_code_.value", "%22FR%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D%2C%22version%22%3A%221.30.153.0%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.lastDailyReport", "1388898872839"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.lastUpdate", "1388913548870"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.manifesturl", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.newtab", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.opensearch", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.pluginsurl", "https://w9u6a2p6.ssl.hwcdn.net/plugin/apps/45918/plugins/093/ff/plugins.json"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.pluginsversion", 48); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.publisher", "Plus HD"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.searchstatus", 0); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.setnewtab", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.thankyou", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.updateinterval", 360); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.ver", 54); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.apps", "45918"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.bic", "1428b460e842d79ed93ef945a1d04940"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.cid", 45918); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.firstrun", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.hadappinstalled", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.installationdate", 1385316094); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.modetype", "production"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.reportInstall", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.statsDailyCounter", 47); user_pref("extensions.adblockplus.currentVersion", "1.8"); user_pref("extensions.adblockplus.fastcollapse", true); user_pref("extensions.adblockplus.lastRuleUpdate", 1375302878); user_pref("extensions.autoDisableScopes", 10); user_pref("extensions.blocklist.pingCountTotal", 198); user_pref("extensions.blocklist.pingCountVersion", 19); user_pref("extensions.checkCompatibility.", false); user_pref("extensions.databaseSchema", 16); user_pref("extensions.enabledAddons", "wrc%40avast.com:8.0.1497,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1"); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20140319.01"); user_pref("extensions.lastAppVersion", "29.0.1"); user_pref("extensions.lastPlatformVersion", "29.0.1"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/plugin"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.wrc.SearchRules.google.com.url", "^http(s)?\\:\\/\\/((.)+\\.)?google\\.(com|[a-z\\.]{2,})\\/(.)*"); user_pref("extensions.wrc.SearchRules.public.avast.com.url", "^http(s)?\\:\\/\\/public\\.avast\\.com\\/(.)*"); user_pref("extensions.wrc.SearchRules.seznam.cz.url", "^http(s)?\\:\\/\\/search\\.seznam\\.cz\\/(.)*"); C:\Users\theo\AppData\Roaming\Mozilla\Firefox\Profiles\opo7jdgy.default\Prefs.js user_pref("browser.search.defaultengine", "Google"); user_pref("browser.startup.homepage_override.buildID", "20140506152807"); user_pref("browser.startup.homepage_override.mstone", "29.0.1"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.InstallationThankYouPage", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.InstallationTime", 1385316094); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.active", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.addressbar", "NA"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.addressbarenhanced", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncdb_dbWasSet", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncdb_dbWasSet_FF25_FIX", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncinternaldb_dbWasSet", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.asyncinternaldb_dbWasSet_FF25_FIX", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.backgroundver", 2); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.certdomaininstaller", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.changeprevious", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.InstallationTime.value", "1385316094"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_aoi.value", "%221388082914%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie._GPL_parent_zoneid.value", "%22471395%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.iframe-exists.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.iframe-exists.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.jw_token.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.jw_token.value", "%221f3a3b11-c748-78b9-df85-60b111f6ffb7%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.load_balancer.expiration", "Sun Jan 05 2014 16:19:28 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%5C%22%3A%20%5C%22http%3A//api28.thetrafficstat.net%5C%22%20%7D%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.previous_page.value", "%22https%3A//www.google.fr/search%3Fq%3Dads+by+plusHD.9+%253F%26ie%3Dutf-8%26oe%3Dutf-8%26rls%3Dorg.mozilla%3Afr%3Aofficial%26client%3Dfirefox-a%26gws_rd%3Dcr%26ei%3DpDrJUr2EAdGU0QXN2YDYBA%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.cookie.user_id.value", "%221428b460e842d79ed93ef945a1d04940%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.description", "Turn YouTube videos to High Definition by default"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.domain", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.enablesearch", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.homepage", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.iframe", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22000680%22%2C%22sub_id%22%3A%220%22%2C%22uzid%22%3A%220%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_appVer.value", "54"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_lastVersion.value", "1"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_meta.value", "%7B%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_nextCheck.expiration", "Sun Jan 05 2014 16:19:08 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_nextCheck.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_queue.value", "%7B%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.__194_lastCheck__.expiration", "Sun Jan 05 2014 11:59:48 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.__194_lastCheck__.value", "true"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb._country_code_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb._country_code_.value", "%22FR%22"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%22417AC21808994E42BB6EA5C27AA07669IE%22%2C%22installer_verifier%22%3A%229dfe148ed3cbc3dabf34f51d8da0d1b5%22%7D%2C%22version%22%3A%221.30.153.0%22%7D"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.lastDailyReport", "1388898872839"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.lastUpdate", "1388913548870"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.manifesturl", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.newtab", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.opensearch", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.pluginsurl", "https://w9u6a2p6.ssl.hwcdn.net/plugin/apps/45918/plugins/093/ff/plugins.json"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.pluginsversion", 48); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.publisher", "Plus HD"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.searchstatus", 0); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.setnewtab", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.thankyou", ""); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.updateinterval", 360); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.45918.ver", 54); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.apps", "45918"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.bic", "1428b460e842d79ed93ef945a1d04940"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.cid", 45918); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.firstrun", false); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.hadappinstalled", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.installationdate", 1385316094); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.modetype", "production"); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.reportInstall", true); user_pref("extensions.ad019febeeb2b4057a3f27def88f2c9cd1cced8ec0ffe43eab4b2fbce5de8e9a4com45918.statsDailyCounter", 47); user_pref("extensions.adblockplus.currentVersion", "1.8"); user_pref("extensions.adblockplus.fastcollapse", true); user_pref("extensions.adblockplus.lastRuleUpdate", 1375302878); user_pref("extensions.blocklist.pingCountTotal", 198); user_pref("extensions.blocklist.pingCountVersion", 19); user_pref("extensions.databaseSchema", 16); user_pref("extensions.enabledAddons", "wrc%40avast.com:8.0.1497,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1"); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20140319.01"); user_pref("extensions.lastAppVersion", "29.0.1"); user_pref("extensions.lastPlatformVersion", "29.0.1"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/plugin"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.wrc.SearchRules.google.com.url", "^http(s)?\\:\\/\\/((.)+\\.)?google\\.(com|[a-z\\.]{2,})\\/(.)*"); user_pref("extensions.wrc.SearchRules.public.avast.com.url", "^http(s)?\\:\\/\\/public\\.avast\\.com\\/(.)*"); user_pref("extensions.wrc.SearchRules.seznam.cz.url", "^http(s)?\\:\\/\\/search\\.seznam\\.cz\\/(.)*"); user_pref("browser.search.defaultenginename", "google"); ---------- | Active Connections TCP 127.0.0.1:5354 theo-HP:49675 ESTABLISHED 1748 TCP 127.0.0.1:5354 theo-HP:49678 ESTABLISHED 1748 TCP 127.0.0.1:5354 theo-HP:54046 ESTABLISHED 1748 TCP 127.0.0.1:5354 theo-HP:54050 ESTABLISHED 1748 TCP 127.0.0.1:5354 theo-HP:54051 ESTABLISHED 1748 TCP 127.0.0.1:5354 theo-HP:54074 ESTABLISHED 1748 TCP 127.0.0.1:5354 theo-HP:54075 ESTABLISHED 1748 TCP 127.0.0.1:27015 theo-HP:49779 ESTABLISHED 1736 TCP 127.0.0.1:27015 theo-HP:54040 ESTABLISHED 1736 TCP 127.0.0.1:27015 theo-HP:54058 ESTABLISHED 1736 TCP 127.0.0.1:27015 theo-HP:54084 ESTABLISHED 1736 TCP 127.0.0.1:49675 theo-HP:5354 ESTABLISHED 1736 TCP 127.0.0.1:49678 theo-HP:5354 ESTABLISHED 1736 TCP 127.0.0.1:49779 theo-HP:27015 ESTABLISHED 2408 TCP 127.0.0.1:49981 theo-HP:49982 ESTABLISHED 6728 TCP 127.0.0.1:49982 theo-HP:49981 ESTABLISHED 6728 TCP 127.0.0.1:51533 theo-HP:51534 ESTABLISHED 1864 TCP 127.0.0.1:51534 theo-HP:51533 ESTABLISHED 1864 TCP 127.0.0.1:51536 theo-HP:51537 ESTABLISHED 1864 TCP 127.0.0.1:51537 theo-HP:51536 ESTABLISHED 1864 TCP 127.0.0.1:53334 theo-HP:53335 ESTABLISHED 6728 TCP 127.0.0.1:53335 theo-HP:53334 ESTABLISHED 6728 TCP 127.0.0.1:53937 theo-HP:53938 ESTABLISHED 8272 TCP 127.0.0.1:53938 theo-HP:53937 ESTABLISHED 8272 TCP 127.0.0.1:54040 theo-HP:27015 ESTABLISHED 4428 TCP 127.0.0.1:54046 theo-HP:5354 ESTABLISHED 4428 TCP 127.0.0.1:54050 theo-HP:5354 ESTABLISHED 4428 TCP 127.0.0.1:54051 theo-HP:5354 ESTABLISHED 4428 TCP 127.0.0.1:54058 theo-HP:27015 ESTABLISHED 4428 TCP 127.0.0.1:54074 theo-HP:5354 ESTABLISHED 1736 TCP 127.0.0.1:54075 theo-HP:5354 ESTABLISHED 1736 TCP 127.0.0.1:54084 theo-HP:27015 ESTABLISHED 8436 TCP 192.168.1.37:53325 162.125.32.129:https ESTABLISHED 6728 TCP 192.168.1.37:53485 ec2-52-203-78-26.compute-1.amazonaws.com:https CLOSE_WAIT 6728 TCP 192.168.1.37:53638 r-148-58-45-5.ff.avast.com:http CLOSE_WAIT 1864 TCP 192.168.1.37:54206 lon25.ff.avast.com:http ESTABLISHED 1864 TCP 192.168.1.37:54209 server-54-192-76-41.cdg50.r.cloudfront.net:https CLOSE_WAIT 6728 TCP 192.168.1.37:55531 r-72-58-45-5.ff.avast.com:http TIME_WAIT 0 TCP 192.168.1.37:55533 104.18.49.98:http CLOSE_WAIT 5128 TCP 192.168.1.37:55534 r-175-58-45-5.ff.avast.com:http TIME_WAIT 0 TCP 192.168.1.37:55535 r-175-58-45-5.ff.avast.com:http TIME_WAIT 0 TCP 192.168.1.37:55539 191.232.139.254:https ESTABLISHED 2964 ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{9b2df388-50fc-46e5-8d70-594d52bc5f4a}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{a1a17bb5-8243-4504-849c-11ac864e9a0d}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{c675deaf-f298-46ae-80b2-07975dfc608c}] "DhcpNameServer"=192.168.1.1 192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{f48cccfb-a39f-4b6b-ba29-471d555b5c89}] "DhcpNameServer"=192.168.1.1 192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{9b2df388-50fc-46e5-8d70-594d52bc5f4a}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{a1a17bb5-8243-4504-849c-11ac864e9a0d}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{c675deaf-f298-46ae-80b2-07975dfc608c}] "DhcpNameServer"=192.168.1.1 192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{f48cccfb-a39f-4b6b-ba29-471d555b5c89}] "DhcpNameServer"=192.168.1.1 192.168.1.1 ---------- | ActiveX [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] - () - [1,1,1,9] - -> [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - () - [10,0,10586,0] - -> [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - () - [12,0,10011,16384] - -> [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] - () - [10,0,10586,494] - -> [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - () - [11,71,10586,0] - -> [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - [] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player) - [12,0,10586,0] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\inf\unregmp2.exe /ShowWMP [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player 12.0) - [12,0,10011,16384] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] - (Themes Setup) - [1,1,1,9] - @%SystemRoot%\system32\themeui.dll,-2682 -> /UserInstall [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] - (Offline Browsing Pack) - [11,71,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - (Microsoft Windows) - [10,0,10586,0] - -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] - (DirectDrawEx) - [4,71,1113,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] - (Internet Explorer Help) - [11,71,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] - (Microsoft Windows Script 5.6) - [5,6,0,8833] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{583AC46A-4A6F-39BC-AEFD-1BC2759FFA51}] - (.NET Framework) - [4,0,30319,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] - (Internet Explorer Setup Tools) - [11,71,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] - (Browsing Enhancements) - [11,71,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - (Microsoft Windows Media Player) - [12,0,10011,16384] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /FirstLogon [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] - (MSN Site Access) - [4,9,9,2] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] - (Address Book 7) - [10,0,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] - (Windows Desktop Update) - [10,0,10586,494] - @%SystemRoot%\system32\shell32.dll,-32969 -> U [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - (Web Platform Customizations) - [11,71,10586,0] - @C:\Windows\System32\ie4uinit.exe,-2000 -> C:\Windows\System32\ie4uinit.exe -UserConfig [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - [] - -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] - (Dynamic HTML Data Binding) - [11,71,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] - (Internet Explorer Core Fonts) - [11,71,10586,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] - (HTML Help) - [10,0,10586,71] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] - (Active Directory Service Interface) - [5,0,00,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}] - (.NET Framework) - [2,0,50727,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player) - [12,0,10011,16384] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /ShowWMP [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player 12.0) - [12,0,10011,16384] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] - (Offline Browsing Pack) - [11,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - (Microsoft Windows) - [10,0,10586,0] - -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] - (DirectDrawEx) - [4,71,1113,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] - (Internet Explorer Help) - [11,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] - (Microsoft Windows Script 5.6) - [5,6,0,8833] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] - (Internet Explorer Setup Tools) - [11,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{600AC0DF-B614-36F9-9E10-28896BD4ACCA}] - (.NET Framework) - [4,0,30319,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] - (Browsing Enhancements) - [11,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - (Microsoft Windows Media Player) - [12,0,10011,16384] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /FirstLogon [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] - (MSN Site Access) - [4,9,9,2] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] - (Address Book 7) - [10,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}] - (.NET Framework) - [2,0,50727,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - () - [] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - [] - -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] - (Dynamic HTML Data Binding) - [11,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}] - (.NET Framework) - [2,0,50727,1] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] - (Internet Explorer Core Fonts) - [11,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] - (HTML Help) - [10,0,10586,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] - (Active Directory Service Interface) - [5,0,00,0] - -> ---------- | Applications [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Classes\Applications\gedit-setup-2.30.1-1.exe] : "C:\Users\theo\Pas important\Downloads\gedit-setup-2.30.1-1.exe" "%1" [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Classes\Applications\gedit.exe] : "C:\Program Files (x86)\gedit\bin\gedit.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\Classes\Applications\iTunes.exe] : "C:\Program Files (x86)\iTunes\iTunes.exe" /open "%L" [HKLM\SOFTWARE\Classes\Applications\LaunchWinApp.exe] : "C:\Windows\system32\LaunchWinApp.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\ois.exe] : C:\PROGRA~1\MICROS~2\Office14\OIS.EXE /shellOpen "%1" [HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\SumatraPDF.exe] : "C:\Program Files (x86)\SumatraPDF\SumatraPDF.exe" "%1" %* [HKLM\SOFTWARE\Classes\Applications\SZBrowser.exe] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\vlc.exe] : "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iTunes.exe] : "C:\Program Files (x86)\iTunes\iTunes.exe" /open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\LaunchWinApp.exe] : "C:\Windows\system32\LaunchWinApp.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ois.exe] : C:\PROGRA~1\MICROS~2\Office14\OIS.EXE /shellOpen "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\SumatraPDF.exe] : "C:\Program Files (x86)\SumatraPDF\SumatraPDF.exe" "%1" %* [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\SZBrowser.exe] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vlc.exe] : "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | DCOMApplications Name: User Notification - AppID: {0010890e-8789-413c-adbc-48f5b511b3af} Name: hpqwmiex - AppID: {0018752E-7735-4B30-9DA9-4A01F024F270} Name: PhotoAcquire - AppID: {00f22b16-589e-4982-a172-a51d9dcceb68} Name: PhotoAcqHWEventHandler - AppID: {00f2b433-44e4-4d88-b2b0-2698a0a91dba} Name: TabTip - AppID: {01419581-4d63-4d43-ac26-6e2fc976c1f3} Name: lfsvc - AppID: {020FB939-2C8B-4DB7-9E90-9527966E38E5} Name: PLA - AppID: {03837503-098b-11d8-9414-505054503030} Name: CTapiLuaLib Class - AppID: {03e15b2e-cca6-451c-8fb0-1e2ee37a27dd} Name: WPDBusEnum - AppID: {03f25b41-e981-4675-a256-27d1393e7488} Name: NvCpl - AppID: {048F26EF-2F89-46C9-99E7-481E40F3F2EC} Name: COpenControlPanel - AppID: {06622D85-6856-4460-8DE1-A81921B41C4B} Name: SMLUA - AppID: {0671E064-7C24-4AC0-AF10-0F3055707C32} Name: PhotoAcqDropTargetEventHandler - AppID: {06A2568A-CED6-4187-BB20-400B8C02BE5A} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {06C792F8-6212-4F39-BF70-E8C0AC965C23} Name: OOBE Bio Enrollment - AppID: {0771f7af-8de6-4bce-9528-2d4a12cb8168} Name: wpnservice - AppID: {077869D3-D0DE-4586-882B-359F80009D0C} Name: sppui - AppID: {0868DC9B-D9A2-4f64-9362-133CEA201299} Name: Retail Demo User COM Agent - AppID: {0886dae5-13ba-49d6-a6ef-d0922e502d96} Name: WIA Extension Host for 64 bit extensions - AppID: {08F646B3-5E7F-4B7A-A5CB-F95445F9F67A} Name: Proximity Sharing - AppID: {08FC06E4-C6B5-40BE-97B0-B80F943C615B} Name: PersistentZoneIdentifier - AppID: {0968e258-16c7-4dba-aa86-462dd61e31a3} Name: Windows Media Player Rich Preview Handler - AppID: {09C5C2B5-1D32-4598-B87E-203F32BB08E3} Name: QuickTimeShellExt - AppID: {0A18A436-2A7A-49F3-A488-30538A2F6323} Name: AxInstSv - AppID: {0B15AFD8-3A99-4A6E-9975-30D66F70BD94} Name: NotificationController App ID - AppID: {0B789C73-D8DA-416D-B665-C1603676CEB1} Name: RASDLGLUA - AppID: {0C3B05FB-3498-40C3-9C03-4B22D735550C} Name: %SystemRoot%\system32\appwiz.cpl - AppID: {0da7bfdf-c0a0-44eb-be82-b7a82c4721de} Name: HpDataProtection - AppID: {0FFE56BF-2994-42C1-81F6-C58F05825C98} Name: IIS W3 Control - AppID: {119817C9-666D-4053-AEDA-627D0E25CCEF} Name: IntelCpHeciSvc - AppID: {11AC3232-E7D7-49CD-ABFE-501700100B3A} Name: Sync Center Client - AppID: {1202DB60-1DAC-42C5-AED5-1ABDD432248E} Name: Virtual Factory for DiagCpl - AppID: {12C21EA7-2EB8-4B55-9249-AC243DA8C666} Name: Shell Create Object Task Server - AppID: {133eac4f-5891-4d04-bada-d84870380a80} Name: Shell Create Object Handler - AppID: {135fd325-45b7-4c30-89f8-4386961669f0} Name: TPM Virtual Smart Card VCard Module Manager - AppID: {150F28F1-49A5-4C28-BE1A-CFA854A1D04B} Name: Remote TPM Virtual Smart Card Manager - AppID: {152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC} Name: ExternalApplication Class - AppID: {1673EE5D-D576-4945-927D-920AFA24166D} Name: TPM Virtual Smart Card Manager - AppID: {16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A} Name: AppleSoftwareUpdateAdmin - AppID: {16D99191-6280-4B33-A2F5-04805A0FC582} Name: Immersive TPM Virtual Smart Card Manager - AppID: {19833350-BF9B-42A1-BDF0-BD1FCBE1FD31} Name: Sync Center Control - AppID: {1A1F4206-0688-4E7F-BE03-D82EC69DF9A5} Name: GIDS Smart Card Simulator Manager - AppID: {1AC32B1A-E379-4CAD-B655-F978A30856EC} Name: %systemroot%\system32\lpksetup.exe - AppID: {1C749B87-568C-4865-8E73-6413F8372CE6} Name: Disc soft DT Lite bus service - AppID: {1CA3841D-15B5-4C70-9751-7A87730A1BE9} Name: Office Licensing COM Server 14 - AppID: {1E886174-DC88-4B83-8BC5-66409EC75F14} Name: rshx32.dll - AppID: {1f2e5c40-9550-11ce-99d2-00aa006e086c} Name: ThirdPartyEapDispatcherPeerConfig - AppID: {1F7D1BE9-7A50-40B6-A605-C4F3696F49C0} Name: Microsoft WMI Provider Subsystem Secured Host - AppID: {1F87137D-0E7C-44d5-8C73-4EFFB68962F2} Name: DetectionAndSharing - AppID: {1fda955b-61ff-11da-978c-0008744faab7} Name: Microsoft Software Protection Platform Admin Object (Inner) - AppID: {205609B7-5E08-443E-B0A7-A7AED3F3A717} Name: Microsoft Windows WSMan Provider Host With User Settings - AppID: {209444d2-2540-495e-962c-a61ad3243526} Name: Provisioning Core - AppID: {217700E0-0000-11DF-ADB9-F4CE462D9137} Name: MSDAINITIALIZE - AppID: {2206CDB0-19C1-11D1-89E0-00C04FD7A829} Name: CortanaExperienceFlow - AppID: {24AC8F2B-4D4A-4C17-9607-6A4B14068F97} Name: IpodService - AppID: {250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30} Name: InstallAgent - AppID: {260eb9de-5cbe-4bff-a99a-3710af55bf1e} Name: Microsoft WBEM Active Scripting Event Consumer Provider - AppID: {266C72E7-62E8-11D1-AD89-00C04FD8FDFF} Name: Exchange Active Sync Policies Broker - AppID: {26795871-6B8F-4115-89DD-986213012798} Name: IMAPI2 - AppID: {273541FF-7F64-5B0F-8F00-5D77AFBE261E} Name: WInRTDesktopBroker - AppID: {27550CA0-E9DE-4186-A566-37A59BB6CA69} Name: Cloud Change Wnf Monitor - AppID: {276D4FD3-C41D-465F-8CA9-A82A7762DF32} Name: netman - AppID: {27AF75ED-20D9-11D1-B1CE-00805FC1270E} Name: WalletService - AppID: {27D6B72D-094D-445A-9ACE-8298CBA0611A} Name: RasMobilityManager - AppID: {292bed96-e9ce-40f8-b71b-c313defa3a78} Name: Windows Live Photo Gallery Autoplay Drop Target - AppID: {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} Name: faultrep.dll - AppID: {2C256447-3F0D-4CBB-9D12-575BB20CDA0A} Name: FileSystemImage - AppID: {2C941FD1-975B-59BE-A960-9A2A262853A5} Name: WalletService - AppID: {2EA38040-0B9C-4379-87FD-4D38BB892F37} Name: DevicesFlow - AppID: {2F93C02D-77F9-46B4-95FB-8CBB81EEB62C} Name: Immersive Shell Broker - AppID: {2FD08A73-D1F1-43EB-B888-24C2496F95FD} Name: ShellServiceHostBrokerProvider - AppID: {30AD8C8E-AE85-42FA-B9E8-7E99E3DFBFC5} Name: Identity Store - AppID: {30d49246-d217-465f-b00b-ac9ddd652eb7} Name: AuthHost - AppID: {31337EC7-5767-11CF-BEAB-00AA006C3606} Name: Immersive Shell - AppID: {316CDED5-E4AE-4B15-9113-7055D84DCC97} Name: BtwHtmlRenderer - AppID: {31FD10BC-77F2-46CC-909B-EA4070218D42} Name: Delivery Optimization Mgmt - AppID: {338B40F9-9D68-4B53-A793-6B9AA0C5F63B} Name: Language Components Installer Com Handler - AppID: {33ADC7D5-BAF1-4661-9822-1FD23E63B39F} Name: Windows Push Notification Platform - AppID: {362cc086-4d81-4824-bbb5-666d34b3197d} Name: TabTip - AppID: {36938566-B1AA-4E77-9B3F-730CF4E996AB} Name: Delivery Optimization - AppID: {379001DE-7108-4A45-8A74-6CD0A9FBEF2C} Name: Microsoft Portable Workspace Launcher - AppID: {37B73D7B-A976-43AE-97E4-BD4977B241F2} Name: CContactDb - AppID: {380689D0-AFAA-47E6-B80E-A33436FE314B} Name: RIMDeviceManager - AppID: {3943117E-57A9-4ED1-9EAA-2566BA544BFB} Name: GamesAppService - AppID: {394447FA-A1B8-4E2D-8677-3441FD66C004} Name: iTunesAddIn - AppID: {3AA2E692-0A50-496B-A91B-9F7AF63B3511} Name: Windows Media Center Search Protocol Handler - AppID: {3B07977C-7A38-455D-AAD5-88500A360D24} Name: LivePhotoAcqHWEventHandler - AppID: {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F} Name: CortanaMapiHelper - AppID: {3BFADDE5-09ED-42AE-8190-2E68B650CFE6} Name: WorkspacePolicyProcessor - AppID: {3C3F40BC-60EB-4567-B90C-480C87C21AC1} Name: igfxcfg - AppID: {3D62E9A1-D243-11D2-B561-00A0C92E6848} Name: CMLUAUTIL - AppID: {3E000D72-A845-4CD9-BD83-80C07C3B881F} Name: Microsoft Windows Remote Shell Host - AppID: {3e5ca495-8d6a-4d1f-ad99-177b426c8b8e} Name: CMSTPLUA - AppID: {3E5FC7F9-9A51-4367-9063-A120244FBEC7} Name: WinInetCacheServer - AppID: {3eb3c877-1f16-487c-9050-104dbcd66683} Name: Out Of Proc Mapi Handler - AppID: {3F5E4B87-C907-4f76-82E4-6FDF0CE90E25} Name: MSTTS DecObj Class Surrogate - AppID: {3F6B5E16-092A-41ED-930B-0B4125D91D4E} Name: Microsoft Windows WSMan Provider Host - AppID: {3feb2f63-0eec-4b96-84ab-da1307e0117c} Name: HTML Application - AppID: {40AEEAB6-8FDA-41e3-9A5F-8350D4CFCA91} Name: Connected User Store - AppID: {40AFA0B6-3B2F-4654-8C3F-161DE85CF80E} Name: EntAppSvc - AppID: {42C21DF5-FB58-4102-90E9-96A213DC7CE8} Name: AccessibilityCplAdmin - AppID: {434A6274-C539-4E99-88FC-44206D942775} Name: SPP External COM Object - AppID: {44831FEC-DC51-4716-A7E1-E898FDF83C85} Name: Thumbnail Extraction Host Class - AppID: {4545dea0-2dfc-4906-a728-6d986ba399a9} Name: Add to Windows Media Player list - AppID: {45597c98-80f6-4549-84ff-752cf55e2d29} Name: Application Activation Manager - AppID: {45BA127D-10A8-46EA-8AB7-56EA9078943C} Name: NvXDSync - AppID: {4680B596-CF8C-44E1-A676-4AAA819E041F} Name: Set Network Location Elevated Virtual Factory - AppID: {46B988E8-BEC2-401F-A1C5-16C694F26D3E} Name: RadioManagement Lib Class - AppID: {478B41E6-3257-4519-BDA8-E971F9843849} Name: ShellServiceHost - AppID: {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} Name: BbDevMgr - AppID: {4848DD90-EDA2-461F-8FE9-B47A067A5225} Name: IASDataStoreComServer - AppID: {48da6741-1bf0-4a44-8325-293086c79077} Name: Microsoft WBEM Unsecured Apartment - AppID: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Name: Telephony App Launcher - AppID: {49EBD8BE-1A92-4A86-A651-70AC565E0FEB} Name: UIAutomationCrossBitnessHook64 Class - AppID: {49f171dd-b51a-40d3-9a6c-52d674cc729d} Name: Virtual Factory for Languages Configuration - AppID: {4A3F2F56-454A-4CC5-9734-BB7D8141AC0A} Name: RASGCWLUA - AppID: {4A6B8BAD-9872-4525-A812-71A52367DC17} Name: wercplsupport.dll - AppID: {4BC67F23-D805-4384-BCA3-6F1EDFF50E2C} Name: Shell Security Editor - AppID: {4D111E08-CBF7-4f12-A926-2C7920AF52FC} Name: Microsoft Volume Shadow Copy Service software provider - AppID: {4db9c793-c48d-449c-9754-46027ee45c94} Name: COM+ Event System - AppID: {4E14FBA2-2E22-11D1-9964-00C04FBBB345} Name: ServiceModule - AppID: {4EB61BAC-A3B6-4760-9581-655041EF4D69} Name: upnpcont.exe - AppID: {4F0AC159-5804-4aa7-AE91-117D6E67BB9B} Name: Shell Computer Accounts - AppID: {4f6bcd94-c2a5-42ce-8dbc-31e794be4630} Name: WkspRT.exe - AppID: {4FCDA643-B15B-41C6-84F8-5E447F6F6D25} Name: iTunesAdmin - AppID: {5011B6DE-E9FA-4518-B5E5-45DE9DD2CDC6} Name: AvastGUIProxy - AppID: {5020EF2C-60F4-47BE-8918-A167229B11EE} Name: WLRemoteEnableAdmin - AppID: {5032734C-9867-41BF-ABDD-24513D68E613} Name: HomeGroup CPL Advanced Settings Writer - AppID: {50a9ab2a-20f8-4d71-9f32-9fd305b49601} Name: Microsoft Windows Font Folder - AppID: {50d69d24-961d-4828-9d1c-5f4717f226d1} Name: wuapihost - AppID: {50E1C3FD-EC35-490E-9CCF-C68F9AE91919} Name: acppage.dll - AppID: {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} Name: %systemroot%\system32\intl.cpl - AppID: {514B5E31-5596-422F-BE58-D804464683B5} Name: enapi - AppID: {5197362F-09ED-45A1-8A5F-E8BD7A7837CA} Name: RemoteProxyFactory32 Class - AppID: {53362C32-A296-4F2D-A2F8-FD984D08340B} Name: RemoteProxyFactory32 Class - AppID: {53362C64-A296-4F2D-A2F8-FD984D08340B} Name: 32-bit Preview Handler Surrogate Host - AppID: {534A1E02-D58F-44f0-B58B-36CBED287C7C} Name: Virtual Disk Service Loader - AppID: {5364ED0E-493F-4B16-9DBF-AE486CF22660} Name: LockScreenContentServer Out of Proc Helper for LockScreenContent Clients - AppID: {536AACFB-5238-4314-B4D4-5B0A2E8B968E} Name: UNS - AppID: {545C8D56-7A88-492D-B38D-559657A3DD4C} Name: ShareFlow - AppID: {549e57e9-b362-49d1-b679-b64d510efe4b} Name: STAPODll - AppID: {5534E918-4467-405a-8002-8C30E1463157} Name: SRS_APO_Universal - AppID: {553C48B2-BA6B-412B-9F8D-2B62B1B912AA} Name: WindowsLiveWriter.exe - AppID: {5564D5FC-DB2D-4658-8DB9-86B822815961} Name: Bonjour - AppID: {56608F9C-223B-4CB6-813D-85EDCCADFB4B} Name: ShapeCollector - AppID: {56676660-4A4D-45B0-B24E-9CF6B35E9ABF} Name: WT - AppID: {568C34F6-73E1-4F3E-ADAE-FF34A076294C} Name: Volume Shadow Copy Service - AppID: {56BE716B-2F76-4dfa-8702-67AE10044F0B} Name: Elevated System Settings COM Host - AppID: {57360832-5F9B-4190-8467-000D2D510212} Name: PrintNotify - AppID: {588E10FA-0618-48A1-BE2F-0AD93E899FCC} Name: FaxCommon Class - AppID: {59347292-B72D-41F2-98C5-E9ACA1B247A2} Name: Authentication UI Terminal Services Bump Dialog - AppID: {59c7f6ec-7d18-412f-a68e-877982768e61} Name: Video Capture Wizard - AppID: {5AB7566D-F75B-4A53-9615-115B6CB1D59B} Name: WalletService - AppID: {5BC7A3A1-E905-414B-9790-E511346F5CA6} Name: Microsoft Maps Background Transfer Service - AppID: {5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309} Name: %SystemRoot%\System32\wsclient.dll - AppID: {5C917E9C-0B2F-40D6-928B-5C43FDB16DF4} Name: WLXMP4ParserThumbnailProvider - AppID: {5D6E8BC8-01F3-41CC-BF7D-D7EEF436896E} Name: WiaWow64 - AppID: {5E1395B2-B685-44e3-8AED-E2304D85ACD1} Name: Splash screen - AppID: {5EAD00DC-0E8B-497C-BDE8-B9153058CBEF} Name: MSSHED - AppID: {5F6C4077-12F5-11D3-8CEE-005004838434} Name: User OOBE Create User Object Server - AppID: {5f7f3f7b-1177-4d4b-b1db-bc6f671b8f25} Name: UIAutomationCrossBitnessHook32 Class - AppID: {60a90a2f-858d-42af-8929-82be9d99e8a1} Name: PDFPrevHndlr - AppID: {6236FF8C-E747-4173-86D3-99F511B61DF3} Name: wlidcli - AppID: {623D5F5E-2F09-427d-8BD7-64495CD9835D} Name: Sync Center (Private) - AppID: {6295DF2D-35EE-11D1-8707-00C04FD93327} Name: BBWebSLLauncher - AppID: {6326880C-E92B-4AE2-BC06-78DF910A7F7B} Name: SRSApoPropPageUAPOExt - AppID: {63544692-8B3E-4207-BB60-965E6F1BCE42} Name: ComUpdatus - AppID: {6390FFFB-1C89-4E0C-AE24-76102B99F750} Name: PenIMC2 - AppID: {63CE6D27-426A-41F9-8E51-549C1132DAE2} Name: Windows Update Agent - AppID: {653C5148-4DCE-4905-9CFD-1B23662D3D9E} Name: FwCplLUA - AppID: {6571503D-D0FB-4D98-BBC3-1FBB2B3F344E} Name: Found New Hardware Wizard - AppID: {658A269B-B922-4e62-B519-50B1CF0787D1} Name: tiledatamodelsvc - AppID: {65E2E13A-7110-4912-9F03-9A42E253D8F6} Name: AvAScr - AppID: {66A841F2-956C-4631-BFE7-C90225F417D6} Name: Background Intelligent Transfer Service - AppID: {69AD4AEE-51BE-439b-A92C-86AE490E8B30} Name: Sync Center Isolation Collection (Private) - AppID: {69F9CB25-25E2-4BE1-AB8F-07AA7CB535E8} Name: SoftwareUpdateApp - AppID: {6A070EEA-E3F8-411E-9D3A-F3814ED6D1A8} Name: MsRdpSessionManager - AppID: {6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F} Name: Watson subscriber for SENS Network Events - AppID: {6CF90891-3E04-4092-B96C-28E071EEEACB} Name: Preview Handler Surrogate Host - AppID: {6d2b5079-2f0b-48dd-ab7f-97cec514d30b} Name: UPnPContainer - AppID: {6d8ff8e0-730d-11d4-bf42-00b0d0118b56} Name: UPnPContainer64 - AppID: {6d8ff8e8-730d-11d4-bf42-00b0d0118b56} Name: SPPComApi - AppID: {6D9A7A40-DDCA-414E-B48E-DFB032C03C1B} Name: TieringEngineService - AppID: {6DF5BCF4-22E9-446D-8763-A2C7677ECF7D} Name: HomeGroup UI Status - AppID: {6f33340d-8a01-473a-b75f-ded88c8360ce} Name: IEWindows - AppID: {6f5bad87-9d5e-459f-bd03-3957407051ca} Name: EditionUpgradeHelper - AppID: {6F65B602-F798-4094-8A41-A2A61961E5E8} Name: HomeGroup Provider Object - AppID: {6F7C8E8F-DC69-4e3f-BC05-439962A05FD5} Name: Out of proc server to enable Insider Hub and Feedback App scenarios to be reached from inside of its appcontainer - AppID: {7006698d-2974-4091-a424-85dd0b909e23} Name: WindowsLiveWriterFilter - AppID: {7054B371-09E3-4BC8-8A61-02D7799EA98A} Name: workfolderssvc - AppID: {712cedb9-16a4-4f79-801d-7de24d8c706e} Name: Sharing Elevated Virtual Factory - AppID: {72A7994A-3092-4054-B6BE-08FF81AEEFFC} Name: User Profile Service DCOM server - AppID: {72E3272B-4EEA-4104-B358-1A282E4FC1AD} Name: Microsoft WMI Provider Subsystem Host - AppID: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} Name: Trusted Installer Service - AppID: {752073A2-23F2-4396-85F0-8FDB879ED0ED} Name: PenIMC4 - AppID: {7568952A-571E-4C70-BEA9-7F9004393436} Name: PrintFilterPipelineSvc - AppID: {76db1bf3-e820-4765-a1b2-0b16a86b1950} Name: ServiceModule - AppID: {76E258F0-DE86-4CEC-9D30-3F728A898741} Name: XWizard Virtual Factory - AppID: {777BA81A-2498-4875-933A-3067DE883070} Name: AcroIEHelperShim - AppID: {77AB4812-5411-4EA9-8437-77AD0F230302} Name: Network and Sharing Center Cpl Elevated Virtual Factory - AppID: {7A076CE1-4B31-452a-A4F1-0304C8738100} Name: Shell FMIFS Wrapper - AppID: {7aa7790d-75d7-484b-98a1-3913d022091d} Name: EapThirdPartyDllHost - AppID: {7B130458-E09C-4823-A8AF-2583DCD9AEC7} Name: Internet Explorer Add-on Installer - AppID: {7B29F495-0F55-49F7-8885-9E8A22CE3829} Name: Shell Create Object Local Server - AppID: {7B6EA1D5-03C2-4AE4-B21C-8D0515CC91B7} Name: WlanPrefLUA - AppID: {7C8AB6D9-8764-4033-8F62-2FE896E54B32} Name: Microsoft Windows Remote Shell Host With User Settings - AppID: {7d378de6-ed8d-426d-91df-0273d07cd7f6} Name: HomeGroup Printing Device Class - AppID: {7DF8EF76-D449-485f-B4EB-58DC96B31EDB} Name: MMC Application Class - AppID: {7e0423cd-1119-0928-900c-e6d4a52a0715} Name: wisptis - AppID: {7F429620-16D1-471E-A81A-114992148034} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {7FC12E96-4CB7-4ABD-ADAA-EF7845B10629} Name: hputils - AppID: {8195693E-0C55-4BE2-A2DB-32376ABC24C4} Name: OpenOffice Service Manager (Ver 1.0) - AppID: {82154420-0FBF-11d4-8313-005004526AB4} Name: CFmIfsEngine host - AppID: {82D94FB3-7FE6-4797-BB72-9A886C66073B} Name: CustReg Class - AppID: {84D586C4-A423-11D2-B943-00C04F79D22F} Name: APSDaemon - AppID: {85187E17-383D-4EC5-B8D6-D9466EE3DD92} Name: Virtual Factory for Usercpl - AppID: {86d5eb8a-859f-4c7b-a76b-2bd819b7a850} Name: CElevateWlanUi - AppID: {86F80216-5DD6-4F43-953B-35EF40A35AEE} Name: ThirdPartyEapDispatcherPeerRuntime - AppID: {87BB326B-E4A0-4DE1-94F0-B9F41D0C6059} Name: AppReadiness Service - AppID: {88283d7c-46f4-47d5-8fc2-db0b5cf0cb54} Name: Activation Manager Shim - AppID: {8A9AE632-CB07-4A11-8872-358A2A271A24} Name: Desktop Wallpaper Factory - AppID: {8B30085D-A3E3-44e3-AE7F-B03A1340EBED} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {8B8C2776-594E-41EA-90D0-8013CACBB9A7} Name: Windows Management and Instrumentation - AppID: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Name: TSTheme - AppID: {8be0366c-8522-40be-8b08-cb26557f2854} Name: IASExtensionHost - AppID: {8C334A55-DDB9-491C-817E-35A6B85D2ECB} Name: AP Client HxHelpPaneServer Class - AppID: {8cec58ae-07a1-11d9-b15e-000d56bfe6ee} Name: TiWorker - AppID: {8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D} Name: Sync Center Schedule Wizard - AppID: {8D8B8E30-C451-421B-8553-D2976AFA648C} Name: WalletService - AppID: {8E44A57C-5638-44D3-9B83-34DF70EB57F2} Name: RdpSa - AppID: {8e7fae4d-cff0-41d3-a326-5a80470264bb} Name: Shell Computer Groups - AppID: {8f3080a6-af99-4f2e-a806-f3d5702a0444} Name: SDRSVC service - AppID: {9037e3cf-1794-4af6-9c8d-92838d7a23db} Name: Virtual Factory for Recovery - AppID: {9200689A-F979-4eea-8830-0E1D6B74821F} Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients - AppID: {924DC564-16A6-42EB-929A-9A61FA7DA06F} Name: HtmlLocalFileResolver - AppID: {93AAD2A0-036A-4B11-A078-DA8776B38139} Name: ServiceModule - AppID: {9465B4B4-5216-4042-9A2C-754D3BCDC410} Name: ServiceModule - AppID: {96D1EED3-701E-4FE5-B996-A543A8465897} Name: PrintIsolationHost - AppID: {98a89e0c-1fde-4c2a-a373-b04831e6aa60} Name: Telephony Incoming Call Toast - AppID: {990F07C7-78DC-4BD2-B145-5F791410BDDE} Name: Shell Hardware Mixed Content Handler - AppID: {995C996E-D918-4a8c-A302-45719A6F4EA7} Name: WLXAutoPlayMgr - AppID: {9B5CDBB0-6D57-4816-BD04-CA9E68DF5610} Name: ShellWindows - AppID: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Name: NVXDPlcy - AppID: {9C5791C4-BCD3-48B8-A10D-CA0279320836} Name: RuntimeBroker - AppID: {9CA88EE3-ACB7-47c8-AFC4-AB702511C276} Name: BioMonitor - AppID: {9D6D21E6-597F-4B63-8CEB-736F77BD2A5E} Name: timedate.cpl - AppID: {9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8} Name: WSearch - AppID: {9E175B9C-F52A-11D8-B9A5-505054503030} Name: WMLSS - AppID: {9E88EF3C-E2BB-4E5E-AFBA-565B81069D7D} Name: ahadmin - AppID: {9fa5c497-f46d-447f-8011-05d03d7d7ddc} Name: CDP Reference Host - AppID: {A0316E2D-8793-4E74-AA48-8CE2ED05BA57} Name: Live Remote Client ActiveX - AppID: {A0CEBC38-C926-4324-A373-ACCA224B549D} Name: WIA Device Manager - AppID: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Name: TrayNotify - AppID: {a2b77517-6d12-4c60-b0c6-725e971ec8fe} Name: rundll32.exe - AppID: {a2d9ca22-a492-400c-b875-78ac25c0a6f3} Name: MhegVM - AppID: {A3637A1F-8CD0-4DA3-9EF5-CC0BD38AF308} Name: Virtual Factory for Windows Firewall Cpl - AppID: {A4B07E49-6567-4FB8-8D39-01920E3B2357} Name: Shell ChkdskEx Dialog - AppID: {a4c31131-ff70-4984-afd6-0609ced53ad6} Name: Nv3DAppShExt - AppID: {A4CF1DBB-664A-4600-9CE3-96FBAA344504} Name: DsmAdminApi - AppID: {A5065670-136D-4FD6-A45F-00C85B90359C} Name: PDFShellInfo - AppID: {A5090E95-F1E2-41C8-BDA1-5AEB6C321FDE} Name: WPDShextAutoplay - AppID: {A55803CC-4D53-404c-8557-FD63DBA95D24} Name: WLIDSvc - AppID: {A6721677-BA21-44E9-9E2A-76466D24D121} Name: Virtual Factory for MaintenanceUI - AppID: {A6BFEA43-501F-456F-A845-983D3AD7B8F0} Name: updaterActiveX - AppID: {A75E0259-1AE1-4046-A5CA-27B2A0DAA8A6} Name: Microsoft Windows Defender - AppID: {A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F} Name: %SystemRoot%\System32\fveui.dll - AppID: {A7A63E5C-3877-4840-8727-C1EA9D7A4D50} Name: SysFxUi - AppID: {A7D2EC8B-B70F-434C-A0CE-0DF324805F7D} Name: VirtualBoxAsw Application - AppID: {A8F69786-BC63-417e-85AF-A2C2D3833032} Name: Delivery Optimization Mgmt - AppID: {AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800} Name: F12AppFrameClient Class - AppID: {AABAA6AA-5398-4C08-AE60-6321A7F05E9C} Name: DEFRAGSVC service - AppID: {ab7c873b-eb14-49a6-be60-a602f80e6d22} Name: Thumbnail Cache Out of Proc Server - AppID: {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} Name: BDEUILauncher Class - AppID: {AB93B6F1-BE76-4185-A488-A9001B105B94} Name: Out of proc server to enable Insider Hub scenarios to be reached from inside of its appcontainer - AppID: {ac0fd47a-37f4-4502-bfee-6b317e479d41} Name: RetailDemo Service - AppID: {ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325} Name: Windows Live Social Object Extractor Engine - AppID: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Name: WPN Srumon Server - AppID: {ada41b3c-c6fd-4a08-8cc1-d6efde67be7d} Name: SwHelper_1163633 - AppID: {AF551664-D2DF-4E34-85DE-46320B13A0B4} Name: TrayToastActivator - AppID: {AFC732E2-BA57-4B3E-A70A-71371F99B871} Name: WorkspaceBroker Class - AppID: {B06FF84E-0A77-4DD2-A919-0EABD8979DC1} Name: TabIps - AppID: {B1445657-5A98-11d9-A4E5-00301BB132BA} Name: DockInterface COM server - AppID: {b21858c6-9711-4257-99c8-5c0084bebce1} Name: Windows Update Agent - Remote Access - AppID: {B366DEBE-645B-43A5-B865-DDD82C345492} Name: AppActivationFailedHandler - AppID: {B3AADFEA-8404-4CBE-A62E-B0B715412C9E} Name: Out Of Proc Mapi Handler - AppID: {b5453d2d-5ad4-4df7-a399-0245244a4b60} Name: Found New Hardware Wizard - AppID: {B6A32FE6-E29D-AEAE-A608-D273E40CA34C} Name: WIA Device Manager 2 - AppID: {B6C292BC-7C88-41EE-8B54-8EC92617E599} Name: Sync Center (Private) - AppID: {B8558612-DF5E-4F95-BB81-8E910B327FB2} Name: WLX Thumbnail Cache Out of Proc Server - AppID: {B8A2E14E-290D-4122-B092-1A7D86198CCE} Name: Windows Media Player - AppID: {B8C54A54-355E-11D3-83EB-00A0C92A2F2D} Name: NVXDApiX - AppID: {B92B577B-628A-442B-A017-E86FB518C6FD} Name: ApplicationActivationImpl - AppID: {B9305506-D05B-4C36-81C5-0E50886C1755} Name: Application Frame Host - AppID: {B9B05098-3E30-483F-87F7-027CA78DA287} Name: Event Object Change 2 - AppID: {BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4} Name: AcroPDF - AppID: {BBAA0E44-3862-490C-8E63-AC2D2D6EF733} Name: SyncHost - AppID: {BBC4356A-F004-4628-A27A-E13D70412B70} Name: Virtual Factory for Power Options Control Panel - AppID: {BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B} Name: Setting Sync Task Factory - AppID: {bcbb3f8c-2889-474f-8fb7-904d4a416145} Name: DfsShlEx.dll - AppID: {BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B} Name: EditionUpgradeManagerObj - AppID: {BD54C901-076B-434E-B6C7-17C531F4AB41} Name: VM IC Heartbeat Service - AppID: {be0fc7f0-f248-4091-a123-34ca29a6901b} Name: Shell AutoPlay Direct - AppID: {BF8841C9-378A-4CAD-B4FC-5091366CBC0D} Name: BTStackServer - AppID: {C05A68C7-580B-11D4-98D0-006008BF430C} Name: ShellBrowserWindow - AppID: {c08afd90-f2a1-11d1-8455-00a0c91f3880} Name: LockAppHost Out of Proc Helper for Lock Apps - AppID: {C08B030B-E91C-479D-BEFD-02DDA7FF1BCF} Name: provsvc.dll - AppID: {c2a71820-3463-498f-bab7-4798795a2ff6} Name: DataExchangeHost - AppID: {C2E9756F-8155-4EAC-9ED5-0B690169D412} Name: cttunesvr - AppID: {C3A34354-660F-41EE-B072-2AEA5E3A80AF} Name: Microsoft Block Level Backup Service - AppID: {C3B65D83-FB15-4e3f-BA04-097D1E2B5AC1} Name: Microsoft IMAPI - AppID: {C49F2185-50A7-11D3-9144-00104BA11C5E} Name: BdeUISrv - AppID: {C4AB7CB7-E735-48FF-AADD-39D09668F444} Name: HomeGroup Listener Service - AppID: {C4CDC408-581C-4480-9FFE-3B1C78D5C20D} Name: Xbox Live Game Saves - AppID: {C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3} Name: Nvvsvc - AppID: {C5EDFC9D-B018-41A4-9877-39AB18469C3A} Name: EntAppSvc - AppID: {C63261E4-6052-41FF-B919-496FECF4C4E5} Name: EmailClient Class - AppID: {C6E0A4C8-A933-411E-8068-406C2391665F} Name: LockScreen Application Notification Broker - AppID: {C89FC3EF-A0DC-4feb-BFBC-F13A9C334D4F} Name: TSWbPrxy.exe - AppID: {C92A9617-0EAE-4235-BD2B-84540EF1FFA9} Name: DictationHost Class - AppID: {C945AD06-534F-460C-8CB4-17C33099AF81} Name: Sync Infrastructure - AppID: {C947D50F-378E-4FF6-8835-FCB50305244D} Name: netprofm - AppID: {C96887DA-A652-4426-905E-4A37546F847C} Name: editionupgradebroker - AppID: {C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125} Name: RCM - AppID: {C9F65BA8-1F8F-4382-AE27-C91FFB29275F} Name: User OOBE Create Elevated Object Server - AppID: {ca8c87c1-929d-45ba-94db-ef8e6cb346ad} Name: OpenSearch Description Create Search Connector Verb Handler - AppID: {CB1DFE3A-EDFF-4d1f-867D-8ADB02926F4B} Name: PrintIsolationSessionHost - AppID: {CB363445-F453-4C1E-8EE4-BD123C5E394F} Name: SkypeIEPlugin - AppID: {CB487EA6-E83B-4F63-8CAE-B1B1D23DA65E} Name: EnhancedStorageShell - AppID: {CC70FEAD-94B9-4F76-88CC-004BB068ACDF} Name: sppui - AppID: {CCFDD24D-CEAB-458B-A4F1-F884973395DF} Name: WcsPlugInServiceLib - AppID: {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607} Name: Windows Media Player Burn Audio CD Handler - AppID: {cdc32574-7521-4124-90c3-8d5605a34933} Name: Elevated-Unelevated Explorer Factory - AppID: {CDCBCFCA-3CDC-436f-A4E2-0E02075250C2} Name: PNPXAssoc.dll - AppID: {cee8ccc9-4f6b-4469-a235-5a22869eef03} Name: sdchange - AppID: {CF254B00-1986-4b24-A92D-463D01F7E395} Name: Event Object Change - AppID: {D0565000-9DF4-11D1-A281-00C04FCA0AA7} Name: HealthDriverBridge - AppID: {D190DCB4-AAAB-4507-A0AF-0AD12F2603A4} Name: Winmgmt MOF Compiler OOP - AppID: {D215781D-019E-4FA0-903D-0CDCDE13A4F5} Name: Color Management - AppID: {D2E7041B-2927-42fb-8E9F-7CE93B6DC937} Name: Bitmap Image - AppID: {D3E34B21-9D75-101A-8C3D-00AA001A1652} Name: ghost - AppID: {D58F39FF-953E-4F45-898F-59F243B9A523} Name: Sync Center User Profile Notification Handler - AppID: {D63AA156-D534-4BAC-9BF1-55359CF5EC30} Name: CloudStorageWizard - AppID: {D8775A07-C529-4EA7-B307-BA7C8CBBDA03} Name: Microsoft Software Protection Platform Admin Object (outer) - AppID: {D8D4249F-A8FB-44A7-8AA0-564E8C385BD6} Name: MSMQ - AppID: {DCBCADF5-DB1b-4764-9320-9a5082af1581} Name: BrowserBrokerServer - AppID: {DD9C53BC-8441-4B94-BD0E-36E6E02A6D61} Name: Srumon Server - AppID: {ddcfd26b-feed-44cd-b71d-79487d2e5e5a} Name: rundll32.exe - AppID: {de5d803e-5d2a-4b5f-9c63-af25a465cc44} Name: AccStore Class - AppID: {DE5DBCDC-104A-4cbc-A4D5-0C2104A142C5} Name: LockScreen Call Broker - AppID: {DE7D3D65-5454-4EF5-9518-776739DAB39F} Name: Profile Notification Host - AppID: {E10F6C3A-F1AE-4adc-AA9D-2FE65525666E} Name: Immersive Print Dialog Surrogate - AppID: {E15FBAC2-C276-4523-92CA-561456EBCF3E} Name: Windows Update Agent User Interface for Published Applications - AppID: {e30984f1-b02b-4c27-a40f-23d11b8c1212} Name: Scan - AppID: {E32549C4-C2B8-4BCC-90D7-0FC3511092BB} Name: Execute Unknown - AppID: {e44e9428-bdbc-4987-a099-40dc8fd255e7} Name: upnphost - AppID: {E495081B-BBA5-4b89-BA3C-3B86A686B87A} Name: TrayDesktopBand - AppID: {E6442437-6C68-4f52-94DD-2CFED267EFB9} Name: Orchestrator Service - AppID: {E7299E79-75E5-47BB-A03D-6D319FB7F886} Name: TokenBroker Out Of Proc COM Server - AppID: {E73A797B-24CE-424A-AD4F-48E98B1E95B8} Name: UICOM - AppID: {E8054D20-497D-4E16-BF41-6E69FCD381A5} Name: iisctl - AppID: {E8FB8615-588F-11D2-9D61-00C04F79C5FE} Name: wscui.cpl - AppID: {E9495B87-D950-4ab5-87A5-FF6D70BF3E90} Name: Remove Device elevation surrogate - AppID: {E95186C7-7D80-4311-843D-0702CBC8B1E4} Name: File Prop Sheet Page Helper - AppID: {E96767E0-7EAA-45E1-8E7D-64414AFF281A} Name: HomeGroup Provider Service - AppID: {EA022610-0748-4c24-B229-6C507EBDFDBB} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8} Name: Immersive Print Dialog Surrogate - AppID: {EB28E902-728E-42C4-97DC-DA89E144C744} Name: Remote Desktop Services Message Server - AppID: {EB521D7D-4095-4E61-88FB-BF25700F142A} Name: ComEvents.ComServiceEvents - AppID: {ECABB0C3-7F19-11D2-978E-0000F8757E2A} Name: ComEvents.ComSystemAppEventData - AppID: {ECABB0C6-7F19-11D2-978E-0000F8757E2A} Name: Play with Windows Media Player - AppID: {ed1d0fdf-4414-470a-a56d-cfb68623fc58} Name: SWDNLD - AppID: {ED372EB0-5B14-484F-A27C-05FF89B6DF25} Name: Windows Media Player Launch - AppID: {ED6BB178-B06A-47ad-98B3-6066E0CF0147} Name: Share Manager - AppID: {edb5f444-cb8d-445a-a523-ec5ab6ea33c7} Name: NVXDBat - AppID: {EF73A51A-EE4A-4E16-9D3A-649245C8F44F} Name: CloudExperienceHost Broker AppID - AppID: {efe2d6d8-a81b-41e7-ae77-e5244ab80522} Name: Microsoft Audio Device Graph Server - AppID: {F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC} Name: AcroBroker - AppID: {F2383816-917A-46CC-AD2A-5013BED3800F} Name: Virtual Disk Service - AppID: {F290BFB2-1864-45B1-8804-2654194A87E7} Name: HPDeviceDetection3 - AppID: {F2C11667-CC5C-46FF-A13C-6DDC30C1154F} Name: FodHelper - AppID: {F2F94BB3-595C-4509-B7EE-243FA2BDEA5B} Name: SPPSurrogate - AppID: {f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801} Name: NVIDIA.Installer2 - AppID: {F370E41B-AFAD-4B49-AFD4-0FEF3FC1375D} Name: NDFAPI - AppID: {F3D3AA8D-EF96-4470-848E-BD70B803047A} Name: PerfCenter Enabler - AppID: {f4be747e-45c4-4701-90f1-d49d9ac30248} Name: sdclt - AppID: {f56b7b2a-5b5a-46d8-b6f9-d927ce34b717} Name: Intel(R) Capability Licensing Service Interface - AppID: {F6189E3E-8B57-4CC9-B6F6-2F1FF1D1D9D4} Name: btwdins - AppID: {F6B856DA-AB94-4355-A42F-EC493BEA79DE} Name: WMPNSSCI - AppID: {F74BCE98-9EB4-4022-8317-11C723E5CCF8} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {F7CDD0DF-887D-463F-AF57-0E442B5C233B} Name: CloudExperienceHost Create System Object Server - AppID: {f7fa3149-91e7-43b7-8040-b707688ced1a} Name: logagent - AppID: {F808DF63-6049-11D1-BA20-006097D2898E} Name: WLIDFDP - AppID: {F828BB1A-2FAE-4AC4-AE6F-CAC9B529F996} Name: RAServer - AppID: {F8FD03A6-DDD9-4C1B-84EE-58159476A0D7} Name: WinInetBrokerServer - AppID: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Name: iTunes - AppID: {F98206B5-F052-4965-9FA0-85F61BC3C19D} Name: NCLUA - AppID: {FA1456D3-4B97-4f9c-8511-2786161DC333} Name: VssEvent - AppID: {FAF53CC4-BD73-4E36-83F1-2B23F46E513E} Name: Shell Hardware Mixed Content Handler Cancelled - AppID: {fb479c02-9ec4-4fed-8599-debe037452cb} Name: BtwNamespaceExt - AppID: {FC30068F-18DF-4885-9FFA-B84D390EAE81} Name: RegisterControl - AppID: {FC38B7C8-9E50-497d-A387-7DEBDAD14160} Name: Hotspot Auth Module - AppID: {FC5EEAF6-0002-11DF-ADB9-F4CE462D9137} Name: appwiz.cpl - AppID: {FCC74B77-EC3E-4dd8-A80B-008A702075A9} Name: Wordpad - AppID: {fd6c8b29-e936-4a61-8da6-b0c12ad3ba00} Name: Proximity UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10C} Name: MP UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10D} Name: Shell Execute Hardware Event Handler - AppID: {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} Name: EntAppSvc - AppID: {FFE1E5FE-F1F0-48C8-953E-72BA272F2744} Name: User Notification - AppID: {0010890e-8789-413c-adbc-48f5b511b3af} Name: hpqwmiex - AppID: {0018752E-7735-4B30-9DA9-4A01F024F270} Name: PhotoAcquire - AppID: {00f22b16-589e-4982-a172-a51d9dcceb68} Name: PhotoAcqHWEventHandler - AppID: {00f2b433-44e4-4d88-b2b0-2698a0a91dba} Name: TabTip - AppID: {01419581-4d63-4d43-ac26-6e2fc976c1f3} Name: lfsvc - AppID: {020FB939-2C8B-4DB7-9E90-9527966E38E5} Name: PLA - AppID: {03837503-098b-11d8-9414-505054503030} Name: CTapiLuaLib Class - AppID: {03e15b2e-cca6-451c-8fb0-1e2ee37a27dd} Name: WPDBusEnum - AppID: {03f25b41-e981-4675-a256-27d1393e7488} Name: NvCpl - AppID: {048F26EF-2F89-46C9-99E7-481E40F3F2EC} Name: COpenControlPanel - AppID: {06622D85-6856-4460-8DE1-A81921B41C4B} Name: SMLUA - AppID: {0671E064-7C24-4AC0-AF10-0F3055707C32} Name: PhotoAcqDropTargetEventHandler - AppID: {06A2568A-CED6-4187-BB20-400B8C02BE5A} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {06C792F8-6212-4F39-BF70-E8C0AC965C23} Name: OOBE Bio Enrollment - AppID: {0771f7af-8de6-4bce-9528-2d4a12cb8168} Name: wpnservice - AppID: {077869D3-D0DE-4586-882B-359F80009D0C} Name: sppui - AppID: {0868DC9B-D9A2-4f64-9362-133CEA201299} Name: Retail Demo User COM Agent - AppID: {0886dae5-13ba-49d6-a6ef-d0922e502d96} Name: WIA Extension Host for 64 bit extensions - AppID: {08F646B3-5E7F-4B7A-A5CB-F95445F9F67A} Name: Proximity Sharing - AppID: {08FC06E4-C6B5-40BE-97B0-B80F943C615B} Name: PersistentZoneIdentifier - AppID: {0968e258-16c7-4dba-aa86-462dd61e31a3} Name: Windows Media Player Rich Preview Handler - AppID: {09C5C2B5-1D32-4598-B87E-203F32BB08E3} Name: QuickTimeShellExt - AppID: {0A18A436-2A7A-49F3-A488-30538A2F6323} Name: AxInstSv - AppID: {0B15AFD8-3A99-4A6E-9975-30D66F70BD94} Name: NotificationController App ID - AppID: {0B789C73-D8DA-416D-B665-C1603676CEB1} Name: RASDLGLUA - AppID: {0C3B05FB-3498-40C3-9C03-4B22D735550C} Name: %SystemRoot%\system32\appwiz.cpl - AppID: {0da7bfdf-c0a0-44eb-be82-b7a82c4721de} Name: HpDataProtection - AppID: {0FFE56BF-2994-42C1-81F6-C58F05825C98} Name: IIS W3 Control - AppID: {119817C9-666D-4053-AEDA-627D0E25CCEF} Name: IntelCpHeciSvc - AppID: {11AC3232-E7D7-49CD-ABFE-501700100B3A} Name: Sync Center Client - AppID: {1202DB60-1DAC-42C5-AED5-1ABDD432248E} Name: Virtual Factory for DiagCpl - AppID: {12C21EA7-2EB8-4B55-9249-AC243DA8C666} Name: Shell Create Object Task Server - AppID: {133eac4f-5891-4d04-bada-d84870380a80} Name: Shell Create Object Handler - AppID: {135fd325-45b7-4c30-89f8-4386961669f0} Name: TPM Virtual Smart Card VCard Module Manager - AppID: {150F28F1-49A5-4C28-BE1A-CFA854A1D04B} Name: Remote TPM Virtual Smart Card Manager - AppID: {152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC} Name: ExternalApplication Class - AppID: {1673EE5D-D576-4945-927D-920AFA24166D} Name: TPM Virtual Smart Card Manager - AppID: {16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A} Name: AppleSoftwareUpdateAdmin - AppID: {16D99191-6280-4B33-A2F5-04805A0FC582} Name: Immersive TPM Virtual Smart Card Manager - AppID: {19833350-BF9B-42A1-BDF0-BD1FCBE1FD31} Name: Sync Center Control - AppID: {1A1F4206-0688-4E7F-BE03-D82EC69DF9A5} Name: GIDS Smart Card Simulator Manager - AppID: {1AC32B1A-E379-4CAD-B655-F978A30856EC} Name: %systemroot%\system32\lpksetup.exe - AppID: {1C749B87-568C-4865-8E73-6413F8372CE6} Name: Disc soft DT Lite bus service - AppID: {1CA3841D-15B5-4C70-9751-7A87730A1BE9} Name: Office Licensing COM Server 14 - AppID: {1E886174-DC88-4B83-8BC5-66409EC75F14} Name: rshx32.dll - AppID: {1f2e5c40-9550-11ce-99d2-00aa006e086c} Name: ThirdPartyEapDispatcherPeerConfig - AppID: {1F7D1BE9-7A50-40B6-A605-C4F3696F49C0} Name: Microsoft WMI Provider Subsystem Secured Host - AppID: {1F87137D-0E7C-44d5-8C73-4EFFB68962F2} Name: DetectionAndSharing - AppID: {1fda955b-61ff-11da-978c-0008744faab7} Name: Microsoft Software Protection Platform Admin Object (Inner) - AppID: {205609B7-5E08-443E-B0A7-A7AED3F3A717} Name: Microsoft Windows WSMan Provider Host With User Settings - AppID: {209444d2-2540-495e-962c-a61ad3243526} Name: Provisioning Core - AppID: {217700E0-0000-11DF-ADB9-F4CE462D9137} Name: MSDAINITIALIZE - AppID: {2206CDB0-19C1-11D1-89E0-00C04FD7A829} Name: CortanaExperienceFlow - AppID: {24AC8F2B-4D4A-4C17-9607-6A4B14068F97} Name: IpodService - AppID: {250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30} Name: InstallAgent - AppID: {260eb9de-5cbe-4bff-a99a-3710af55bf1e} Name: Microsoft WBEM Active Scripting Event Consumer Provider - AppID: {266C72E7-62E8-11D1-AD89-00C04FD8FDFF} Name: Exchange Active Sync Policies Broker - AppID: {26795871-6B8F-4115-89DD-986213012798} Name: IMAPI2 - AppID: {273541FF-7F64-5B0F-8F00-5D77AFBE261E} Name: WInRTDesktopBroker - AppID: {27550CA0-E9DE-4186-A566-37A59BB6CA69} Name: Cloud Change Wnf Monitor - AppID: {276D4FD3-C41D-465F-8CA9-A82A7762DF32} Name: netman - AppID: {27AF75ED-20D9-11D1-B1CE-00805FC1270E} Name: WalletService - AppID: {27D6B72D-094D-445A-9ACE-8298CBA0611A} Name: RasMobilityManager - AppID: {292bed96-e9ce-40f8-b71b-c313defa3a78} Name: Windows Live Photo Gallery Autoplay Drop Target - AppID: {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} Name: faultrep.dll - AppID: {2C256447-3F0D-4CBB-9D12-575BB20CDA0A} Name: FileSystemImage - AppID: {2C941FD1-975B-59BE-A960-9A2A262853A5} Name: WalletService - AppID: {2EA38040-0B9C-4379-87FD-4D38BB892F37} Name: DevicesFlow - AppID: {2F93C02D-77F9-46B4-95FB-8CBB81EEB62C} Name: Immersive Shell Broker - AppID: {2FD08A73-D1F1-43EB-B888-24C2496F95FD} Name: ShellServiceHostBrokerProvider - AppID: {30AD8C8E-AE85-42FA-B9E8-7E99E3DFBFC5} Name: Identity Store - AppID: {30d49246-d217-465f-b00b-ac9ddd652eb7} Name: AuthHost - AppID: {31337EC7-5767-11CF-BEAB-00AA006C3606} Name: Immersive Shell - AppID: {316CDED5-E4AE-4B15-9113-7055D84DCC97} Name: BtwHtmlRenderer - AppID: {31FD10BC-77F2-46CC-909B-EA4070218D42} Name: Delivery Optimization Mgmt - AppID: {338B40F9-9D68-4B53-A793-6B9AA0C5F63B} Name: Language Components Installer Com Handler - AppID: {33ADC7D5-BAF1-4661-9822-1FD23E63B39F} Name: Windows Push Notification Platform - AppID: {362cc086-4d81-4824-bbb5-666d34b3197d} Name: TabTip - AppID: {36938566-B1AA-4E77-9B3F-730CF4E996AB} Name: Delivery Optimization - AppID: {379001DE-7108-4A45-8A74-6CD0A9FBEF2C} Name: Microsoft Portable Workspace Launcher - AppID: {37B73D7B-A976-43AE-97E4-BD4977B241F2} Name: CContactDb - AppID: {380689D0-AFAA-47E6-B80E-A33436FE314B} Name: RIMDeviceManager - AppID: {3943117E-57A9-4ED1-9EAA-2566BA544BFB} Name: GamesAppService - AppID: {394447FA-A1B8-4E2D-8677-3441FD66C004} Name: iTunesAddIn - AppID: {3AA2E692-0A50-496B-A91B-9F7AF63B3511} Name: Windows Media Center Search Protocol Handler - AppID: {3B07977C-7A38-455D-AAD5-88500A360D24} Name: LivePhotoAcqHWEventHandler - AppID: {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F} Name: CortanaMapiHelper - AppID: {3BFADDE5-09ED-42AE-8190-2E68B650CFE6} Name: WorkspacePolicyProcessor - AppID: {3C3F40BC-60EB-4567-B90C-480C87C21AC1} Name: igfxcfg - AppID: {3D62E9A1-D243-11D2-B561-00A0C92E6848} Name: CMLUAUTIL - AppID: {3E000D72-A845-4CD9-BD83-80C07C3B881F} Name: Microsoft Windows Remote Shell Host - AppID: {3e5ca495-8d6a-4d1f-ad99-177b426c8b8e} Name: CMSTPLUA - AppID: {3E5FC7F9-9A51-4367-9063-A120244FBEC7} Name: WinInetCacheServer - AppID: {3eb3c877-1f16-487c-9050-104dbcd66683} Name: Out Of Proc Mapi Handler - AppID: {3F5E4B87-C907-4f76-82E4-6FDF0CE90E25} Name: MSTTS DecObj Class Surrogate - AppID: {3F6B5E16-092A-41ED-930B-0B4125D91D4E} Name: Microsoft Windows WSMan Provider Host - AppID: {3feb2f63-0eec-4b96-84ab-da1307e0117c} Name: HTML Application - AppID: {40AEEAB6-8FDA-41e3-9A5F-8350D4CFCA91} Name: Connected User Store - AppID: {40AFA0B6-3B2F-4654-8C3F-161DE85CF80E} Name: EntAppSvc - AppID: {42C21DF5-FB58-4102-90E9-96A213DC7CE8} Name: AccessibilityCplAdmin - AppID: {434A6274-C539-4E99-88FC-44206D942775} Name: SPP External COM Object - AppID: {44831FEC-DC51-4716-A7E1-E898FDF83C85} Name: Thumbnail Extraction Host Class - AppID: {4545dea0-2dfc-4906-a728-6d986ba399a9} Name: Add to Windows Media Player list - AppID: {45597c98-80f6-4549-84ff-752cf55e2d29} Name: Application Activation Manager - AppID: {45BA127D-10A8-46EA-8AB7-56EA9078943C} Name: NvXDSync - AppID: {4680B596-CF8C-44E1-A676-4AAA819E041F} Name: Set Network Location Elevated Virtual Factory - AppID: {46B988E8-BEC2-401F-A1C5-16C694F26D3E} Name: RadioManagement Lib Class - AppID: {478B41E6-3257-4519-BDA8-E971F9843849} Name: ShellServiceHost - AppID: {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} Name: BbDevMgr - AppID: {4848DD90-EDA2-461F-8FE9-B47A067A5225} Name: IASDataStoreComServer - AppID: {48da6741-1bf0-4a44-8325-293086c79077} Name: Microsoft WBEM Unsecured Apartment - AppID: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Name: Telephony App Launcher - AppID: {49EBD8BE-1A92-4A86-A651-70AC565E0FEB} Name: UIAutomationCrossBitnessHook64 Class - AppID: {49f171dd-b51a-40d3-9a6c-52d674cc729d} Name: Virtual Factory for Languages Configuration - AppID: {4A3F2F56-454A-4CC5-9734-BB7D8141AC0A} Name: RASGCWLUA - AppID: {4A6B8BAD-9872-4525-A812-71A52367DC17} Name: wercplsupport.dll - AppID: {4BC67F23-D805-4384-BCA3-6F1EDFF50E2C} Name: Shell Security Editor - AppID: {4D111E08-CBF7-4f12-A926-2C7920AF52FC} Name: Microsoft Volume Shadow Copy Service software provider - AppID: {4db9c793-c48d-449c-9754-46027ee45c94} Name: COM+ Event System - AppID: {4E14FBA2-2E22-11D1-9964-00C04FBBB345} Name: ServiceModule - AppID: {4EB61BAC-A3B6-4760-9581-655041EF4D69} Name: upnpcont.exe - AppID: {4F0AC159-5804-4aa7-AE91-117D6E67BB9B} Name: Shell Computer Accounts - AppID: {4f6bcd94-c2a5-42ce-8dbc-31e794be4630} Name: WkspRT.exe - AppID: {4FCDA643-B15B-41C6-84F8-5E447F6F6D25} Name: iTunesAdmin - AppID: {5011B6DE-E9FA-4518-B5E5-45DE9DD2CDC6} Name: AvastGUIProxy - AppID: {5020EF2C-60F4-47BE-8918-A167229B11EE} Name: WLRemoteEnableAdmin - AppID: {5032734C-9867-41BF-ABDD-24513D68E613} Name: HomeGroup CPL Advanced Settings Writer - AppID: {50a9ab2a-20f8-4d71-9f32-9fd305b49601} Name: Microsoft Windows Font Folder - AppID: {50d69d24-961d-4828-9d1c-5f4717f226d1} Name: wuapihost - AppID: {50E1C3FD-EC35-490E-9CCF-C68F9AE91919} Name: acppage.dll - AppID: {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} Name: %systemroot%\system32\intl.cpl - AppID: {514B5E31-5596-422F-BE58-D804464683B5} Name: enapi - AppID: {5197362F-09ED-45A1-8A5F-E8BD7A7837CA} Name: RemoteProxyFactory32 Class - AppID: {53362C32-A296-4F2D-A2F8-FD984D08340B} Name: RemoteProxyFactory32 Class - AppID: {53362C64-A296-4F2D-A2F8-FD984D08340B} Name: 32-bit Preview Handler Surrogate Host - AppID: {534A1E02-D58F-44f0-B58B-36CBED287C7C} Name: Virtual Disk Service Loader - AppID: {5364ED0E-493F-4B16-9DBF-AE486CF22660} Name: LockScreenContentServer Out of Proc Helper for LockScreenContent Clients - AppID: {536AACFB-5238-4314-B4D4-5B0A2E8B968E} Name: UNS - AppID: {545C8D56-7A88-492D-B38D-559657A3DD4C} Name: ShareFlow - AppID: {549e57e9-b362-49d1-b679-b64d510efe4b} Name: STAPODll - AppID: {5534E918-4467-405a-8002-8C30E1463157} Name: SRS_APO_Universal - AppID: {553C48B2-BA6B-412B-9F8D-2B62B1B912AA} Name: WindowsLiveWriter.exe - AppID: {5564D5FC-DB2D-4658-8DB9-86B822815961} Name: Bonjour - AppID: {56608F9C-223B-4CB6-813D-85EDCCADFB4B} Name: ShapeCollector - AppID: {56676660-4A4D-45B0-B24E-9CF6B35E9ABF} Name: WT - AppID: {568C34F6-73E1-4F3E-ADAE-FF34A076294C} Name: Volume Shadow Copy Service - AppID: {56BE716B-2F76-4dfa-8702-67AE10044F0B} Name: Elevated System Settings COM Host - AppID: {57360832-5F9B-4190-8467-000D2D510212} Name: PrintNotify - AppID: {588E10FA-0618-48A1-BE2F-0AD93E899FCC} Name: FaxCommon Class - AppID: {59347292-B72D-41F2-98C5-E9ACA1B247A2} Name: Authentication UI Terminal Services Bump Dialog - AppID: {59c7f6ec-7d18-412f-a68e-877982768e61} Name: Video Capture Wizard - AppID: {5AB7566D-F75B-4A53-9615-115B6CB1D59B} Name: WalletService - AppID: {5BC7A3A1-E905-414B-9790-E511346F5CA6} Name: Microsoft Maps Background Transfer Service - AppID: {5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309} Name: %SystemRoot%\System32\wsclient.dll - AppID: {5C917E9C-0B2F-40D6-928B-5C43FDB16DF4} Name: WLXMP4ParserThumbnailProvider - AppID: {5D6E8BC8-01F3-41CC-BF7D-D7EEF436896E} Name: WiaWow64 - AppID: {5E1395B2-B685-44e3-8AED-E2304D85ACD1} Name: Splash screen - AppID: {5EAD00DC-0E8B-497C-BDE8-B9153058CBEF} Name: MSSHED - AppID: {5F6C4077-12F5-11D3-8CEE-005004838434} Name: User OOBE Create User Object Server - AppID: {5f7f3f7b-1177-4d4b-b1db-bc6f671b8f25} Name: UIAutomationCrossBitnessHook32 Class - AppID: {60a90a2f-858d-42af-8929-82be9d99e8a1} Name: PDFPrevHndlr - AppID: {6236FF8C-E747-4173-86D3-99F511B61DF3} Name: wlidcli - AppID: {623D5F5E-2F09-427d-8BD7-64495CD9835D} Name: Sync Center (Private) - AppID: {6295DF2D-35EE-11D1-8707-00C04FD93327} Name: BBWebSLLauncher - AppID: {6326880C-E92B-4AE2-BC06-78DF910A7F7B} Name: SRSApoPropPageUAPOExt - AppID: {63544692-8B3E-4207-BB60-965E6F1BCE42} Name: ComUpdatus - AppID: {6390FFFB-1C89-4E0C-AE24-76102B99F750} Name: PenIMC2 - AppID: {63CE6D27-426A-41F9-8E51-549C1132DAE2} Name: Windows Update Agent - AppID: {653C5148-4DCE-4905-9CFD-1B23662D3D9E} Name: FwCplLUA - AppID: {6571503D-D0FB-4D98-BBC3-1FBB2B3F344E} Name: Found New Hardware Wizard - AppID: {658A269B-B922-4e62-B519-50B1CF0787D1} Name: tiledatamodelsvc - AppID: {65E2E13A-7110-4912-9F03-9A42E253D8F6} Name: AvAScr - AppID: {66A841F2-956C-4631-BFE7-C90225F417D6} Name: Background Intelligent Transfer Service - AppID: {69AD4AEE-51BE-439b-A92C-86AE490E8B30} Name: Sync Center Isolation Collection (Private) - AppID: {69F9CB25-25E2-4BE1-AB8F-07AA7CB535E8} Name: SoftwareUpdateApp - AppID: {6A070EEA-E3F8-411E-9D3A-F3814ED6D1A8} Name: MsRdpSessionManager - AppID: {6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F} Name: Watson subscriber for SENS Network Events - AppID: {6CF90891-3E04-4092-B96C-28E071EEEACB} Name: Preview Handler Surrogate Host - AppID: {6d2b5079-2f0b-48dd-ab7f-97cec514d30b} Name: UPnPContainer - AppID: {6d8ff8e0-730d-11d4-bf42-00b0d0118b56} Name: UPnPContainer64 - AppID: {6d8ff8e8-730d-11d4-bf42-00b0d0118b56} Name: SPPComApi - AppID: {6D9A7A40-DDCA-414E-B48E-DFB032C03C1B} Name: TieringEngineService - AppID: {6DF5BCF4-22E9-446D-8763-A2C7677ECF7D} Name: HomeGroup UI Status - AppID: {6f33340d-8a01-473a-b75f-ded88c8360ce} Name: IEWindows - AppID: {6f5bad87-9d5e-459f-bd03-3957407051ca} Name: EditionUpgradeHelper - AppID: {6F65B602-F798-4094-8A41-A2A61961E5E8} Name: HomeGroup Provider Object - AppID: {6F7C8E8F-DC69-4e3f-BC05-439962A05FD5} Name: Out of proc server to enable Insider Hub and Feedback App scenarios to be reached from inside of its appcontainer - AppID: {7006698d-2974-4091-a424-85dd0b909e23} Name: WindowsLiveWriterFilter - AppID: {7054B371-09E3-4BC8-8A61-02D7799EA98A} Name: workfolderssvc - AppID: {712cedb9-16a4-4f79-801d-7de24d8c706e} Name: Sharing Elevated Virtual Factory - AppID: {72A7994A-3092-4054-B6BE-08FF81AEEFFC} Name: User Profile Service DCOM server - AppID: {72E3272B-4EEA-4104-B358-1A282E4FC1AD} Name: Microsoft WMI Provider Subsystem Host - AppID: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} Name: Trusted Installer Service - AppID: {752073A2-23F2-4396-85F0-8FDB879ED0ED} Name: PenIMC4 - AppID: {7568952A-571E-4C70-BEA9-7F9004393436} Name: PrintFilterPipelineSvc - AppID: {76db1bf3-e820-4765-a1b2-0b16a86b1950} Name: ServiceModule - AppID: {76E258F0-DE86-4CEC-9D30-3F728A898741} Name: XWizard Virtual Factory - AppID: {777BA81A-2498-4875-933A-3067DE883070} Name: AcroIEHelperShim - AppID: {77AB4812-5411-4EA9-8437-77AD0F230302} Name: Network and Sharing Center Cpl Elevated Virtual Factory - AppID: {7A076CE1-4B31-452a-A4F1-0304C8738100} Name: Shell FMIFS Wrapper - AppID: {7aa7790d-75d7-484b-98a1-3913d022091d} Name: EapThirdPartyDllHost - AppID: {7B130458-E09C-4823-A8AF-2583DCD9AEC7} Name: Internet Explorer Add-on Installer - AppID: {7B29F495-0F55-49F7-8885-9E8A22CE3829} Name: Shell Create Object Local Server - AppID: {7B6EA1D5-03C2-4AE4-B21C-8D0515CC91B7} Name: WlanPrefLUA - AppID: {7C8AB6D9-8764-4033-8F62-2FE896E54B32} Name: Microsoft Windows Remote Shell Host With User Settings - AppID: {7d378de6-ed8d-426d-91df-0273d07cd7f6} Name: HomeGroup Printing Device Class - AppID: {7DF8EF76-D449-485f-B4EB-58DC96B31EDB} Name: MMC Application Class - AppID: {7e0423cd-1119-0928-900c-e6d4a52a0715} Name: wisptis - AppID: {7F429620-16D1-471E-A81A-114992148034} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {7FC12E96-4CB7-4ABD-ADAA-EF7845B10629} Name: hputils - AppID: {8195693E-0C55-4BE2-A2DB-32376ABC24C4} Name: OpenOffice Service Manager (Ver 1.0) - AppID: {82154420-0FBF-11d4-8313-005004526AB4} Name: CFmIfsEngine host - AppID: {82D94FB3-7FE6-4797-BB72-9A886C66073B} Name: CustReg Class - AppID: {84D586C4-A423-11D2-B943-00C04F79D22F} Name: APSDaemon - AppID: {85187E17-383D-4EC5-B8D6-D9466EE3DD92} Name: Virtual Factory for Usercpl - AppID: {86d5eb8a-859f-4c7b-a76b-2bd819b7a850} Name: CElevateWlanUi - AppID: {86F80216-5DD6-4F43-953B-35EF40A35AEE} Name: ThirdPartyEapDispatcherPeerRuntime - AppID: {87BB326B-E4A0-4DE1-94F0-B9F41D0C6059} Name: AppReadiness Service - AppID: {88283d7c-46f4-47d5-8fc2-db0b5cf0cb54} Name: Activation Manager Shim - AppID: {8A9AE632-CB07-4A11-8872-358A2A271A24} Name: Desktop Wallpaper Factory - AppID: {8B30085D-A3E3-44e3-AE7F-B03A1340EBED} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {8B8C2776-594E-41EA-90D0-8013CACBB9A7} Name: Windows Management and Instrumentation - AppID: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Name: TSTheme - AppID: {8be0366c-8522-40be-8b08-cb26557f2854} Name: IASExtensionHost - AppID: {8C334A55-DDB9-491C-817E-35A6B85D2ECB} Name: AP Client HxHelpPaneServer Class - AppID: {8cec58ae-07a1-11d9-b15e-000d56bfe6ee} Name: TiWorker - AppID: {8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D} Name: Sync Center Schedule Wizard - AppID: {8D8B8E30-C451-421B-8553-D2976AFA648C} Name: WalletService - AppID: {8E44A57C-5638-44D3-9B83-34DF70EB57F2} Name: RdpSa - AppID: {8e7fae4d-cff0-41d3-a326-5a80470264bb} Name: Shell Computer Groups - AppID: {8f3080a6-af99-4f2e-a806-f3d5702a0444} Name: SDRSVC service - AppID: {9037e3cf-1794-4af6-9c8d-92838d7a23db} Name: Virtual Factory for Recovery - AppID: {9200689A-F979-4eea-8830-0E1D6B74821F} Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients - AppID: {924DC564-16A6-42EB-929A-9A61FA7DA06F} Name: HtmlLocalFileResolver - AppID: {93AAD2A0-036A-4B11-A078-DA8776B38139} Name: ServiceModule - AppID: {9465B4B4-5216-4042-9A2C-754D3BCDC410} Name: ServiceModule - AppID: {96D1EED3-701E-4FE5-B996-A543A8465897} Name: PrintIsolationHost - AppID: {98a89e0c-1fde-4c2a-a373-b04831e6aa60} Name: Telephony Incoming Call Toast - AppID: {990F07C7-78DC-4BD2-B145-5F791410BDDE} Name: Shell Hardware Mixed Content Handler - AppID: {995C996E-D918-4a8c-A302-45719A6F4EA7} Name: WLXAutoPlayMgr - AppID: {9B5CDBB0-6D57-4816-BD04-CA9E68DF5610} Name: ShellWindows - AppID: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Name: NVXDPlcy - AppID: {9C5791C4-BCD3-48B8-A10D-CA0279320836} Name: RuntimeBroker - AppID: {9CA88EE3-ACB7-47c8-AFC4-AB702511C276} Name: BioMonitor - AppID: {9D6D21E6-597F-4B63-8CEB-736F77BD2A5E} Name: timedate.cpl - AppID: {9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8} Name: WSearch - AppID: {9E175B9C-F52A-11D8-B9A5-505054503030} Name: WMLSS - AppID: {9E88EF3C-E2BB-4E5E-AFBA-565B81069D7D} Name: ahadmin - AppID: {9fa5c497-f46d-447f-8011-05d03d7d7ddc} Name: CDP Reference Host - AppID: {A0316E2D-8793-4E74-AA48-8CE2ED05BA57} Name: Live Remote Client ActiveX - AppID: {A0CEBC38-C926-4324-A373-ACCA224B549D} Name: WIA Device Manager - AppID: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Name: TrayNotify - AppID: {a2b77517-6d12-4c60-b0c6-725e971ec8fe} Name: rundll32.exe - AppID: {a2d9ca22-a492-400c-b875-78ac25c0a6f3} Name: MhegVM - AppID: {A3637A1F-8CD0-4DA3-9EF5-CC0BD38AF308} Name: Virtual Factory for Windows Firewall Cpl - AppID: {A4B07E49-6567-4FB8-8D39-01920E3B2357} Name: Shell ChkdskEx Dialog - AppID: {a4c31131-ff70-4984-afd6-0609ced53ad6} Name: Nv3DAppShExt - AppID: {A4CF1DBB-664A-4600-9CE3-96FBAA344504} Name: DsmAdminApi - AppID: {A5065670-136D-4FD6-A45F-00C85B90359C} Name: PDFShellInfo - AppID: {A5090E95-F1E2-41C8-BDA1-5AEB6C321FDE} Name: WPDShextAutoplay - AppID: {A55803CC-4D53-404c-8557-FD63DBA95D24} Name: WLIDSvc - AppID: {A6721677-BA21-44E9-9E2A-76466D24D121} Name: Virtual Factory for MaintenanceUI - AppID: {A6BFEA43-501F-456F-A845-983D3AD7B8F0} Name: updaterActiveX - AppID: {A75E0259-1AE1-4046-A5CA-27B2A0DAA8A6} Name: Microsoft Windows Defender - AppID: {A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F} Name: %SystemRoot%\System32\fveui.dll - AppID: {A7A63E5C-3877-4840-8727-C1EA9D7A4D50} Name: SysFxUi - AppID: {A7D2EC8B-B70F-434C-A0CE-0DF324805F7D} Name: VirtualBoxAsw Application - AppID: {A8F69786-BC63-417e-85AF-A2C2D3833032} Name: Delivery Optimization Mgmt - AppID: {AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800} Name: F12AppFrameClient Class - AppID: {AABAA6AA-5398-4C08-AE60-6321A7F05E9C} Name: DEFRAGSVC service - AppID: {ab7c873b-eb14-49a6-be60-a602f80e6d22} Name: Thumbnail Cache Out of Proc Server - AppID: {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} Name: BDEUILauncher Class - AppID: {AB93B6F1-BE76-4185-A488-A9001B105B94} Name: Out of proc server to enable Insider Hub scenarios to be reached from inside of its appcontainer - AppID: {ac0fd47a-37f4-4502-bfee-6b317e479d41} Name: RetailDemo Service - AppID: {ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325} Name: Windows Live Social Object Extractor Engine - AppID: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Name: WPN Srumon Server - AppID: {ada41b3c-c6fd-4a08-8cc1-d6efde67be7d} Name: SwHelper_1163633 - AppID: {AF551664-D2DF-4E34-85DE-46320B13A0B4} Name: TrayToastActivator - AppID: {AFC732E2-BA57-4B3E-A70A-71371F99B871} Name: WorkspaceBroker Class - AppID: {B06FF84E-0A77-4DD2-A919-0EABD8979DC1} Name: TabIps - AppID: {B1445657-5A98-11d9-A4E5-00301BB132BA} Name: DockInterface COM server - AppID: {b21858c6-9711-4257-99c8-5c0084bebce1} Name: Windows Update Agent - Remote Access - AppID: {B366DEBE-645B-43A5-B865-DDD82C345492} Name: AppActivationFailedHandler - AppID: {B3AADFEA-8404-4CBE-A62E-B0B715412C9E} Name: Out Of Proc Mapi Handler - AppID: {b5453d2d-5ad4-4df7-a399-0245244a4b60} Name: Found New Hardware Wizard - AppID: {B6A32FE6-E29D-AEAE-A608-D273E40CA34C} Name: WIA Device Manager 2 - AppID: {B6C292BC-7C88-41EE-8B54-8EC92617E599} Name: Sync Center (Private) - AppID: {B8558612-DF5E-4F95-BB81-8E910B327FB2} Name: WLX Thumbnail Cache Out of Proc Server - AppID: {B8A2E14E-290D-4122-B092-1A7D86198CCE} Name: Windows Media Player - AppID: {B8C54A54-355E-11D3-83EB-00A0C92A2F2D} Name: NVXDApiX - AppID: {B92B577B-628A-442B-A017-E86FB518C6FD} Name: ApplicationActivationImpl - AppID: {B9305506-D05B-4C36-81C5-0E50886C1755} Name: Application Frame Host - AppID: {B9B05098-3E30-483F-87F7-027CA78DA287} Name: Event Object Change 2 - AppID: {BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4} Name: AcroPDF - AppID: {BBAA0E44-3862-490C-8E63-AC2D2D6EF733} Name: SyncHost - AppID: {BBC4356A-F004-4628-A27A-E13D70412B70} Name: Virtual Factory for Power Options Control Panel - AppID: {BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B} Name: Setting Sync Task Factory - AppID: {bcbb3f8c-2889-474f-8fb7-904d4a416145} Name: DfsShlEx.dll - AppID: {BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B} Name: EditionUpgradeManagerObj - AppID: {BD54C901-076B-434E-B6C7-17C531F4AB41} Name: VM IC Heartbeat Service - AppID: {be0fc7f0-f248-4091-a123-34ca29a6901b} Name: Shell AutoPlay Direct - AppID: {BF8841C9-378A-4CAD-B4FC-5091366CBC0D} Name: BTStackServer - AppID: {C05A68C7-580B-11D4-98D0-006008BF430C} Name: ShellBrowserWindow - AppID: {c08afd90-f2a1-11d1-8455-00a0c91f3880} Name: LockAppHost Out of Proc Helper for Lock Apps - AppID: {C08B030B-E91C-479D-BEFD-02DDA7FF1BCF} Name: provsvc.dll - AppID: {c2a71820-3463-498f-bab7-4798795a2ff6} Name: DataExchangeHost - AppID: {C2E9756F-8155-4EAC-9ED5-0B690169D412} Name: cttunesvr - AppID: {C3A34354-660F-41EE-B072-2AEA5E3A80AF} Name: Microsoft Block Level Backup Service - AppID: {C3B65D83-FB15-4e3f-BA04-097D1E2B5AC1} Name: Microsoft IMAPI - AppID: {C49F2185-50A7-11D3-9144-00104BA11C5E} Name: BdeUISrv - AppID: {C4AB7CB7-E735-48FF-AADD-39D09668F444} Name: HomeGroup Listener Service - AppID: {C4CDC408-581C-4480-9FFE-3B1C78D5C20D} Name: Xbox Live Game Saves - AppID: {C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3} Name: Nvvsvc - AppID: {C5EDFC9D-B018-41A4-9877-39AB18469C3A} Name: EntAppSvc - AppID: {C63261E4-6052-41FF-B919-496FECF4C4E5} Name: EmailClient Class - AppID: {C6E0A4C8-A933-411E-8068-406C2391665F} Name: LockScreen Application Notification Broker - AppID: {C89FC3EF-A0DC-4feb-BFBC-F13A9C334D4F} Name: TSWbPrxy.exe - AppID: {C92A9617-0EAE-4235-BD2B-84540EF1FFA9} Name: DictationHost Class - AppID: {C945AD06-534F-460C-8CB4-17C33099AF81} Name: Sync Infrastructure - AppID: {C947D50F-378E-4FF6-8835-FCB50305244D} Name: netprofm - AppID: {C96887DA-A652-4426-905E-4A37546F847C} Name: editionupgradebroker - AppID: {C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125} Name: RCM - AppID: {C9F65BA8-1F8F-4382-AE27-C91FFB29275F} Name: User OOBE Create Elevated Object Server - AppID: {ca8c87c1-929d-45ba-94db-ef8e6cb346ad} Name: OpenSearch Description Create Search Connector Verb Handler - AppID: {CB1DFE3A-EDFF-4d1f-867D-8ADB02926F4B} Name: PrintIsolationSessionHost - AppID: {CB363445-F453-4C1E-8EE4-BD123C5E394F} Name: SkypeIEPlugin - AppID: {CB487EA6-E83B-4F63-8CAE-B1B1D23DA65E} Name: EnhancedStorageShell - AppID: {CC70FEAD-94B9-4F76-88CC-004BB068ACDF} Name: sppui - AppID: {CCFDD24D-CEAB-458B-A4F1-F884973395DF} Name: WcsPlugInServiceLib - AppID: {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607} Name: Windows Media Player Burn Audio CD Handler - AppID: {cdc32574-7521-4124-90c3-8d5605a34933} Name: Elevated-Unelevated Explorer Factory - AppID: {CDCBCFCA-3CDC-436f-A4E2-0E02075250C2} Name: PNPXAssoc.dll - AppID: {cee8ccc9-4f6b-4469-a235-5a22869eef03} Name: sdchange - AppID: {CF254B00-1986-4b24-A92D-463D01F7E395} Name: Event Object Change - AppID: {D0565000-9DF4-11D1-A281-00C04FCA0AA7} Name: HealthDriverBridge - AppID: {D190DCB4-AAAB-4507-A0AF-0AD12F2603A4} Name: Winmgmt MOF Compiler OOP - AppID: {D215781D-019E-4FA0-903D-0CDCDE13A4F5} Name: Color Management - AppID: {D2E7041B-2927-42fb-8E9F-7CE93B6DC937} Name: Bitmap Image - AppID: {D3E34B21-9D75-101A-8C3D-00AA001A1652} Name: ghost - AppID: {D58F39FF-953E-4F45-898F-59F243B9A523} Name: Sync Center User Profile Notification Handler - AppID: {D63AA156-D534-4BAC-9BF1-55359CF5EC30} Name: CloudStorageWizard - AppID: {D8775A07-C529-4EA7-B307-BA7C8CBBDA03} Name: Microsoft Software Protection Platform Admin Object (outer) - AppID: {D8D4249F-A8FB-44A7-8AA0-564E8C385BD6} Name: MSMQ - AppID: {DCBCADF5-DB1b-4764-9320-9a5082af1581} Name: BrowserBrokerServer - AppID: {DD9C53BC-8441-4B94-BD0E-36E6E02A6D61} Name: Srumon Server - AppID: {ddcfd26b-feed-44cd-b71d-79487d2e5e5a} Name: rundll32.exe - AppID: {de5d803e-5d2a-4b5f-9c63-af25a465cc44} Name: AccStore Class - AppID: {DE5DBCDC-104A-4cbc-A4D5-0C2104A142C5} Name: LockScreen Call Broker - AppID: {DE7D3D65-5454-4EF5-9518-776739DAB39F} Name: Profile Notification Host - AppID: {E10F6C3A-F1AE-4adc-AA9D-2FE65525666E} Name: Immersive Print Dialog Surrogate - AppID: {E15FBAC2-C276-4523-92CA-561456EBCF3E} Name: Windows Update Agent User Interface for Published Applications - AppID: {e30984f1-b02b-4c27-a40f-23d11b8c1212} Name: Scan - AppID: {E32549C4-C2B8-4BCC-90D7-0FC3511092BB} Name: Execute Unknown - AppID: {e44e9428-bdbc-4987-a099-40dc8fd255e7} Name: upnphost - AppID: {E495081B-BBA5-4b89-BA3C-3B86A686B87A} Name: TrayDesktopBand - AppID: {E6442437-6C68-4f52-94DD-2CFED267EFB9} Name: Orchestrator Service - AppID: {E7299E79-75E5-47BB-A03D-6D319FB7F886} Name: TokenBroker Out Of Proc COM Server - AppID: {E73A797B-24CE-424A-AD4F-48E98B1E95B8} Name: UICOM - AppID: {E8054D20-497D-4E16-BF41-6E69FCD381A5} Name: iisctl - AppID: {E8FB8615-588F-11D2-9D61-00C04F79C5FE} Name: wscui.cpl - AppID: {E9495B87-D950-4ab5-87A5-FF6D70BF3E90} Name: Remove Device elevation surrogate - AppID: {E95186C7-7D80-4311-843D-0702CBC8B1E4} Name: File Prop Sheet Page Helper - AppID: {E96767E0-7EAA-45E1-8E7D-64414AFF281A} Name: HomeGroup Provider Service - AppID: {EA022610-0748-4c24-B229-6C507EBDFDBB} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8} Name: Immersive Print Dialog Surrogate - AppID: {EB28E902-728E-42C4-97DC-DA89E144C744} Name: Remote Desktop Services Message Server - AppID: {EB521D7D-4095-4E61-88FB-BF25700F142A} Name: ComEvents.ComServiceEvents - AppID: {ECABB0C3-7F19-11D2-978E-0000F8757E2A} Name: ComEvents.ComSystemAppEventData - AppID: {ECABB0C6-7F19-11D2-978E-0000F8757E2A} Name: Play with Windows Media Player - AppID: {ed1d0fdf-4414-470a-a56d-cfb68623fc58} Name: SWDNLD - AppID: {ED372EB0-5B14-484F-A27C-05FF89B6DF25} Name: Windows Media Player Launch - AppID: {ED6BB178-B06A-47ad-98B3-6066E0CF0147} Name: Share Manager - AppID: {edb5f444-cb8d-445a-a523-ec5ab6ea33c7} Name: NVXDBat - AppID: {EF73A51A-EE4A-4E16-9D3A-649245C8F44F} Name: CloudExperienceHost Broker AppID - AppID: {efe2d6d8-a81b-41e7-ae77-e5244ab80522} Name: Microsoft Audio Device Graph Server - AppID: {F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC} Name: AcroBroker - AppID: {F2383816-917A-46CC-AD2A-5013BED3800F} Name: Virtual Disk Service - AppID: {F290BFB2-1864-45B1-8804-2654194A87E7} Name: HPDeviceDetection3 - AppID: {F2C11667-CC5C-46FF-A13C-6DDC30C1154F} Name: FodHelper - AppID: {F2F94BB3-595C-4509-B7EE-243FA2BDEA5B} Name: SPPSurrogate - AppID: {f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801} Name: NVIDIA.Installer2 - AppID: {F370E41B-AFAD-4B49-AFD4-0FEF3FC1375D} Name: NDFAPI - AppID: {F3D3AA8D-EF96-4470-848E-BD70B803047A} Name: PerfCenter Enabler - AppID: {f4be747e-45c4-4701-90f1-d49d9ac30248} Name: sdclt - AppID: {f56b7b2a-5b5a-46d8-b6f9-d927ce34b717} Name: Intel(R) Capability Licensing Service Interface - AppID: {F6189E3E-8B57-4CC9-B6F6-2F1FF1D1D9D4} Name: btwdins - AppID: {F6B856DA-AB94-4355-A42F-EC493BEA79DE} Name: WMPNSSCI - AppID: {F74BCE98-9EB4-4022-8317-11C723E5CCF8} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {F7CDD0DF-887D-463F-AF57-0E442B5C233B} Name: CloudExperienceHost Create System Object Server - AppID: {f7fa3149-91e7-43b7-8040-b707688ced1a} Name: logagent - AppID: {F808DF63-6049-11D1-BA20-006097D2898E} Name: WLIDFDP - AppID: {F828BB1A-2FAE-4AC4-AE6F-CAC9B529F996} Name: RAServer - AppID: {F8FD03A6-DDD9-4C1B-84EE-58159476A0D7} Name: WinInetBrokerServer - AppID: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Name: iTunes - AppID: {F98206B5-F052-4965-9FA0-85F61BC3C19D} Name: NCLUA - AppID: {FA1456D3-4B97-4f9c-8511-2786161DC333} Name: VssEvent - AppID: {FAF53CC4-BD73-4E36-83F1-2B23F46E513E} Name: Shell Hardware Mixed Content Handler Cancelled - AppID: {fb479c02-9ec4-4fed-8599-debe037452cb} Name: BtwNamespaceExt - AppID: {FC30068F-18DF-4885-9FFA-B84D390EAE81} Name: RegisterControl - AppID: {FC38B7C8-9E50-497d-A387-7DEBDAD14160} Name: Hotspot Auth Module - AppID: {FC5EEAF6-0002-11DF-ADB9-F4CE462D9137} Name: appwiz.cpl - AppID: {FCC74B77-EC3E-4dd8-A80B-008A702075A9} Name: Wordpad - AppID: {fd6c8b29-e936-4a61-8da6-b0c12ad3ba00} Name: Proximity UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10C} Name: MP UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10D} Name: Shell Execute Hardware Event Handler - AppID: {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} Name: EntAppSvc - AppID: {FFE1E5FE-F1F0-48C8-953E-72BA272F2744} Name: User Notification - AppID: {0010890e-8789-413c-adbc-48f5b511b3af} Name: hpqwmiex - AppID: {0018752E-7735-4B30-9DA9-4A01F024F270} Name: PhotoAcquire - AppID: {00f22b16-589e-4982-a172-a51d9dcceb68} Name: PhotoAcqHWEventHandler - AppID: {00f2b433-44e4-4d88-b2b0-2698a0a91dba} Name: TabTip - AppID: {01419581-4d63-4d43-ac26-6e2fc976c1f3} Name: lfsvc - AppID: {020FB939-2C8B-4DB7-9E90-9527966E38E5} Name: PLA - AppID: {03837503-098b-11d8-9414-505054503030} Name: CTapiLuaLib Class - AppID: {03e15b2e-cca6-451c-8fb0-1e2ee37a27dd} Name: WPDBusEnum - AppID: {03f25b41-e981-4675-a256-27d1393e7488} Name: NvCpl - AppID: {048F26EF-2F89-46C9-99E7-481E40F3F2EC} Name: COpenControlPanel - AppID: {06622D85-6856-4460-8DE1-A81921B41C4B} Name: SMLUA - AppID: {0671E064-7C24-4AC0-AF10-0F3055707C32} Name: PhotoAcqDropTargetEventHandler - AppID: {06A2568A-CED6-4187-BB20-400B8C02BE5A} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {06C792F8-6212-4F39-BF70-E8C0AC965C23} Name: OOBE Bio Enrollment - AppID: {0771f7af-8de6-4bce-9528-2d4a12cb8168} Name: wpnservice - AppID: {077869D3-D0DE-4586-882B-359F80009D0C} Name: sppui - AppID: {0868DC9B-D9A2-4f64-9362-133CEA201299} Name: Retail Demo User COM Agent - AppID: {0886dae5-13ba-49d6-a6ef-d0922e502d96} Name: WIA Extension Host for 64 bit extensions - AppID: {08F646B3-5E7F-4B7A-A5CB-F95445F9F67A} Name: Proximity Sharing - AppID: {08FC06E4-C6B5-40BE-97B0-B80F943C615B} Name: PersistentZoneIdentifier - AppID: {0968e258-16c7-4dba-aa86-462dd61e31a3} Name: Windows Media Player Rich Preview Handler - AppID: {09C5C2B5-1D32-4598-B87E-203F32BB08E3} Name: QuickTimeShellExt - AppID: {0A18A436-2A7A-49F3-A488-30538A2F6323} Name: AxInstSv - AppID: {0B15AFD8-3A99-4A6E-9975-30D66F70BD94} Name: NotificationController App ID - AppID: {0B789C73-D8DA-416D-B665-C1603676CEB1} Name: RASDLGLUA - AppID: {0C3B05FB-3498-40C3-9C03-4B22D735550C} Name: %SystemRoot%\system32\appwiz.cpl - AppID: {0da7bfdf-c0a0-44eb-be82-b7a82c4721de} Name: HpDataProtection - AppID: {0FFE56BF-2994-42C1-81F6-C58F05825C98} Name: IIS W3 Control - AppID: {119817C9-666D-4053-AEDA-627D0E25CCEF} Name: IntelCpHeciSvc - AppID: {11AC3232-E7D7-49CD-ABFE-501700100B3A} Name: Sync Center Client - AppID: {1202DB60-1DAC-42C5-AED5-1ABDD432248E} Name: Virtual Factory for DiagCpl - AppID: {12C21EA7-2EB8-4B55-9249-AC243DA8C666} Name: Shell Create Object Task Server - AppID: {133eac4f-5891-4d04-bada-d84870380a80} Name: Shell Create Object Handler - AppID: {135fd325-45b7-4c30-89f8-4386961669f0} Name: TPM Virtual Smart Card VCard Module Manager - AppID: {150F28F1-49A5-4C28-BE1A-CFA854A1D04B} Name: Remote TPM Virtual Smart Card Manager - AppID: {152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC} Name: ExternalApplication Class - AppID: {1673EE5D-D576-4945-927D-920AFA24166D} Name: TPM Virtual Smart Card Manager - AppID: {16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A} Name: AppleSoftwareUpdateAdmin - AppID: {16D99191-6280-4B33-A2F5-04805A0FC582} Name: Immersive TPM Virtual Smart Card Manager - AppID: {19833350-BF9B-42A1-BDF0-BD1FCBE1FD31} Name: Sync Center Control - AppID: {1A1F4206-0688-4E7F-BE03-D82EC69DF9A5} Name: GIDS Smart Card Simulator Manager - AppID: {1AC32B1A-E379-4CAD-B655-F978A30856EC} Name: %systemroot%\system32\lpksetup.exe - AppID: {1C749B87-568C-4865-8E73-6413F8372CE6} Name: Disc soft DT Lite bus service - AppID: {1CA3841D-15B5-4C70-9751-7A87730A1BE9} Name: Office Licensing COM Server 14 - AppID: {1E886174-DC88-4B83-8BC5-66409EC75F14} Name: rshx32.dll - AppID: {1f2e5c40-9550-11ce-99d2-00aa006e086c} Name: ThirdPartyEapDispatcherPeerConfig - AppID: {1F7D1BE9-7A50-40B6-A605-C4F3696F49C0} Name: Microsoft WMI Provider Subsystem Secured Host - AppID: {1F87137D-0E7C-44d5-8C73-4EFFB68962F2} Name: DetectionAndSharing - AppID: {1fda955b-61ff-11da-978c-0008744faab7} Name: Microsoft Software Protection Platform Admin Object (Inner) - AppID: {205609B7-5E08-443E-B0A7-A7AED3F3A717} Name: Microsoft Windows WSMan Provider Host With User Settings - AppID: {209444d2-2540-495e-962c-a61ad3243526} Name: Provisioning Core - AppID: {217700E0-0000-11DF-ADB9-F4CE462D9137} Name: MSDAINITIALIZE - AppID: {2206CDB0-19C1-11D1-89E0-00C04FD7A829} Name: CortanaExperienceFlow - AppID: {24AC8F2B-4D4A-4C17-9607-6A4B14068F97} Name: IpodService - AppID: {250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30} Name: InstallAgent - AppID: {260eb9de-5cbe-4bff-a99a-3710af55bf1e} Name: Microsoft WBEM Active Scripting Event Consumer Provider - AppID: {266C72E7-62E8-11D1-AD89-00C04FD8FDFF} Name: Exchange Active Sync Policies Broker - AppID: {26795871-6B8F-4115-89DD-986213012798} Name: IMAPI2 - AppID: {273541FF-7F64-5B0F-8F00-5D77AFBE261E} Name: WInRTDesktopBroker - AppID: {27550CA0-E9DE-4186-A566-37A59BB6CA69} Name: Cloud Change Wnf Monitor - AppID: {276D4FD3-C41D-465F-8CA9-A82A7762DF32} Name: netman - AppID: {27AF75ED-20D9-11D1-B1CE-00805FC1270E} Name: WalletService - AppID: {27D6B72D-094D-445A-9ACE-8298CBA0611A} Name: RasMobilityManager - AppID: {292bed96-e9ce-40f8-b71b-c313defa3a78} Name: Windows Live Photo Gallery Autoplay Drop Target - AppID: {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} Name: faultrep.dll - AppID: {2C256447-3F0D-4CBB-9D12-575BB20CDA0A} Name: FileSystemImage - AppID: {2C941FD1-975B-59BE-A960-9A2A262853A5} Name: WalletService - AppID: {2EA38040-0B9C-4379-87FD-4D38BB892F37} Name: DevicesFlow - AppID: {2F93C02D-77F9-46B4-95FB-8CBB81EEB62C} Name: Immersive Shell Broker - AppID: {2FD08A73-D1F1-43EB-B888-24C2496F95FD} Name: ShellServiceHostBrokerProvider - AppID: {30AD8C8E-AE85-42FA-B9E8-7E99E3DFBFC5} Name: Identity Store - AppID: {30d49246-d217-465f-b00b-ac9ddd652eb7} Name: AuthHost - AppID: {31337EC7-5767-11CF-BEAB-00AA006C3606} Name: Immersive Shell - AppID: {316CDED5-E4AE-4B15-9113-7055D84DCC97} Name: BtwHtmlRenderer - AppID: {31FD10BC-77F2-46CC-909B-EA4070218D42} Name: Delivery Optimization Mgmt - AppID: {338B40F9-9D68-4B53-A793-6B9AA0C5F63B} Name: Language Components Installer Com Handler - AppID: {33ADC7D5-BAF1-4661-9822-1FD23E63B39F} Name: Windows Push Notification Platform - AppID: {362cc086-4d81-4824-bbb5-666d34b3197d} Name: TabTip - AppID: {36938566-B1AA-4E77-9B3F-730CF4E996AB} Name: Delivery Optimization - AppID: {379001DE-7108-4A45-8A74-6CD0A9FBEF2C} Name: Microsoft Portable Workspace Launcher - AppID: {37B73D7B-A976-43AE-97E4-BD4977B241F2} Name: CContactDb - AppID: {380689D0-AFAA-47E6-B80E-A33436FE314B} Name: RIMDeviceManager - AppID: {3943117E-57A9-4ED1-9EAA-2566BA544BFB} Name: GamesAppService - AppID: {394447FA-A1B8-4E2D-8677-3441FD66C004} Name: iTunesAddIn - AppID: {3AA2E692-0A50-496B-A91B-9F7AF63B3511} Name: Windows Media Center Search Protocol Handler - AppID: {3B07977C-7A38-455D-AAD5-88500A360D24} Name: LivePhotoAcqHWEventHandler - AppID: {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F} Name: CortanaMapiHelper - AppID: {3BFADDE5-09ED-42AE-8190-2E68B650CFE6} Name: WorkspacePolicyProcessor - AppID: {3C3F40BC-60EB-4567-B90C-480C87C21AC1} Name: igfxcfg - AppID: {3D62E9A1-D243-11D2-B561-00A0C92E6848} Name: CMLUAUTIL - AppID: {3E000D72-A845-4CD9-BD83-80C07C3B881F} Name: Microsoft Windows Remote Shell Host - AppID: {3e5ca495-8d6a-4d1f-ad99-177b426c8b8e} Name: CMSTPLUA - AppID: {3E5FC7F9-9A51-4367-9063-A120244FBEC7} Name: WinInetCacheServer - AppID: {3eb3c877-1f16-487c-9050-104dbcd66683} Name: Out Of Proc Mapi Handler - AppID: {3F5E4B87-C907-4f76-82E4-6FDF0CE90E25} Name: MSTTS DecObj Class Surrogate - AppID: {3F6B5E16-092A-41ED-930B-0B4125D91D4E} Name: Microsoft Windows WSMan Provider Host - AppID: {3feb2f63-0eec-4b96-84ab-da1307e0117c} Name: HTML Application - AppID: {40AEEAB6-8FDA-41e3-9A5F-8350D4CFCA91} Name: Connected User Store - AppID: {40AFA0B6-3B2F-4654-8C3F-161DE85CF80E} Name: EntAppSvc - AppID: {42C21DF5-FB58-4102-90E9-96A213DC7CE8} Name: AccessibilityCplAdmin - AppID: {434A6274-C539-4E99-88FC-44206D942775} Name: SPP External COM Object - AppID: {44831FEC-DC51-4716-A7E1-E898FDF83C85} Name: Thumbnail Extraction Host Class - AppID: {4545dea0-2dfc-4906-a728-6d986ba399a9} Name: Add to Windows Media Player list - AppID: {45597c98-80f6-4549-84ff-752cf55e2d29} Name: Application Activation Manager - AppID: {45BA127D-10A8-46EA-8AB7-56EA9078943C} Name: NvXDSync - AppID: {4680B596-CF8C-44E1-A676-4AAA819E041F} Name: Set Network Location Elevated Virtual Factory - AppID: {46B988E8-BEC2-401F-A1C5-16C694F26D3E} Name: RadioManagement Lib Class - AppID: {478B41E6-3257-4519-BDA8-E971F9843849} Name: ShellServiceHost - AppID: {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} Name: BbDevMgr - AppID: {4848DD90-EDA2-461F-8FE9-B47A067A5225} Name: IASDataStoreComServer - AppID: {48da6741-1bf0-4a44-8325-293086c79077} Name: Microsoft WBEM Unsecured Apartment - AppID: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Name: Telephony App Launcher - AppID: {49EBD8BE-1A92-4A86-A651-70AC565E0FEB} Name: UIAutomationCrossBitnessHook64 Class - AppID: {49f171dd-b51a-40d3-9a6c-52d674cc729d} Name: Virtual Factory for Languages Configuration - AppID: {4A3F2F56-454A-4CC5-9734-BB7D8141AC0A} Name: RASGCWLUA - AppID: {4A6B8BAD-9872-4525-A812-71A52367DC17} Name: wercplsupport.dll - AppID: {4BC67F23-D805-4384-BCA3-6F1EDFF50E2C} Name: Shell Security Editor - AppID: {4D111E08-CBF7-4f12-A926-2C7920AF52FC} Name: Microsoft Volume Shadow Copy Service software provider - AppID: {4db9c793-c48d-449c-9754-46027ee45c94} Name: COM+ Event System - AppID: {4E14FBA2-2E22-11D1-9964-00C04FBBB345} Name: ServiceModule - AppID: {4EB61BAC-A3B6-4760-9581-655041EF4D69} Name: upnpcont.exe - AppID: {4F0AC159-5804-4aa7-AE91-117D6E67BB9B} Name: Shell Computer Accounts - AppID: {4f6bcd94-c2a5-42ce-8dbc-31e794be4630} Name: WkspRT.exe - AppID: {4FCDA643-B15B-41C6-84F8-5E447F6F6D25} Name: iTunesAdmin - AppID: {5011B6DE-E9FA-4518-B5E5-45DE9DD2CDC6} Name: WLRemoteEnableAdmin - AppID: {5032734C-9867-41BF-ABDD-24513D68E613} Name: HomeGroup CPL Advanced Settings Writer - AppID: {50a9ab2a-20f8-4d71-9f32-9fd305b49601} Name: Microsoft Windows Font Folder - AppID: {50d69d24-961d-4828-9d1c-5f4717f226d1} Name: wuapihost - AppID: {50E1C3FD-EC35-490E-9CCF-C68F9AE91919} Name: acppage.dll - AppID: {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} Name: %systemroot%\system32\intl.cpl - AppID: {514B5E31-5596-422F-BE58-D804464683B5} Name: enapi - AppID: {5197362F-09ED-45A1-8A5F-E8BD7A7837CA} Name: RemoteProxyFactory32 Class - AppID: {53362C32-A296-4F2D-A2F8-FD984D08340B} Name: RemoteProxyFactory32 Class - AppID: {53362C64-A296-4F2D-A2F8-FD984D08340B} Name: 32-bit Preview Handler Surrogate Host - AppID: {534A1E02-D58F-44f0-B58B-36CBED287C7C} Name: Virtual Disk Service Loader - AppID: {5364ED0E-493F-4B16-9DBF-AE486CF22660} Name: LockScreenContentServer Out of Proc Helper for LockScreenContent Clients - AppID: {536AACFB-5238-4314-B4D4-5B0A2E8B968E} Name: UNS - AppID: {545C8D56-7A88-492D-B38D-559657A3DD4C} Name: ShareFlow - AppID: {549e57e9-b362-49d1-b679-b64d510efe4b} Name: STAPODll - AppID: {5534E918-4467-405a-8002-8C30E1463157} Name: SRS_APO_Universal - AppID: {553C48B2-BA6B-412B-9F8D-2B62B1B912AA} Name: WindowsLiveWriter.exe - AppID: {5564D5FC-DB2D-4658-8DB9-86B822815961} Name: Bonjour - AppID: {56608F9C-223B-4CB6-813D-85EDCCADFB4B} Name: ShapeCollector - AppID: {56676660-4A4D-45B0-B24E-9CF6B35E9ABF} Name: WT - AppID: {568C34F6-73E1-4F3E-ADAE-FF34A076294C} Name: Volume Shadow Copy Service - AppID: {56BE716B-2F76-4dfa-8702-67AE10044F0B} Name: Elevated System Settings COM Host - AppID: {57360832-5F9B-4190-8467-000D2D510212} Name: PrintNotify - AppID: {588E10FA-0618-48A1-BE2F-0AD93E899FCC} Name: FaxCommon Class - AppID: {59347292-B72D-41F2-98C5-E9ACA1B247A2} Name: Authentication UI Terminal Services Bump Dialog - AppID: {59c7f6ec-7d18-412f-a68e-877982768e61} Name: Video Capture Wizard - AppID: {5AB7566D-F75B-4A53-9615-115B6CB1D59B} Name: WalletService - AppID: {5BC7A3A1-E905-414B-9790-E511346F5CA6} Name: Microsoft Maps Background Transfer Service - AppID: {5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309} Name: %SystemRoot%\System32\wsclient.dll - AppID: {5C917E9C-0B2F-40D6-928B-5C43FDB16DF4} Name: WLXMP4ParserThumbnailProvider - AppID: {5D6E8BC8-01F3-41CC-BF7D-D7EEF436896E} Name: WiaWow64 - AppID: {5E1395B2-B685-44e3-8AED-E2304D85ACD1} Name: Splash screen - AppID: {5EAD00DC-0E8B-497C-BDE8-B9153058CBEF} Name: MSSHED - AppID: {5F6C4077-12F5-11D3-8CEE-005004838434} Name: User OOBE Create User Object Server - AppID: {5f7f3f7b-1177-4d4b-b1db-bc6f671b8f25} Name: UIAutomationCrossBitnessHook32 Class - AppID: {60a90a2f-858d-42af-8929-82be9d99e8a1} Name: PDFPrevHndlr - AppID: {6236FF8C-E747-4173-86D3-99F511B61DF3} Name: wlidcli - AppID: {623D5F5E-2F09-427d-8BD7-64495CD9835D} Name: Sync Center (Private) - AppID: {6295DF2D-35EE-11D1-8707-00C04FD93327} Name: BBWebSLLauncher - AppID: {6326880C-E92B-4AE2-BC06-78DF910A7F7B} Name: SRSApoPropPageUAPOExt - AppID: {63544692-8B3E-4207-BB60-965E6F1BCE42} Name: ComUpdatus - AppID: {6390FFFB-1C89-4E0C-AE24-76102B99F750} Name: PenIMC2 - AppID: {63CE6D27-426A-41F9-8E51-549C1132DAE2} Name: Windows Update Agent - AppID: {653C5148-4DCE-4905-9CFD-1B23662D3D9E} Name: FwCplLUA - AppID: {6571503D-D0FB-4D98-BBC3-1FBB2B3F344E} Name: Found New Hardware Wizard - AppID: {658A269B-B922-4e62-B519-50B1CF0787D1} Name: tiledatamodelsvc - AppID: {65E2E13A-7110-4912-9F03-9A42E253D8F6} Name: AvAScr - AppID: {66A841F2-956C-4631-BFE7-C90225F417D6} Name: Background Intelligent Transfer Service - AppID: {69AD4AEE-51BE-439b-A92C-86AE490E8B30} Name: Sync Center Isolation Collection (Private) - AppID: {69F9CB25-25E2-4BE1-AB8F-07AA7CB535E8} Name: MsRdpSessionManager - AppID: {6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F} Name: Watson subscriber for SENS Network Events - AppID: {6CF90891-3E04-4092-B96C-28E071EEEACB} Name: Preview Handler Surrogate Host - AppID: {6d2b5079-2f0b-48dd-ab7f-97cec514d30b} Name: UPnPContainer - AppID: {6d8ff8e0-730d-11d4-bf42-00b0d0118b56} Name: UPnPContainer64 - AppID: {6d8ff8e8-730d-11d4-bf42-00b0d0118b56} Name: SPPComApi - AppID: {6D9A7A40-DDCA-414E-B48E-DFB032C03C1B} Name: TieringEngineService - AppID: {6DF5BCF4-22E9-446D-8763-A2C7677ECF7D} Name: HomeGroup UI Status - AppID: {6f33340d-8a01-473a-b75f-ded88c8360ce} Name: IEWindows - AppID: {6f5bad87-9d5e-459f-bd03-3957407051ca} Name: EditionUpgradeHelper - AppID: {6F65B602-F798-4094-8A41-A2A61961E5E8} Name: HomeGroup Provider Object - AppID: {6F7C8E8F-DC69-4e3f-BC05-439962A05FD5} Name: Out of proc server to enable Insider Hub and Feedback App scenarios to be reached from inside of its appcontainer - AppID: {7006698d-2974-4091-a424-85dd0b909e23} Name: WindowsLiveWriterFilter - AppID: {7054B371-09E3-4BC8-8A61-02D7799EA98A} Name: workfolderssvc - AppID: {712cedb9-16a4-4f79-801d-7de24d8c706e} Name: Sharing Elevated Virtual Factory - AppID: {72A7994A-3092-4054-B6BE-08FF81AEEFFC} Name: User Profile Service DCOM server - AppID: {72E3272B-4EEA-4104-B358-1A282E4FC1AD} Name: Microsoft WMI Provider Subsystem Host - AppID: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} Name: Trusted Installer Service - AppID: {752073A2-23F2-4396-85F0-8FDB879ED0ED} Name: PenIMC4 - AppID: {7568952A-571E-4C70-BEA9-7F9004393436} Name: PrintFilterPipelineSvc - AppID: {76db1bf3-e820-4765-a1b2-0b16a86b1950} Name: ServiceModule - AppID: {76E258F0-DE86-4CEC-9D30-3F728A898741} Name: XWizard Virtual Factory - AppID: {777BA81A-2498-4875-933A-3067DE883070} Name: AcroIEHelperShim - AppID: {77AB4812-5411-4EA9-8437-77AD0F230302} Name: Network and Sharing Center Cpl Elevated Virtual Factory - AppID: {7A076CE1-4B31-452a-A4F1-0304C8738100} Name: Shell FMIFS Wrapper - AppID: {7aa7790d-75d7-484b-98a1-3913d022091d} Name: EapThirdPartyDllHost - AppID: {7B130458-E09C-4823-A8AF-2583DCD9AEC7} Name: Internet Explorer Add-on Installer - AppID: {7B29F495-0F55-49F7-8885-9E8A22CE3829} Name: Shell Create Object Local Server - AppID: {7B6EA1D5-03C2-4AE4-B21C-8D0515CC91B7} Name: WlanPrefLUA - AppID: {7C8AB6D9-8764-4033-8F62-2FE896E54B32} Name: Microsoft Windows Remote Shell Host With User Settings - AppID: {7d378de6-ed8d-426d-91df-0273d07cd7f6} Name: HomeGroup Printing Device Class - AppID: {7DF8EF76-D449-485f-B4EB-58DC96B31EDB} Name: MMC Application Class - AppID: {7e0423cd-1119-0928-900c-e6d4a52a0715} Name: wisptis - AppID: {7F429620-16D1-471E-A81A-114992148034} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {7FC12E96-4CB7-4ABD-ADAA-EF7845B10629} Name: hputils - AppID: {8195693E-0C55-4BE2-A2DB-32376ABC24C4} Name: OpenOffice Service Manager (Ver 1.0) - AppID: {82154420-0FBF-11d4-8313-005004526AB4} Name: CFmIfsEngine host - AppID: {82D94FB3-7FE6-4797-BB72-9A886C66073B} Name: CustReg Class - AppID: {84D586C4-A423-11D2-B943-00C04F79D22F} Name: APSDaemon - AppID: {85187E17-383D-4EC5-B8D6-D9466EE3DD92} Name: Virtual Factory for Usercpl - AppID: {86d5eb8a-859f-4c7b-a76b-2bd819b7a850} Name: CElevateWlanUi - AppID: {86F80216-5DD6-4F43-953B-35EF40A35AEE} Name: ThirdPartyEapDispatcherPeerRuntime - AppID: {87BB326B-E4A0-4DE1-94F0-B9F41D0C6059} Name: AppReadiness Service - AppID: {88283d7c-46f4-47d5-8fc2-db0b5cf0cb54} Name: Activation Manager Shim - AppID: {8A9AE632-CB07-4A11-8872-358A2A271A24} Name: Desktop Wallpaper Factory - AppID: {8B30085D-A3E3-44e3-AE7F-B03A1340EBED} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {8B8C2776-594E-41EA-90D0-8013CACBB9A7} Name: Windows Management and Instrumentation - AppID: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Name: TSTheme - AppID: {8be0366c-8522-40be-8b08-cb26557f2854} Name: IASExtensionHost - AppID: {8C334A55-DDB9-491C-817E-35A6B85D2ECB} Name: AP Client HxHelpPaneServer Class - AppID: {8cec58ae-07a1-11d9-b15e-000d56bfe6ee} Name: TiWorker - AppID: {8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D} Name: Sync Center Schedule Wizard - AppID: {8D8B8E30-C451-421B-8553-D2976AFA648C} Name: WalletService - AppID: {8E44A57C-5638-44D3-9B83-34DF70EB57F2} Name: RdpSa - AppID: {8e7fae4d-cff0-41d3-a326-5a80470264bb} Name: Shell Computer Groups - AppID: {8f3080a6-af99-4f2e-a806-f3d5702a0444} Name: SDRSVC service - AppID: {9037e3cf-1794-4af6-9c8d-92838d7a23db} Name: Virtual Factory for Recovery - AppID: {9200689A-F979-4eea-8830-0E1D6B74821F} Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients - AppID: {924DC564-16A6-42EB-929A-9A61FA7DA06F} Name: HtmlLocalFileResolver - AppID: {93AAD2A0-036A-4B11-A078-DA8776B38139} Name: ServiceModule - AppID: {9465B4B4-5216-4042-9A2C-754D3BCDC410} Name: ServiceModule - AppID: {96D1EED3-701E-4FE5-B996-A543A8465897} Name: PrintIsolationHost - AppID: {98a89e0c-1fde-4c2a-a373-b04831e6aa60} Name: Telephony Incoming Call Toast - AppID: {990F07C7-78DC-4BD2-B145-5F791410BDDE} Name: Shell Hardware Mixed Content Handler - AppID: {995C996E-D918-4a8c-A302-45719A6F4EA7} Name: WLXAutoPlayMgr - AppID: {9B5CDBB0-6D57-4816-BD04-CA9E68DF5610} Name: ShellWindows - AppID: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Name: NVXDPlcy - AppID: {9C5791C4-BCD3-48B8-A10D-CA0279320836} Name: RuntimeBroker - AppID: {9CA88EE3-ACB7-47c8-AFC4-AB702511C276} Name: BioMonitor - AppID: {9D6D21E6-597F-4B63-8CEB-736F77BD2A5E} Name: timedate.cpl - AppID: {9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8} Name: WSearch - AppID: {9E175B9C-F52A-11D8-B9A5-505054503030} Name: WMLSS - AppID: {9E88EF3C-E2BB-4E5E-AFBA-565B81069D7D} Name: ahadmin - AppID: {9fa5c497-f46d-447f-8011-05d03d7d7ddc} Name: CDP Reference Host - AppID: {A0316E2D-8793-4E74-AA48-8CE2ED05BA57} Name: Live Remote Client ActiveX - AppID: {A0CEBC38-C926-4324-A373-ACCA224B549D} Name: WIA Device Manager - AppID: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Name: TrayNotify - AppID: {a2b77517-6d12-4c60-b0c6-725e971ec8fe} Name: rundll32.exe - AppID: {a2d9ca22-a492-400c-b875-78ac25c0a6f3} Name: MhegVM - AppID: {A3637A1F-8CD0-4DA3-9EF5-CC0BD38AF308} Name: Virtual Factory for Windows Firewall Cpl - AppID: {A4B07E49-6567-4FB8-8D39-01920E3B2357} Name: Shell ChkdskEx Dialog - AppID: {a4c31131-ff70-4984-afd6-0609ced53ad6} Name: Nv3DAppShExt - AppID: {A4CF1DBB-664A-4600-9CE3-96FBAA344504} Name: DsmAdminApi - AppID: {A5065670-136D-4FD6-A45F-00C85B90359C} Name: PDFShellInfo - AppID: {A5090E95-F1E2-41C8-BDA1-5AEB6C321FDE} Name: WPDShextAutoplay - AppID: {A55803CC-4D53-404c-8557-FD63DBA95D24} Name: WLIDSvc - AppID: {A6721677-BA21-44E9-9E2A-76466D24D121} Name: Virtual Factory for MaintenanceUI - AppID: {A6BFEA43-501F-456F-A845-983D3AD7B8F0} Name: updaterActiveX - AppID: {A75E0259-1AE1-4046-A5CA-27B2A0DAA8A6} Name: Microsoft Windows Defender - AppID: {A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F} Name: %SystemRoot%\System32\fveui.dll - AppID: {A7A63E5C-3877-4840-8727-C1EA9D7A4D50} Name: SysFxUi - AppID: {A7D2EC8B-B70F-434C-A0CE-0DF324805F7D} Name: VirtualBoxAsw Application - AppID: {A8F69786-BC63-417e-85AF-A2C2D3833032} Name: Delivery Optimization Mgmt - AppID: {AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800} Name: F12AppFrameClient Class - AppID: {AABAA6AA-5398-4C08-AE60-6321A7F05E9C} Name: DEFRAGSVC service - AppID: {ab7c873b-eb14-49a6-be60-a602f80e6d22} Name: Thumbnail Cache Out of Proc Server - AppID: {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} Name: BDEUILauncher Class - AppID: {AB93B6F1-BE76-4185-A488-A9001B105B94} Name: Out of proc server to enable Insider Hub scenarios to be reached from inside of its appcontainer - AppID: {ac0fd47a-37f4-4502-bfee-6b317e479d41} Name: RetailDemo Service - AppID: {ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325} Name: Windows Live Social Object Extractor Engine - AppID: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Name: WPN Srumon Server - AppID: {ada41b3c-c6fd-4a08-8cc1-d6efde67be7d} Name: SwHelper_1163633 - AppID: {AF551664-D2DF-4E34-85DE-46320B13A0B4} Name: TrayToastActivator - AppID: {AFC732E2-BA57-4B3E-A70A-71371F99B871} Name: WorkspaceBroker Class - AppID: {B06FF84E-0A77-4DD2-A919-0EABD8979DC1} Name: TabIps - AppID: {B1445657-5A98-11d9-A4E5-00301BB132BA} Name: DockInterface COM server - AppID: {b21858c6-9711-4257-99c8-5c0084bebce1} Name: Windows Update Agent - Remote Access - AppID: {B366DEBE-645B-43A5-B865-DDD82C345492} Name: AppActivationFailedHandler - AppID: {B3AADFEA-8404-4CBE-A62E-B0B715412C9E} Name: Out Of Proc Mapi Handler - AppID: {b5453d2d-5ad4-4df7-a399-0245244a4b60} Name: Found New Hardware Wizard - AppID: {B6A32FE6-E29D-AEAE-A608-D273E40CA34C} Name: WIA Device Manager 2 - AppID: {B6C292BC-7C88-41EE-8B54-8EC92617E599} Name: Sync Center (Private) - AppID: {B8558612-DF5E-4F95-BB81-8E910B327FB2} Name: WLX Thumbnail Cache Out of Proc Server - AppID: {B8A2E14E-290D-4122-B092-1A7D86198CCE} Name: Windows Media Player - AppID: {B8C54A54-355E-11D3-83EB-00A0C92A2F2D} Name: NVXDApiX - AppID: {B92B577B-628A-442B-A017-E86FB518C6FD} Name: ApplicationActivationImpl - AppID: {B9305506-D05B-4C36-81C5-0E50886C1755} Name: Application Frame Host - AppID: {B9B05098-3E30-483F-87F7-027CA78DA287} Name: Event Object Change 2 - AppID: {BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4} Name: AcroPDF - AppID: {BBAA0E44-3862-490C-8E63-AC2D2D6EF733} Name: SyncHost - AppID: {BBC4356A-F004-4628-A27A-E13D70412B70} Name: Virtual Factory for Power Options Control Panel - AppID: {BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B} Name: Setting Sync Task Factory - AppID: {bcbb3f8c-2889-474f-8fb7-904d4a416145} Name: DfsShlEx.dll - AppID: {BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B} Name: EditionUpgradeManagerObj - AppID: {BD54C901-076B-434E-B6C7-17C531F4AB41} Name: VM IC Heartbeat Service - AppID: {be0fc7f0-f248-4091-a123-34ca29a6901b} Name: Shell AutoPlay Direct - AppID: {BF8841C9-378A-4CAD-B4FC-5091366CBC0D} Name: BTStackServer - AppID: {C05A68C7-580B-11D4-98D0-006008BF430C} Name: ShellBrowserWindow - AppID: {c08afd90-f2a1-11d1-8455-00a0c91f3880} Name: LockAppHost Out of Proc Helper for Lock Apps - AppID: {C08B030B-E91C-479D-BEFD-02DDA7FF1BCF} Name: provsvc.dll - AppID: {c2a71820-3463-498f-bab7-4798795a2ff6} Name: DataExchangeHost - AppID: {C2E9756F-8155-4EAC-9ED5-0B690169D412} Name: cttunesvr - AppID: {C3A34354-660F-41EE-B072-2AEA5E3A80AF} Name: Microsoft Block Level Backup Service - AppID: {C3B65D83-FB15-4e3f-BA04-097D1E2B5AC1} Name: Microsoft IMAPI - AppID: {C49F2185-50A7-11D3-9144-00104BA11C5E} Name: BdeUISrv - AppID: {C4AB7CB7-E735-48FF-AADD-39D09668F444} Name: HomeGroup Listener Service - AppID: {C4CDC408-581C-4480-9FFE-3B1C78D5C20D} Name: Xbox Live Game Saves - AppID: {C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3} Name: Nvvsvc - AppID: {C5EDFC9D-B018-41A4-9877-39AB18469C3A} Name: EntAppSvc - AppID: {C63261E4-6052-41FF-B919-496FECF4C4E5} Name: EmailClient Class - AppID: {C6E0A4C8-A933-411E-8068-406C2391665F} Name: LockScreen Application Notification Broker - AppID: {C89FC3EF-A0DC-4feb-BFBC-F13A9C334D4F} Name: TSWbPrxy.exe - AppID: {C92A9617-0EAE-4235-BD2B-84540EF1FFA9} Name: DictationHost Class - AppID: {C945AD06-534F-460C-8CB4-17C33099AF81} Name: Sync Infrastructure - AppID: {C947D50F-378E-4FF6-8835-FCB50305244D} Name: netprofm - AppID: {C96887DA-A652-4426-905E-4A37546F847C} Name: editionupgradebroker - AppID: {C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125} Name: RCM - AppID: {C9F65BA8-1F8F-4382-AE27-C91FFB29275F} Name: User OOBE Create Elevated Object Server - AppID: {ca8c87c1-929d-45ba-94db-ef8e6cb346ad} Name: OpenSearch Description Create Search Connector Verb Handler - AppID: {CB1DFE3A-EDFF-4d1f-867D-8ADB02926F4B} Name: PrintIsolationSessionHost - AppID: {CB363445-F453-4C1E-8EE4-BD123C5E394F} Name: SkypeIEPlugin - AppID: {CB487EA6-E83B-4F63-8CAE-B1B1D23DA65E} Name: EnhancedStorageShell - AppID: {CC70FEAD-94B9-4F76-88CC-004BB068ACDF} Name: sppui - AppID: {CCFDD24D-CEAB-458B-A4F1-F884973395DF} Name: WcsPlugInServiceLib - AppID: {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607} Name: Windows Media Player Burn Audio CD Handler - AppID: {cdc32574-7521-4124-90c3-8d5605a34933} Name: Elevated-Unelevated Explorer Factory - AppID: {CDCBCFCA-3CDC-436f-A4E2-0E02075250C2} Name: PNPXAssoc.dll - AppID: {cee8ccc9-4f6b-4469-a235-5a22869eef03} Name: sdchange - AppID: {CF254B00-1986-4b24-A92D-463D01F7E395} Name: Event Object Change - AppID: {D0565000-9DF4-11D1-A281-00C04FCA0AA7} Name: HealthDriverBridge - AppID: {D190DCB4-AAAB-4507-A0AF-0AD12F2603A4} Name: Winmgmt MOF Compiler OOP - AppID: {D215781D-019E-4FA0-903D-0CDCDE13A4F5} Name: Color Management - AppID: {D2E7041B-2927-42fb-8E9F-7CE93B6DC937} Name: Bitmap Image - AppID: {D3E34B21-9D75-101A-8C3D-00AA001A1652} Name: ghost - AppID: {D58F39FF-953E-4F45-898F-59F243B9A523} Name: Sync Center User Profile Notification Handler - AppID: {D63AA156-D534-4BAC-9BF1-55359CF5EC30} Name: CloudStorageWizard - AppID: {D8775A07-C529-4EA7-B307-BA7C8CBBDA03} Name: Microsoft Software Protection Platform Admin Object (outer) - AppID: {D8D4249F-A8FB-44A7-8AA0-564E8C385BD6} Name: MSMQ - AppID: {DCBCADF5-DB1b-4764-9320-9a5082af1581} Name: BrowserBrokerServer - AppID: {DD9C53BC-8441-4B94-BD0E-36E6E02A6D61} Name: Srumon Server - AppID: {ddcfd26b-feed-44cd-b71d-79487d2e5e5a} Name: rundll32.exe - AppID: {de5d803e-5d2a-4b5f-9c63-af25a465cc44} Name: AccStore Class - AppID: {DE5DBCDC-104A-4cbc-A4D5-0C2104A142C5} Name: LockScreen Call Broker - AppID: {DE7D3D65-5454-4EF5-9518-776739DAB39F} Name: Profile Notification Host - AppID: {E10F6C3A-F1AE-4adc-AA9D-2FE65525666E} Name: Immersive Print Dialog Surrogate - AppID: {E15FBAC2-C276-4523-92CA-561456EBCF3E} Name: Windows Update Agent User Interface for Published Applications - AppID: {e30984f1-b02b-4c27-a40f-23d11b8c1212} Name: Scan - AppID: {E32549C4-C2B8-4BCC-90D7-0FC3511092BB} Name: Execute Unknown - AppID: {e44e9428-bdbc-4987-a099-40dc8fd255e7} Name: upnphost - AppID: {E495081B-BBA5-4b89-BA3C-3B86A686B87A} Name: TrayDesktopBand - AppID: {E6442437-6C68-4f52-94DD-2CFED267EFB9} Name: Orchestrator Service - AppID: {E7299E79-75E5-47BB-A03D-6D319FB7F886} Name: TokenBroker Out Of Proc COM Server - AppID: {E73A797B-24CE-424A-AD4F-48E98B1E95B8} Name: UICOM - AppID: {E8054D20-497D-4E16-BF41-6E69FCD381A5} Name: iisctl - AppID: {E8FB8615-588F-11D2-9D61-00C04F79C5FE} Name: wscui.cpl - AppID: {E9495B87-D950-4ab5-87A5-FF6D70BF3E90} Name: Remove Device elevation surrogate - AppID: {E95186C7-7D80-4311-843D-0702CBC8B1E4} Name: File Prop Sheet Page Helper - AppID: {E96767E0-7EAA-45E1-8E7D-64414AFF281A} Name: HomeGroup Provider Service - AppID: {EA022610-0748-4c24-B229-6C507EBDFDBB} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8} Name: Immersive Print Dialog Surrogate - AppID: {EB28E902-728E-42C4-97DC-DA89E144C744} Name: Remote Desktop Services Message Server - AppID: {EB521D7D-4095-4E61-88FB-BF25700F142A} Name: ComEvents.ComServiceEvents - AppID: {ECABB0C3-7F19-11D2-978E-0000F8757E2A} Name: ComEvents.ComSystemAppEventData - AppID: {ECABB0C6-7F19-11D2-978E-0000F8757E2A} Name: Play with Windows Media Player - AppID: {ed1d0fdf-4414-470a-a56d-cfb68623fc58} Name: SWDNLD - AppID: {ED372EB0-5B14-484F-A27C-05FF89B6DF25} Name: Windows Media Player Launch - AppID: {ED6BB178-B06A-47ad-98B3-6066E0CF0147} Name: Share Manager - AppID: {edb5f444-cb8d-445a-a523-ec5ab6ea33c7} Name: NVXDBat - AppID: {EF73A51A-EE4A-4E16-9D3A-649245C8F44F} Name: CloudExperienceHost Broker AppID - AppID: {efe2d6d8-a81b-41e7-ae77-e5244ab80522} Name: Microsoft Audio Device Graph Server - AppID: {F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC} Name: AcroBroker - AppID: {F2383816-917A-46CC-AD2A-5013BED3800F} Name: Virtual Disk Service - AppID: {F290BFB2-1864-45B1-8804-2654194A87E7} Name: HPDeviceDetection3 - AppID: {F2C11667-CC5C-46FF-A13C-6DDC30C1154F} Name: FodHelper - AppID: {F2F94BB3-595C-4509-B7EE-243FA2BDEA5B} Name: SPPSurrogate - AppID: {f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801} Name: NVIDIA.Installer2 - AppID: {F370E41B-AFAD-4B49-AFD4-0FEF3FC1375D} Name: NDFAPI - AppID: {F3D3AA8D-EF96-4470-848E-BD70B803047A} Name: PerfCenter Enabler - AppID: {f4be747e-45c4-4701-90f1-d49d9ac30248} Name: sdclt - AppID: {f56b7b2a-5b5a-46d8-b6f9-d927ce34b717} Name: Intel(R) Capability Licensing Service Interface - AppID: {F6189E3E-8B57-4CC9-B6F6-2F1FF1D1D9D4} Name: btwdins - AppID: {F6B856DA-AB94-4355-A42F-EC493BEA79DE} Name: WMPNSSCI - AppID: {F74BCE98-9EB4-4022-8317-11C723E5CCF8} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {F7CDD0DF-887D-463F-AF57-0E442B5C233B} Name: CloudExperienceHost Create System Object Server - AppID: {f7fa3149-91e7-43b7-8040-b707688ced1a} Name: logagent - AppID: {F808DF63-6049-11D1-BA20-006097D2898E} Name: WLIDFDP - AppID: {F828BB1A-2FAE-4AC4-AE6F-CAC9B529F996} Name: RAServer - AppID: {F8FD03A6-DDD9-4C1B-84EE-58159476A0D7} Name: WinInetBrokerServer - AppID: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Name: iTunes - AppID: {F98206B5-F052-4965-9FA0-85F61BC3C19D} Name: NCLUA - AppID: {FA1456D3-4B97-4f9c-8511-2786161DC333} Name: VssEvent - AppID: {FAF53CC4-BD73-4E36-83F1-2B23F46E513E} Name: Shell Hardware Mixed Content Handler Cancelled - AppID: {fb479c02-9ec4-4fed-8599-debe037452cb} Name: BtwNamespaceExt - AppID: {FC30068F-18DF-4885-9FFA-B84D390EAE81} Name: RegisterControl - AppID: {FC38B7C8-9E50-497d-A387-7DEBDAD14160} Name: Hotspot Auth Module - AppID: {FC5EEAF6-0002-11DF-ADB9-F4CE462D9137} Name: appwiz.cpl - AppID: {FCC74B77-EC3E-4dd8-A80B-008A702075A9} Name: Wordpad - AppID: {fd6c8b29-e936-4a61-8da6-b0c12ad3ba00} Name: Proximity UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10C} Name: MP UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10D} Name: Shell Execute Hardware Event Handler - AppID: {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} Name: EntAppSvc - AppID: {FFE1E5FE-F1F0-48C8-953E-72BA272F2744} Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-32-559" Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0771f7af-8de6-4bce-9528-2d4a12cb8168}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{0771f7af-8de6-4bce-9528-2d4a12cb8168}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{077869D3-D0DE-4586-882B-359F80009D0C}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{077869D3-D0DE-4586-882B-359F80009D0C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{077869D3-D0DE-4586-882B-359F80009D0C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{077869D3-D0DE-4586-882B-359F80009D0C}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{0868DC9B-D9A2-4f64-9362-133CEA201299}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0868DC9B-D9A2-4f64-9362-133CEA201299}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{119817C9-666D-4053-AEDA-627D0E25CCEF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{119817C9-666D-4053-AEDA-627D0E25CCEF}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{136A0DC7-DF5C-4271-A2AC-15DF1A1323F2}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{136A0DC7-DF5C-4271-A2AC-15DF1A1323F2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{16D99191-6280-4B33-A2F5-04805A0FC582}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{16D99191-6280-4B33-A2F5-04805A0FC582}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-547" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-556" Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F14}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F14}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F14}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F14}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{205609B7-5E08-443E-B0A7-A7AED3F3A717}" - Win32_SID.SID="S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628" Win32_DCOMApplication.AppID="{205609B7-5E08-443E-B0A7-A7AED3F3A717}" - Win32_SID.SID="S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-556" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-15-3-1024-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067" Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{2A947841-0594-48CF-9C53-A08C95C22B55}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{2A947841-0594-48CF-9C53-A08C95C22B55}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-15-3-1024-1314380931-3989923313-3249193833-1963115619-3940350845-1282913705-2904921893-3519892189" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1212" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{37B05236-FFB5-4D42-B0C8-4A36CBF1BE62}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{37B05236-FFB5-4D42-B0C8-4A36CBF1BE62}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4680B596-CF8C-44E1-A676-4AAA819E041F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4680B596-CF8C-44E1-A676-4AAA819E041F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4680B596-CF8C-44E1-A676-4AAA819E041F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4680B596-CF8C-44E1-A676-4AAA819E041F}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{478B41E6-3257-4519-BDA8-E971F9843849}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{478B41E6-3257-4519-BDA8-E971F9843849}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{478B41E6-3257-4519-BDA8-E971F9843849}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{478B41E6-3257-4519-BDA8-E971F9843849}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-80-611605672-2879557022-2206624263-4029342278-3129212340" Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4FCDA643-B15B-41C6-84F8-5E447F6F6D25}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{5011B6DE-E9FA-4518-B5E5-45DE9DD2CDC6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{5011B6DE-E9FA-4518-B5E5-45DE9DD2CDC6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5011B6DE-E9FA-4518-B5E5-45DE9DD2CDC6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{5032734C-9867-41BF-ABDD-24513D68E613}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5032734C-9867-41BF-ABDD-24513D68E613}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{5032734C-9867-41BF-ABDD-24513D68E613}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-32-2707581722-3970398075-3301609242-3412871183-2565310287-2959982868-2531230773-2372594412" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-15-3-1024-2707581722-3970398075-3301609242-3412871183-2565310287-2959982868-2531230773-2372594412" Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{59347292-B72D-41F2-98C5-E9ACA1B247A2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{59347292-B72D-41F2-98C5-E9ACA1B247A2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-15-3-1024-3625662137-2682091254-856171984-2868379045-3001028726-1009205972-4175949866-684286152" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1031" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376" Win32_DCOMApplication.AppID="{5C917E9C-0B2F-40D6-928B-5C43FDB16DF4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{5C917E9C-0B2F-40D6-928B-5C43FDB16DF4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5C917E9C-0B2F-40D6-928B-5C43FDB16DF4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{5E176815-9A63-4A69-810F-62E90D36612A}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{5E176815-9A63-4A69-810F-62E90D36612A}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6390FFFB-1C89-4E0C-AE24-76102B99F750}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6390FFFB-1C89-4E0C-AE24-76102B99F750}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6390FFFB-1C89-4E0C-AE24-76102B99F750}" - Win32_SID.SID="S-1-5-21-2532391380-2442022221-794288624-1000" Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{65E2E13A-7110-4912-9F03-9A42E253D8F6}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{65E2E13A-7110-4912-9F03-9A42E253D8F6}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6CF9B800-50DB-46B5-9218-EACF07F5E414}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{6CF9B800-50DB-46B5-9218-EACF07F5E414}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6CF9B800-50DB-46B5-9218-EACF07F5E414}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{6CF9B800-50DB-46B5-9218-EACF07F5E414}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{6CF9B800-50DB-46B5-9218-EACF07F5E414}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{730BFCEC-E4BF-4D3A-9FBB-01DD132467A4}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-32-546" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{84D586C4-A423-11D2-B943-00C04F79D22F}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-15-3-1024-1701033769-137094913-3738083205-577272984-1204217555-1180762924-3352773070-2589626690" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1210" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A0316E2D-8793-4E74-AA48-8CE2ED05BA57}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{B06FF84E-0A77-4DD2-A919-0EABD8979DC1}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{B06FF84E-0A77-4DD2-A919-0EABD8979DC1}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708" Win32_DCOMApplication.AppID="{B366DEBE-645B-43A5-B865-DDD82C345492}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{B8C54A54-355E-11D3-83EB-00A0C92A2F2D}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{B8C54A54-355E-11D3-83EB-00A0C92A2F2D}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{C5EDFC9D-B018-41A4-9877-39AB18469C3A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{C5EDFC9D-B018-41A4-9877-39AB18469C3A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C5EDFC9D-B018-41A4-9877-39AB18469C3A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C5EDFC9D-B018-41A4-9877-39AB18469C3A}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C92A9617-0EAE-4235-BD2B-84540EF1FFA9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CCFDD24D-CEAB-458B-A4F1-F884973395DF}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{CCFDD24D-CEAB-458B-A4F1-F884973395DF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CF254B00-1986-4b24-A92D-463D01F7E395}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CF254B00-1986-4b24-A92D-463D01F7E395}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{D215781D-019E-4FA0-903D-0CDCDE13A4F5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{D63377CC-5B83-4213-BCA8-1E6CD0462F2A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{D63377CC-5B83-4213-BCA8-1E6CD0462F2A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}" - Win32_SID.SID="S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628" Win32_DCOMApplication.AppID="{D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}" - Win32_SID.SID="S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464" Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-32-551" Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-80-364023826-931424190-487969545-1024119571-74567675" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F8FD03A6-DDD9-4C1B-84EE-58159476A0D7}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-556" Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{FE2F9D0D-18A4-4845-BA41-DE6451A66D11}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-32-544" ---------- | Svchost - Netsvcs (Whitelisted) NetSetupSvc - %SystemRoot%\System32\NetSetupSvc.dll : %SystemRoot%\System32\svchost.exe -k netsvcs UserManager - %SystemRoot%\System32\usermgr.dll : %SystemRoot%\system32\svchost.exe -k netsvcs ---------- | Software [HKU\S-1-5-18\Software\45918InstEnd] [HKU\S-1-5-18\Software\4E28C607CF06AA6208020DCDFAF2937A] [HKU\S-1-5-18\Software\7BC7120CE13AB1935E25FFEAC5614D8A] [HKU\S-1-5-18\Software\AppDataLow] [HKU\S-1-5-18\Software\Apple Inc.] [HKU\S-1-5-18\Software\Avast Software] [HKU\S-1-5-18\Software\B1CA1D637BFBEEA7ACBB2CB997609F45] [HKU\S-1-5-18\Software\CBD5DCBBF51CDE119B2F62F2E996E82C] [HKU\S-1-5-18\Software\Dropbox] [HKU\S-1-5-18\Software\Google] [HKU\S-1-5-18\Software\Hewlett-Packard] [HKU\S-1-5-18\Software\Macromedia] [HKU\S-1-5-18\Software\Microsoft] [HKU\S-1-5-18\Software\MozillaPlugins] [HKU\S-1-5-18\Software\NVIDIA Corporation] [HKU\S-1-5-18\Software\Piriform] [HKU\S-1-5-18\Software\Policies] [HKU\S-1-5-18\Software\RegisteredApplications] [HKU\S-1-5-18\Software\Skype] [HKU\S-1-5-18\Software\SSScan] [HKU\S-1-5-18\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}] [HKU\S-1-5-18\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}] [HKU\S-1-5-18\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-18\Software\Microsoft\Windows\DWM] [HKU\S-1-5-18\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001_Classes\Software\Microsoft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001_Classes\Software\Piriform] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001_Classes\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Adobe] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\AppDataLow] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Apple Computer, Inc.] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Apple Inc.] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\AuthenTec] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Autodesk] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Avast Software] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\AWIND] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\BcmSetup] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\C120DLUSB] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Chromium] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Clients] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\CodeBlocks] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\ComfortSoftware] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\CyberLink] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Disc Soft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Dropbox] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\DropboxUpdate] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\e-academy Inc.] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\EPSON] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Extended Systems] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Facebook] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\g3n-h@ckm@n] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Google] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\GSC Game World] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Hewlett-Packard] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\IM Providers] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Intel] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\JavaSoft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Local AppWizard-Generated Applications] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Macromedia] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\MainConcept] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Mozilla] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\MozillaPlugins] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Netscape] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\NVIDIA Corporation] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\ODBC] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\OpenOffice] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Policies] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\PopCap] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\QtProject] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\RegisteredApplications] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Research In Motion] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\SecuROM] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Skype] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\SkypeRS] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Symantec] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Synaptics] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\sysinternals] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Trolltech] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\UsbFix] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Widcomm] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Wow6432Node] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\ZebHelpProcess Helper] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\{B2CB09FF-2453-4f85-9F40-21C05BE4CBA8}] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\AppDataLow\Software\Adobe] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\AppDataLow\Software\JavaSoft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\Roaming] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\AppDataLow] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Google] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\GSC Game World] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Policies] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-2532391380-2442022221-794288624-1000\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-20\Software\Microsoft] [HKU\S-1-5-20\Software\Policies] [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-20\Software\Microsoft\Windows\DWM] [HKU\S-1-5-20\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-20\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-19\Software\Microsoft] [HKU\S-1-5-19\Software\Policies] [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-19\Software\Microsoft\Windows\DWM] [HKU\S-1-5-19\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-19\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\AdsFix] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\Apple Inc.] [HKLM\Software\ATI Technologies] [HKLM\Software\AuthenTec] [HKLM\Software\Autodesk] [HKLM\Software\AVAST Software] [HKLM\Software\Broadcom] [HKLM\Software\CBSTEST] [HKLM\Software\Clients] [HKLM\Software\CXT] [HKLM\Software\Cyberlink] [HKLM\Software\Dell] [HKLM\Software\Disc Soft] [HKLM\Software\EPSON] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\GEAR Software] [HKLM\Software\Hewlett-Packard] [HKLM\Software\HPQ] [HKLM\Software\Huawei technologies] [HKLM\Software\IDT] [HKLM\Software\IM Providers] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\Khronos] [HKLM\Software\Macromedia] [HKLM\Software\Macrovision] [HKLM\Software\mcafeeupdater] [HKLM\Software\MGTEK] [HKLM\Software\Microsoft] [HKLM\Software\Mozilla] [HKLM\Software\MozillaPlugins] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\Partner] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\Realtek Semiconductor Corp.] [HKLM\Software\RegisteredApplications] [HKLM\Software\RTLSetup] [HKLM\Software\Sonic] [HKLM\Software\SRS Labs] [HKLM\Software\Synaptics] [HKLM\Software\sysinternals] [HKLM\Software\WhlProvider] [HKLM\Software\WOW6432Node] [HKLM\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}] [HKLM\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}] [HKLM\Software\Microsoft\Windows\ClickNote] [HKLM\Software\Microsoft\Windows\Configuration] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\DWM] [HKLM\Software\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\Microsoft\Windows\Help] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\apphost] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\iissvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wswpnservice] [HKLM\Software\WOW6432Node\AbiWord] [HKLM\Software\WOW6432Node\Adobe] [HKLM\Software\WOW6432Node\AppDataLow] [HKLM\Software\WOW6432Node\Apple Computer, Inc.] [HKLM\Software\WOW6432Node\Apple Inc.] [HKLM\Software\WOW6432Node\AuthenTec] [HKLM\Software\WOW6432Node\Autodesk] [HKLM\Software\WOW6432Node\AVAST Software] [HKLM\Software\WOW6432Node\Bytemobile] [HKLM\Software\WOW6432Node\Caphyon] [HKLM\Software\WOW6432Node\CyberLink] [HKLM\Software\WOW6432Node\dotNetInstaller] [HKLM\Software\WOW6432Node\Dropbox] [HKLM\Software\WOW6432Node\DropboxUpdate] [HKLM\Software\WOW6432Node\EasyBits] [HKLM\Software\WOW6432Node\EPSON] [HKLM\Software\WOW6432Node\Evernote] [HKLM\Software\WOW6432Node\Extended Systems] [HKLM\Software\WOW6432Node\Firefox] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\Hewlett-Packard] [HKLM\Software\WOW6432Node\Huawei technologies] [HKLM\Software\WOW6432Node\IDT] [HKLM\Software\WOW6432Node\IM Providers] [HKLM\Software\WOW6432Node\IncrediMail] [HKLM\Software\WOW6432Node\Insyde] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\JavaSoft] [HKLM\Software\WOW6432Node\JreMetrics] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\LogMeInRescueCallingCard] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\WOW6432Node\McAfee.com] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\mozilla.org] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\NVIDIA Corporation] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\OpenOffice] [HKLM\Software\WOW6432Node\Realtek] [HKLM\Software\WOW6432Node\Realtek Semiconductor Corp.] [HKLM\Software\WOW6432Node\Research In Motion] [HKLM\Software\WOW6432Node\SCi Games] [HKLM\Software\WOW6432Node\Skype] [HKLM\Software\WOW6432Node\SOSVirus] [HKLM\Software\WOW6432Node\SSScan] [HKLM\Software\WOW6432Node\Symantec] [HKLM\Software\WOW6432Node\Sysinternals] [HKLM\Software\WOW6432Node\TGUID] [HKLM\Software\WOW6432Node\tmptmp] [HKLM\Software\WOW6432Node\Validity] [HKLM\Software\WOW6432Node\VideoLAN] [HKLM\Software\WOW6432Node\WhlProvider] [HKLM\Software\WOW6432Node\WildTangent] [HKLM\Software\WOW6432Node\Win32 Services] [HKLM\Software\WOW6432Node\WinZiper] [HKLM\Software\WOW6432Node\Wow6432Node] [HKLM\Software\WOW6432Node\Yahoo] [HKLM\Software\WOW6432Node\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}] [HKLM\Software\WOW6432Node\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}] [HKLM\Software\WOW6432Node\{E6276374-DE18-4AA5-A365-9016A2F98A2D}] [HKLM\Software\WOW6432Node\{G6276374-DEEE-4AAA-A355-9016A2F98A2D}] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\iissvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc] ---------- | FeatureControl [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL] "WindowsAnytimeUpgradeUI.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION] "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "infopath.exe"="0" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS] "HelpPane.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG] "HelpPane.exe"="1" "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT] "HelpPane.exe"="1" "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT] "HelpPane.exe"="1" "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] "HelpPane.exe"="10000" "prevhost.exe"="8000" "sllauncher.exe"="8000" "XMLViewerHPSF.exe"="11000" "HPSFViewer.exe"="11000" "HPCF.exe"="11000" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING] "iexplore.exe"="1" "*"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "SAPfewgsrv.exe"="0" "SAPGUI.exe"="0" "SAPGuiIT.exe"="0" "SAPLgPad.exe"="0" "SAPLOGON.exe"="0" "Scale_for_R3.exe"="0" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP] "ieuser.exe"="1" "iexplore.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK] "YahooMusicEngine.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE] "HelpPane.exe"="100000" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT] "devenv.exe"="1" "dexplore.exe"="1" "helppane.exe"="1" "PresentationHost.exe"="0" "sllauncher.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS] "msfeedssync.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS] "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES] "sidebar.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE] "HelpPane.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG] ""="" "msiexec.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART] "cs.exe"="1" "waol.exe"="1" "wm.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS] "iexplore.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS] "helppane.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS] "wlmail.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "sllauncher.exe"="1" "clview.exe"="1" "msaccess.exe"="1" "Groove.exe"="1" "OUTLOOK.EXE"="1" "powerpnt.exe"="1" "excel.exe"="1" "winwordd.exe"="1" "winword.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] "explorer.exe"="4" "sllauncher.exe"="6" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] "explorer.exe"="2" "sllauncher.exe"="6" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MEMPROTECT_MODE] "*"="3" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME] "mshta.exe"="1" "outlook.exe"="1" "sidebar.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="0" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN] "explorer.exe"="0" "iexplore.exe"="0" "wmplayer.exe"="1" "ehExtHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING] "communicator.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD] "msimn.exe"="1" "prevhost.exe"="1" "winmail.exe"="1" "wmplayer.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE] "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND] "prevhost.exe"="1" "wmplayer.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE] "HelpPane.exe"="0" "prevhost.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG] "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN] "msimn.exe"="1" "outlook.exe"="1" "winmail.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK] "HelpPane.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL] "excel.exe"="1" "infopath.exe"="1" "powerpnt.exe"="1" "winword.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE] "HelpPane.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD] "msn.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER] "iexplore.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION] "explorer.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "ehExtHost.exe"="1" "clview.exe"="1" "GROOVE.EXE"="1" "OUTLOOK.EXE"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION] "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "infopath.exe"="0" "wmplayer.exe"="1" "wlmail.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS] "HelpPane.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG] "HelpPane.exe"="1" "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT] "HelpPane.exe"="1" "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT] "HelpPane.exe"="1" "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] "HelpPane.exe"="10000" "prevhost.exe"="8000" "sllauncher.exe"="8000" "mbam.exe"="11000" "Skype.exe"="10001" "SkypeBrowserHost.exe"="10001" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING] "iexplore.exe"="1" "*"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "SAPfewgsrv.exe"="0" "SAPGUI.exe"="0" "SAPGuiIT.exe"="0" "SAPLgPad.exe"="0" "SAPLOGON.exe"="0" "Scale_for_R3.exe"="0" "wmplayer.exe"="1" "wlmail.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP] "ieuser.exe"="1" "iexplore.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK] "YahooMusicEngine.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE] "HelpPane.exe"="100000" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT] "devenv.exe"="1" "dexplore.exe"="1" "helppane.exe"="1" "PresentationHost.exe"="0" "sllauncher.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS] "msfeedssync.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS] "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES] "sidebar.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE] "HelpPane.exe"="1" "wmplayer.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG] ""="" "msiexec.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART] "cs.exe"="1" "waol.exe"="1" "wm.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS] "iexplore.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS] "helppane.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS] "wlmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] "explorer.exe"="4" "sllauncher.exe"="6" "Skype.exe"="6" "SkypeBrowserHost.exe"="6" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] "explorer.exe"="2" "msnmsgr.exe"="6" "sllauncher.exe"="6" "Skype.exe"="6" "SkypeBrowserHost.exe"="6" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MEMPROTECT_MODE] "*"="3" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME] "mshta.exe"="1" "outlook.exe"="1" "sidebar.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" "ehexthost32.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN] "explorer.exe"="0" "iexplore.exe"="0" "wmplayer.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING] "communicator.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD] "msimn.exe"="1" "prevhost.exe"="1" "winmail.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE] "PresentationHost.exe"="1" "wlmail.exe"="1" "WindowsLiveWriter.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND] "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE] "HelpPane.exe"="0" "prevhost.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG] "PresentationHost.exe"="1" "sllauncher.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN] "msimn.exe"="1" "outlook.exe"="1" "winmail.exe"="1" "wlmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK] "HelpPane.exe"="1" "wmplayer.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL] "excel.exe"="1" "infopath.exe"="1" "powerpnt.exe"="1" "winword.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "ehexthost32.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE] "HelpPane.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WARN_ON_SEC_CERT_REV_FAILED] "mbam.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD] "msn.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER] "iexplore.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION] "explorer.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" "wlmail.exe"="1" "ehexthost32.exe"="1" ---------- | The Created last ones ¦ Modified [MD5.00000000000000000000000000000000] - [22/07/2016 18:20:38] - |D| - [0] - C:\Program Files (x86)\Firefox_temp [MD5.7EFB1577EFBD72521E670188AA546C7D] - [14/07/2016 10:48:19] - |A| - [53208] - C:\WINDOWS\avastSS.scr [MD5.E396258CFD8F84E8F2C24930E6D88C67] - [13/07/2016 20:55:14] - |A| - [4515256] - C:\WINDOWS\explorer.exe [MD5.430DE1635CE173440D34ABA1676113D7] - [13/07/2016 20:53:37] - |A| - [994816] - C:\WINDOWS\HelpPane.exe [MD5.8848CED16D446BAC9A48236CFF9E0B69] - [01/07/2016 22:21:16] - |A| - [563946023] - C:\WINDOWS\MEMORY.DMP [MD5.00000000000000000000000000000000] - [01/07/2016 22:21:22] - |D| - [310284] - C:\WINDOWS\Minidump [MD5.9FA0FB567C8CC8E9590FB35483771B7C] - [05/07/2016 19:40:55] - |A| - [39772160] - C:\WINDOWS\Installer\529c4bd.msi [MD5.324354A1923C4F531BDC0046906C4C10] - [04/07/2016 18:15:10] - |RA| - [39859200] - C:\WINDOWS\Installer\ada2b5.msp [MD5.A67E2F3D60DA58C6C599BB9A7645883B] - [14/07/2016 17:11:49] - |A| - [550424] - C:\WINDOWS\Installer\MSI1AB0.tmp [MD5.3C5A9FD95E7A757B6BA5154A56403A1F] - [14/07/2016 17:11:53] - |A| - [311920] - C:\WINDOWS\Installer\MSI299B.tmp [MD5.3C5A9FD95E7A757B6BA5154A56403A1F] - [14/07/2016 17:04:24] - |A| - [311920] - C:\WINDOWS\Installer\MSI4FB9.tmp [MD5.9471017B246F1B3DBBD8984ECC1F4293] - [14/07/2016 16:48:32] - |A| - [85504] - C:\WINDOWS\Installer\MSIC7BB.tmp [MD5.200EB7671D84357CFDE07E377A597899] - [14/07/2016 16:46:24] - |A| - [148992] - C:\WINDOWS\Installer\MSID2F2.tmp [MD5.7C4E0B035A89024ACE50ED6153B543BC] - [14/07/2016 16:48:43] - |A| - [166032] - C:\WINDOWS\Installer\MSIF2E5.tmp [MD5.00000000000000000000000000000000] - [05/07/2016 19:42:27] - |D| - [145760] - C:\WINDOWS\Installer\{FC965A47-4839-40CA-B618-18F486F042C6} [MD5.9F0D0E63D6B10C2222B4FCC784AA3A4E] - [13/07/2016 20:55:29] - |A| - [315392] - C:\WINDOWS\system32\aadcloudap.dll [MD5.17D3651E968F5E7712110FC70BFC973D] - [13/07/2016 20:55:58] - |A| - [853504] - C:\WINDOWS\system32\aadtb.dll [MD5.F785587BCA673FB606BD3618EB767EEE] - [13/07/2016 20:52:02] - |A| - [92352] - C:\WINDOWS\system32\acmigration.dll [MD5.827B2A2F64465D19DF9F655FE7F10384] - [13/07/2016 20:52:34] - |A| - [565760] - C:\WINDOWS\system32\ActionCenterCPL.dll [MD5.8F533910E5D0A63500B17F486331259F] - [13/07/2016 20:53:34] - |A| - [356864] - C:\WINDOWS\system32\ActivationManager.dll [MD5.A499B4A9A1F4989BD37F812BC6DC0298] - [13/07/2016 20:51:22] - |A| - [4775424] - C:\WINDOWS\system32\actxprxy.dll [MD5.EF6BD61D1F7B3E4C20EEC44F9B07E06D] - [13/07/2016 20:52:02] - |A| - [1223872] - C:\WINDOWS\system32\aeinv.dll [MD5.83A5F89896E625650148CEFCABD8418D] - [13/07/2016 20:51:51] - |A| - [219136] - C:\WINDOWS\system32\aepic.dll [MD5.FDDC75FDB8F9B581E3D6513FB85256E8] - [13/07/2016 20:53:46] - |A| - [342016] - C:\WINDOWS\system32\APHostService.dll [MD5.7B2FEC36A1166CBAB50135FCE044D9CE] - [13/07/2016 20:53:25] - |A| - [86528] - C:\WINDOWS\system32\AppCapture.dll [MD5.177306E7F752A627A82D1F362A01FADE] - [13/07/2016 20:54:48] - |A| - [1159168] - C:\WINDOWS\system32\ApplicationFrame.dll [MD5.B6C299CDD0D76D3A8073D934E00C8400] - [13/07/2016 20:52:04] - |A| - [1505984] - C:\WINDOWS\system32\appraiser.dll [MD5.682F73D86501D75B131A1D59539A475D] - [13/07/2016 20:51:46] - |A| - [504320] - C:\WINDOWS\system32\AppReadiness.dll [MD5.ACF6FB6941AAF8EEBFF3C2B9C79C3F14] - [13/07/2016 20:53:39] - |A| - [287744] - C:\WINDOWS\system32\apprepapi.dll [MD5.1F1C41F53373FCD4DA82C5A16E748E05] - [13/07/2016 20:53:27] - |A| - [381952] - C:\WINDOWS\system32\apprepsync.dll [MD5.E7A27A6CD6CC6EA66342482FAAA8A2A7] - [13/07/2016 20:54:48] - |A| - [814080] - C:\WINDOWS\system32\appwiz.cpl [MD5.7B8C0E8D6B84BB841D50779D643C2A22] - [13/07/2016 20:54:07] - |A| - [2066432] - C:\WINDOWS\system32\AppXDeploymentExtensions.dll [MD5.AA27A3DF5CDA714F0DD47A48FE7CA8C3] - [13/07/2016 20:54:06] - |A| - [2168320] - C:\WINDOWS\system32\AppXDeploymentServer.dll [MD5.4E118AC95A15BD14B8C1E49C5B4CD79B] - [14/07/2016 10:49:30] - |A| - [390984] - C:\WINDOWS\system32\aswBoot.exe [MD5.5C6F3312EACE1409DC2C4C2AD5D2719D] - [13/07/2016 20:55:07] - |A| - [1054208] - C:\WINDOWS\system32\audiosrv.dll [MD5.B2FD8E42044B7A2C18AE54A60ACDDE6B] - [13/07/2016 20:56:03] - |A| - [2352128] - C:\WINDOWS\system32\authui.dll [MD5.63E75187FFFA108A78C67E14122C45B0] - [13/07/2016 20:55:24] - |A| - [865792] - C:\WINDOWS\system32\AzureSettingSyncProvider.dll [MD5.7A809AC3187F404168EAD29FB96A7854] - [13/07/2016 20:53:25] - |A| - [414720] - C:\WINDOWS\system32\bcastdvr.exe [MD5.20CD3B9C674909CCB1966F58A778DC68] - [13/07/2016 20:54:11] - |A| - [7200256] - C:\WINDOWS\system32\BingMaps.dll [MD5.453207816AB95A0376887BE01FAE30E1] - [13/07/2016 20:55:05] - |A| - [587776] - C:\WINDOWS\system32\bisrv.dll [MD5.C063C35A67FBECF53E4F31D44D253170] - [13/07/2016 20:51:22] - |A| - [91136] - C:\WINDOWS\system32\browserbroker.dll [MD5.04F404D7F9CAC583ED45DCA0C496E893] - [13/07/2016 20:55:37] - |A| - [218624] - C:\WINDOWS\system32\cdd.dll [MD5.E8720AD5391738C5EBCCCF696B46C000] - [13/07/2016 20:54:23] - |A| - [59392] - C:\WINDOWS\system32\cdpreference.exe [MD5.88E3BA684A7B1247762E1D401076D4C2] - [13/07/2016 20:54:47] - |A| - [287744] - C:\WINDOWS\system32\cdpsvc.dll [MD5.150EB8C1C9AE50F354A4CB5778E5951E] - [13/07/2016 20:52:44] - |A| - [459776] - C:\WINDOWS\system32\certcli.dll [MD5.F432A642F2C6266788080704C63C7427] - [13/07/2016 20:53:42] - |A| - [2912256] - C:\WINDOWS\system32\CertEnroll.dll [MD5.1F4AB277DB73A3C731B669D33C560405] - [13/07/2016 20:56:22] - |A| - [7832576] - C:\WINDOWS\system32\Chakra.dll [MD5.C7ACF177D1EB5C3F00D4FC728BBF9DFD] - [13/07/2016 20:55:24] - |A| - [764928] - C:\WINDOWS\system32\Chakradiag.dll [MD5.DF85A7B895A73421A50E955B94719F2F] - [13/07/2016 20:52:38] - |A| - [78040] - C:\WINDOWS\system32\Clipc.dll [MD5.E72BB94A4010EBA7074DFEB25D67BDC3] - [13/07/2016 20:52:38] - |A| - [625000] - C:\WINDOWS\system32\ClipSVC.dll [MD5.20688A78EC7B410B2C099C80C5F758D8] - [13/07/2016 20:53:44] - |A| - [1128104] - C:\WINDOWS\system32\ClipUp.exe [MD5.603A69A513DCDDBF0DA209395071BA0C] - [13/07/2016 20:55:42] - |A| - [1063936] - C:\WINDOWS\system32\comdlg32.dll [MD5.65952E564FABBE1348E8DDBC9E85A5BC] - [13/07/2016 20:52:04] - |A| - [50368] - C:\WINDOWS\system32\CompatTelRunner.exe [MD5.A71D446195E2B8090621C884D5DC3532] - [13/07/2016 20:51:59] - |A| - [2656408] - C:\WINDOWS\system32\CoreUIComponents.dll [MD5.B0296912EC10003945B68D19E9F4BC53] - [13/07/2016 20:51:55] - |A| - [440320] - C:\WINDOWS\system32\CredProvDataModel.dll [MD5.BF224299C98EA48FC9E4D3607C3148FB] - [13/07/2016 20:54:36] - |A| - [258560] - C:\WINDOWS\system32\credprovs.dll [MD5.244116AB9BC360772163F995CAF7FB8D] - [13/07/2016 20:55:02] - |A| - [1848584] - C:\WINDOWS\system32\crypt32.dll [MD5.FD8FBE19342CF2032F32C303B7D93A05] - [13/07/2016 20:56:11] - |A| - [5503488] - C:\WINDOWS\system32\d2d1.dll [MD5.957FA4FB89B1BE9D699C9927B0F3C384] - [13/07/2016 20:55:34] - |A| - [1240064] - C:\WINDOWS\system32\d3d10.dll [MD5.780B8E002BC11116E3C28DBEC6A3847D] - [13/07/2016 20:55:26] - |A| - [185856] - C:\WINDOWS\system32\d3d10_1.dll [MD5.584B28F7DA74E26FF45B83CFABABB599] - [13/07/2016 20:56:43] - |A| - [2773096] - C:\WINDOWS\system32\d3d11.dll [MD5.556E7C9734B9D2581022C56A23C96B78] - [13/07/2016 20:55:56] - |A| - [2145032] - C:\WINDOWS\system32\d3d9.dll [MD5.7FD5DC5E567910FD3B8F6FEA9A80DD4E] - [13/07/2016 20:55:47] - |A| - [4456448] - C:\WINDOWS\system32\D3DCompiler_47.dll [MD5.5CD61D0822FCAC328DE501357445577D] - [13/07/2016 20:54:43] - |A| - [484352] - C:\WINDOWS\system32\DataSenseHandlers.dll [MD5.2AE0CAA966E0FA3ED4DC193A3DD71D3A] - [13/07/2016 20:51:53] - |A| - [5123072] - C:\WINDOWS\system32\dbgeng.dll [MD5.63EA8167E8F4FC8388E6F95D4D724917] - [13/07/2016 20:55:02] - |A| - [911648] - C:\WINDOWS\system32\dcomp.dll [MD5.B5FF07AFF96EFB80B930985B5B1A7CAB] - [13/07/2016 20:51:26] - |A| - [286720] - C:\WINDOWS\system32\deviceaccess.dll [MD5.283269F7F32FDF5835B1FB2233013735] - [13/07/2016 20:56:00] - |A| - [284352] - C:\WINDOWS\system32\DeviceCensus.exe [MD5.A3024762D19A31B0CDC361097E73294D] - [13/07/2016 20:54:41] - |A| - [564224] - C:\WINDOWS\system32\DevicePairing.dll [MD5.A2BE69243B678C4FD05DFD4AEC83A725] - [13/07/2016 20:51:59] - |A| - [559808] - C:\WINDOWS\system32\devinv.dll [MD5.6D63B50C49E869AF2F5B189FDD6CE784] - [13/07/2016 20:53:57] - |A| - [1443840] - C:\WINDOWS\system32\diagperf.dll [MD5.5F1CAF0E823BADD5576555CC876F1067] - [13/07/2016 20:52:58] - |A| - [1613664] - C:\WINDOWS\system32\diagtrack.dll [MD5.B40875B8854291BD6919527ABB8DD8AE] - [13/07/2016 20:53:27] - |A| - [368640] - C:\WINDOWS\system32\diagtrack_win.dll [MD5.F78D7C2D5139D658817A2823FCD6037A] - [13/07/2016 20:54:40] - |A| - [775168] - C:\WINDOWS\system32\Display.dll [MD5.E995CBD7C59AB97414489C7CC3B7E09C] - [13/07/2016 20:51:41] - |A| - [504832] - C:\WINDOWS\system32\dlnashext.dll [MD5.16455536238D9F0920E0AF07037D9434] - [13/07/2016 20:54:50] - |A| - [128000] - C:\WINDOWS\system32\dmcsps.dll [MD5.6A9D3DD35E13B1009E7A712E6D164B8A] - [13/07/2016 20:52:35] - |A| - [274432] - C:\WINDOWS\system32\dmdskmgr.dll [MD5.D9B2EDDCC1EE10A31389EE62B4CDDEC2] - [13/07/2016 20:54:51] - |A| - [503600] - C:\WINDOWS\system32\DMRServer.dll [MD5.6FFA21CD6166BB456262BDEFC2C5E3DE] - [13/07/2016 20:53:25] - |A| - [318976] - C:\WINDOWS\system32\domgmt.dll [MD5.13F1408690E108A987CA77141C4358E5] - [13/07/2016 20:54:01] - |A| - [1097216] - C:\WINDOWS\system32\dosvc.dll [MD5.C8E72A76B943CEF7A6C830BDB51E7B50] - [13/07/2016 20:51:33] - |A| - [319488] - C:\WINDOWS\system32\dot3ui.dll [MD5.CE12FF056FBB4D78970A5D695D8C00BB] - [13/07/2016 20:55:48] - |A| - [1755648] - C:\WINDOWS\system32\dui70.dll [MD5.EFFFC67D0F0D2608BC294E01700FB4A3] - [13/07/2016 20:55:34] - |A| - [599040] - C:\WINDOWS\system32\duser.dll [MD5.ED922E0D9B4F1E4821B680EDEEE147EC] - [13/07/2016 20:55:11] - |A| - [1946112] - C:\WINDOWS\system32\dwmcore.dll [MD5.402CA5304470A5034EAA1FEDBB7564A7] - [13/07/2016 20:51:51] - |A| - [2445312] - C:\WINDOWS\system32\DWrite.dll [MD5.BD7E2F50A8C984500358E1AE1D1B89FC] - [13/07/2016 20:56:00] - |A| - [648256] - C:\WINDOWS\system32\dxgi.dll [MD5.55A6448A7AC0ACB238D56DFF7C280ABE] - [13/07/2016 20:55:39] - |A| - [290816] - C:\WINDOWS\system32\dxtrans.dll [MD5.D9D652506DD07CD49F3D20A3BBDD613B] - [13/07/2016 20:52:40] - |A| - [333312] - C:\WINDOWS\system32\eapp3hst.dll [MD5.AE4655837703FFA4AB079B22B66BB3C2] - [13/07/2016 20:52:57] - |A| - [352256] - C:\WINDOWS\system32\eappcfg.dll [MD5.FE87844A9D75F2D6D0752DF25EBF776B] - [13/07/2016 20:52:34] - |A| - [113152] - C:\WINDOWS\system32\eappgnui.dll [MD5.EB7C132D02CC40FB6538D53447447B2A] - [13/07/2016 20:52:28] - |A| - [308736] - C:\WINDOWS\system32\eapphost.dll [MD5.ACEDA3F655270B39586A7E8D37F1ADC2] - [13/07/2016 20:52:29] - |A| - [72192] - C:\WINDOWS\system32\eappprxy.dll [MD5.40A9F59FD6B24C045F1D6076E6489CE6] - [13/07/2016 20:53:32] - |A| - [174592] - C:\WINDOWS\system32\easwrt.dll [MD5.F823DAB5F96CC6A966DF0F1B487C51A0] - [13/07/2016 20:56:40] - |A| - [22379520] - C:\WINDOWS\system32\edgehtml.dll [MD5.97AF27209BA7058F21C8879E773CED86] - [13/07/2016 20:53:39] - |A| - [305152] - C:\WINDOWS\system32\edputil.dll [MD5.F8E7D71D4E1E57EF304805D2D770ED0A] - [13/07/2016 20:54:40] - |A| - [619520] - C:\WINDOWS\system32\efswrt.dll [MD5.3182FCAF6AAF478791DE5B430C912D4D] - [13/07/2016 20:51:42] - |A| - [314368] - C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll [MD5.DFCC151C6AC8E5D50D27ACB34286835C] - [13/07/2016 20:55:02] - |A| - [642048] - C:\WINDOWS\system32\enterprisecsps.dll [MD5.3E9CD04F3FB54D4C3CEF3393ABF743BC] - [13/07/2016 20:52:39] - |A| - [254464] - C:\WINDOWS\system32\ExecModelClient.dll [MD5.D29BE449B728CD126D5ACA3E823C8907] - [13/07/2016 20:52:00] - |A| - [4827136] - C:\WINDOWS\system32\ExplorerFrame.dll [MD5.4176712BADB6903C8419B66E678CE816] - [13/07/2016 20:53:43] - |A| - [440320] - C:\WINDOWS\system32\fhcfg.dll [MD5.89C78489A7F929362858F4DFD86746E7] - [13/07/2016 20:53:34] - |A| - [252928] - C:\WINDOWS\system32\fhengine.dll [MD5.45521E32AB1D383F9E85674D0F035543] - [13/07/2016 20:53:36] - |A| - [469504] - C:\WINDOWS\system32\fhsettingsprovider.dll [MD5.E3D83E92FB3FAFD2E89A89850A0D9355] - [13/07/2016 20:54:27] - |A| - [90624] - C:\WINDOWS\system32\FingerprintEnrollment.dll [MD5.F1BA85CF2AEE08860C8D5BF82C342F44] - [13/07/2016 20:55:31] - |A| - [1671168] - C:\WINDOWS\system32\FntCache.dll [MD5.81F9278A83AD6F42C5DE6FEAAFBEA8AB] - [13/07/2016 20:53:33] - |A| - [715776] - C:\WINDOWS\system32\GamePanel.exe [MD5.79E567E98D8F2BA20E52EBFAD92C20ED] - [13/07/2016 20:54:49] - |A| - [2731008] - C:\WINDOWS\system32\gameux.dll [MD5.E54FA914CF17AE4AFB18291F31BA3063] - [13/07/2016 20:55:48] - |A| - [1717248] - C:\WINDOWS\system32\GdiPlus.dll [MD5.08EF12456EDFB557DC424AFD9CF4AAE1] - [13/07/2016 20:54:04] - |A| - [587456] - C:\WINDOWS\system32\generaltel.dll [MD5.531662DC0764C1A1E333BD05D4485333] - [13/07/2016 20:52:25] - |A| - [321536] - C:\WINDOWS\system32\GlobCollationHost.dll [MD5.511198CBBA38AE0D733553B0F31C770C] - [13/07/2016 20:54:45] - |A| - [636928] - C:\WINDOWS\system32\hgcpl.dll [MD5.632C3792D2BFC67E2F8B2A2CFC09CEEF] - [13/07/2016 20:52:27] - |A| - [14848] - C:\WINDOWS\system32\IconCodecService.dll [MD5.771BC991BEB5DFD93B9347B18F62F216] - [13/07/2016 20:54:35] - |A| - [110080] - C:\WINDOWS\system32\IdCtrls.dll [MD5.69FB22CE0A11E8D55B0BA43D515B854B] - [13/07/2016 20:55:33] - |A| - [1752576] - C:\WINDOWS\system32\ieapfltr.dll [MD5.B4EF28C61CE2755D7F1842BFA122B60E] - [13/07/2016 20:56:24] - |A| - [13385728] - C:\WINDOWS\system32\ieframe.dll [MD5.FD93D230DAF156F0EAF41C7C039C8D71] - [13/07/2016 20:55:13] - |A| - [3675512] - C:\WINDOWS\system32\iertutil.dll [MD5.416CB546F36D3E5A5B5286E0066ED285] - [13/07/2016 20:52:27] - |A| - [585728] - C:\WINDOWS\system32\ieui.dll [MD5.5E5BEC886CC2503C4F18AF2153B169AF] - [13/07/2016 20:54:22] - |A| - [957952] - C:\WINDOWS\system32\IKEEXT.DLL [MD5.4C21A65A6ACDF10B181D45E08DC15D24] - [13/07/2016 20:55:51] - |A| - [2127360] - C:\WINDOWS\system32\inetcpl.cpl [MD5.5B646920CE059478EED19BC7EFF72C7E] - [13/07/2016 20:55:36] - |A| - [167936] - C:\WINDOWS\system32\inetpp.dll [MD5.5CB0052CBF1DBF36071AD520245F32D6] - [13/07/2016 20:51:54] - |A| - [310464] - C:\WINDOWS\system32\invagent.dll [MD5.3AFCB780F17144A42F99128AD7E55A02] - [13/07/2016 20:53:53] - |A| - [1056256] - C:\WINDOWS\system32\JpMapControl.dll [MD5.3CC983011177A815A94218EB38E13241] - [13/07/2016 20:56:14] - |A| - [4895232] - C:\WINDOWS\system32\jscript9.dll [MD5.9B2BFADCB00CF39F0EBD3D690FC56220] - [13/07/2016 20:52:45] - |A| - [1997328] - C:\WINDOWS\system32\KernelBase.dll [MD5.2F022C0682885EFF4CFB0B62143482B5] - [13/07/2016 20:51:31] - |A| - [71168] - C:\WINDOWS\system32\LegacyNetUX.dll [MD5.1AD6967BB8F7D4495271715DC3E38CEB] - [13/07/2016 20:51:29] - |A| - [206848] - C:\WINDOWS\system32\LegacyNetUXHost.exe [MD5.196E3B5FB1D1A76D41A0C9A9A0B2F698] - [13/07/2016 20:52:34] - |A| - [236032] - C:\WINDOWS\system32\licensingdiag.exe [MD5.EDE31817FC0A574E7CC3AF7E544C8951] - [13/07/2016 20:54:35] - |A| - [279040] - C:\WINDOWS\system32\ListSvc.dll [MD5.28B5AB1D9C97737A3801658F12BDBCB6] - [13/07/2016 20:56:02] - |A| - [1121792] - C:\WINDOWS\system32\localspl.dll [MD5.6FDD8828032595D90AEB946A809089D8] - [13/07/2016 20:54:53] - |A| - [480768] - C:\WINDOWS\system32\LockAppBroker.dll [MD5.3AE63804B34BC99FFD101DFD54012EB8] - [13/07/2016 20:55:02] - |A| - [303216] - C:\WINDOWS\system32\LockAppHost.exe [MD5.72BE361C64D50557765CB9C8E56BB9B6] - [13/07/2016 20:54:39] - |A| - [529920] - C:\WINDOWS\system32\LogonController.dll [MD5.05A027F27937EB29B89743A51B1313EA] - [13/07/2016 20:54:04] - |A| - [460800] - C:\WINDOWS\system32\MapConfiguration.dll [MD5.76BA7FDD3EA3764C0CADB522FF3F4715] - [13/07/2016 20:54:03] - |A| - [939520] - C:\WINDOWS\system32\MapControlCore.dll [MD5.923EC7EA1E8BE1C7706A2AC5DD28FF5B] - [13/07/2016 20:53:27] - |A| - [120320] - C:\WINDOWS\system32\MapsBtSvc.dll [MD5.5BDBA05692A03279E2EB9F26DB53E148] - [13/07/2016 20:53:26] - |A| - [89088] - C:\WINDOWS\system32\MapsCSP.dll [MD5.1D077E04EA82EF6D2E389182FF8C9A31] - [13/07/2016 20:54:04] - |A| - [853504] - C:\WINDOWS\system32\MapsStore.dll [MD5.DA3572238188A1145DC11800F581A30E] - [13/07/2016 20:53:29] - |A| - [28672] - C:\WINDOWS\system32\mapsupdatetask.dll [MD5.65A7997831D78845FDA12E2C87491670] - [13/07/2016 20:53:53] - |A| - [896512] - C:\WINDOWS\system32\MbaeApiPublic.dll [MD5.4EAE9C70DAB294850557E0A2B13DC3C2] - [13/07/2016 20:53:38] - |A| - [674304] - C:\WINDOWS\system32\mbsmsapi.dll [MD5.EBF31825A4C505188DC598F28C4E25F5] - [13/07/2016 20:53:55] - |A| - [586208] - C:\WINDOWS\system32\mf.dll [MD5.510702AC9FD86E3A5CDB68AC3DC14928] - [13/07/2016 20:55:55] - |A| - [498960] - C:\WINDOWS\system32\MFCaptureEngine.dll [MD5.64168D292D236456C6F5E6D48DE90528] - [13/07/2016 20:56:10] - |A| - [2582016] - C:\WINDOWS\system32\MFMediaEngine.dll [MD5.C64FA0D0AAF5EEE0E65EFB34DDDD2918] - [13/07/2016 20:56:02] - |A| - [1299504] - C:\WINDOWS\system32\mfnetsrc.dll [MD5.E3BF6CDE2DDE478E88667F1C9F33DBBC] - [13/07/2016 20:56:01] - |A| - [1092464] - C:\WINDOWS\system32\mfplat.dll [MD5.3801440364B05BDFA96CF6071D45CD7C] - [13/07/2016 20:53:40] - |A| - [35656] - C:\WINDOWS\system32\mfpmp.exe [MD5.409A46FE4B2A6133400572D2B26C6152] - [13/07/2016 20:55:58] - |A| - [847656] - C:\WINDOWS\system32\mfsvr.dll [MD5.980258BAC6A086976DADB45D2A2233BC] - [13/07/2016 20:54:46] - |A| - [941568] - C:\WINDOWS\system32\MiracastReceiver.dll [MD5.9516AE004E3A945BA090B2CD7754B8AE] - [13/07/2016 20:52:35] - |A| - [870400] - C:\WINDOWS\system32\modernexecserver.dll [MD5.1FD91D9B6FA03C97DC8C1DD29775BBA5] - [13/07/2016 20:54:18] - |A| - [7977472] - C:\WINDOWS\system32\mos.dll [MD5.98E3D2BB421424B0457F8B7C46113110] - [13/07/2016 20:53:51] - |A| - [72704] - C:\WINDOWS\system32\moshost.dll [MD5.8EC8ECAB9AF9A5F23872031391AE6BB3] - [13/07/2016 20:53:50] - |A| - [66560] - C:\WINDOWS\system32\MosHostClient.dll [MD5.C0ADEBE6980D501C0D5B2FD321F78D19] - [13/07/2016 20:53:53] - |A| - [270848] - C:\WINDOWS\system32\moshostcore.dll [MD5.B3880D0DB160EDC7903B9F32C833812F] - [13/07/2016 20:53:48] - |A| - [74752] - C:\WINDOWS\system32\MosStorage.dll [MD5.02122FD1A32C205DAA2EEC6462E60226] - [13/07/2016 20:55:56] - |A| - [784384] - C:\WINDOWS\system32\msfeeds.dll [MD5.4EB384E80857EC28F54766042D3BAB1E] - [13/07/2016 20:56:06] - |A| - [3355136] - C:\WINDOWS\system32\msftedit.dll [MD5.D5BDFD4F497EE8A2859E72809046CE89] - [13/07/2016 20:56:42] - |A| - [24610304] - C:\WINDOWS\system32\mshtml.dll [MD5.8B46C06B69A8AB4636539783FEACE54F] - [13/07/2016 20:54:34] - |A| - [316928] - C:\WINDOWS\system32\msieftp.dll [MD5.EA4B8BDD3CFFA0B5C7A605189D79184A] - [13/07/2016 20:54:28] - |A| - [6675968] - C:\WINDOWS\system32\mspaint.exe [MD5.7B5D06BDED5DFDF28597A9C5F72E85CE] - [13/07/2016 20:53:29] - |A| - [40960] - C:\WINDOWS\system32\msscntrs.dll [MD5.B9A5A35B9EB23AD507A3BABB35C5B67D] - [13/07/2016 20:53:50] - |A| - [1051648] - C:\WINDOWS\system32\MsSpellCheckingFacility.dll [MD5.D627ED29A07745EB1A5A7405FBFA2381] - [13/07/2016 20:53:31] - |A| - [147456] - C:\WINDOWS\system32\mssph.dll [MD5.5EE16195544A95C09FB12B5594D229FE] - [13/07/2016 20:53:45] - |A| - [247296] - C:\WINDOWS\system32\mssphtb.dll [MD5.028CE336DC0BD5D258716403C277674E] - [13/07/2016 20:54:01] - |A| - [2597888] - C:\WINDOWS\system32\mssrch.dll [MD5.749BEA2C23422B51F5340F42784F817D] - [13/07/2016 20:53:20] - |A| - [7533568] - C:\WINDOWS\system32\mstscax.dll [MD5.8559C1E30B9404590783497563A7A8AA] - [13/07/2016 20:54:59] - |A| - [1902592] - C:\WINDOWS\system32\msxml3.dll [MD5.C4DF2DEF5283FB1C44C6920F2FDD83BC] - [13/07/2016 20:54:44] - |A| - [44032] - C:\WINDOWS\system32\musdialoghandlers.dll [MD5.8CA9FBB305EFB04585BAC36B7B29C14B] - [13/07/2016 20:51:46] - |A| - [172032] - C:\WINDOWS\system32\MusNotification.exe [MD5.9DC794AC6F27E96F976990C6C7FC4862] - [13/07/2016 20:51:40] - |A| - [57344] - C:\WINDOWS\system32\MusNotificationUx.exe [MD5.0AC905009A2ED68715675E086B805316] - [13/07/2016 20:52:58] - |A| - [407552] - C:\WINDOWS\system32\MusUpdateHandlers.dll [MD5.C93639FAB08F564D92AB5CFF29C2BFCD] - [13/07/2016 20:51:37] - |A| - [1216512] - C:\WINDOWS\system32\netcenter.dll [MD5.B9F994EA5B90838A7B10DEDCC4E41C2B] - [13/07/2016 20:52:32] - |A| - [270336] - C:\WINDOWS\system32\netplwiz.dll [MD5.329E7ACF649A721B8A5B3F0A9976F91F] - [13/07/2016 20:52:42] - |A| - [2800128] - C:\WINDOWS\system32\netshell.dll [MD5.FAAC4810F40849AB551C0B5557DF9D4B] - [13/07/2016 20:54:42] - |A| - [237056] - C:\WINDOWS\system32\NetworkDesktopSettings.dll [MD5.240F6A0AAEEAB059BC0B7D8B72637F72] - [13/07/2016 20:55:14] - |A| - [2609664] - C:\WINDOWS\system32\NetworkMobileSettings.dll [MD5.66989014C94A5AE3600DAFEA225C4DB8] - [13/07/2016 20:55:25] - |A| - [89600] - C:\WINDOWS\system32\NFCProvisioningPlugin.dll [MD5.F648E0821CACC7E547562321332E12B1] - [13/07/2016 20:53:56] - |A| - [988160] - C:\WINDOWS\system32\NMAA.dll [MD5.DA7B203B42D2F32FB03AE8DFEB56F326] - [13/07/2016 20:53:51] - |A| - [529408] - C:\WINDOWS\system32\NotificationController.dll [MD5.95E5BA5E26BE4A4097458E1F316A8616] - [13/07/2016 20:56:18] - |A| - [7469408] - C:\WINDOWS\system32\ntoskrnl.exe [MD5.1D5D1656DF134068A04480DB4B1E1753] - [13/07/2016 20:55:34] - |A| - [349184] - C:\WINDOWS\system32\ntprint.dll [MD5.F747C037C6CC055E664235BF0EA9A30C] - [13/07/2016 20:51:38] - |A| - [882688] - C:\WINDOWS\system32\ntshrui.dll [MD5.F8D77A486B78DB6FA44F2F7DF5D7F65C] - [13/07/2016 20:52:29] - |A| - [285184] - C:\WINDOWS\system32\oemlicense.dll [MD5.642D4E1DE69A3D180D4962D6977AAAB3] - [13/07/2016 20:55:57] - |A| - [1322248] - C:\WINDOWS\system32\ole32.dll [MD5.354D204E888E96FC12E0D1F94A98D300] - [13/07/2016 20:54:46] - |A| - [364032] - C:\WINDOWS\system32\OneBackupHandler.dll [MD5.7EA42087AEE36B39F2758475B91AD5F3] - [13/07/2016 20:53:45] - |A| - [515072] - C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll [MD5.A4BC389CAEA0203FD33849FA8431AA88] - [13/07/2016 20:51:23] - |A| - [224256] - C:\WINDOWS\system32\PackageStateRoaming.dll [MD5.1435F76294D5E1D1017D5C6D47CA3F80] - [13/07/2016 20:53:41] - |A| - [106928] - C:\WINDOWS\system32\phoneactivate.exe [MD5.FC749BCC3387CBBEE57539F414B24EB9] - [13/07/2016 20:52:28] - |A| - [583680] - C:\WINDOWS\system32\PhotoScreensaver.scr [MD5.B2F6749368EEE07AF0B09755B1636F4F] - [13/07/2016 20:54:38] - |A| - [458752] - C:\WINDOWS\system32\PlayToDevice.dll [MD5.1CA267651F0295A6B809EFCED2846F70] - [13/07/2016 20:55:06] - |A| - [697856] - C:\WINDOWS\system32\PlayToManager.dll [MD5.2A64B3002165F3842EDCFA048624284F] - [13/07/2016 20:54:29] - |A| - [283648] - C:\WINDOWS\system32\PlayToReceiver.dll [MD5.7324FB4B99D7485728862DE165946846] - [13/07/2016 20:52:56] - |A| - [1814528] - C:\WINDOWS\system32\pnidui.dll [MD5.19348CC554A839CDFE5F79A42EBBBFAB] - [13/07/2016 20:51:33] - |A| - [589824] - C:\WINDOWS\system32\PrintDialogs.dll [MD5.DC61C9AF4B96DB3CAB08168B8E9D3455] - [13/07/2016 20:51:50] - |A| - [2050560] - C:\WINDOWS\system32\PrintDialogs3D.dll [MD5.F6A078D3FC7853D5A220413A239660CC] - [13/07/2016 20:55:50] - |A| - [1603224] - C:\WINDOWS\system32\propsys.dll [MD5.C9B1B0285A5AA53774BF3D91891072E2] - [13/07/2016 20:55:53] - |A| - [296960] - C:\WINDOWS\system32\provengine.dll [MD5.C9AC70AC6FEBDCFE585436FD9E3901B1] - [13/07/2016 20:55:52] - |A| - [287232] - C:\WINDOWS\system32\provhandlers.dll [MD5.D08B38F8E8A995FC673E8D5ADABBFD13] - [13/07/2016 20:55:38] - |A| - [192000] - C:\WINDOWS\system32\provisioningcsp.dll [MD5.3F4BDBBA1F3BBECBA656503BD0C16BEA] - [13/07/2016 20:55:51] - |A| - [168960] - C:\WINDOWS\system32\provops.dll [MD5.09291D797572201BF39B685E57B7C73B] - [13/07/2016 20:54:25] - |A| - [556032] - C:\WINDOWS\system32\PsmServiceExtHost.dll [MD5.F9941B95928AB5717C6AE871941A8F44] - [13/07/2016 20:54:30] - |A| - [387072] - C:\WINDOWS\system32\qdvd.dll [MD5.34D17C28C8B8DC7F98365A60300B40B4] - [13/07/2016 20:55:26] - |A| - [341504] - C:\WINDOWS\system32\RADCUI.dll [MD5.4148FE81CAA1383F97FA4F8A21A4700C] - [13/07/2016 20:52:46] - |A| - [733184] - C:\WINDOWS\system32\rasapi32.dll [MD5.FCC66CE466375869F873C9DA3A3C9453] - [13/07/2016 20:51:32] - |A| - [947200] - C:\WINDOWS\system32\rasgcw.dll [MD5.757F9AA7EA001014DC9352C6144301BF] - [13/07/2016 20:53:46] - |A| - [3053568] - C:\WINDOWS\system32\rdpcore.dll [MD5.00B6D59BBA3D3061EE5210970ACC758C] - [13/07/2016 20:52:59] - |A| - [4171264] - C:\WINDOWS\system32\rdpcorets.dll [MD5.9430C60EBCAE82C0D27050C3FA231D1D] - [13/07/2016 20:52:30] - |A| - [84480] - C:\WINDOWS\system32\rdpudd.dll [MD5.C439E5B6E3EB38C9C7611C393348503B] - [13/07/2016 20:54:54] - |A| - [1073152] - C:\WINDOWS\system32\RDXService.dll [MD5.B204C799C5903272284D802DBFCF8F37] - [13/07/2016 20:54:52] - |A| - [315392] - C:\WINDOWS\system32\RDXTaskFactory.dll [MD5.2786EAC53204EC98E5DD85C1A9DBA965] - [13/07/2016 20:53:27] - |A| - [1087488] - C:\WINDOWS\system32\reseteng.dll [MD5.5E3427306DC41D80467C9B4ACDE7A9B5] - [13/07/2016 20:54:55] - |A| - [849920] - C:\WINDOWS\system32\samsrv.dll [MD5.EB9699F8F050E41A2661E56090FB9988] - [13/07/2016 20:53:39] - |A| - [992256] - C:\WINDOWS\system32\sbe.dll [MD5.4D82582733D9F437F544D3F8F98CE159] - [13/07/2016 20:51:57] - |A| - [1001472] - C:\WINDOWS\system32\schedsvc.dll [MD5.F34470B288B2EF590B3ECA8BA4C90D95] - [13/07/2016 20:52:44] - |A| - [233984] - C:\WINDOWS\system32\schtasks.exe [MD5.309B981F0EB10916BD0BF2972BB33841] - [13/07/2016 20:51:33] - |A| - [1213440] - C:\WINDOWS\system32\sdengin2.dll [MD5.723C6C3DE056D3EB76F7520BEF5947B4] - [13/07/2016 20:51:26] - |A| - [150528] - C:\WINDOWS\system32\sdrsvc.dll [MD5.C56BFF5D26E3CD34EEB79213B6220C14] - [13/07/2016 20:51:24] - |A| - [129536] - C:\WINDOWS\system32\sdshext.dll [MD5.8FB500C462988EE33368E6E099638384] - [13/07/2016 20:53:36] - |A| - [394240] - C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll [MD5.4E762D96FA52AB55A796E373C0557361] - [13/07/2016 20:53:29] - |A| - [203776] - C:\WINDOWS\system32\SearchFilterHost.exe [MD5.A5AE758495A6F7BAB269CCDC960CAAD6] - [13/07/2016 20:53:44] - |A| - [549888] - C:\WINDOWS\system32\SearchFolder.dll [MD5.38F120F3E9F4C87A4825F12B33849BA5] - [13/07/2016 20:53:56] - |A| - [938496] - C:\WINDOWS\system32\SearchIndexer.exe [MD5.877EAB65117EF1A49C28F815F10E3A87] - [13/07/2016 20:53:43] - |A| - [334848] - C:\WINDOWS\system32\SearchProtocolHost.exe [MD5.21E74A7A50345F64A2E494C6B6AE0DF2] - [13/07/2016 20:53:38] - |A| - [243712] - C:\WINDOWS\system32\SettingMonitor.dll [MD5.B66654D85A6C6F915E7D4827317739FA] - [13/07/2016 20:55:04] - |A| - [2125312] - C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll [MD5.318C685A15E02A8573DC3A2772804B21] - [13/07/2016 20:54:53] - |A| - [253440] - C:\WINDOWS\system32\SettingsHandlers_Maps.dll [MD5.1CFFDC8E62372CBD2C4C1AB9ADAA0C35] - [13/07/2016 20:55:16] - |A| - [3994624] - C:\WINDOWS\system32\SettingsHandlers_nt.dll [MD5.D2DAA7F5299D1612ACEF0C282BE4F47C] - [13/07/2016 20:54:29] - |A| - [492544] - C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll [MD5.7DF705D181132AAB5AE5B25A8FF32215] - [13/07/2016 20:53:49] - |A| - [613376] - C:\WINDOWS\system32\SettingSync.dll [MD5.6E8F12E9EF754A715D62B5EEA045BE62] - [13/07/2016 20:53:55] - |A| - [984576] - C:\WINDOWS\system32\SettingSyncCore.dll [MD5.9F1B8A631FD76E9702A58904D4F249BE] - [13/07/2016 20:53:49] - |A| - [566104] - C:\WINDOWS\system32\SettingSyncHost.exe [MD5.70B0FB34458FCA020297A595205FC82F] - [13/07/2016 20:55:05] - |A| - [990208] - C:\WINDOWS\system32\SharedStartModel.dll [MD5.C821BB49409012C6CD024F21959CC051] - [13/07/2016 20:53:52] - |A| - [638976] - C:\WINDOWS\system32\ShareHost.dll [MD5.FD0F8299FDBEC22C8DBFA66CB4BD5B1B] - [13/07/2016 20:55:39] - |A| - [725776] - C:\WINDOWS\system32\SHCore.dll [MD5.6ADFA862EDA342F416C05C9E88A69899] - [13/07/2016 20:52:07] - |A| - [22561256] - C:\WINDOWS\system32\shell32.dll [MD5.509589754EDDE7F1EE879366F5692990] - [13/07/2016 20:54:51] - |A| - [182784] - C:\WINDOWS\system32\shutdownux.dll [MD5.C5D55EF423F535D5A6766DB727BEB7E5] - [13/07/2016 20:52:44] - |A| - [160768] - C:\WINDOWS\system32\SimAuth.dll [MD5.6CA35CF766C04B30BBE9F99CB70D1DE1] - [13/07/2016 20:52:46] - |A| - [193024] - C:\WINDOWS\system32\SimCfg.dll [MD5.9F77B66EC74300D30720B1001E2CD044] - [13/07/2016 20:53:02] - |A| - [1037824] - C:\WINDOWS\system32\SmartcardCredentialProvider.dll [MD5.9E2BC2A7D1E3862327B5626CEE56C46E] - [13/07/2016 20:54:00] - |A| - [1487872] - C:\WINDOWS\system32\SpeechPal.dll [MD5.939D80772D59831E50B03CDBD99049DF] - [13/07/2016 20:56:11] - |A| - [1540224] - C:\WINDOWS\system32\sppobjs.dll [MD5.49B666BCCF59226549F64656584318EA] - [13/07/2016 20:52:18] - |A| - [6536256] - C:\WINDOWS\system32\sppsvc.exe [MD5.B5D83BCE06D70B120D8AC889EEE4A14A] - [13/07/2016 20:55:54] - |A| - [692136] - C:\WINDOWS\system32\sppwinob.dll [MD5.995974222B873687A88C25FFCDB644F7] - [13/07/2016 20:53:58] - |A| - [965632] - C:\WINDOWS\system32\SRH.dll [MD5.04ABF2BA35F85E88076A44B6FF19D3EE] - [13/07/2016 20:54:05] - |A| - [1716736] - C:\WINDOWS\system32\SRHInproc.dll [MD5.40B3D3F1F3DFF9C839F2FDAAB070D877] - [13/07/2016 20:55:38] - |A| - [465920] - C:\WINDOWS\system32\StikyNot.exe [MD5.96576465D2259ADDE056451DBCBEAF3D] - [13/07/2016 20:54:35] - |A| - [656896] - C:\WINDOWS\system32\sud.dll [MD5.681C50548D26B77E32C5A0ED3054A0C5] - [13/07/2016 20:54:46] - |A| - [3415040] - C:\WINDOWS\system32\SyncCenter.dll [MD5.7E6CF2485E67AE7AA84B0556612F22CA] - [13/07/2016 20:54:52] - |A| - [714240] - C:\WINDOWS\system32\SystemSettings.Handlers.dll [MD5.CAEF382AD301DB79D004254E400719B2] - [13/07/2016 20:54:41] - |A| - [492544] - C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll [MD5.7DE46FA7E3A14535E5D971C977F874D9] - [13/07/2016 20:54:44] - |A| - [374008] - C:\WINDOWS\system32\SystemSettingsAdminFlows.exe [MD5.FEC2E3FF1F1D79E569DE372A020D1909] - [13/07/2016 20:55:12] - |A| - [3585536] - C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll [MD5.064EDB04AB15F985E5E9DE0D9B236958] - [13/07/2016 20:51:33] - |A| - [429056] - C:\WINDOWS\system32\taskcomp.dll [MD5.2D27946C8EC1AA93A26FEC2C7909CD05] - [13/07/2016 20:51:43] - |A| - [299520] - C:\WINDOWS\system32\taskeng.exe [MD5.F86A7E3BA31FB9AEF5E6EF29B65E202E] - [13/07/2016 20:53:52] - |A| - [1238584] - C:\WINDOWS\system32\Taskmgr.exe [MD5.5A1580ADA5F4F38DC1CD0E9C1B98C6BF] - [13/07/2016 20:54:41] - |A| - [2563584] - C:\WINDOWS\system32\themecpl.dll [MD5.B7BA7030B50FC782F44D28B63C28B535] - [13/07/2016 20:52:37] - |A| - [2902528] - C:\WINDOWS\system32\themeui.dll [MD5.00110FDAF3380A23D360AEA5551B8D03] - [13/07/2016 20:55:55] - |A| - [821760] - C:\WINDOWS\system32\TokenBroker.dll [MD5.F6222E15A014A6026CD7F860006407C4] - [13/07/2016 20:53:43] - |A| - [47616] - C:\WINDOWS\system32\TpmTasks.dll [MD5.E7AF5609667C0BF1BC80A9D2E2303C35] - [13/07/2016 20:54:09] - |A| - [3577344] - C:\WINDOWS\system32\tquery.dll [MD5.35548DDC03345511E3B3F6C1237FFD6F] - [13/07/2016 20:51:49] - |A| - [1040800] - C:\WINDOWS\system32\twinapi.appcore.dll [MD5.0C66FD155A553C3C1775F9EEE4C52F91] - [13/07/2016 20:55:47] - |A| - [701952] - C:\WINDOWS\system32\twinapi.dll [MD5.06A6BED5044BFA97C1988568DD628777] - [13/07/2016 20:53:11] - |A| - [2444800] - C:\WINDOWS\system32\twinui.appcore.dll [MD5.73B90D7C3DEF1941F783BE0391C0F057] - [13/07/2016 20:55:18] - |A| - [11545088] - C:\WINDOWS\system32\twinui.dll [MD5.127925766866C52F147A2FFC0C0358A5] - [13/07/2016 20:52:39] - |A| - [87040] - C:\WINDOWS\system32\tzautoupdate.dll [MD5.6DF9F08ED418A400857E5570E842A559] - [13/07/2016 20:51:44] - |A| - [838144] - C:\WINDOWS\system32\uDWM.dll [MD5.FA01865117A7529561E1F19FD0354D2E] - [13/07/2016 20:53:04] - |A| - [4170240] - C:\WINDOWS\system32\UIRibbon.dll [MD5.ECDD8B72980581EF23F5BA0AFF04767F] - [13/07/2016 20:52:41] - |A| - [584704] - C:\WINDOWS\system32\UIRibbonRes.dll [MD5.A09C212408747F8074D957375B9C486C] - [13/07/2016 20:51:45] - |A| - [268288] - C:\WINDOWS\system32\updatehandlers.dll [MD5.231099370F84D4AA4B373B0BD0B71D8F] - [13/07/2016 20:55:07] - |A| - [1729024] - C:\WINDOWS\system32\urlmon.dll [MD5.02DF62B54CEDC85DAC946FF3F01171F5] - [13/07/2016 20:52:43] - |A| - [1385472] - C:\WINDOWS\system32\usercpl.dll [MD5.210F58F5F18D1DBF0B6F75BE33D8B06C] - [13/07/2016 20:51:39] - |A| - [651776] - C:\WINDOWS\system32\UserLanguagesCpl.dll [MD5.50F7B408700BF28CF9986821E0486A16] - [13/07/2016 20:51:47] - |A| - [379392] - C:\WINDOWS\system32\usocore.dll [MD5.5D339458DA9FEA6E314817B7DDD4D351] - [13/07/2016 20:55:57] - |A| - [605184] - C:\WINDOWS\system32\vbscript.dll [MD5.F2503C00653F06AD926553E2C4F69376] - [13/07/2016 20:54:45] - |A| - [1294336] - C:\WINDOWS\system32\wcnwiz.dll [MD5.CFD91D429BA902F1E3EF09434BFEAF53] - [13/07/2016 20:52:35] - |A| - [1048576] - C:\WINDOWS\system32\WebcamUi.dll [MD5.F3EB6A22AFB3893ACD4E7C1B02382A3F] - [13/07/2016 20:55:31] - |A| - [262144] - C:\WINDOWS\system32\webcheck.dll [MD5.D41EC066D915E4825121AE2687596BC2] - [13/07/2016 20:55:39] - |A| - [496640] - C:\WINDOWS\system32\webio.dll [MD5.871DB0260278B46C50D17C5CF4AEB12F] - [13/07/2016 20:51:46] - |A| - [1291776] - C:\WINDOWS\system32\werconcpl.dll [MD5.B86D30AE36165FC84E56AAD4EFBCF527] - [13/07/2016 20:54:24] - |A| - [451584] - C:\WINDOWS\system32\werui.dll [MD5.8C837B999EE2D443E8C19677C4BB7F60] - [13/07/2016 20:51:24] - |A| - [677376] - C:\WINDOWS\system32\wiaaut.dll [MD5.ED82578312E8B2D2D1D2F87CD77695AC] - [13/07/2016 20:55:57] - |A| - [1387520] - C:\WINDOWS\system32\win32kbase.sys [MD5.4EC98235B7BFCA3705279A9E9242C648] - [13/07/2016 20:56:07] - |A| - [3589632] - C:\WINDOWS\system32\win32kfull.sys [MD5.02B2863417FF2E5E34BD42EBF8B49528] - [13/07/2016 20:55:43] - |A| - [841728] - C:\WINDOWS\system32\win32spl.dll [MD5.CBCA5650B97DFE6D86E4F4DC0D3DD86B] - [13/07/2016 20:55:46] - |A| - [828928] - C:\WINDOWS\system32\Windows.AccountsControl.dll [MD5.A143C34D5DFADCDDBB88CC396DC1F802] - [13/07/2016 20:52:28] - |A| - [859136] - C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll [MD5.E9CEE634054C1EE9D3112A2E86190FEC] - [13/07/2016 20:52:22] - |A| - [330240] - C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll [MD5.4F56CB4CE94272928D1F884A5798456C] - [13/07/2016 20:53:40] - |A| - [538112] - C:\WINDOWS\system32\Windows.Cortana.Desktop.dll [MD5.29BB9364FD70012F169516312CAB0FB7] - [13/07/2016 20:54:39] - |A| - [317440] - C:\WINDOWS\system32\Windows.Cortana.OneCore.dll [MD5.1849F8CCD27258F69EAABC334A87846C] - [13/07/2016 20:54:14] - |A| - [6973952] - C:\WINDOWS\system32\Windows.Data.Pdf.dll [MD5.7E6FCD52B7EE309145A51A286ED18224] - [13/07/2016 20:52:30] - |A| - [344064] - C:\WINDOWS\system32\Windows.Devices.Picker.dll [MD5.82AC452307257A4B3F08856EE84EE2EC] - [13/07/2016 20:55:44] - |A| - [892416] - C:\WINDOWS\system32\Windows.Devices.SmartCards.dll [MD5.7A576DA811BCF5843C909D9BC9AEC351] - [13/07/2016 20:52:33] - |A| - [522240] - C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll [MD5.E6AA08DC29AA637E861DAF0AB3E21888] - [13/07/2016 20:53:02] - |A| - [1567744] - C:\WINDOWS\system32\Windows.Globalization.dll [MD5.E17447519BC01492E3234C90890800D4] - [13/07/2016 20:51:39] - |A| - [368128] - C:\WINDOWS\system32\Windows.Graphics.dll [MD5.5E126FBE705D91361A3A26DAF9A55838] - [13/07/2016 20:53:57] - |A| - [2103296] - C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll [MD5.DEB8CA5DE728ECB09706765DFAC90DBA] - [13/07/2016 20:52:46] - |A| - [596480] - C:\WINDOWS\system32\Windows.Graphics.Printing.dll [MD5.56A8197D9FAE5D63ED0CED92BD03F4F8] - [13/07/2016 20:53:45] - |A| - [450048] - C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll [MD5.D907D75D41B373D2F8DBD9E0E8B041C1] - [13/07/2016 20:54:57] - |A| - [730352] - C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll [MD5.0E52D076B5FDCD59AEC112BD7665E2E7] - [13/07/2016 20:56:08] - |A| - [3428864] - C:\WINDOWS\system32\Windows.Media.dll [MD5.950575747FCDCAF5CD7692664DBFE903] - [13/07/2016 20:55:43] - |A| - [1434112] - C:\WINDOWS\system32\Windows.Media.Editing.dll [MD5.024199E28832EEF1418AC3E93894FB75] - [13/07/2016 20:53:41] - |A| - [376536] - C:\WINDOWS\system32\Windows.Media.MediaControl.dll [MD5.5712B5F645838BFC583AB4A5E9684572] - [13/07/2016 20:55:00] - |A| - [1575936] - C:\WINDOWS\system32\Windows.Media.Speech.dll [MD5.4DDF78E93CF079FD19D80CB45DA9611D] - [13/07/2016 20:53:51] - |A| - [1036288] - C:\WINDOWS\system32\Windows.Media.Streaming.dll [MD5.E7DA2262B7A9C793FEBD14088AE4C72F] - [13/07/2016 20:51:39] - |A| - [900608] - C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll [MD5.FC0F06DFE5FD20CCFCE17F3180746D24] - [13/07/2016 20:55:58] - |A| - [576000] - C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll [MD5.4FE86093AE50EDBB2C51F719AE366AA2] - [13/07/2016 20:55:45] - |A| - [697344] - C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll [MD5.720627CBA30152DFA93E8438BCEAA167] - [13/07/2016 20:55:44] - |A| - [708608] - C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll [MD5.E274C4B6C496B72CCE171CB56C51C41A] - [13/07/2016 20:53:33] - |A| - [51200] - C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll [MD5.7FA43A7587D5D6AA8FFE42A271CF2585] - [13/07/2016 20:53:29] - |A| - [45056] - C:\WINDOWS\system32\Windows.Speech.Pal.dll [MD5.17139E61D556444B6FCE67920E71D369] - [13/07/2016 20:54:59] - |A| - [2745856] - C:\WINDOWS\system32\Windows.StateRepository.dll [MD5.0B1DA49D8F816ED7CF44B112B2F348DD] - [13/07/2016 20:54:29] - |A| - [59904] - C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll [MD5.86236B9417AA659DF48C45162C148167] - [13/07/2016 20:54:34] - |A| - [64000] - C:\WINDOWS\system32\Windows.StateRepositoryClient.dll [MD5.12FEFF0CACF65E3FB5531E2D19728FB0] - [13/07/2016 20:55:45] - |A| - [337336] - C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll [MD5.4B80239138EB21B50A1FBA54FDB15860] - [13/07/2016 20:52:10] - |A| - [6605544] - C:\WINDOWS\system32\windows.storage.dll [MD5.D62B0829530BBBA204ECA98B57FC4C58] - [13/07/2016 20:52:32] - |A| - [817152] - C:\WINDOWS\system32\Windows.Storage.Search.dll [MD5.F35D067F84D5F8EE3ACEEC3188FF3B40] - [13/07/2016 20:54:40] - |A| - [414720] - C:\WINDOWS\system32\Windows.UI.BioFeedback.dll [MD5.324F99E7B2B6739370D398D3C79A6DFD] - [13/07/2016 20:54:37] - |A| - [475648] - C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll [MD5.1EF7B8D9AF97BA18A61E6256300A2E78] - [13/07/2016 20:55:01] - |A| - [1211904] - C:\WINDOWS\system32\Windows.UI.Cred.dll [MD5.E772B8EEE1D142622192ADFF4DA1618B] - [13/07/2016 20:51:28] - |A| - [673280] - C:\WINDOWS\system32\Windows.UI.dll [MD5.F099E147846A9CFF5D26E9292D77F8A9] - [13/07/2016 20:55:54] - |A| - [1797120] - C:\WINDOWS\system32\Windows.UI.Immersive.dll [MD5.C731DF7843CA87A97969FC182298D8F0] - [13/07/2016 20:55:16] - |A| - [2635776] - C:\WINDOWS\system32\Windows.UI.Logon.dll [MD5.AA39F6642940FD8D4781701AD73776AD] - [13/07/2016 20:54:32] - |A| - [188416] - C:\WINDOWS\system32\Windows.UI.PicturePassword.dll [MD5.552E1A170B36D372CA67A5990E95BF13] - [13/07/2016 20:54:12] - |A| - [6312448] - C:\WINDOWS\system32\Windows.UI.Search.dll [MD5.E269E5AE6F0B70FC5093DF5D438C5FD2] - [13/07/2016 20:55:05] - |A| - [1390080] - C:\WINDOWS\system32\Windows.UI.Shell.dll [MD5.2DEED9D59520DD7DF44C4D4F58C3B046] - [13/07/2016 20:52:16] - |A| - [16985088] - C:\WINDOWS\system32\Windows.UI.Xaml.dll [MD5.63660131B3B6F976F28E75F37DFB2F5F] - [13/07/2016 20:51:48] - |A| - [1776768] - C:\WINDOWS\system32\WindowsCodecs.dll [MD5.E249D7A2B7998EF00990E56190D738B1] - [13/07/2016 20:55:36] - |A| - [276480] - C:\WINDOWS\system32\WindowsCodecsExt.dll [MD5.4FBF7735D43C338B9F6A1F86116451E5] - [13/07/2016 20:52:55] - |A| - [28851224] - C:\WINDOWS\system32\WindowsCodecsRaw.dll [MD5.1EEBC6859473037A1A671738AD083C7D] - [13/07/2016 20:55:15] - |A| - [3026944] - C:\WINDOWS\system32\wininet.dll [MD5.BB46F924BAF7128D44B25783ED785A18] - [13/07/2016 20:54:48] - |A| - [448000] - C:\WINDOWS\system32\winipcfile.dll [MD5.C1257DCFD6031469F154CF44E0769613] - [13/07/2016 20:54:49] - |A| - [1141248] - C:\WINDOWS\system32\winipcsecproc.dll [MD5.BB861E878479CCBCF55D4242AC400E36] - [13/07/2016 20:51:35] - |A| - [1317640] - C:\WINDOWS\system32\winload.efi [MD5.8C01DAF52F9923A4B9DF31F1D9331567] - [13/07/2016 20:51:36] - |A| - [1141504] - C:\WINDOWS\system32\winload.exe [MD5.96D121188D91FB4C9C878F30A3F7086F] - [13/07/2016 20:55:55] - |A| - [1552104] - C:\WINDOWS\system32\winmde.dll [MD5.5DB913462AD1D5EB8766E5A51922D661] - [13/07/2016 20:54:31] - |A| - [2012672] - C:\WINDOWS\system32\winmsipc.dll [MD5.C55144832FF73830BBBC0B5B6EED6383] - [13/07/2016 20:51:35] - |A| - [1030416] - C:\WINDOWS\system32\winresume.efi [MD5.11FB4531482E461A71E5303F53FFDC92] - [13/07/2016 20:51:34] - |A| - [874968] - C:\WINDOWS\system32\winresume.exe [MD5.6C647A171ACA3838441206BBE715B0D7] - [13/07/2016 20:55:31] - |A| - [198144] - C:\WINDOWS\system32\winsrv.dll [MD5.B26725818ECD6486A3FEB0509ED66CB3] - [13/07/2016 20:54:52] - |A| - [519680] - C:\WINDOWS\system32\WLanConn.dll [MD5.9E5D0971925AF8E8EBAB3A98991500BD] - [13/07/2016 20:54:43] - |A| - [510464] - C:\WINDOWS\system32\WlanMediaManager.dll [MD5.D3C6155DF570181F97488A3186E4E8E2] - [13/07/2016 20:54:35] - |A| - [412672] - C:\WINDOWS\system32\wlanui.dll [MD5.D78D829952282676116A92E1C5C3A89F] - [13/07/2016 20:53:45] - |A| - [37232] - C:\WINDOWS\system32\wldp.dll [MD5.E5830830FB987CB46C18AB55ECC7763A] - [13/07/2016 20:51:42] - |A| - [341504] - C:\WINDOWS\system32\wmicmiplugin.dll [MD5.6E415D9BFD8D1BC0354C3B0E4A0E1C56] - [13/07/2016 20:56:27] - |A| - [14252544] - C:\WINDOWS\system32\wmp.dll [MD5.E750AFEDBCC48016787CB4F6644923E4] - [13/07/2016 20:51:45] - |A| - [1847808] - C:\WINDOWS\system32\WMPDMC.exe [MD5.C9BB741EB879D6B5A6CDBE88315B030B] - [13/07/2016 20:54:35] - |A| - [373248] - C:\WINDOWS\system32\WmpDui.dll [MD5.9D86BE6C15D60535AE36AA0D8DECFC51] - [13/07/2016 20:53:36] - |A| - [394752] - C:\WINDOWS\system32\WMPhoto.dll [MD5.79F5E0E53F4D42D1DB0D83D719C551C9] - [13/07/2016 20:54:58] - |A| - [1554152] - C:\WINDOWS\system32\wmpmde.dll [MD5.FC3D54BD8FBD8A053223D1EC6E9103A4] - [13/07/2016 20:55:42] - |A| - [388896] - C:\WINDOWS\system32\wmpps.dll [MD5.3B6CCFF7AD385842A9638DCF654ABCD4] - [13/07/2016 20:52:57] - |A| - [1872896] - C:\WINDOWS\system32\workfolderssvc.dll [MD5.6D6E9C9C70E196F6833A96C267327368] - [13/07/2016 20:55:09] - |A| - [2876928] - C:\WINDOWS\system32\Wpc.dll [MD5.08C501FB351842DC6B5A34DFA705C28C] - [13/07/2016 20:55:03] - |A| - [1750440] - C:\WINDOWS\system32\WpcMon.exe [MD5.9E625D3F5AAC433191CF4F16174DDE05] - [13/07/2016 20:54:26] - |A| - [824320] - C:\WINDOWS\system32\WpcWebFilter.dll [MD5.1AC7CA0E0DA703106B6DFACD2C84E520] - [13/07/2016 20:55:01] - |A| - [2285568] - C:\WINDOWS\system32\WpcWebSync.dll [MD5.80625D0A23E439BCAA2C3021042A5EBF] - [13/07/2016 20:55:45] - |A| - [2088960] - C:\WINDOWS\system32\wpdshext.dll [MD5.C2F73C1C869B72BF897379A6B02CB5C2] - [13/07/2016 20:55:32] - |A| - [69120] - C:\WINDOWS\system32\WPDShServiceObj.dll [MD5.634E0909C598C5BA50E0890D7CAFD795] - [13/07/2016 20:53:58] - |A| - [870400] - C:\WINDOWS\system32\wpncore.dll [MD5.BA46DFBCD3D906776F0F803B6C0B5690] - [13/07/2016 20:53:35] - |A| - [185344] - C:\WINDOWS\system32\WSClient.dll [MD5.1E099AE79C6D58063E0B4F538732B87F] - [13/07/2016 20:53:40] - |A| - [3449168] - C:\WINDOWS\system32\WSService.dll [MD5.518ABEC8D3C1EEB1C64FDC3B77CD428C] - [13/07/2016 20:53:47] - |A| - [961536] - C:\WINDOWS\system32\WSShared.dll [MD5.8E908E944599C9134A209D5876884C07] - [13/07/2016 20:53:35] - |A| - [183808] - C:\WINDOWS\system32\WSSync.dll [MD5.CC270562CC41D32D118D9EA75E966FE5] - [13/07/2016 20:52:37] - |A| - [26408] - C:\WINDOWS\system32\wuauclt.exe [MD5.F2A9089A715EC55EA8A5C660F724A7B3] - [13/07/2016 20:53:13] - |A| - [2280448] - C:\WINDOWS\system32\wuaueng.dll [MD5.862FCF0385E0D94A2CD2FB4604096CDB] - [13/07/2016 20:53:31] - |A| - [200192] - C:\WINDOWS\system32\WUDFPlatform.dll [MD5.FA913C83823C2BA250E80AAE2E3905D1] - [13/07/2016 20:55:53] - |A| - [381952] - C:\WINDOWS\system32\wuuhext.dll [MD5.0C41EA00D56409637B157DAA3C7ECDE0] - [13/07/2016 20:55:19] - |A| - [808288] - C:\WINDOWS\system32\WWAHost.exe [MD5.6630413C9F5E87F0C097D77AD96CBBC3] - [13/07/2016 20:54:56] - |A| - [465920] - C:\WINDOWS\system32\wwanconn.dll [MD5.FB468F3E01B83C0878F024B8B15F8A78] - [13/07/2016 20:54:42] - |A| - [6572032] - C:\WINDOWS\system32\wwanmm.dll [MD5.928C7B3D285CD3485267E6B819748DA4] - [13/07/2016 20:53:03] - |A| - [4646912] - C:\WINDOWS\system32\xpsrchvw.exe [MD5.5FCE18E28E0439C147A16323961CD1FA] - [13/07/2016 20:51:49] - |A| - [3046400] - C:\WINDOWS\system32\xpsservices.dll [MD5.E57B9A2BBBBB39F369A1141472A3DDFD] - [13/07/2016 20:54:37] - |A| - [392192] - C:\WINDOWS\system32\zipfldr.dll [MD5.33110D78697A1B771E1B30675B39CE46] - [13/07/2016 20:52:21] - |A| - [112640] - C:\WINDOWS\system32\Drivers\bthenum.sys [MD5.2D54FE808BAF96666D0CE9B05B8C768F] - [13/07/2016 20:53:01] - |A| - [954368] - C:\WINDOWS\system32\Drivers\bthport.sys [MD5.B32316BCF974882E715A3459C953AD56] - [13/07/2016 20:52:21] - |A| - [84992] - C:\WINDOWS\system32\Drivers\BTHUSB.SYS [MD5.309E3CFC5309CECD9317A69990716A87] - [13/07/2016 20:54:54] - |A| - [604928] - C:\WINDOWS\system32\Drivers\cng.sys [MD5.97BFC3BD9F910B24EB956FF3387C71CF] - [13/07/2016 20:56:09] - |A| - [1987936] - C:\WINDOWS\system32\Drivers\dxgkrnl.sys [MD5.66FDDD2004332EED0A8262E9762EB457] - [13/07/2016 20:55:37] - |A| - [393568] - C:\WINDOWS\system32\Drivers\dxgmms1.sys [MD5.91A2D07C017068FD2F11414E8D676EC5] - [13/07/2016 20:55:52] - |A| - [577376] - C:\WINDOWS\system32\Drivers\dxgmms2.sys [MD5.5DFF4CF4DF7FD11AE5A1DAD8C67619D2] - [13/07/2016 20:54:55] - |A| - [161632] - C:\WINDOWS\system32\Drivers\ksecpkg.sys [MD5.D41D8CD98F00B204E9800998ECF8427E] - [10/07/2016 17:25:16] - |AH| - [0] - C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf [MD5.549DFD8240CF20BFBD88AD9D89325DBF] - [13/07/2016 20:54:44] - |A| - [530432] - C:\WINDOWS\system32\Drivers\nwifi.sys [MD5.EF94E21C3220AE3F8539542EC0B3FF06] - [13/07/2016 20:54:58] - |A| - [331616] - C:\WINDOWS\system32\Drivers\pci.sys [MD5.1CDA6D0A2345AA589949AE9C83853913] - [13/07/2016 20:51:36] - |A| - [277856] - C:\WINDOWS\system32\Drivers\sdbus.sys [MD5.CF63BF6AAEDF721E37F9E216FD321B8E] - [13/07/2016 20:51:47] - |A| - [2403168] - C:\WINDOWS\system32\Drivers\tcpip.sys [MD5.19157418D05756492D3F54751EC5B041] - [13/07/2016 20:55:34] - |A| - [546816] - C:\WINDOWS\syswow64\ActionCenterCPL.dll [MD5.BBB9376A3D8764A6763183340625FCEA] - [13/07/2016 20:54:24] - |A| - [70656] - C:\WINDOWS\syswow64\AppCapture.dll [MD5.E48A7C15B395A8F1537CE249183D508F] - [13/07/2016 20:52:33] - |A| - [190464] - C:\WINDOWS\syswow64\apprepapi.dll [MD5.8686191CF27D6707FC890A6CD4CB552A] - [13/07/2016 20:52:24] - |A| - [260096] - C:\WINDOWS\syswow64\apprepsync.dll [MD5.AE3444858CB88D033427C1E9D6FE749E] - [13/07/2016 20:53:38] - |A| - [738816] - C:\WINDOWS\syswow64\appwiz.cpl [MD5.96E0F50ABD43C92B4B66154113C701DE] - [13/07/2016 20:54:03] - |A| - [2155008] - C:\WINDOWS\syswow64\authui.dll [MD5.56BBCFD02C4C5248CAF8EAF8236A4674] - [13/07/2016 20:54:22] - |A| - [667648] - C:\WINDOWS\syswow64\AzureSettingSyncProvider.dll [MD5.312472050BECE16F51493C95CCE91B57] - [13/07/2016 20:54:24] - |A| - [334336] - C:\WINDOWS\syswow64\bcastdvr.exe [MD5.3BFBC5158CC4CA508FEC8284DB6727FD] - [13/07/2016 20:56:13] - |A| - [5205504] - C:\WINDOWS\syswow64\BingMaps.dll [MD5.4907E0A9216A6DCEAB351F534A97FAFC] - [13/07/2016 20:54:33] - |A| - [339456] - C:\WINDOWS\syswow64\certcli.dll [MD5.C34CC619C1F747F81D2C2C47D5C1B095] - [13/07/2016 20:54:08] - |A| - [2604032] - C:\WINDOWS\syswow64\CertEnroll.dll [MD5.31AC81040FBFB538619282F47C3ED884] - [13/07/2016 20:56:15] - |A| - [5660672] - C:\WINDOWS\syswow64\Chakra.dll [MD5.DFB970BC93678AFA2F95A51BF1506049] - [13/07/2016 20:53:39] - |A| - [64584] - C:\WINDOWS\syswow64\Clipc.dll [MD5.03BF64E3FD79A5C4FD0B51659B164EDC] - [13/07/2016 20:54:30] - |A| - [965120] - C:\WINDOWS\syswow64\comdlg32.dll [MD5.766F809BC576BC57FF3B7C343D1E8881] - [13/07/2016 20:54:04] - |A| - [1862008] - C:\WINDOWS\syswow64\CoreUIComponents.dll [MD5.ADCC41AF6513D5192E0C1A250D2ED4A1] - [13/07/2016 20:54:00] - |A| - [348672] - C:\WINDOWS\syswow64\CredProvDataModel.dll [MD5.2E7375FB616E7F729B077628F9BF2537] - [13/07/2016 20:51:28] - |A| - [220672] - C:\WINDOWS\syswow64\credprovs.dll [MD5.E247EAA09FE6397200205FA90BF87C1D] - [13/07/2016 20:53:00] - |A| - [1536600] - C:\WINDOWS\syswow64\crypt32.dll [MD5.00C8B201BE1C9705906A484DBE5D6332] - [13/07/2016 20:53:11] - |A| - [4759040] - C:\WINDOWS\syswow64\d2d1.dll [MD5.4963662B1CBB0035FD5D6832824DC7B6] - [13/07/2016 20:53:18] - |A| - [2186864] - C:\WINDOWS\syswow64\d3d11.dll [MD5.4102898869C3F72FBD50E7A7D003F530] - [13/07/2016 20:53:56] - |A| - [1866104] - C:\WINDOWS\syswow64\d3d9.dll [MD5.9FFEF91F0BEE39FAE2305ACE3C11B4A8] - [13/07/2016 20:54:39] - |A| - [3695104] - C:\WINDOWS\syswow64\D3DCompiler_47.dll [MD5.7CF445915FC12FA890EFE5D43AD8B2F9] - [13/07/2016 20:53:54] - |A| - [4078080] - C:\WINDOWS\syswow64\dbgeng.dll [MD5.83CF09D8FE73DC8FA7374C98B32243DF] - [13/07/2016 20:53:05] - |A| - [675064] - C:\WINDOWS\syswow64\dcomp.dll [MD5.C9D3FB6CD5BE57D44C4136B19EFAE986] - [15/07/2016 15:03:05] - |A| - [4761] - C:\WINDOWS\syswow64\debug.log [MD5.1E00F1B16E727B3D23F6516988F2E7EA] - [13/07/2016 20:53:30] - |A| - [502272] - C:\WINDOWS\syswow64\DevicePairing.dll [MD5.1E506E10685E8774F12BF5E2F10197F1] - [13/07/2016 20:53:32] - |A| - [736768] - C:\WINDOWS\syswow64\Display.dll [MD5.A3F164387FAF9C571959C73361317F04] - [13/07/2016 20:52:30] - |A| - [442368] - C:\WINDOWS\syswow64\dlnashext.dll [MD5.415F514AA00B37A1772639F7B22BC305] - [13/07/2016 20:51:34] - |A| - [217600] - C:\WINDOWS\syswow64\dmdskmgr.dll [MD5.29C26A25041DC901A01A021D31B0FDD8] - [13/07/2016 20:55:26] - |A| - [292864] - C:\WINDOWS\syswow64\dot3ui.dll [MD5.332384C9BF8D46044F3A5189A2E7C6FE] - [13/07/2016 20:51:40] - |A| - [1448960] - C:\WINDOWS\syswow64\dui70.dll [MD5.737FC213AB9B3494E8677D12F08B8703] - [13/07/2016 20:51:30] - |A| - [482816] - C:\WINDOWS\syswow64\duser.dll [MD5.0313658DF0E7A0F28F9580AF15B37531] - [13/07/2016 20:53:09] - |A| - [1626112] - C:\WINDOWS\syswow64\dwmcore.dll [MD5.DE4C532C704002ED07B523208327629C] - [13/07/2016 20:55:44] - |A| - [1987072] - C:\WINDOWS\syswow64\DWrite.dll [MD5.7CDA291CF22B91DDBB88B5089EBE25CE] - [13/07/2016 20:53:06] - |A| - [521152] - C:\WINDOWS\syswow64\dxgi.dll [MD5.6AA3C6E88196938932ADE02296C33458] - [13/07/2016 20:55:36] - |A| - [268800] - C:\WINDOWS\syswow64\dxtrans.dll [MD5.733B5C5DCFEB74A288F69272A79FCBF7] - [13/07/2016 20:52:27] - |A| - [248320] - C:\WINDOWS\syswow64\eapp3hst.dll [MD5.19D8F7D29B8B94071DAC6453690BB5CA] - [13/07/2016 20:52:39] - |A| - [284160] - C:\WINDOWS\syswow64\eappcfg.dll [MD5.5642D8C9041FF6F1EE88E42C90639CA8] - [13/07/2016 20:52:25] - |A| - [96256] - C:\WINDOWS\syswow64\eappgnui.dll [MD5.4FAB17214FC37489C59B19CED55D4B7F] - [13/07/2016 20:52:27] - |A| - [238592] - C:\WINDOWS\syswow64\eapphost.dll [MD5.9160F82BF248F5CD2A5CA4C109369D41] - [13/07/2016 20:52:29] - |A| - [55808] - C:\WINDOWS\syswow64\eappprxy.dll [MD5.21CB86D69B268182994F981471FCBB82] - [13/07/2016 20:56:34] - |A| - [18674176] - C:\WINDOWS\syswow64\edgehtml.dll [MD5.EA11A61E656D6CC6F5001F8366B2BA08] - [13/07/2016 20:52:26] - |A| - [279040] - C:\WINDOWS\syswow64\edputil.dll [MD5.051FDE1463E8468FACFC38C63B4D8FE3] - [13/07/2016 20:51:27] - |A| - [442880] - C:\WINDOWS\syswow64\efswrt.dll [MD5.C5C5F307A1A9039B96A8EAF6D58AE6C1] - [04/07/2016 19:39:17] - |A| - [72] - C:\WINDOWS\syswow64\EN_120468.html [MD5.BC98A3374DAB7CE9E600A667FDCD9F96] - [13/07/2016 20:51:31] - |A| - [193536] - C:\WINDOWS\syswow64\ExecModelClient.dll [MD5.B6113983ED77D6FE99BDEE461E7BE004] - [13/07/2016 20:54:10] - |A| - [4074160] - C:\WINDOWS\syswow64\explorer.exe [MD5.23D61B1CFA38F287D8C31A4816315454] - [13/07/2016 20:55:10] - |A| - [4413440] - C:\WINDOWS\syswow64\ExplorerFrame.dll [MD5.7457B7747A4C3D1088F02904A7E198E0] - [12/07/2016 20:16:20] - |A| - [6079168] - C:\WINDOWS\syswow64\FlashPlayerInstaller.exe [MD5.C8D298F6CE6886A274A58F2C392F4ECF] - [04/07/2016 19:39:16] - |A| - [72] - C:\WINDOWS\syswow64\fr_115312.html [MD5.64B619A6CE464E494651950794CE8264] - [13/07/2016 20:54:26] - |A| - [541184] - C:\WINDOWS\syswow64\GamePanel.exe [MD5.67BA16BD6265C9E401A3814137ECF8F4] - [13/07/2016 20:53:47] - |A| - [2578432] - C:\WINDOWS\syswow64\gameux.dll [MD5.4F79496B51E1A67B496FF6A407D22D30] - [13/07/2016 20:54:50] - |A| - [1467392] - C:\WINDOWS\syswow64\GdiPlus.dll [MD5.7BB466A82CD38CCBEE666D475BB2F3D2] - [13/07/2016 20:51:24] - |A| - [199680] - C:\WINDOWS\syswow64\GlobCollationHost.dll [MD5.C0D3B98EB0C657DDEB0C033D01C6D9E7] - [13/07/2016 20:53:38] - |A| - [574976] - C:\WINDOWS\syswow64\hgcpl.dll [MD5.9E2490246907BC5DFF0D06E975A98FE9] - [13/07/2016 20:54:25] - |A| - [12288] - C:\WINDOWS\syswow64\IconCodecService.dll [MD5.9459503897809956B533141003277298] - [13/07/2016 20:53:33] - |A| - [92160] - C:\WINDOWS\syswow64\IdCtrls.dll [MD5.973057A6623492B1620B0167D320BD4D] - [13/07/2016 20:55:35] - |A| - [1526272] - C:\WINDOWS\syswow64\ieapfltr.dll [MD5.350ED2186E2C0E80ABCE270C9A52647E] - [13/07/2016 20:56:17] - |A| - [12128256] - C:\WINDOWS\syswow64\ieframe.dll [MD5.608F7830161D98DBDD6324F74E9165C4] - [13/07/2016 20:55:12] - |A| - [2921880] - C:\WINDOWS\syswow64\iertutil.dll [MD5.8A62CEED5A0DD6C76C921F8B47187CA3] - [13/07/2016 20:52:24] - |A| - [477184] - C:\WINDOWS\syswow64\ieui.dll [MD5.447D69BB274546D00C8DBF23C2DBDBCE] - [13/07/2016 20:55:52] - |A| - [2050048] - C:\WINDOWS\syswow64\inetcpl.cpl [MD5.0B6A790F69FC2D67EEFF6F015EF24C5B] - [13/07/2016 20:55:52] - |A| - [800768] - C:\WINDOWS\syswow64\JpMapControl.dll [MD5.79C50C86572AF5891D1196569C9D2EB1] - [13/07/2016 20:56:13] - |A| - [3663360] - C:\WINDOWS\syswow64\jscript9.dll [MD5.F45E83301A6C99D342C600B5B29BCD71] - [13/07/2016 20:52:39] - |A| - [1557776] - C:\WINDOWS\syswow64\KernelBase.dll [MD5.EEB99F0E02F9243F18691C75CD16AEE4] - [13/07/2016 20:53:35] - |A| - [207872] - C:\WINDOWS\syswow64\licensingdiag.exe [MD5.D7BDD6C833746E64F1652D6CDE47701F] - [13/07/2016 20:53:49] - |A| - [372224] - C:\WINDOWS\syswow64\LockAppBroker.dll [MD5.236FB0CAF33B0EB94893BF7299F3D00D] - [13/07/2016 20:53:55] - |A| - [254656] - C:\WINDOWS\syswow64\LockAppHost.exe [MD5.644CE64AB3ED902711CB0B86CF4ECA22] - [13/07/2016 20:51:44] - |A| - [434688] - C:\WINDOWS\syswow64\LogonController.dll [MD5.3F695F3A23A019E6DF7BAC57276B1E77] - [13/07/2016 20:55:55] - |A| - [349696] - C:\WINDOWS\syswow64\MapConfiguration.dll [MD5.CB84B6382E21D875D0EC9665CD6908B8] - [13/07/2016 20:56:00] - |A| - [711680] - C:\WINDOWS\syswow64\MapControlCore.dll [MD5.B7299EF9D5D4C7D480AC5A8ACEA402E1] - [13/07/2016 20:55:24] - |A| - [87040] - C:\WINDOWS\syswow64\MapsBtSvc.dll [MD5.AF1D02B5F78B3D0522458E8240672582] - [13/07/2016 20:54:55] - |A| - [673280] - C:\WINDOWS\syswow64\MbaeApiPublic.dll [MD5.1CDEF66CFD26AF241D8546896F77B8A5] - [13/07/2016 20:54:34] - |A| - [489984] - C:\WINDOWS\syswow64\mbsmsapi.dll [MD5.F3B12C931650835388F43DB2DF606657] - [13/07/2016 20:51:48] - |A| - [511320] - C:\WINDOWS\syswow64\mf.dll [MD5.B572C03916EC3A8BE05CB2199D4A3263] - [13/07/2016 20:52:38] - |A| - [451936] - C:\WINDOWS\syswow64\MFCaptureEngine.dll [MD5.59976482DB1C9F2F41DF62AA9A1B01C5] - [13/07/2016 20:53:12] - |A| - [2062336] - C:\WINDOWS\syswow64\MFMediaEngine.dll [MD5.57D00F9D60519705D37BAFB852771443] - [13/07/2016 20:53:08] - |A| - [1118208] - C:\WINDOWS\syswow64\mfnetsrc.dll [MD5.A489CECF560EA0421C04277904210395] - [13/07/2016 20:53:07] - |A| - [925576] - C:\WINDOWS\syswow64\mfplat.dll [MD5.734C17FFE65F9E0436BDAD566A613D8C] - [13/07/2016 20:51:36] - |A| - [32040] - C:\WINDOWS\syswow64\mfpmp.exe [MD5.3B5A60CFD5EA636133A0A9F8CD4EDC45] - [13/07/2016 20:53:08] - |A| - [709176] - C:\WINDOWS\syswow64\mfsvr.dll [MD5.00000000000000000000000000000000] - [02/07/2016 09:56:23] - |SD| - [0] - C:\WINDOWS\syswow64\Microsoft [MD5.D5ACEA2845E642A7ABF383C316CABDA6] - [13/07/2016 20:56:19] - |A| - [6295552] - C:\WINDOWS\syswow64\mos.dll [MD5.E4873BE74A0BE6F30A6948F882E6E7FC] - [13/07/2016 20:55:44] - |A| - [50176] - C:\WINDOWS\syswow64\MosHostClient.dll [MD5.0BBEA534AB25CEBFE72BD191FF84F593] - [13/07/2016 20:55:43] - |A| - [59904] - C:\WINDOWS\syswow64\MosStorage.dll [MD5.BEF902286DC49188F8435B1C2474AE96] - [13/07/2016 20:55:54] - |A| - [687616] - C:\WINDOWS\syswow64\msfeeds.dll [MD5.E5DD7B8A4023B9277C434405849BB43A] - [13/07/2016 20:54:07] - |A| - [2680320] - C:\WINDOWS\syswow64\msftedit.dll [MD5.01ECA12A5BF2D571FCE11C05419C3E50] - [13/07/2016 20:56:36] - |A| - [19347968] - C:\WINDOWS\syswow64\mshtml.dll [MD5.1EEC0939B2B99EF1F53B14D9205041AD] - [13/07/2016 20:53:32] - |A| - [282624] - C:\WINDOWS\syswow64\msieftp.dll [MD5.D4DE4F98D350823BACCA6D7F753D74D4] - [13/07/2016 20:53:29] - |A| - [6471168] - C:\WINDOWS\syswow64\mspaint.exe [MD5.C2230C9A5F4DA4FE5EF9462047429082] - [13/07/2016 20:54:25] - |A| - [32768] - C:\WINDOWS\syswow64\msscntrs.dll [MD5.B27FEB21C56278185E7B7A77722C6819] - [13/07/2016 20:52:52] - |A| - [777728] - C:\WINDOWS\syswow64\MsSpellCheckingFacility.dll [MD5.F3C7017623E0F1F04016E5041A106FC8] - [13/07/2016 20:54:36] - |A| - [119296] - C:\WINDOWS\syswow64\mssph.dll [MD5.4BC42306D03B539D0EDDD81CC0AE0CD3] - [13/07/2016 20:54:40] - |A| - [244736] - C:\WINDOWS\syswow64\mssphtb.dll [MD5.6500AB640E37FBFBE0D57B24F8BC6F30] - [13/07/2016 20:55:00] - |A| - [1984000] - C:\WINDOWS\syswow64\mssrch.dll [MD5.EF539679E1F6FA5DFDCE4D013A3D37CF] - [13/07/2016 20:56:06] - |A| - [6740992] - C:\WINDOWS\syswow64\mstscax.dll [MD5.2FE56BAE736FE2AD20950ECED0FFD6D1] - [13/07/2016 20:54:38] - |A| - [1588224] - C:\WINDOWS\syswow64\msxml3.dll [MD5.E3E6CA2D3FAADDEE4FC8A934FA42FA3D] - [13/07/2016 20:55:29] - |A| - [1171456] - C:\WINDOWS\syswow64\netcenter.dll [MD5.F99386465A196CA0129AE92307FF472D] - [13/07/2016 20:55:29] - |A| - [197120] - C:\WINDOWS\syswow64\netplwiz.dll [MD5.F964FA5FA4FAB1B2D9E6638A0CF0D7E7] - [13/07/2016 20:52:44] - |A| - [2679808] - C:\WINDOWS\syswow64\netshell.dll [MD5.631450FBA9C8677C00F5A577905ECE36] - [13/07/2016 20:55:25] - |A| - [784896] - C:\WINDOWS\syswow64\NMAA.dll [MD5.ABFB6150CA07482BCF3D3FDE3B62152A] - [13/07/2016 20:54:33] - |A| - [309760] - C:\WINDOWS\syswow64\ntprint.dll [MD5.34B1DD62B3F090A0466241F84F1E9AE0] - [13/07/2016 20:52:38] - |A| - [802816] - C:\WINDOWS\syswow64\ntshrui.dll [MD5.77D3FB612C75A70CDA55889616DF3969] - [13/07/2016 20:53:31] - |A| - [205312] - C:\WINDOWS\syswow64\oemlicense.dll [MD5.F0781A46DFE3A6C48FCA23FCDDA69B4B] - [13/07/2016 20:51:41] - |A| - [957608] - C:\WINDOWS\syswow64\ole32.dll [MD5.FC03376F464F07369BC07A6D9BE8CA8D] - [13/07/2016 20:52:40] - |A| - [88576] - C:\WINDOWS\syswow64\olepro32.dll [MD5.61D86AEAE520B20FD3AE5C68327239EB] - [13/07/2016 20:53:35] - |A| - [400896] - C:\WINDOWS\syswow64\OneDriveSettingSyncProvider.dll [MD5.53903FCDBE698C8804D0B479F4F5E29B] - [13/07/2016 20:55:56] - |A| - [517632] - C:\WINDOWS\syswow64\PlayToManager.dll [MD5.ED3335C188873DD766C73C98F06A3BEA] - [13/07/2016 20:55:25] - |A| - [216576] - C:\WINDOWS\syswow64\PlayToReceiver.dll [MD5.65585F1DB21193BA2DEB7C034984E2E8] - [13/07/2016 20:52:31] - |A| - [519168] - C:\WINDOWS\syswow64\PrintDialogs.dll [MD5.AF3369020E352540743E7664F7CAA189] - [13/07/2016 20:53:54] - |A| - [1355336] - C:\WINDOWS\syswow64\propsys.dll [MD5.404EA5D1E9451EAB6D37403B7CFAD736] - [13/07/2016 20:51:32] - |A| - [123392] - C:\WINDOWS\syswow64\ProximityCommon.dll [MD5.9484654938AE332E2BD2EFEA8F596376] - [13/07/2016 20:51:34] - |A| - [569856] - C:\WINDOWS\syswow64\qdvd.dll [MD5.B34DE2B803625C572C664C495FC3F720] - [13/07/2016 20:55:32] - |A| - [846336] - C:\WINDOWS\syswow64\rasgcw.dll [MD5.CB82FEFF538C7889DD58EF66B8FDB9FD] - [13/07/2016 20:55:35] - |A| - [2632192] - C:\WINDOWS\syswow64\rdpcore.dll [MD5.836FF4B7A3AC93E7D659F4FCCF7E0309] - [13/07/2016 20:54:36] - |A| - [779264] - C:\WINDOWS\syswow64\sbe.dll [MD5.4A8E1182ECF552141C2C165B0A137E50] - [13/07/2016 20:52:36] - |A| - [186880] - C:\WINDOWS\syswow64\schtasks.exe [MD5.8DBFE13F50BE7578913003EE5256AEBE] - [13/07/2016 20:54:29] - |A| - [282624] - C:\WINDOWS\syswow64\Search.ProtocolHandler.MAPI2.dll [MD5.D0B4D167CB9BA37A62BA8E7B7934F517] - [13/07/2016 20:51:37] - |A| - [460800] - C:\WINDOWS\syswow64\SearchFolder.dll [MD5.F370A686221023EC003D96BB1FBA57A0] - [13/07/2016 20:54:56] - |A| - [760320] - C:\WINDOWS\syswow64\SearchIndexer.exe [MD5.4C629B1F6E54578C7875057FD5C53E5F] - [13/07/2016 20:54:29] - |A| - [282624] - C:\WINDOWS\syswow64\SearchProtocolHost.exe [MD5.E2C0139812E0030B26F2E7B156C726A4] - [13/07/2016 20:53:35] - |A| - [184832] - C:\WINDOWS\syswow64\SettingMonitor.dll [MD5.D69DDC0073FA31032D7F9379D054679F] - [13/07/2016 20:53:57] - |A| - [503296] - C:\WINDOWS\syswow64\SettingSync.dll [MD5.0162996989471778328E929D58B1041E] - [13/07/2016 20:54:01] - |A| - [754176] - C:\WINDOWS\syswow64\SettingSyncCore.dll [MD5.D00ACFADE7EE80F0C45CC0B94EB5D21A] - [13/07/2016 20:53:47] - |A| - [465760] - C:\WINDOWS\syswow64\SettingSyncHost.exe [MD5.245BCE64F9396340F4E84FB140DD6CA6] - [13/07/2016 20:53:50] - |A| - [489984] - C:\WINDOWS\syswow64\ShareHost.dll [MD5.B726B6583C0E880B59BE3C4463C27BAB] - [13/07/2016 20:52:41] - |A| - [569752] - C:\WINDOWS\syswow64\SHCore.dll [MD5.3EEAC377D273ABB2B6FB02DBFE8E307E] - [13/07/2016 20:53:17] - |A| - [21123320] - C:\WINDOWS\syswow64\shell32.dll [MD5.E71CB29D5B7F76DD58677381CBFE6847] - [13/07/2016 20:52:35] - |A| - [129024] - C:\WINDOWS\syswow64\SimAuth.dll [MD5.42D425CA43C93CC578D1AEA96D1E39F0] - [13/07/2016 20:52:47] - |A| - [157696] - C:\WINDOWS\syswow64\SimCfg.dll [MD5.1CB309C3183A1249C0F3241BB3BA66DD] - [13/07/2016 20:53:50] - |A| - [736768] - C:\WINDOWS\syswow64\SmartcardCredentialProvider.dll [MD5.8B70A4CDB39E270F7F892C82BDB641A5] - [13/07/2016 20:53:05] - |A| - [799744] - C:\WINDOWS\syswow64\SRH.dll [MD5.0B1427CECB2D744C61E841DF0B905592] - [13/07/2016 20:53:09] - |A| - [1445888] - C:\WINDOWS\syswow64\SRHInproc.dll [MD5.2311952A48D5D22080073E5AD4621509] - [13/07/2016 20:53:36] - |A| - [629760] - C:\WINDOWS\syswow64\sud.dll [MD5.2F7684C2601F30ED0A5AFCB3AD295152] - [13/07/2016 20:53:42] - |A| - [3301376] - C:\WINDOWS\syswow64\SyncCenter.dll [MD5.E7AF52CE93D93984F11E5021024CA085] - [13/07/2016 20:52:38] - |A| - [356352] - C:\WINDOWS\syswow64\taskcomp.dll [MD5.FBA0E803ED70D649630DCA8EEC625414] - [13/07/2016 20:52:43] - |A| - [240640] - C:\WINDOWS\syswow64\taskeng.exe [MD5.38F874DC40AED7FE90ABED3006FF20B9] - [13/07/2016 20:52:57] - |A| - [1083656] - C:\WINDOWS\syswow64\Taskmgr.exe [MD5.212B595D06DB8A90B540E970E493CD6F] - [13/07/2016 20:53:37] - |A| - [2519552] - C:\WINDOWS\syswow64\themecpl.dll [MD5.F843B18F29E440CB4599F3674E03B0A5] - [13/07/2016 20:53:34] - |A| - [2849792] - C:\WINDOWS\syswow64\themeui.dll [MD5.4C5CD8F1A3B88B8B7B9F57F2E256FAFC] - [13/07/2016 20:55:40] - |A| - [639488] - C:\WINDOWS\syswow64\TokenBroker.dll [MD5.A233DD6D55CDBC80890E6D0702F727B5] - [13/07/2016 20:55:04] - |A| - [2771968] - C:\WINDOWS\syswow64\tquery.dll [MD5.A5B6DDDF137C8118B93D00404510741D] - [13/07/2016 20:51:46] - |A| - [836760] - C:\WINDOWS\syswow64\twinapi.appcore.dll [MD5.643BBA6FB3DA30DC0294F14D72EEFAAB] - [13/07/2016 20:53:51] - |A| - [581632] - C:\WINDOWS\syswow64\twinapi.dll [MD5.409D5D7EB68EDC5E5751A1F437F8C58E] - [13/07/2016 20:52:00] - |A| - [2000896] - C:\WINDOWS\syswow64\twinui.appcore.dll [MD5.A582CC5D97DA29AFE99024BBE96673F3] - [13/07/2016 20:54:16] - |A| - [9919488] - C:\WINDOWS\syswow64\twinui.dll [MD5.D613DBA2E2D43264B6D5C1933F3A71FC] - [13/07/2016 20:53:04] - |A| - [3459584] - C:\WINDOWS\syswow64\UIRibbon.dll [MD5.FC4E7D3027D748E2D131C9DED39D4976] - [13/07/2016 20:52:23] - |A| - [584704] - C:\WINDOWS\syswow64\UIRibbonRes.dll [MD5.7D5E17FC31FA563A94A8251AF8ADDEE4] - [13/07/2016 20:53:09] - |A| - [1498624] - C:\WINDOWS\syswow64\urlmon.dll [MD5.32E42A131A187BCAD87EA3A2A09498B9] - [13/07/2016 20:55:33] - |A| - [1249280] - C:\WINDOWS\syswow64\usercpl.dll [MD5.C41C3339364B262957110B2C6C32FF3D] - [13/07/2016 20:54:37] - |A| - [573440] - C:\WINDOWS\syswow64\UserLanguagesCpl.dll [MD5.88A5A640F1C46936CEA62B7B42969E8E] - [13/07/2016 20:51:54] - |A| - [502784] - C:\WINDOWS\syswow64\vbscript.dll [MD5.B6A9C98BFE60CB8DC992033108F3C4F0] - [13/07/2016 20:51:28] - |A| - [1226752] - C:\WINDOWS\syswow64\wcnwiz.dll [MD5.94B32AFBC8D832B3CC39C87DACCF4CEE] - [13/07/2016 20:52:30] - |A| - [879616] - C:\WINDOWS\syswow64\WebcamUi.dll [MD5.86FBB78A2D77D9BDD58F0D72A2E4D934] - [13/07/2016 20:55:27] - |A| - [230400] - C:\WINDOWS\syswow64\webcheck.dll [MD5.D6D84F133DC05DB51FE689BB2066D43E] - [13/07/2016 20:55:35] - |A| - [405504] - C:\WINDOWS\syswow64\webio.dll [MD5.A3E1888B827AD9132A35657C48C9762B] - [13/07/2016 20:53:38] - |A| - [578048] - C:\WINDOWS\syswow64\wiaaut.dll [MD5.E78E204A005D6DDEBBFA453380D6E847] - [13/07/2016 20:52:29] - |A| - [585216] - C:\WINDOWS\syswow64\Windows.AccountsControl.dll [MD5.162EE6B2FD2EBF008AF0B12C7E07A6D8] - [13/07/2016 20:55:24] - |A| - [250880] - C:\WINDOWS\syswow64\Windows.ApplicationModel.Store.TestingFramework.dll [MD5.40C2D19E230CDCBA7707DB5C5A9C6419] - [13/07/2016 20:54:13] - |A| - [5323776] - C:\WINDOWS\syswow64\Windows.Data.Pdf.dll [MD5.5A9CDDA8859CDA201006EE7BB84BC673] - [13/07/2016 20:55:28] - |A| - [254976] - C:\WINDOWS\syswow64\Windows.Devices.Picker.dll [MD5.257C46467A3C9FA96EA59B8B7DFCCA75] - [13/07/2016 20:55:28] - |A| - [559616] - C:\WINDOWS\syswow64\Windows.Devices.SmartCards.dll [MD5.ED87A6D9B014FC9D5CF57B9D7F54EA15] - [13/07/2016 20:53:31] - |A| - [386560] - C:\WINDOWS\syswow64\Windows.Devices.WiFiDirect.dll [MD5.5AF1EAB54122BA45CA59C10FAF3CC558] - [13/07/2016 20:51:44] - |A| - [1228800] - C:\WINDOWS\syswow64\Windows.Globalization.dll [MD5.CF97D32C0BD24525307676C04F4A32DF] - [13/07/2016 20:54:43] - |A| - [298496] - C:\WINDOWS\syswow64\Windows.Graphics.dll [MD5.B99334A08D3E9CE2D4A4BFB8BBC4CB76] - [13/07/2016 20:54:44] - |A| - [1448960] - C:\WINDOWS\syswow64\Windows.Graphics.Printing.3D.dll [MD5.50B851ADFFAC3B2EFD1B5DE4D8A94277] - [13/07/2016 20:53:44] - |A| - [468992] - C:\WINDOWS\syswow64\Windows.Graphics.Printing.dll [MD5.BD869430C7B7CCD5FE0C3D9D6D344953] - [13/07/2016 20:53:10] - |A| - [2798080] - C:\WINDOWS\syswow64\Windows.Media.dll [MD5.734026191E38F421D62D0067D89B0E35] - [13/07/2016 20:52:34] - |A| - [1063936] - C:\WINDOWS\syswow64\Windows.Media.Editing.dll [MD5.76B34D04F94D7A8D47763C4E8285F88B] - [13/07/2016 20:54:50] - |A| - [1117184] - C:\WINDOWS\syswow64\Windows.Media.Speech.dll [MD5.A4879DCB9CBE6F67661F0EF4D5A59092] - [13/07/2016 20:52:39] - |A| - [835072] - C:\WINDOWS\syswow64\Windows.Media.Streaming.dll [MD5.B39E043BCB704FF6F0D0DEADBCBA754D] - [13/07/2016 20:52:34] - |A| - [683008] - C:\WINDOWS\syswow64\Windows.Networking.BackgroundTransfer.dll [MD5.C40419A7C19D8C10AD7F7C923044FCFF] - [13/07/2016 20:55:43] - |A| - [523776] - C:\WINDOWS\syswow64\Windows.Security.Authentication.OnlineId.dll [MD5.97C7434D1268B8AA10A615415C92CE9A] - [13/07/2016 20:55:30] - |A| - [496128] - C:\WINDOWS\syswow64\Windows.Security.Authentication.Web.Core.dll [MD5.80BD175A8820F5D1C0913DE1BA2A0400] - [13/07/2016 20:51:22] - |A| - [40960] - C:\WINDOWS\syswow64\Windows.Shell.Search.UriHandler.dll [MD5.937208F90E70A7A415F05932ABD72DFB] - [13/07/2016 20:52:29] - |A| - [34304] - C:\WINDOWS\syswow64\Windows.Speech.Pal.dll [MD5.CF034E3697C5CA79777F94116D57C6A6] - [13/07/2016 20:53:01] - |A| - [2179584] - C:\WINDOWS\syswow64\Windows.StateRepository.dll [MD5.492C152E65A4F59D0FDDE2F2E0C34DE8] - [13/07/2016 20:52:24] - |A| - [48128] - C:\WINDOWS\syswow64\Windows.StateRepositoryBroker.dll [MD5.10882529EF2A92C7E5ACCC0E6EDF8390] - [13/07/2016 20:52:29] - |A| - [48640] - C:\WINDOWS\syswow64\Windows.StateRepositoryClient.dll [MD5.4BBFE28B6732D30D01C8880CEB254BB5] - [13/07/2016 20:52:45] - |A| - [256192] - C:\WINDOWS\syswow64\Windows.Storage.ApplicationData.dll [MD5.394B995CB6ADFEED1A37DD15FADE5068] - [13/07/2016 20:56:20] - |A| - [5240960] - C:\WINDOWS\syswow64\windows.storage.dll [MD5.414967EA08650001DD671FEFE37633E7] - [13/07/2016 20:51:30] - |A| - [645632] - C:\WINDOWS\syswow64\Windows.Storage.Search.dll [MD5.A65CFA79A13690155545A5FEEEC4FC42] - [13/07/2016 20:53:33] - |A| - [283136] - C:\WINDOWS\syswow64\Windows.UI.BioFeedback.dll [MD5.70BE5D31CD548715F88398D7B56E99B5] - [13/07/2016 20:53:33] - |A| - [315904] - C:\WINDOWS\syswow64\Windows.UI.BlockedShutdown.dll [MD5.541C337FA4551C852FA4371AD3BF9C5B] - [13/07/2016 20:53:48] - |A| - [764928] - C:\WINDOWS\syswow64\Windows.UI.Cred.dll [MD5.8F81BC95794B0C17812988D44D000170] - [13/07/2016 20:53:52] - |A| - [1582080] - C:\WINDOWS\syswow64\Windows.UI.Immersive.dll [MD5.E43E3D372FB0B976124C3A4F080556C6] - [13/07/2016 20:54:10] - |A| - [1799680] - C:\WINDOWS\syswow64\Windows.UI.Logon.dll [MD5.23F74037E71A1D1D827A3F0DDCB8A697] - [13/07/2016 20:51:57] - |A| - [4404736] - C:\WINDOWS\syswow64\Windows.UI.Search.dll [MD5.D8F75D59301833722BFB4893A47F57F2] - [13/07/2016 20:56:30] - |A| - [13018112] - C:\WINDOWS\syswow64\Windows.UI.Xaml.dll [MD5.236B3202BBB1FCD6C3319A994056E108] - [13/07/2016 20:55:49] - |A| - [1522160] - C:\WINDOWS\syswow64\WindowsCodecs.dll [MD5.702A77C8EB30026CF6C16F9B1439F166] - [13/07/2016 20:52:33] - |A| - [238592] - C:\WINDOWS\syswow64\WindowsCodecsExt.dll [MD5.FFA3300F8C8542A92015C7FF48A16AF9] - [13/07/2016 20:52:51] - |A| - [28083144] - C:\WINDOWS\syswow64\WindowsCodecsRaw.dll [MD5.21BE44272CAC55D1B6C88C1E0BA78F8E] - [13/07/2016 20:53:12] - |A| - [2501632] - C:\WINDOWS\syswow64\wininet.dll [MD5.CEEA8FA78E1652BB7219FC118E9F67EE] - [13/07/2016 20:53:34] - |A| - [330752] - C:\WINDOWS\syswow64\winipcfile.dll [MD5.BEC15702CE3242133B95F0E2C69FFC88] - [13/07/2016 20:53:43] - |A| - [980480] - C:\WINDOWS\syswow64\winipcsecproc.dll [MD5.EACDCB7EA7696B10EF5CC65040A44923] - [13/07/2016 20:54:57] - |A| - [1349640] - C:\WINDOWS\syswow64\winmde.dll [MD5.2086CC9E5A8C75F246A75EE606988B77] - [13/07/2016 20:53:28] - |A| - [1508352] - C:\WINDOWS\syswow64\winmsipc.dll [MD5.5A0B501B638941EAF2BEABCE3C645769] - [13/07/2016 20:51:27] - |A| - [413696] - C:\WINDOWS\syswow64\WLanConn.dll [MD5.9208E440059270395C320190BFA9EE0E] - [13/07/2016 20:55:32] - |A| - [368128] - C:\WINDOWS\syswow64\wlanui.dll [MD5.BF370250794A9405AD153A4C1A4F5BBD] - [13/07/2016 20:52:40] - |A| - [32552] - C:\WINDOWS\syswow64\wldp.dll [MD5.87755FF83726D908224C08C180D42C72] - [13/07/2016 20:56:25] - |A| - [12586496] - C:\WINDOWS\syswow64\wmp.dll [MD5.5A69A6CB031970F5E0BBD4E967D32924] - [13/07/2016 20:53:07] - |A| - [1497088] - C:\WINDOWS\syswow64\WMPDMC.exe [MD5.6B50CF0D71F727CEDF49216FD4AC0FB9] - [13/07/2016 20:53:30] - |A| - [290304] - C:\WINDOWS\syswow64\WmpDui.dll [MD5.A7CD30176029F60B56F5590E37310103] - [13/07/2016 20:54:38] - |A| - [339968] - C:\WINDOWS\syswow64\WMPhoto.dll [MD5.FC42E59329315A30F397490033055D28] - [13/07/2016 20:55:03] - |A| - [2217984] - C:\WINDOWS\syswow64\Wpc.dll [MD5.B33928C3DED11908104A38E0C3090F7F] - [13/07/2016 20:54:25] - |A| - [572928] - C:\WINDOWS\syswow64\WpcWebFilter.dll [MD5.968DD3AA844E40932950709FD9CB9556] - [13/07/2016 20:55:31] - |A| - [1976832] - C:\WINDOWS\syswow64\wpdshext.dll [MD5.75869FD635879D9B0DCED6B6E4FEFDCD] - [13/07/2016 20:55:25] - |A| - [57344] - C:\WINDOWS\syswow64\WPDShServiceObj.dll [MD5.9A6B1DB1667CDD276A208F5AE5646948] - [13/07/2016 20:52:26] - |A| - [151552] - C:\WINDOWS\syswow64\WSClient.dll [MD5.B61C9BA4E125BC5FFF338D7B11BAC6EC] - [13/07/2016 20:52:40] - |A| - [805888] - C:\WINDOWS\syswow64\WSShared.dll [MD5.3E97CC7E938C4D15FCC27EC33C898606] - [13/07/2016 20:52:31] - |A| - [153088] - C:\WINDOWS\syswow64\WSSync.dll [MD5.D0A2BA04B1E3F6C1F0E52F65D97EF39D] - [13/07/2016 20:55:19] - |A| - [703840] - C:\WINDOWS\syswow64\WWAHost.exe [MD5.FC26697351E186D415E53BF83D37DAAD] - [13/07/2016 20:52:56] - |A| - [3555840] - C:\WINDOWS\syswow64\xpsrchvw.exe [MD5.F459F8A639AE35E8ECA718832BEDDB53] - [13/07/2016 20:55:46] - |A| - [2102272] - C:\WINDOWS\syswow64\xpsservices.dll [MD5.B18B0885CEFFA800A8C39EBDF41CE5A8] - [13/07/2016 20:53:32] - |A| - [347648] - C:\WINDOWS\syswow64\zipfldr.dll ---------- | Drives D: [04/06/2016 14:40:23] - |A| - (.-.) - [418] - (0.0.0.0) - D:\Lecteur de CD - Raccourci.lnk [16/06/2012 08:56:23] - |RASH| - (.-.) - [67] - (0.0.0.0) - D:\Desktop.ini ---------- | C: [17/07/2016 17:34:55] - |SHD| - [27357984] - C:\$RECYCLE.BIN [16/07/2016 21:47:15] - |D| - [5058549128] - C:\AdsFix [MD5.AB3E26D840427114B904D3F9B9194074] - [19/07/2016 22:40:08] - |A| - (.-.) - [162] - (0.0.0.0) - C:\AdsFix.txt [MD5.60D486CA73FF3DA5EF30F827D7EE607A] - [16/07/2016 21:48:22] - |A| - (.-.) - [202502] - (0.0.0.0) - C:\AdsFix_17_07_2016_17_31_14.txt [08/09/2012 15:16:40] - |D| - [0] - C:\AuthLog [06/06/2015 15:32:39] - |D| - [3641907561] - C:\Autodesk [26/06/2016 14:04:50] - |RASHD| - [3] - C:\Autorun.inf [02/01/2007 05:25:08] - |SHD| - [15743284] - C:\boot [MD5.259525CFB422E6AC8E87BC9777B1DF73] - [02/01/2007 05:25:08] - |RASH| - (.-.) - [383786] - (0.0.0.0) - C:\bootmgr [MD5.93B885ADFE0DA089CDF634904FD59F71] - [30/10/2015 12:13:44] - |N| - (.-.) - [1] - (0.0.0.0) - C:\BOOTNXT [15/05/2016 17:25:25] - |D| - [0] - C:\Cossacks [MD5.241260E02886C50F2DA06CB3BA24B4E1] - [14/11/2015 19:00:41] - |A| - (.-.) - [2099] - (0.0.0.0) - C:\DelFix.txt [09/12/2014 01:28:54] - |AD| - [2635924] - C:\DETMINERO [14/07/2009 09:08:56] - |SHD| - [442187473619] - C:\Documents and Settings [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1028.txt [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1031.txt [MD5.99C22D4A31F4EAD4351B71D6F4E5F6A1] - [07/11/2007 11:00:40] - |A| - (.-.) - [10134] - (0.0.0.0) - C:\eula.1033.txt [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1036.txt [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1040.txt [MD5.9B15A3A055CC6E67EA191A1B7885649A] - [07/11/2007 11:00:40] - |A| - (.-.) - [118] - (0.0.0.0) - C:\eula.1041.txt [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1042.txt [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.2052.txt [MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 11:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.3082.txt [MD5.E7832D67AD190A920970CB5ADFC6D5D1] - [05/08/2015 14:10:36] - |A| - (.-.) - [383] - (0.0.0.0) - C:\ftconfig.ini [MD5.BA672C8C09635932A8E66052F81145B4] - [04/01/2014 21:21:56] - |A| - (.-.) - [47] - (0.0.0.0) - C:\GESYSTEM.LOG [MD5.0A6B586FABD072BD7382B5E24194EAC7] - [07/11/2007 11:00:40] - |A| - (.-.) - [1110] - (0.0.0.0) - C:\globdata.ini [MD5.8FC7A4FA13AF81439264A059ED4C628B] - [24/04/2016 02:41:22] - |A| - (.-.) - [1712] - (0.0.0.0) - C:\Google Chrome.lnk [MD5.D41D8CD98F00B204E9800998ECF8427E] - [17/07/2016 17:31:14] - |ASH| - (.-.) - [3142033408] - (0.0.0.0) - C:\hiberfil.sys [30/11/2011 06:23:24] - |D| - [194961362] - C:\HP [10/06/2016 22:36:53] - |D| - [342787] - C:\inetpub [MD5.520A6D1CBCC9CF642C625FE814C93C58] - [07/11/2007 11:03:18] - |A| - (.© Microsoft Corporation. - External Installer.) - [562688] - (9.0.21022.8) - C:\install.exe [MD5.0DA9AB4977F3E7BA8C65734DF42FDAB6] - [07/11/2007 11:00:40] - |A| - (.-.) - [843] - (0.0.0.0) - C:\install.ini [MD5.4151A4D07640863783F837E588235837] - [07/11/2007 11:03:18] - |A| - (.(C) Microsoft Corporation. - UI Wrapper Resource DLL.) - [76304] - (9.0.21022.8) - C:\install.res.1028.dll [MD5.3B8A82E04238655EAEF97E074FB29911] - [07/11/2007 11:03:18] - |A| - (.© Microsoft Corporation. Alle Rechte vorbehalten. - Ressourcen-DLL für UI-Wrapper.) - [96272] - (9.0.21022.8) - C:\install.res.1031.dll [MD5.9EDEB8B1C5C0A4CD3A3016B85108127D] - [07/11/2007 11:03:18] - |A| - (.© Microsoft Corporation. - UI Wrapper Resource DLL.) - [91152] - (9.0.21022.8) - C:\install.res.1033.dll [MD5.5B6FF470CFA7087690E61F87E81EF78A] - [07/11/2007 11:03:18] - |A| - (.© Microsoft Corporation. Tous droits réservés. - UI Wrapper Resource DLL.) - [97296] - (9.0.21022.8) - C:\install.res.1036.dll [MD5.6310AB8FC9E3DBEE80592FC453A34FEE] - [07/11/2007 11:03:18] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - DLL di risorse del wrapper dell'interfaccia utente.) - [95248] - (9.0.21022.8) - C:\install.res.1040.dll [MD5.13ED4517152203DE4BC52ACC0255D952] - [07/11/2007 11:03:18] - |A| - (.(C) Copyright Microsoft Corporation. - UI Wrapper Resource DLL.) - [81424] - (9.0.21022.8) - C:\install.res.1041.dll [MD5.0D4FB4095EA49C1EC89B9E8DB0B936A3] - [07/11/2007 11:03:18] - |A| - (.(C) Microsoft Corporation. - UI 래퍼 리소스 DLL.) - [79888] - (9.0.21022.8) - C:\install.res.1042.dll [MD5.D7366B34E8AFB605C39EF56E2201FE85] - [07/11/2007 11:03:18] - |A| - (.(C) Microsoft Corporation。保留所有权利。 - 用户界面包装资源 DLL.) - [75792] - (9.0.21022.8) - C:\install.res.2052.dll [MD5.41BB37A347121F3E5E88D85100638B79] - [07/11/2007 11:03:18] - |A| - (.© Microsoft Corporation. Reservados todos los derechos. - Archivo DLL de recursos del contenedor de la interfaz de usuario.) - [96272] - (9.0.21022.8) - C:\install.res.3082.dll [15/06/2012 22:08:16] - |D| - [832784] - C:\Intel [MD5.E85A0604817CC7BA12642436D72C2834] - [18/11/2015 15:27:22] - |A| - (.-.) - [29842] - (0.0.0.0) - C:\License.rtf [27/04/2016 09:50:24] - |D| - [16285696] - C:\Logs [MD5.6F89B7ADD710AD1EA3D758CF2DCC0A01] - [29/06/2016 21:24:01] - |A| - (.-.) - [110114] - (0.0.0.0) - C:\Look_my_hardware.tmp [MD5.9A3D0B58A36A776D0003DB06EB622369] - [15/11/2015 21:57:23] - |A| - (.-.) - [566676] - (0.0.0.0) - C:\mbam2.txt [MD5.BA672C8C09635932A8E66052F81145B4] - [04/01/2014 21:21:56] - |A| - (.-.) - [47] - (0.0.0.0) - C:\MEM.LOG [02/12/2015 18:06:24] - |RHD| - [1470757184] - C:\MSOCache [MD5.D41D8CD98F00B204E9800998ECF8427E] - [15/06/2012 23:12:21] - |ASH| - (.-.) - [4294967296] - (0.0.0.0) - C:\pagefile.sys [30/10/2015 11:24:24] - |D| - [0] - C:\PerfLogs [30/10/2015 10:28:30] - |RD| - [8569867499] - C:\Program Files [30/10/2015 10:28:30] - |RD| - [8471661479] - C:\Program Files (x86) [30/10/2015 11:24:24] - |HD| - [110121780707] - C:\ProgramData [29/06/2016 21:11:36] - |D| - [540601] - C:\QuickDiag [MD5.CABAC85484A99E4CAB20ACA21D2C8ADA] - [22/07/2016 18:16:44] - |A| - (.-.) - [759092] - (0.0.0.0) - C:\QuickDiag.txt [MD5.C5500E09718553F890D29785383956FE] - [29/06/2016 21:53:30] - |RA| - (.-.) - [1577228] - (0.0.0.0) - C:\QuickDiag_29_06_2016_21_53_30.txt [MD5.9E75AA212F0EFE11624C21CCAC185A19] - [29/06/2016 22:53:45] - |RA| - (.-.) - [1623767] - (0.0.0.0) - C:\QuickDiag_29_06_2016_22_53_45.txt [10/06/2016 22:51:46] - |SHD| - [406680336] - C:\Recovery [MD5.56EA7E2FAD797C2E5C2D27990A060AF5] - [05/09/2013 14:53:04] - |A| - (.-.) - [466] - (0.0.0.0) - C:\Recovery (D) - Raccourci.lnk [MD5.D41D8CD98F00B204E9800998ECF8427E] - [10/06/2016 19:53:17] - |ASH| - (.-.) - [268435456] - (0.0.0.0) - C:\swapfile.sys [10/02/2011 23:23:20] - |D| - [3377643040] - C:\SWSetup [16/06/2012 06:55:33] - |SHD| - [0] - C:\System Volume Information [10/02/2011 23:23:20] - |D| - [77078134] - C:\SYSTEM.SAV [14/12/2013 21:19:40] - |D| - [0] - C:\Temp [15/11/2015 22:06:44] - |AD| - [4515571] - C:\UsbFix [30/10/2015 10:28:30] - |RD| - [456013991468] - C:\Users [MD5.06FBA95313F26E300917C6CEA4480890] - [07/11/2007 11:00:40] - |A| - (.-.) - [5686] - (0.0.0.0) - C:\vcredist.bmp [MD5.E10F2F6E6379E9185F71AEC1421F37B4] - [07/11/2007 11:09:22] - |A| - (.-.) - [1442522] - (0.0.0.0) - C:\VC_RED.cab [MD5.E0951D3CB1038EB2D2B2B2F336E1AB32] - [07/11/2007 11:12:28] - |A| - (.-.) - [232960] - (0.0.0.0) - C:\VC_RED.MSI [30/10/2015 10:28:30] - |D| - [28584879753] - C:\Windows ---------- | C:\WINDOWS [30/10/2015 11:24:24] - |D| - [802] - C:\WINDOWS\addins [30/10/2015 11:24:24] - |D| - [28116842] - C:\WINDOWS\appcompat [30/10/2015 11:24:24] - |D| - [12360910] - C:\WINDOWS\AppPatch [30/10/2015 11:24:24] - |D| - [0] - C:\WINDOWS\AppReadiness [30/10/2015 11:24:24] - |RD| - [1636298432] - C:\WINDOWS\assembly [MD5.A46472DDF69B3642DB4FAD4182877CF0] - [21/03/2013 14:32:29] - |A| - (.-.) - [20480] - (0.0.0.0) - C:\WINDOWS\AutodeskReCap.mst [MD5.7EFB1577EFBD72521E670188AA546C7D] - [14/07/2016 10:48:19] - |A| - (.Copyright (c) 2014 AVAST Software - avast! Screen Saver stub.) - [53208] - (12.1.3076.0) - C:\WINDOWS\avastSS.scr [30/10/2015 11:24:24] - |D| - [241412] - C:\WINDOWS\bcastdvr [MD5.DE3C720C11A91557E1DFDFF0DB2AA3C2] - [30/10/2015 11:17:47] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [61952] - (10.0.10586.0) - C:\WINDOWS\bfsvc.exe [30/10/2015 11:24:24] - |D| - [32716961] - C:\WINDOWS\Boot [MD5.6D3273C3C5FBECA83310898410C88F24] - [27/04/2016 09:40:14] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [30/10/2015 11:24:24] - |D| - [2380376] - C:\WINDOWS\Branding [30/10/2015 11:11:39] - |D| - [0] - C:\WINDOWS\CbsTemp [MD5.3AFFB8ECAA4D239581FE738532D245FF] - [10/06/2016 19:12:42] - |A| - (.-.) - [6545] - (0.0.0.0) - C:\WINDOWS\comsetup.log [MD5.F59060E298148DE24DEBB3E8321C4407] - [27/04/2016 09:30:17] - |A| - (.-.) - [31816] - (0.0.0.0) - C:\WINDOWS\Core.xml [MD5.179F6B6B1C24926C3F19BFFA1CA960E8] - [25/02/2012 02:26:30] - |A| - (.-.) - [12] - (0.0.0.0) - C:\WINDOWS\CSUP.txt [30/10/2015 11:24:24] - |D| - [8970858] - C:\WINDOWS\Cursors [30/10/2015 11:24:24] - |D| - [654722] - C:\WINDOWS\debug [30/10/2015 11:24:24] - |RD| - [20934] - C:\WINDOWS\DesktopTileResources [30/10/2015 11:24:24] - |RD| - [3032320] - C:\WINDOWS\DevicesFlow [MD5.7A88330456227BD021A5F8BC265F9E0B] - [10/06/2016 19:07:59] - |A| - (.-.) - [14259] - (0.0.0.0) - C:\WINDOWS\diagerr.xml [30/10/2015 11:24:24] - |D| - [4217368] - C:\WINDOWS\diagnostics [MD5.70757BB715401D58378CEFA1164902C8] - [10/06/2016 19:07:59] - |A| - (.-.) - [13338] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml [27/04/2016 09:12:00] - |D| - [0] - C:\WINDOWS\DigitalLocker [30/10/2015 11:24:24] - |SD| - [878945] - C:\WINDOWS\Downloaded Program Files [MD5.7052CC6C5856232CACD8154283BDEF25] - [12/06/2016 13:09:47] - |A| - (.-.) - [4118] - (0.0.0.0) - C:\WINDOWS\DPINST.LOG [MD5.37E22309F95AADBA95B2F37FC2FA9790] - [30/10/2015 11:25:57] - |A| - (.-.) - [7269] - (0.0.0.0) - C:\WINDOWS\DtcInstall.log [16/06/2012 06:57:03] - |D| - [0] - C:\WINDOWS\ehome [30/10/2015 11:24:24] - |HD| - [44568] - C:\WINDOWS\ELAMBKUP [24/02/2012 18:07:37] - |D| - [106864] - C:\WINDOWS\en [27/04/2016 09:12:00] - |D| - [0] - C:\WINDOWS\en-US [17/11/2015 00:52:13] - |D| - [190217493] - C:\WINDOWS\ERUNT [MD5.E396258CFD8F84E8F2C24930E6D88C67] - [13/07/2016 20:55:14] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4515256] - (10.0.10586.494) - C:\WINDOWS\explorer.exe [30/10/2015 11:24:24] - |RSD| - [412243371] - C:\WINDOWS\Fonts [24/02/2012 18:07:20] - |D| - [107376] - C:\WINDOWS\fr [27/04/2016 09:12:00] - |D| - [134144] - C:\WINDOWS\fr-FR [30/10/2015 11:24:24] - |D| - [25769840] - C:\WINDOWS\Globalization [30/10/2015 11:24:24] - |D| - [92423363] - C:\WINDOWS\Help [MD5.430DE1635CE173440D34ABA1676113D7] - [13/07/2016 20:53:37] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [994816] - (10.0.10586.494) - C:\WINDOWS\HelpPane.exe [15/06/2012 22:20:20] - |D| - [7277612] - C:\WINDOWS\Hewlett-Packard [MD5.C7228F24B9130C64DCF4C390A04A775C] - [30/10/2015 11:17:54] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.10586.0) - C:\WINDOWS\hh.exe [MD5.F23049DAF0BE26A0E61760B8F6AC74EB] - [06/09/2011 14:34:28] - |A| - (.-.) - [7736] - (0.0.0.0) - C:\WINDOWS\hpDSTRES.DLL [MD5.EF11785EAE8890650AE5EDCA6E6AD722] - [10/06/2016 19:59:33] - |A| - (.-.) - [22279] - (0.0.0.0) - C:\WINDOWS\iis.log [30/10/2015 11:24:24] - |D| - [173194846] - C:\WINDOWS\IME [30/10/2015 11:24:24] - |RD| - [6840341] - C:\WINDOWS\ImmersiveControlPanel [30/10/2015 11:21:47] - |D| - [193901172] - C:\WINDOWS\INF [30/10/2015 11:24:24] - |D| - [943476491] - C:\WINDOWS\InfusedApps [30/10/2015 11:24:24] - |D| - [36258450] - C:\WINDOWS\InputMethod [30/10/2015 11:24:24] - |SHD| - [8182901882] - C:\WINDOWS\Installer [30/10/2015 11:24:24] - |D| - [89407] - C:\WINDOWS\L2Schemas [30/10/2015 11:24:24] - |D| - [275628] - C:\WINDOWS\LiveKernelReports [30/10/2015 10:31:03] - |D| - [41495473] - C:\WINDOWS\Logs [MD5.B76FB326A850CB5F345008107126A96D] - [27/04/2016 00:39:54] - |A| - (.-.) - [1342] - (0.0.0.0) - C:\WINDOWS\lsasetup.log [30/10/2015 11:24:24] - |RSD| - [27636877] - C:\WINDOWS\Media [MD5.8848CED16D446BAC9A48236CFF9E0B69] - [01/07/2016 22:21:16] - |A| - (.-.) - [563946023] - (0.0.0.0) - C:\WINDOWS\MEMORY.DMP [MD5.23AF90D2355D8C83AA4567EF1763B467] - [30/10/2015 11:17:40] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [30/10/2015 11:24:24] - |D| - [817982015] - C:\WINDOWS\Microsoft.NET [30/10/2015 11:24:24] - |D| - [2371] - C:\WINDOWS\Migration [01/07/2016 22:21:22] - |D| - [310284] - C:\WINDOWS\Minidump [30/10/2015 11:24:24] - |RD| - [470257] - C:\WINDOWS\MiracastView [30/10/2015 11:24:24] - |D| - [0] - C:\WINDOWS\ModemLogs [MD5.B9FB94A8DA62711C6955825DEFB25C5A] - [14/07/2009 06:35:42] - |A| - (.-.) - [1405] - (0.0.0.0) - C:\WINDOWS\msdfmap.ini [MD5.60336413E419C2EA5E215F1A32061E40] - [30/10/2015 11:19:28] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [244736] - (10.0.10586.0) - C:\WINDOWS\notepad.exe [27/04/2016 09:17:47] - |D| - [418530] - C:\WINDOWS\OCR [MD5.3D6C79A2099B7E8CEE90EF3031BF3DCD] - [09/12/2015 00:52:22] - |A| - (.-.) - [28] - (0.0.0.0) - C:\WINDOWS\ODBC.INI [30/10/2015 11:24:24] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [10/06/2016 22:52:22] - |DC| - [306530418] - C:\WINDOWS\Panther [30/10/2015 11:24:24] - |D| - [29253438] - C:\WINDOWS\Performance [MD5.A6A391B123EE88E434DF7943562E7B26] - [05/06/2016 18:14:45] - |A| - (.-.) - [371930] - (0.0.0.0) - C:\WINDOWS\PFRO.log [30/10/2015 11:24:24] - |D| - [1136442] - C:\WINDOWS\PLA [30/10/2015 11:24:24] - |D| - [2566565] - C:\WINDOWS\PolicyDefinitions [10/06/2016 19:54:23] - |D| - [19544167] - C:\WINDOWS\Prefetch [30/10/2015 11:24:24] - |RD| - [1963312] - C:\WINDOWS\PrintDialog [30/10/2015 11:24:24] - |D| - [1297393] - C:\WINDOWS\Provisioning [30/10/2015 11:24:24] - |RD| - [770223] - C:\WINDOWS\PurchaseDialog [MD5.D9D56AFAA121BD6B4206F7FF3DA84BBA] - [30/10/2015 11:17:48] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [320512] - (10.0.10586.0) - C:\WINDOWS\regedit.exe [30/10/2015 11:24:24] - |D| - [1095144] - C:\WINDOWS\Registration [30/10/2015 11:24:24] - |D| - [6059899] - C:\WINDOWS\rescache [30/10/2015 11:24:24] - |D| - [3730756] - C:\WINDOWS\Resources [30/10/2015 11:24:24] - |D| - [0] - C:\WINDOWS\SchCache [30/10/2015 11:24:24] - |D| - [121229] - C:\WINDOWS\schemas [30/10/2015 11:24:24] - |D| - [10033648] - C:\WINDOWS\security [27/04/2016 09:38:17] - |D| - [125800868] - C:\WINDOWS\ServiceProfiles [30/10/2015 10:28:30] - |D| - [97373246] - C:\WINDOWS\servicing [30/10/2015 11:26:37] - |D| - [42] - C:\WINDOWS\Setup [MD5.D1C9C03CF36F745ECA691E24A5164B0A] - [27/04/2016 09:40:06] - |A| - (.-.) - [27600] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [27/04/2016 09:40:06] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log [27/04/2016 09:29:00] - |D| - [281848] - C:\WINDOWS\ShellNew [27/04/2016 09:17:19] - |D| - [6828144] - C:\WINDOWS\SKB [05/09/2012 15:29:47] - |D| - [426870447] - C:\WINDOWS\SoftwareDistribution [30/10/2015 11:24:24] - |D| - [103543755] - C:\WINDOWS\Speech [30/10/2015 11:24:24] - |D| - [50814701] - C:\WINDOWS\Speech_OneCore [MD5.3BB80AF91D069F97006DCCC031164903] - [30/10/2015 11:18:09] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [128000] - (10.0.10586.0) - C:\WINDOWS\splwow64.exe [MD5.94BFCE236D6340011721470E394056E3] - [10/06/2016 19:55:51] - |A| - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [1425408] - (1.0.6418.0) - C:\WINDOWS\sttray64.exe [17/02/2014 01:31:49] - |D| - [0] - C:\WINDOWS\Sun [30/10/2015 11:24:24] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [14/07/2009 06:34:57] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [30/10/2015 10:28:30] - |D| - [5680630392] - C:\WINDOWS\System32 [30/10/2015 11:24:25] - |D| - [158572489] - C:\WINDOWS\SystemApps [30/10/2015 11:24:25] - |D| - [18175861] - C:\WINDOWS\SystemResources [30/10/2015 10:28:37] - |D| - [1489032658] - C:\WINDOWS\SysWOW64 [30/10/2015 11:24:25] - |D| - [0] - C:\WINDOWS\TAPI [14/07/2009 07:20:14] - |D| - [8004] - C:\WINDOWS\Tasks [30/10/2015 11:24:25] - |D| - [513192] - C:\WINDOWS\Temp [30/10/2015 11:24:25] - |D| - [0] - C:\WINDOWS\tracing [30/10/2015 11:24:25] - |D| - [7680] - C:\WINDOWS\twain_32 [MD5.669A44C0BCA67D8CDE111F7FBA91EE86] - [30/10/2015 11:19:30] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [60416] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [MD5.792E1D15913A5A1CA8F8640E279F8C3F] - [22/04/2002 17:50:04] - |RA| - (.Copyright © 2000 GSC Game World - Cossacks Setup Utility for Win32.) - [4284416] - (1.0.0.1) - C:\WINDOWS\uncsetup.exe [30/10/2015 11:24:25] - |D| - [12420] - C:\WINDOWS\Vss [30/10/2015 11:24:25] - |D| - [24491619] - C:\WINDOWS\Web [MD5.75BCB46627D81E7A643F0A65B350B031] - [14/07/2009 06:34:57] - |A| - (.-.) - [580] - (0.0.0.0) - C:\WINDOWS\win.ini [MD5.C844CA459F3B209329984772269B6E56] - [30/10/2015 11:18:16] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.038356387332650843BCB352BB89A101] - [05/09/2012 15:30:18] - |A| - (.-.) - [275] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.8C459D003560EA9817F7CDB29AA55382] - [30/10/2015 11:18:29] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [10240] - (10.0.10586.0) - C:\WINDOWS\winhlp32.exe [30/10/2015 10:28:30] - |D| - [6556982709] - C:\WINDOWS\WinSxS [MD5.4D620865394151B96C54752B743D6D12] - [13/05/2011 18:42:24] - |A| - (.© 2010 Microsoft Corporation. Tous droits réservés. - Écran de veille photos Windows Live.) - [302448] - (15.4.3538.513) - C:\WINDOWS\WLXPGSS.SCR [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [30/10/2015 11:18:41] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.E9C22DCE95A6E5B6C37FED42B3749E32] - [30/10/2015 11:18:14] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.10586.0) - C:\WINDOWS\write.exe [MD5.F9F4905664C5B42B49E78EFA12D1A6B6] - [24/02/2012 18:07:10] - |A| - (.-.) - [20] - (0.0.0.0) - C:\WINDOWS\øôé ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [10/09/2015 23:15:32] - C:\WINDOWS\Installer\101c8fd4.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [11/12/2015 21:57:00] - C:\WINDOWS\Installer\1049b7f3.msi : (HP Support Solutions Framework - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [13/12/2015 16:45:34] - C:\WINDOWS\Installer\1049bdff.msi : (HP Support Assistant - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [13/12/2015 16:55:01] - C:\WINDOWS\Installer\1049be05.msi : (Blank Project Template - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\115fe4dd.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\116dd68.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\1857527.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\1b28f8a.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\1c40a27a.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\1c5f33d.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [26/10/2012 10:50:24] - C:\WINDOWS\Installer\1e518399.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\1f37b07d.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [15/06/2012 22:23:06] - C:\WINDOWS\Installer\20f6f.msi : (Blank Project Template - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/12/2011 13:57:58] - C:\WINDOWS\Installer\20fa2.msi : ( - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/12/2011 19:37:26] - C:\WINDOWS\Installer\20fa8.msi : ( - ©2011 Hewlett-Packard Development Compay, L.P.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [04/02/2012 11:35:52] - C:\WINDOWS\Installer\20fae.msi : (HP Documentation - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/12/2011 19:43:00] - C:\WINDOWS\Installer\2125c.msi : (Intel(R) Trusted Connect Service Client - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [15/06/2012 22:13:52] - C:\WINDOWS\Installer\21262.msi : (Validity WBF DDK install package - Validity Sensors, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [06/12/2011 04:20:36] - C:\WINDOWS\Installer\2126f.msi : (WIDCOMM Bluetooth Profile Pack - Broadcom Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\2315c.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/02/2014 17:54:00] - C:\WINDOWS\Installer\24eafce1.msi : ([ProductName] Installer - Apple Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/02/2014 17:55:54] - C:\WINDOWS\Installer\24eafced.msi : (Apple Software Update Installer - Apple Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\29d7f0a0.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\2aba04b7.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/10/2013 19:50:14] - C:\WINDOWS\Installer\2d3e1fa9.msi : ( - © 2008-2011 Hewlett-Packard Development Compay, L.P.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [09/12/2013 15:12:42] - C:\WINDOWS\Installer\2dc46137.msi : ( - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [09/12/2013 15:12:44] - C:\WINDOWS\Installer\2dc4613e.msi : (Autodesk Material Library Base Resolution Image Library - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [11/02/2014 00:55:08] - C:\WINDOWS\Installer\2dc46146.msi : (Autodesk Content Service - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [12/02/2014 15:59:05] - C:\WINDOWS\Installer\2dc4614c.msi : (Autodesk Content Service Language Pack - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [13/02/2014 04:02:45] - C:\WINDOWS\Installer\2dc46155.msi : (AutoCAD 2015 - Autodesk, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/02/2014 07:48:23] - C:\WINDOWS\Installer\2dc4615e.msi : (AutoCAD 2015 LanguagePack - French - Autodesk, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/02/2014 07:48:21] - C:\WINDOWS\Installer\2dc46166.msi : (AutoCAD 2015 - Autodesk, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [22/01/2014 06:26:20] - C:\WINDOWS\Installer\2dc4616d.msi : (SketchUp Import - Autodesk, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/02/2014 15:38:59] - C:\WINDOWS\Installer\2dc4617c.msi : (Autodesk ReCap - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [22/01/2014 06:22:26] - C:\WINDOWS\Installer\2dc46182.msi : (This plug-in can be used with AutoCAD to simplify the process of managing apps installed from Exchange - AutoCAD Apps) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [22/01/2014 06:24:10] - C:\WINDOWS\Installer\2dc46188.msi : (A plug-in to see the apps featuerd on the Autodesk Exchange website - AutoCAD Apps) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [13/02/2014 02:36:37] - C:\WINDOWS\Installer\2dc4618e.msi : (Autodesk AutoCAD Performance Feedback Tool Version 1.2.2 - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/01/2014 21:18:36] - C:\WINDOWS\Installer\2dc46194.msi : (Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit - Autodesk) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/11/2012 21:43:51] - C:\WINDOWS\Installer\3035e268.msi : (HP 3D DriveGuard - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\330fe.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 20:15:32] - C:\WINDOWS\Installer\3417aa82.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 20:15:32] - C:\WINDOWS\Installer\385b0b8c.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 20:15:32] - C:\WINDOWS\Installer\3936d3ed.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/09/2013 16:25:19] - C:\WINDOWS\Installer\3956f6e0.msi : (Blank Project Template -) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/03/2013 21:55:02] - C:\WINDOWS\Installer\3956f714.msi : (Blank Project Template - Research In Motion Ltd.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/09/2013 16:46:50] - C:\WINDOWS\Installer\3956f778.msi : (BlackBerry Device Software Updater - Research In Motion Ltd) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/07/2015 00:16:59] - C:\WINDOWS\Installer\3a512695.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/09/2013 16:26:42] - C:\WINDOWS\Installer\401e38.msi : (OpenOffice 4.0.1 - OpenOffice) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\49506806.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\49a6a.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/06/2014 00:23:18] - C:\WINDOWS\Installer\49a6a55.msi : (Google Update Helper - Google Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\4faf0c23.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/07/2016 19:40:55] - C:\WINDOWS\Installer\529c4bd.msi : (Skype - Skype Technologies S.A.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\53a7f76f.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [17/11/2015 00:35:26] - C:\WINDOWS\Installer\5b23f90.msi : (Java SE Runtime Environment 8 Update 60 - Oracle Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [17/11/2015 00:35:22] - C:\WINDOWS\Installer\5b23f96.msi : (Java Auto Updater - Oracle Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\695f1c0.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/12/2015 00:51:05] - C:\WINDOWS\Installer\6d77598.msi : (Dropbox Update Helper - Dropbox, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\78141cab.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/07/2015 00:16:59] - C:\WINDOWS\Installer\78b7dce.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/08/2013 15:03:14] - C:\WINDOWS\Installer\7d68fbe.msi : (Blank Project Template - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\7f8d052.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [17/04/2015 21:37:51] - C:\WINDOWS\Installer\7fa79ab7.msi : (Skype - Skype Technologies S.A.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/09/2012 20:44:32] - C:\WINDOWS\Installer\7fc1ed.msi : ( - e-academy Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/12/2013 14:16:14] - C:\WINDOWS\Installer\8734e7e.msi : ( - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/12/2013 14:43:38] - C:\WINDOWS\Installer\88c501d.msi : (Build Version: 1.6.0.87 - AuthenTec, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/12/2013 14:44:42] - C:\WINDOWS\Installer\88c5fea.msi : (Build Version: 6.0.100.276 - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [30/09/2012 20:53:18] - C:\WINDOWS\Installer\938423.msi : (HP Software Framework - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\97783b18.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/02/2012 17:57:30] - C:\WINDOWS\Installer\bcf1.msi : (Evernote v. 4.5.2 - Evernote Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [13/10/2011 06:47:02] - C:\WINDOWS\Installer\bcfb.msi : ( - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/11/2011 08:42:18] - C:\WINDOWS\Installer\bd05.msi : (swMSM - Adobe Systems, Inc) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/07/2015 00:16:59] - C:\WINDOWS\Installer\bf64148.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/06/2011 03:56:12] - C:\WINDOWS\Installer\c35f.msi : (ADOBER~1.0|Adobe Reader X - Adobe Systems Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/02/2012 18:09:02] - C:\WINDOWS\Installer\c365.msi : (Blank Project Template - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/02/2012 18:09:20] - C:\WINDOWS\Installer\c36f.msi : (HP Auto - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/02/2012 18:09:33] - C:\WINDOWS\Installer\c374.msi : (Blank Project Template - InstallShield) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/02/2012 18:09:37] - C:\WINDOWS\Installer\c379.msi : (Blank Project Template - InstallShield) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/02/2012 18:09:47] - C:\WINDOWS\Installer\c382.msi : (Blank Project Template - InstallShield) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/08/2011 02:02:14] - C:\WINDOWS\Installer\c387.msi : ( - © 2008-2011 Hewlett-Packard Development Compay, L.P.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/11/2011 04:26:18] - C:\WINDOWS\Installer\c391.msi : ( - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 23:15:32] - C:\WINDOWS\Installer\c6803d7.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/09/2015 22:15:32] - C:\WINDOWS\Installer\decc089.msi : ( - Akamai Technologies, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [06/08/2014 02:07:52] - C:\WINDOWS\Installer\e6f59170.msi : (Facebook Video Calling 3.1.0.521 - Skype Limited) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [21/09/2014 15:29:24] - C:\WINDOWS\Installer\f4df5fb.msi : (Apple Application Support Installer - Apple Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [21/09/2014 15:32:08] - C:\WINDOWS\Installer\f4df665.msi : (Apple Mobile Device Support Installer - Apple Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [21/09/2014 15:42:47] - C:\WINDOWS\Installer\f4e06be.msi : (iTunes Installer - Apple Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [15/06/2012 22:13:52] - C:\WINDOWS\Installer\WBFDDK4.3.301.0.msi : (Validity WBF DDK install package - Validity Sensors, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/06/2016 17:15:10] - [79085] - C:\WINDOWS\Installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\ARPPRODUCTICON.exe () - () [14/09/2013 16:52:01] - [53248] - C:\WINDOWS\Installer\{06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [24/02/2012 18:09:04] - [53248] - C:\WINDOWS\Installer\{07FA4960-B038-49EB-891B-9F95930AA544}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/12/2013 14:16:35] - [211335] - C:\WINDOWS\Installer\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}\_853F67D554F05449430E7E.exe () - () [13/06/2015 04:08:31] - [145760] - C:\WINDOWS\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe () - () [24/02/2012 18:09:47] - [53248] - C:\WINDOWS\Installer\{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [06/06/2015 21:56:01] - [520584] - C:\WINDOWS\Installer\{31ABA3F2-0000-1033-0102-111D43815377}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe (Copyright 2014 Autodesk, Inc.) - (Autodesk component) [24/02/2012 18:09:34] - [53248] - C:\WINDOWS\Installer\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [06/06/2015 21:18:03] - [40960] - C:\WINDOWS\Installer\{427F733F-4D6C-45BC-9324-EB743104C321}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [06/06/2015 21:18:03] - [520584] - C:\WINDOWS\Installer\{427F733F-4D6C-45BC-9324-EB743104C321}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe (Copyright 2014 Autodesk, Inc.) - (Autodesk component) [19/12/2013 19:22:06] - [203574] - C:\WINDOWS\Installer\{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268}\ARPPRODUCTICON.exe () - () [19/12/2013 19:22:06] - [203574] - C:\WINDOWS\Installer\{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268}\NewShortcut2_BA1337F8EDC745D18616163C68AB0BDD.exe () - () [19/12/2013 19:22:06] - [203574] - C:\WINDOWS\Installer\{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268}\NewShortcut3_9798CA2CBAAD4F4897906E8383FD14D2.exe () - () [19/12/2013 19:22:06] - [203574] - C:\WINDOWS\Installer\{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268}\NewShortcut4_DF0B4F2AD0594E62BDA0D52E22F952C7.exe () - () [08/03/2014 15:06:21] - [145760] - C:\WINDOWS\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe () - () [14/09/2013 16:28:08] - [413696] - C:\WINDOWS\Installer\{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/09/2013 16:28:08] - [69632] - C:\WINDOWS\Installer\{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [10/10/2013 19:51:49] - [132754] - C:\WINDOWS\Installer\{53B17A98-5BF0-40BC-AAFF-850A357975AC}\_853F67D554F05449430E7E.exe () - () [06/06/2015 21:38:50] - [487424] - C:\WINDOWS\Installer\{5783F2D7-E001-0000-0102-0060B0CE6BBA}\Acad162_icon.exe () - () [06/06/2015 21:38:50] - [520584] - C:\WINDOWS\Installer\{5783F2D7-E001-0000-0102-0060B0CE6BBA}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe (Copyright 2014 Autodesk, Inc.) - (Autodesk component) [06/06/2015 21:45:23] - [487424] - C:\WINDOWS\Installer\{5783F2D7-E001-040C-1102-0060B0CE6BBA}\Acad162_icon.exe () - () [06/06/2015 21:45:23] - [520584] - C:\WINDOWS\Installer\{5783F2D7-E001-040C-1102-0060B0CE6BBA}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe (Copyright 2014 Autodesk, Inc.) - (Autodesk component) [06/06/2015 21:45:41] - [487424] - C:\WINDOWS\Installer\{5783F2D7-E001-040C-2102-0060B0CE6BBA}\Acad162_icon.exe () - () [15/06/2012 22:28:43] - [57306] - C:\WINDOWS\Installer\{5A847522-375C-4D05-BD3D-88C450CC047F}\_748CF3066D4B22D1BE1B27.exe () - () [15/06/2012 22:28:43] - [57306] - C:\WINDOWS\Installer\{5A847522-375C-4D05-BD3D-88C450CC047F}\_853F67D554F05449430E7E.exe () - () [24/02/2012 18:05:46] - [10134] - C:\WINDOWS\Installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726}\ARPPRODUCTICON.exe () - () [30/09/2012 20:53:33] - [90022] - C:\WINDOWS\Installer\{63EA6400-F30C-4C5C-8E64-6A448D1E9310}\app_1.exe () - () [15/06/2012 22:16:16] - [46284] - C:\WINDOWS\Installer\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}\ARPPRODUCTICON.exe () - () [01/02/2014 02:04:43] - [53248] - C:\WINDOWS\Installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F}\ARPPRODUCTICON.exe (Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc.) - (InstallShield) [08/03/2014 16:08:08] - [27136] - C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe () - () [13/12/2015 16:51:20] - [98304] - C:\WINDOWS\Installer\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}\ARPPRODUCTICON.exe (Copyright (c) 2014 Flexera Software LLC.) - (InstallShield) [28/08/2014 16:31:07] - [145760] - C:\WINDOWS\Installer\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\SkypeIcon.exe () - () [15/06/2012 22:27:24] - [203574] - C:\WINDOWS\Installer\{880B5A98-B242-4B53-BD6F-41EA17495EAD}\NewShortcut3_9798CA2CBAAD4F4897906E8383FD14D2.exe () - () [15/06/2012 22:27:24] - [203574] - C:\WINDOWS\Installer\{880B5A98-B242-4B53-BD6F-41EA17495EAD}\NewShortcut4_DF0B4F2AD0594E62BDA0D52E22F952C7.exe () - () [06/06/2015 21:20:24] - [520584] - C:\WINDOWS\Installer\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe (Copyright 2014 Autodesk, Inc.) - (Autodesk component) [06/06/2015 21:19:33] - [40960] - C:\WINDOWS\Installer\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [06/06/2015 21:19:33] - [520584] - C:\WINDOWS\Installer\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe (Copyright 2014 Autodesk, Inc.) - (Autodesk component) [15/06/2012 22:23:18] - [86016] - C:\WINDOWS\Installer\{AE856388-AFAD-4753-81DF-D96B19D0A17C}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [15/06/2012 22:23:18] - [94208] - C:\WINDOWS\Installer\{AE856388-AFAD-4753-81DF-D96B19D0A17C}\hpDST_D9DC8CBE9F454412B02CE9167A3B0B7E.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [15/06/2012 22:23:18] - [86016] - C:\WINDOWS\Installer\{AE856388-AFAD-4753-81DF-D96B19D0A17C}\NewShortcut5_52C60A88DCC44773893759562A87A4C1.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [15/06/2012 22:28:55] - [287038] - C:\WINDOWS\Installer\{B288E426-9954-451C-B811-B0F234CF0EDD}\NotebookDocs.exe () - () [14/09/2013 16:42:13] - [413696] - C:\WINDOWS\Installer\{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/09/2013 16:42:13] - [413696] - C:\WINDOWS\Installer\{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}\NewShortcut1_9F9ABBA94B874F449DBFBD7EB1332F16.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/09/2013 16:42:13] - [413696] - C:\WINDOWS\Installer\{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}\NewShortcut2_5B2EDCAA303A43629DACC3FFFABD0901.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/09/2013 16:42:13] - [69632] - C:\WINDOWS\Installer\{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}\NewShortcut4_838BDC75346D4F49BD1D5328F986CD86.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [13/12/2015 16:55:25] - [53248] - C:\WINDOWS\Installer\{C9EF1AAF-B542-41C8-A537-1142DA5D4AEC}\ARPPRODUCTICON.exe (Copyright (c) 2014 Flexera Software LLC.) - (InstallShield) [24/02/2012 18:09:20] - [94208] - C:\WINDOWS\Installer\{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [15/06/2012 22:27:54] - [132754] - C:\WINDOWS\Installer\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}\_545360052FE5251FC42524.exe () - () [15/06/2012 22:27:54] - [132754] - C:\WINDOWS\Installer\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}\_853F67D554F05449430E7E.exe () - () [15/06/2012 22:27:54] - [132754] - C:\WINDOWS\Installer\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}\_DB182DFA045F51D90A2FFF.exe () - () [15/06/2012 22:27:54] - [132754] - C:\WINDOWS\Installer\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}\_F0B6794B426F10CD985B4A.exe () - () [24/02/2012 18:03:54] - [66164] - C:\WINDOWS\Installer\{DBCD5E64-7379-4648-9444-8A6558DCB614}\_6FEFF9B68218417F98F549.exe () - () [24/02/2012 18:06:54] - [80395] - C:\WINDOWS\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe () - () [07/12/2012 23:45:07] - [145760] - C:\WINDOWS\Installer\{EA17F4FC-FDBF-4CF8-A529-2D983132D053}\SkypeIcon.exe () - () [24/02/2012 18:09:55] - [132754] - C:\WINDOWS\Installer\{ED1BD69A-07E3-418C-91F1-D856582581BF}\_853F67D554F05449430E7E.exe () - () [21/09/2014 15:48:14] - [380928] - C:\WINDOWS\Installer\{F46AA0F1-E284-4878-A462-5F11B9166C0E}\iTunesIco.exe () - () [24/02/2012 18:09:40] - [339968] - C:\WINDOWS\Installer\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [24/02/2012 18:10:44] - [193257] - C:\WINDOWS\Installer\{F9DF0B5D-554B-45D2-8698-7C467FAF4BCA}\_0EC656EA26E9492994C6EA.exe () - () [24/02/2012 18:10:44] - [193257] - C:\WINDOWS\Installer\{F9DF0B5D-554B-45D2-8698-7C467FAF4BCA}\_853F67D554F05449430E7E.exe () - () [08/11/2012 21:44:20] - [8598] - C:\WINDOWS\Installer\{F9E399CB-046F-45FD-A67F-CF399E2128E4}\controlPanelIcon.exe () - () [05/07/2016 19:42:27] - [145760] - C:\WINDOWS\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe () - () ---------- | %System%\*.in* [30/10/2015 11:18:41] - [3458] - C:\WINDOWS\System32\ieuinit.inf [15/06/2012 22:15:51] - [1071192] - C:\WINDOWS\System32\oem21.inf [10/06/2016 19:55:21] - [1089238] - C:\WINDOWS\System32\oem22.inf [11/04/2014 23:39:44] - [1089238] - C:\WINDOWS\System32\oem47.inf [10/06/2016 20:00:08] - [2139720] - C:\WINDOWS\System32\PerfStringBackup.INI [30/10/2015 11:18:09] - [60124] - C:\WINDOWS\System32\tcpmon.ini [30/10/2015 11:17:49] - [2269] - C:\WINDOWS\System32\WimBootCompress.ini [30/10/2015 11:19:39] - [3458] - C:\WINDOWS\Syswow64\ieuinit.inf [29/03/2013 00:19:02] - [942] - C:\WINDOWS\Syswow64\InstallUtil.InstallLog [10/06/2016 20:00:02] - [2036216] - C:\WINDOWS\Syswow64\PerfStringBackup.INI [30/10/2015 11:18:25] - [2269] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | [Administrateur] [27/04/2016 09:43:26] - |HD| - [128772901] - C:\Users\Administrateur\AppData [27/04/2016 09:43:26] - |SHD| - [158397] - C:\Users\Administrateur\Application Data [27/04/2016 09:50:35] - |RD| - [412] - C:\Users\Administrateur\Contacts [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\Cookies [27/04/2016 09:43:26] - |RD| - [282] - C:\Users\Administrateur\Desktop [27/04/2016 09:43:26] - |RD| - [1914] - C:\Users\Administrateur\Documents [27/04/2016 09:43:26] - |RD| - [282] - C:\Users\Administrateur\Downloads [27/04/2016 09:43:26] - |RD| - [690] - C:\Users\Administrateur\Favorites [27/04/2016 09:43:26] - |RD| - [2015] - C:\Users\Administrateur\Links [27/04/2016 09:43:26] - |SHD| - [128614504] - C:\Users\Administrateur\Local Settings [27/04/2016 09:43:26] - |SHD| - [45106] - C:\Users\Administrateur\Menu Démarrer [27/04/2016 09:43:26] - |SHD| - [1914] - C:\Users\Administrateur\Mes documents [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\Modèles [27/04/2016 09:43:26] - |RD| - [504] - C:\Users\Administrateur\Music [27/04/2016 09:43:26] - |ASH| - [524288] - C:\Users\Administrateur\NTUSER.DAT [27/04/2016 09:43:26] - |ASH| - [16384] - C:\Users\Administrateur\ntuser.dat.LOG1 [27/04/2016 09:43:26] - |ASH| - [185344] - C:\Users\Administrateur\ntuser.dat.LOG2 [27/04/2016 09:43:26] - |ASH| - [65536] - C:\Users\Administrateur\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TM.blf [27/04/2016 09:43:26] - |ASH| - [524288] - C:\Users\Administrateur\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TMContainer00000000000000000001.regtrans-ms [27/04/2016 09:43:26] - |ASH| - [524288] - C:\Users\Administrateur\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TMContainer00000000000000000002.regtrans-ms [27/04/2016 09:43:26] - |ASH| - [20] - C:\Users\Administrateur\ntuser.ini [27/04/2016 09:51:45] - |RD| - [105] - C:\Users\Administrateur\OneDrive [27/04/2016 09:43:26] - |RD| - [504] - C:\Users\Administrateur\Pictures [27/04/2016 09:43:26] - |SHD| - [9184] - C:\Users\Administrateur\Recent [27/04/2016 09:43:26] - |RD| - [282] - C:\Users\Administrateur\Saved Games [27/04/2016 09:50:36] - |RD| - [1872] - C:\Users\Administrateur\Searches [27/04/2016 09:43:26] - |SHD| - [5508] - C:\Users\Administrateur\SendTo [27/04/2016 09:43:26] - |RD| - [504] - C:\Users\Administrateur\Videos [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\Voisinage d'impression [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\Voisinage réseau [27/04/2016 09:45:51] - |D| - [0] - C:\Users\Administrateur\AppData\Local\ActiveSync [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\AppData\Local\Application Data [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\AppData\Local\Historique [27/04/2016 09:53:08] - |AH| - [3368] - C:\Users\Administrateur\AppData\Local\IconCache.db [27/04/2016 09:43:26] - |D| - [114026756] - C:\Users\Administrateur\AppData\Local\Microsoft [27/04/2016 09:43:33] - |D| - [3500604] - C:\Users\Administrateur\AppData\Local\Packages [27/04/2016 09:43:26] - |D| - [0] - C:\Users\Administrateur\AppData\Local\Temp [27/04/2016 09:43:26] - |SHD| - [0] - C:\Users\Administrateur\AppData\Local\Temporary Internet Files [27/04/2016 09:43:32] - |D| - [11083776] - C:\Users\Administrateur\AppData\Local\TileDataLayer [27/04/2016 09:50:35] - |ASH| - [174] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [27/04/2016 09:43:26] - |SHD| - [22466] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [27/04/2016 09:43:26] - |RD| - [22466] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [27/04/2016 09:43:26] - |RD| - [3888] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [27/04/2016 09:43:26] - |RD| - [2925] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [27/04/2016 09:50:36] - |RD| - [174] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [27/04/2016 09:50:35] - |ASH| - [174] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [27/04/2016 09:43:26] - |D| - [170] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [27/04/2016 09:51:46] - |A| - [2405] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [27/04/2016 09:50:36] - |RD| - [174] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [27/04/2016 09:43:26] - |RD| - [5318] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [27/04/2016 09:43:26] - |RSD| - [7238] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [27/04/2016 09:50:36] - |ASH| - [174] - C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Public] [27/04/2016 09:50:35] - |RHD| - [196] - C:\Users\Public\AccountPictures [14/07/2009 07:20:08] - |RHD| - [40997] - C:\Users\Public\Desktop [30/10/2015 11:24:29] - |ASH| - [174] - C:\Users\Public\desktop.ini [14/07/2009 07:20:08] - |RD| - [15768698] - C:\Users\Public\Documents [14/07/2009 07:20:08] - |RD| - [174] - C:\Users\Public\Downloads [14/07/2009 07:20:08] - |RHD| - [0] - C:\Users\Public\Favorites [30/10/2015 11:24:24] - |RHD| - [1135] - C:\Users\Public\Libraries [14/07/2009 07:20:08] - |RD| - [80538] - C:\Users\Public\Music [14/07/2009 07:20:08] - |RD| - [7791339] - C:\Users\Public\Pictures [16/06/2012 06:57:02] - |RD| - [0] - C:\Users\Public\Recorded TV [15/06/2012 22:29:39] - |D| - [29982] - C:\Users\Public\Symantec [14/07/2009 07:20:08] - |RD| - [380] - C:\Users\Public\Videos ---------- | [theo] [17/11/2015 00:22:17] - |D| - [56] - C:\Users\theo\.oracle_jre_usage [27/11/2013 20:30:36] - |A| - [20521] - C:\Users\theo\.recently-used.xbel [15/12/2015 23:36:32] - |A| - [65306] - C:\Users\theo\12348492_10153789753324313_2023332601_n.jpg [15/12/2015 23:36:24] - |A| - [71253] - C:\Users\theo\1899086_10153789753289313_1211222942_n.jpg [10/03/2014 21:21:18] - |A| - [59892] - C:\Users\theo\AfficheResultatsPrimoDemandeur-1.pdf [10/03/2014 21:21:01] - |A| - [49654] - C:\Users\theo\AfficheResultatsPrimoDemandeur.pdf [16/12/2015 18:30:43] - |A| - [86769] - C:\Users\theo\anallehydro3.jpg [16/12/2015 18:30:31] - |A| - [111211] - C:\Users\theo\annalehydo.jpg [16/12/2015 18:30:13] - |A| - [132500] - C:\Users\theo\annalehydor2014.jpg [02/04/2016 01:38:01] - |A| - [12915] - C:\Users\theo\Appartement.docx [10/06/2016 20:01:10] - |HD| - [29438351413] - C:\Users\theo\AppData [10/06/2016 20:01:10] - |SHD| - [1963454032] - C:\Users\theo\Application Data [04/01/2016 22:08:00] - |A| - [14802] - C:\Users\theo\attestation Scolaire 2016-théo.pdf [18/12/2015 21:07:57] - |A| - [54676] - C:\Users\theo\AttestationDroits.pdf [09/06/2015 21:31:33] - |A| - [14802] - C:\Users\theo\attestationScolaire.pdf [03/01/2015 13:49:14] - |A| - [234540] - C:\Users\theo\AvionLundi.pdf [08/09/2012 16:33:25] - |D| - [150813] - C:\Users\theo\Banque [14/10/2014 21:41:02] - |A| - [989] - C:\Users\theo\Banque.lnk [04/01/2015 20:37:38] - |A| - [311658] - C:\Users\theo\Billet bus.docx [06/03/2014 14:43:54] - |A| - [22815] - C:\Users\theo\Controverse.docx [29/05/2015 01:11:43] - |A| - [16212] - C:\Users\theo\Convention.docx [10/06/2016 20:01:10] - |SHD| - [3033] - C:\Users\theo\Cookies [21/09/2014 15:21:29] - |D| - [1244002676] - C:\Users\theo\Cycle Ingé [05/09/2012 15:30:32] - |RD| - [4397595174] - C:\Users\theo\Desktop [29/05/2016 12:22:47] - |A| - [334016] - C:\Users\theo\doc.pdf [29/05/2015 01:06:09] - |A| - [65041] - C:\Users\theo\Doc1.docx [10/06/2016 20:50:01] - |RD| - [282] - C:\Users\theo\Documents [10/06/2016 20:50:01] - |RD| - [282] - C:\Users\theo\Downloads [08/12/2015 00:56:13] - |RD| - [198] - C:\Users\theo\Dropbox [29/07/2014 13:04:15] - |A| - [12493] - C:\Users\theo\Europe de l_Est.xlsx [14/01/2014 17:25:34] - |D| - [1109751943] - C:\Users\theo\I don't know [21/02/2015 19:17:05] - |A| - [14583] - C:\Users\theo\Idée Bar.docx [05/11/2013 00:32:07] - |A| - [1265671] - C:\Users\theo\imagefondecran.svm [12/06/2016 13:10:41] - |SHD| - [24444] - C:\Users\theo\IntelGraphicsProfiles [06/08/2015 18:07:12] - |A| - [128844] - C:\Users\theo\le bar.png [06/08/2015 17:20:39] - |A| - [114704] - C:\Users\theo\lebar.png [10/06/2016 20:01:10] - |SHD| - [27093118473] - C:\Users\theo\Local Settings [08/12/2015 00:42:18] - |D| - [5301527056] - C:\Users\theo\logiciel [10/06/2016 20:01:10] - |SHD| - [77800] - C:\Users\theo\Menu Démarrer [10/06/2016 20:01:10] - |SHD| - [282] - C:\Users\theo\Mes documents [10/06/2016 20:01:10] - |SHD| - [0] - C:\Users\theo\Modèles [05/09/2012 15:30:32] - |RD| - [709738022] - C:\Users\theo\Music [10/06/2016 20:01:10] - |ASH| - [5242880] - C:\Users\theo\NTUSER.DAT [10/06/2016 20:01:10] - |ASH| - [819200] - C:\Users\theo\ntuser.dat.LOG1 [10/06/2016 20:01:10] - |ASH| - [524288] - C:\Users\theo\ntuser.dat.LOG2 [10/06/2016 20:01:10] - |ASH| - [65536] - C:\Users\theo\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TM.blf [10/06/2016 20:01:10] - |ASH| - [524288] - C:\Users\theo\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TMContainer00000000000000000001.regtrans-ms [10/06/2016 20:01:10] - |ASH| - [524288] - C:\Users\theo\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TMContainer00000000000000000002.regtrans-ms [10/06/2016 20:49:29] - |SH| - [20] - C:\Users\theo\ntuser.ini [10/06/2016 21:02:17] - |RD| - [95] - C:\Users\theo\OneDrive [16/11/2014 21:35:41] - |D| - [19698369] - C:\Users\theo\Papiers administratifs [08/09/2012 16:38:37] - |D| - [3848778103] - C:\Users\theo\Pas important [10/06/2016 20:02:38] - |D| - [337697240] - C:\Users\theo\Passé [05/09/2012 15:30:32] - |RD| - [4978294620] - C:\Users\theo\Pictures [09/06/2015 01:48:45] - |A| - [607655] - C:\Users\theo\Place sonus.pdf [30/10/2013 15:41:30] - |A| - [2568410] - C:\Users\theo\PrésentationGLSE.odp [10/06/2016 20:01:10] - |SHD| - [809364] - C:\Users\theo\Recent [02/12/2015 20:33:43] - |A| - [73216] - C:\Users\theo\Rendu 2.xls [21/01/2015 12:45:21] - |A| - [4410] - C:\Users\theo\RyanairBoardingPass aller.pdf [21/01/2015 12:46:01] - |A| - [227685] - C:\Users\theo\RyanairBoardingPass retour.pdf [22/04/2015 23:49:06] - |A| - [164102] - C:\Users\theo\RyanairBoardingPass-IRKCJE_CRL-EDI.pdf [22/04/2015 23:52:21] - |A| - [165351] - C:\Users\theo\RyanairBoardingPass-LKNMQZ_EDI-BZR.pdf [21/01/2015 22:10:43] - |A| - [207033] - C:\Users\theo\RyanairBoardingPassaller (1).pdf [21/01/2015 22:09:54] - |A| - [207033] - C:\Users\theo\RyanairBoardingPassaller.pdf [26/01/2013 16:54:41] - |A| - [355] - C:\Users\theo\Réseau - Raccourci.lnk [21/04/2015 21:55:55] - |A| - [100125] - C:\Users\theo\Scottish Citylink.pdf [10/06/2016 20:01:10] - |SHD| - [6496] - C:\Users\theo\SendTo [10/10/2012 23:27:03] - |ASH| - [702464] - C:\Users\theo\Thumbs.db [08/09/2012 16:33:14] - |D| - [211963] - C:\Users\theo\TI89Titanium [01/11/2015 17:35:16] - |A| - [1073680] - C:\Users\theo\Ticket-Print.pdf [01/11/2015 17:35:31] - |A| - [1073856] - C:\Users\theo\Ticket-Print1.pdf [07/06/2015 13:40:01] - |D| - [4988928] - C:\Users\theo\Tracing [21/09/2014 15:21:11] - |A| - [1196] - C:\Users\theo\Téléchargements.lnk [14/01/2014 17:35:43] - |D| - [3938081] - C:\Users\theo\Vacances [05/09/2012 15:30:32] - |RD| - [265550883675] - C:\Users\theo\Videos [10/06/2016 20:01:10] - |SHD| - [0] - C:\Users\theo\Voisinage d'impression [10/06/2016 20:01:10] - |SHD| - [0] - C:\Users\theo\Voisinage réseau [30/10/2013 15:39:30] - |AH| - [165] - C:\Users\theo\~$DiapoGLSE.pptx [23/04/2013 17:14:13] - |AH| - [162] - C:\Users\theo\~$E-synthèse.doc [11/12/2013 01:38:55] - |AH| - [162] - C:\Users\theo\~$gedeprojet.docx [12/12/2013 22:48:02] - |AH| - [162] - C:\Users\theo\~$nexeprojet.docx [06/03/2014 14:43:54] - |AH| - [162] - C:\Users\theo\~$ntroverse.docx [17/12/2013 02:10:05] - |AH| - [162] - C:\Users\theo\~$ojetmiseenpage.docx [30/10/2013 14:18:33] - |AH| - [162] - C:\Users\theo\~$ojetPolytech info et debut.docx [30/11/2013 20:10:16] - |AH| - [162] - C:\Users\theo\~$ojetpolytechpartieApplicaiton.docx [02/04/2016 01:38:05] - |AH| - [162] - C:\Users\theo\~$partement.docx [02/10/2013 18:54:03] - |AH| - [162] - C:\Users\theo\~$PORTANT.docx [12/11/2013 19:42:47] - |AH| - [162] - C:\Users\theo\~$pport de stage corrigé par moi oct 2013.doc [16/06/2013 21:59:42] - |AH| - [162] - C:\Users\theo\~$pport de stage.docx [23/04/2013 14:11:18] - |AH| - [162] - C:\Users\theo\~$tretien-conducteur de travaux.docx [21/02/2015 19:17:06] - |AH| - [162] - C:\Users\theo\~$ée Bar.docx [11/12/2013 01:38:54] - |AH| - [44467] - C:\Users\theo\~WRL3078.tmp [10/06/2016 20:52:10] - |D| - [0] - C:\Users\theo\AppData\Local\ActiveSync [08/08/2014 21:21:45] - |D| - [374846] - C:\Users\theo\AppData\Local\Adobe [08/03/2014 16:08:13] - |D| - [0] - C:\Users\theo\AppData\Local\Apple [08/03/2014 16:11:00] - |D| - [20572494] - C:\Users\theo\AppData\Local\Apple Computer [10/06/2016 20:01:10] - |SHD| - [25074727654] - C:\Users\theo\AppData\Local\Application Data [22/03/2014 15:04:16] - |D| - [230479755] - C:\Users\theo\AppData\Local\Apps [05/09/2012 15:31:29] - |D| - [2977] - C:\Users\theo\AppData\Local\AuthenTec [06/06/2015 21:45:03] - |D| - [73135716] - C:\Users\theo\AppData\Local\Autodesk [14/07/2016 13:38:26] - |D| - [0] - C:\Users\theo\AppData\Local\CEF [10/06/2016 21:21:57] - |D| - [18882580] - C:\Users\theo\AppData\Local\Comms [08/09/2012 02:46:18] - |D| - [4305588] - C:\Users\theo\AppData\Local\CrashDumps [08/12/2013 04:08:36] - |D| - [4925] - C:\Users\theo\AppData\Local\CyberLink [13/11/2013 00:01:01] - |A| - [3584] - C:\Users\theo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [10/09/2012 15:42:16] - |D| - [1308241] - C:\Users\theo\AppData\Local\Diagnostics [12/03/2016 19:41:06] - |D| - [1952] - C:\Users\theo\AppData\Local\Disc_Soft_Ltd [14/09/2013 16:46:22] - |D| - [59253760] - C:\Users\theo\AppData\Local\Downloaded Installations [08/12/2015 00:51:08] - |D| - [11732460] - C:\Users\theo\AppData\Local\Dropbox [08/09/2012 20:45:29] - |D| - [968328] - C:\Users\theo\AppData\Local\e-academy Inc [17/06/2015 20:03:22] - |D| - [0] - C:\Users\theo\AppData\Local\Edulang [20/11/2015 13:25:16] - |D| - [0] - C:\Users\theo\AppData\Local\ElevatedDiagnostics [24/11/2014 03:58:22] - |SHD| - [0] - C:\Users\theo\AppData\Local\EmieBrowserModeList [14/06/2014 21:48:29] - |SHD| - [0] - C:\Users\theo\AppData\Local\EmieSiteList [14/06/2014 21:48:29] - |SHD| - [0] - C:\Users\theo\AppData\Local\EmieUserList [19/02/2014 02:04:45] - |D| - [15843372] - C:\Users\theo\AppData\Local\Facebook [30/06/2016 20:14:19] - |D| - [364756776] - C:\Users\theo\AppData\Local\Firefox [08/09/2012 15:19:01] - |A| - [148432] - C:\Users\theo\AppData\Local\GDIPFONTCACHEV1.DAT [08/09/2012 15:07:43] - |D| - [135174029] - C:\Users\theo\AppData\Local\Google [03/06/2015 21:17:48] - |D| - [71] - C:\Users\theo\AppData\Local\GWX [05/09/2012 15:32:20] - |D| - [32495] - C:\Users\theo\AppData\Local\Hewlett-Packard [05/09/2012 15:31:46] - |D| - [2747] - C:\Users\theo\AppData\Local\Hewlett-Packard_Company [10/06/2016 20:01:10] - |SHD| - [290] - C:\Users\theo\AppData\Local\Historique [05/09/2012 16:01:27] - |D| - [2140] - C:\Users\theo\AppData\Local\HP [12/06/2016 12:54:08] - |AH| - [85730] - C:\Users\theo\AppData\Local\IconCache.db [15/02/2013 22:27:10] - |D| - [0] - C:\Users\theo\AppData\Local\Macromedia [10/06/2016 20:01:10] - |D| - [537831424] - C:\Users\theo\AppData\Local\Microsoft [06/10/2012 13:56:00] - |D| - [189544] - C:\Users\theo\AppData\Local\Microsoft Games [08/09/2012 22:06:12] - |D| - [218584] - C:\Users\theo\AppData\Local\Microsoft Help [10/06/2016 21:51:02] - |D| - [87548] - C:\Users\theo\AppData\Local\MicrosoftEdge [15/02/2013 19:59:48] - |D| - [369650360] - C:\Users\theo\AppData\Local\Mozilla [10/06/2016 20:57:15] - |D| - [0] - C:\Users\theo\AppData\Local\NetworkTiles [17/07/2016 17:34:39] - |D| - [21466454] - C:\Users\theo\AppData\Local\NVIDIA [10/06/2016 20:49:48] - |D| - [148876277] - C:\Users\theo\AppData\Local\Packages [27/10/2014 03:00:01] - |D| - [84299281] - C:\Users\theo\AppData\Local\Popcorn Time [27/10/2014 03:01:30] - |D| - [3686537] - C:\Users\theo\AppData\Local\Popcorn-Time [30/09/2013 16:31:21] - |D| - [0] - C:\Users\theo\AppData\Local\Programs [10/06/2016 20:51:35] - |D| - [0] - C:\Users\theo\AppData\Local\Publishers [05/09/2012 15:31:48] - |D| - [373] - C:\Users\theo\AppData\Local\RemEngine [14/09/2013 16:45:05] - |D| - [135279612] - C:\Users\theo\AppData\Local\Research In Motion [28/08/2014 16:31:21] - |D| - [0] - C:\Users\theo\AppData\Local\Skype [10/06/2016 20:01:10] - |D| - [121770496] - C:\Users\theo\AppData\Local\Temp [10/06/2016 20:01:10] - |SHD| - [163732426] - C:\Users\theo\AppData\Local\Temporary Internet Files [10/06/2016 20:49:43] - |D| - [12722176] - C:\Users\theo\AppData\Local\TileDataLayer [05/09/2012 15:31:09] - |D| - [0] - C:\Users\theo\AppData\Local\VirtualStore [05/09/2012 15:41:52] - |ASH| - [174] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [10/06/2016 20:01:10] - |SHD| - [38813] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [10/06/2016 20:01:10] - |RD| - [38813] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [24/11/2013 21:57:09] - |D| - [0] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor [10/06/2016 20:01:10] - |RD| - [3888] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [10/06/2016 20:01:10] - |RD| - [3976] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [05/09/2012 15:41:52] - |RD| - [174] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [06/06/2015 21:59:23] - |D| - [2242] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk [16/05/2013 17:48:23] - |D| - [4703] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks [10/06/2016 20:50:00] - |ASH| - [174] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [22/03/2014 15:06:37] - |D| - [483] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\fleex SAS [10/06/2016 20:57:35] - |A| - [1047] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fonctionnalités optionnelles.lnk [04/01/2014 21:21:26] - |D| - [438] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [22/04/2016 21:28:05] - |A| - [2062] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [10/06/2016 20:01:10] - |D| - [170] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [10/06/2016 21:02:17] - |A| - [2441] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [27/10/2014 03:01:13] - |D| - [4285] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time [05/09/2012 15:41:52] - |RD| - [174] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [10/06/2016 20:01:10] - |RD| - [5318] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [12/03/2016 19:42:35] - |D| - [0] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Test Simulator [10/06/2016 20:01:10] - |RSD| - [7238] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [05/09/2012 15:41:52] - |ASH| - [174] - C:\Users\theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [UpdatusUser] [10/06/2016 20:01:12] - |HD| - [1592629] - C:\Users\UpdatusUser\AppData [10/06/2016 20:01:12] - |SHD| - [41846] - C:\Users\UpdatusUser\Application Data [15/06/2012 22:11:49] - |D| - [0] - C:\Users\UpdatusUser\Contacts [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\Cookies [15/06/2012 22:11:47] - |RD| - [1024] - C:\Users\UpdatusUser\Desktop [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Documents [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Downloads [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Favorites [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Links [10/06/2016 20:01:12] - |SHD| - [1547369] - C:\Users\UpdatusUser\Local Settings [10/06/2016 20:01:12] - |SHD| - [38812] - C:\Users\UpdatusUser\Menu Démarrer [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\Mes documents [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\Modèles [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Music [10/06/2016 20:01:12] - |ASH| - [524288] - C:\Users\UpdatusUser\NTUSER.DAT [10/06/2016 20:01:12] - |ASH| - [147456] - C:\Users\UpdatusUser\ntuser.dat.LOG1 [10/06/2016 20:01:12] - |ASH| - [65536] - C:\Users\UpdatusUser\ntuser.dat.LOG2 [10/06/2016 20:01:12] - |ASH| - [65536] - C:\Users\UpdatusUser\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TM.blf [10/06/2016 20:01:12] - |ASH| - [524288] - C:\Users\UpdatusUser\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TMContainer00000000000000000001.regtrans-ms [10/06/2016 20:01:12] - |ASH| - [524288] - C:\Users\UpdatusUser\NTUSER.DAT{404b0371-0bf7-11e6-9eee-c7f85b4f6d8d}.TMContainer00000000000000000002.regtrans-ms [10/06/2016 20:24:10] - |SH| - [20] - C:\Users\UpdatusUser\ntuser.ini [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Pictures [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\Recent [15/06/2012 22:11:47] - |D| - [0] - C:\Users\UpdatusUser\Saved Games [15/06/2012 22:11:49] - |D| - [0] - C:\Users\UpdatusUser\Searches [10/06/2016 20:01:12] - |SHD| - [1684] - C:\Users\UpdatusUser\SendTo [15/06/2012 22:11:47] - |RD| - [0] - C:\Users\UpdatusUser\Videos [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\Voisinage d'impression [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\Voisinage réseau [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\AppData\Local\Application Data [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\AppData\Local\Historique [10/06/2016 20:01:12] - |D| - [1547369] - C:\Users\UpdatusUser\AppData\Local\Microsoft [10/06/2016 20:01:12] - |D| - [0] - C:\Users\UpdatusUser\AppData\Local\Temp [10/06/2016 20:01:12] - |SHD| - [0] - C:\Users\UpdatusUser\AppData\Local\Temporary Internet Files [10/06/2016 20:01:12] - |SHD| - [19406] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [10/06/2016 20:01:12] - |D| - [19406] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [10/06/2016 20:01:12] - |RD| - [3888] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [10/06/2016 20:01:12] - |RD| - [2792] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [10/06/2016 20:01:12] - |D| - [170] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [10/06/2016 20:01:12] - |RD| - [5318] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [10/06/2016 20:01:12] - |RSD| - [7238] - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | C:\ProgramData [24/02/2012 18:08:17] - |D| - [487836655] - C:\ProgramData\Adobe [08/03/2014 16:06:30] - |D| - [94412443] - C:\ProgramData\Apple [08/03/2014 16:09:47] - |D| - [72514422] - C:\ProgramData\Apple Computer [10/06/2016 20:29:59] - |SHD| - [101340704962] - C:\ProgramData\Application Data [06/06/2015 20:41:05] - |AD| - [508918373] - C:\ProgramData\Autodesk [08/09/2012 15:06:46] - |D| - [321038397] - C:\ProgramData\AVAST Software [05/09/2012 15:30:21] - |SHD| - [40997] - C:\ProgramData\Bureau [15/09/2012 19:08:58] - |HD| - [19096543] - C:\ProgramData\CanonBJ [30/10/2015 11:24:24] - |D| - [0] - C:\ProgramData\Comms [08/12/2013 04:09:10] - |D| - [41795] - C:\ProgramData\CyberLink [12/03/2016 19:21:37] - |D| - [3120] - C:\ProgramData\DAEMON Tools Lite [11/09/2014 20:37:29] - |D| - [1880003] - C:\ProgramData\DatacardService [10/06/2016 20:29:59] - |SHD| - [15768698] - C:\ProgramData\Documents [15/06/2012 22:26:51] - |D| - [121016532] - C:\ProgramData\Downloaded Installations [08/12/2015 00:51:08] - |D| - [553250] - C:\ProgramData\Dropbox [09/12/2013 22:11:47] - |D| - [1421884] - C:\ProgramData\Easybits Magic Desktop for HP [01/02/2013 23:27:56] - |D| - [4910563] - C:\ProgramData\EPSON [05/09/2012 15:30:21] - |SHD| - [0] - C:\ProgramData\Favoris [07/06/2015 14:01:26] - |D| - [44950] - C:\ProgramData\FLEXnet [24/02/2012 18:05:58] - |AD| - [216129832] - C:\ProgramData\Hewlett-Packard [19/12/2013 14:43:39] - |D| - [412] - C:\ProgramData\HP SimplePass 2011 [15/06/2012 22:08:54] - |D| - [276223] - C:\ProgramData\Intel [15/11/2015 20:41:07] - |D| - [19280177] - C:\ProgramData\Malwarebytes [05/09/2012 15:30:21] - |SHD| - [586370] - C:\ProgramData\Menu Démarrer [18/01/2013 18:02:24] - |D| - [2174976] - C:\ProgramData\MGTEK [30/10/2015 11:24:24] - |SD| - [2153568961] - C:\ProgramData\Microsoft [08/09/2012 22:05:53] - |D| - [34684] - C:\ProgramData\Microsoft Help [27/04/2016 09:50:56] - |D| - [0] - C:\ProgramData\Microsoft OneDrive [02/12/2015 17:59:47] - |A| - [153] - C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc [05/09/2012 15:30:21] - |SHD| - [31386] - C:\ProgramData\Modèles [15/02/2013 19:58:23] - |D| - [231] - C:\ProgramData\Mozilla [15/06/2012 22:26:21] - |D| - [15285] - C:\ProgramData\Norton [15/06/2012 22:25:43] - |D| - [36295928] - C:\ProgramData\NortonInstaller [15/04/2016 18:39:33] - |RASH| - [290] - C:\ProgramData\ntuser.pol [17/07/2016 17:32:43] - |D| - [83192361] - C:\ProgramData\NVIDIA [15/06/2012 22:11:14] - |D| - [3287755] - C:\ProgramData\NVIDIA Corporation [13/02/2014 18:20:07] - |D| - [70997662] - C:\ProgramData\Oracle [06/06/2015 20:45:20] - |D| - [14559178] - C:\ProgramData\Package Cache [28/08/2013 19:01:58] - |D| - [32641505] - C:\ProgramData\PopCap Games [30/10/2015 11:24:24] - |D| - [1000] - C:\ProgramData\regid.1991-06.com.microsoft [14/09/2013 16:42:02] - |D| - [63421] - C:\ProgramData\Research In Motion [24/02/2012 18:05:55] - |D| - [244445872] - C:\ProgramData\Skype [30/10/2015 11:24:24] - |D| - [0] - C:\ProgramData\SoftwareDistribution [15/06/2012 22:36:04] - |D| - [3756] - C:\ProgramData\Synaptics [15/06/2012 22:23:47] - |D| - [90183] - C:\ProgramData\Temp [05/09/2012 16:39:47] - |D| - [74220] - C:\ProgramData\TrueSuite [12/03/2016 19:43:05] - |A| - [4096] - C:\ProgramData\T_Simulator.db [30/10/2015 11:24:24] - |D| - [2262] - C:\ProgramData\USOPrivate [27/04/2016 09:44:18] - |D| - [1810432] - C:\ProgramData\USOShared [24/02/2012 18:00:00] - |D| - [4219064800] - C:\ProgramData\WildTangent [01/02/2014 02:01:46] - |D| - [45529590] - C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F} ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [30/10/2015 11:24:28] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [05/09/2012 15:30:21] - |SHD| - [293098] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [30/10/2015 11:24:24] - |RD| - [293098] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [24/11/2013 21:57:09] - |D| - [3985] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor [30/10/2015 11:24:24] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [30/10/2015 11:24:24] - |RD| - [16904] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [30/10/2015 11:24:24] - |RD| - [20488] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [24/02/2012 18:08:36] - |A| - [2441] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [08/03/2014 16:08:08] - |A| - [2519] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [06/06/2015 21:18:04] - |D| - [25210] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk [14/07/2016 13:34:14] - |A| - [1082] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk [14/09/2013 16:28:08] - |D| - [3536] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry [16/05/2013 17:48:24] - |D| - [1109] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks [24/02/2012 18:05:58] - |RD| - [6053] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat [15/05/2016 16:41:42] - |D| - [5798] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cossacks - European Wars [12/03/2016 19:22:04] - |D| - [903] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite [30/10/2015 11:24:28] - |ASH| - [1140] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [30/10/2015 11:18:13] - |RAS| - [853] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk [09/12/2014 01:28:55] - |D| - [1191] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DetMinero v1.2 Clé de Détermination des Minéraux au microscope polarisant [30/10/2015 11:19:28] - |RAS| - [2197] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk [12/07/2016 19:40:27] - |D| - [1312] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox [04/02/2016 07:06:36] - |D| - [3335] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Alarm Clock [14/07/2009 09:32:38] - |RD| - [38498] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [16/06/2015 21:51:55] - |D| - [1867] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gedit [14/06/2014 22:08:31] - |D| - [1367] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [24/04/2016 22:39:37] - |A| - [948] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [19/12/2013 19:22:06] - |D| - [1910] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP [24/02/2012 18:11:15] - |RD| - [7812] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support [30/10/2015 11:19:28] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [21/09/2014 15:48:14] - |D| - [3906] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [17/11/2015 00:35:51] - |D| - [6728] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [30/10/2015 11:24:24] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [15/11/2015 20:41:11] - |D| - [5226] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware [02/12/2015 18:10:37] - |D| - [50191] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [18/03/2013 16:48:44] - |D| - [2338] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [30/10/2015 11:17:57] - |RAS| - [2219] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk [23/05/2016 20:50:39] - |A| - [1104] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [05/09/2012 15:31:53] - |RD| - [4567] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos [30/10/2013 15:06:33] - |SD| - [6254] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1 [30/10/2015 11:19:28] - |RAS| - [2199] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk [24/02/2012 17:57:34] - |RD| - [2606] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools [04/01/2014 21:10:34] - |D| - [2926] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SCi Games [30/10/2015 11:18:07] - |RAS| - [1588] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk [24/02/2012 18:03:54] - |RD| - [6547] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection [02/12/2015 18:53:46] - |D| - [3055] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint [05/09/2012 15:31:53] - |RD| - [2289] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services [07/04/2016 13:25:10] - |D| - [2097] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [30/10/2015 11:24:24] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [17/11/2015 00:47:40] - |A| - [1889] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk [30/10/2015 11:24:24] - |RD| - [4033] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [27/04/2016 09:29:00] - |RHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC [12/03/2016 19:42:35] - |D| - [3106] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Test Simulator [09/09/2012 20:15:31] - |D| - [6750] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [24/02/2012 18:07:22] - |RD| - [4580] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live [24/02/2012 18:07:02] - |A| - [1458] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk [24/02/2012 18:06:54] - |A| - [2486] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk [24/02/2012 18:07:16] - |A| - [1305] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk [24/02/2012 18:07:12] - |A| - [1374] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk [10/06/2016 20:13:38] - |A| - [1576] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [15/04/2016 16:40:40] - |D| - [1936] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [30/10/2015 11:24:28] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | C:\Program Files (x86) [16/06/2016 18:10:53] - |D| - [0] - C:\Program Files (x86)\9eq3e1l5 [24/11/2013 21:54:51] - |AD| - [28542654] - C:\Program Files (x86)\AbiWord [24/02/2012 18:08:12] - |D| - [478056058] - C:\Program Files (x86)\Adobe [08/03/2014 16:08:06] - |AD| - [2428606] - C:\Program Files (x86)\Apple Software Update [29/06/2016 22:27:37] - |D| - [0] - C:\Program Files (x86)\asyjf01s [06/06/2015 21:20:02] - |D| - [145463935] - C:\Program Files (x86)\Autodesk [08/03/2014 16:07:05] - |AD| - [631113] - C:\Program Files (x86)\Bonjour [16/05/2013 17:48:21] - |D| - [247489619] - C:\Program Files (x86)\CodeBlocks [30/10/2015 10:28:30] - |D| - [1103751221] - C:\Program Files (x86)\Common Files [05/06/2016 17:13:31] - |D| - [225149522] - C:\Program Files (x86)\CyberLink [30/10/2015 11:24:28] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [08/12/2015 00:51:08] - |D| - [252199409] - C:\Program Files (x86)\Dropbox [15/06/2012 22:22:35] - |AD| - [114640613] - C:\Program Files (x86)\EasyBits For Kids [24/02/2012 17:57:32] - |D| - [178870257] - C:\Program Files (x86)\Evernote [30/06/2016 20:13:55] - |AD| - [181872486] - C:\Program Files (x86)\Firefox [22/07/2016 18:20:38] - |D| - [0] - C:\Program Files (x86)\Firefox_temp [04/02/2016 07:06:33] - |AD| - [5435282] - C:\Program Files (x86)\FreeAlarmClock [06/11/2013 13:31:24] - |AD| - [89325506] - C:\Program Files (x86)\gedit [08/09/2012 15:07:43] - |D| - [311506676] - C:\Program Files (x86)\Google [24/02/2012 17:54:07] - |AD| - [463767475] - C:\Program Files (x86)\Hewlett-Packard [24/02/2012 18:00:04] - |AD| - [967789576] - C:\Program Files (x86)\HP Games [19/12/2013 14:47:07] - |AD| - [96948909] - C:\Program Files (x86)\HP SimplePass [24/02/2012 18:11:18] - |HD| - [35595640] - C:\Program Files (x86)\InstallShield Installation Information [15/06/2012 22:08:19] - |D| - [147825264] - C:\Program Files (x86)\Intel [30/10/2015 11:24:24] - |D| - [2156014] - C:\Program Files (x86)\Internet Explorer [21/09/2014 15:47:43] - |AD| - [198560466] - C:\Program Files (x86)\iTunes [17/11/2015 00:35:33] - |D| - [164104922] - C:\Program Files (x86)\Java [15/11/2015 20:41:07] - |AD| - [59533516] - C:\Program Files (x86)\Malwarebytes Anti-Malware [15/06/2012 22:29:08] - |D| - [0] - C:\Program Files (x86)\Microsoft [02/12/2015 18:08:43] - |D| - [39769547] - C:\Program Files (x86)\Microsoft Analysis Services [24/02/2012 18:04:49] - |D| - [46707764] - C:\Program Files (x86)\Microsoft Office [18/03/2013 16:47:14] - |AD| - [42886030] - C:\Program Files (x86)\Microsoft Silverlight [24/02/2012 18:07:10] - |AD| - [1829877] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition [02/12/2015 18:49:39] - |AD| - [1909559] - C:\Program Files (x86)\Microsoft Visual Studio 8 [30/10/2015 11:24:24] - |D| - [8175999] - C:\Program Files (x86)\Microsoft.NET [10/05/2014 12:12:58] - |AD| - [97135445] - C:\Program Files (x86)\Mozilla Firefox [23/05/2016 20:50:33] - |D| - [236993] - C:\Program Files (x86)\Mozilla Maintenance Service [10/06/2016 22:36:53] - |AD| - [26521] - C:\Program Files (x86)\MSBuild [15/06/2012 22:11:12] - |D| - [7175872] - C:\Program Files (x86)\NVIDIA Corporation [24/02/2012 17:57:45] - |RD| - [22169126] - C:\Program Files (x86)\Online Services [30/10/2013 15:04:37] - |AD| - [332641952] - C:\Program Files (x86)\OpenOffice 4 [06/05/2016 20:01:35] - |D| - [15174182] - C:\Program Files (x86)\Parametres SFR 3G [15/04/2016 16:39:01] - |D| - [0] - C:\Program Files (x86)\QQBrowser [29/06/2016 20:26:46] - |D| - [0] - C:\Program Files (x86)\r0jgkjer [15/06/2012 22:12:42] - |D| - [17410003] - C:\Program Files (x86)\Realtek [10/06/2016 22:36:53] - |D| - [38450433] - C:\Program Files (x86)\Reference Assemblies [14/09/2013 16:27:55] - |D| - [65677457] - C:\Program Files (x86)\Research In Motion [04/01/2014 21:10:24] - |D| - [1660448249] - C:\Program Files (x86)\SCi Games [28/08/2014 16:31:06] - |RD| - [87229745] - C:\Program Files (x86)\Skype [17/11/2015 00:47:38] - |AD| - [11100584] - C:\Program Files (x86)\SumatraPDF [15/06/2012 22:29:39] - |D| - [762296] - C:\Program Files (x86)\SymSilent [16/06/2016 18:11:07] - |D| - [3617620] - C:\Program Files (x86)\TData [12/03/2016 19:42:02] - |D| - [125115770] - C:\Program Files (x86)\Test Simulator [03/06/2016 17:38:08] - |D| - [3134150] - C:\Program Files (x86)\TXQQBrowser [14/07/2009 08:57:06] - |HD| - [0] - C:\Program Files (x86)\Uninstall Information [09/09/2012 20:15:11] - |D| - [97663883] - C:\Program Files (x86)\VideoLAN [30/05/2016 20:40:45] - |D| - [14671760] - C:\Program Files (x86)\Wi-Fi Modem [24/02/2012 18:00:01] - |D| - [9660011] - C:\Program Files (x86)\WildTangent Games [30/10/2015 11:24:24] - |D| - [1465856] - C:\Program Files (x86)\Windows Defender [24/02/2012 18:06:43] - |AD| - [185046778] - C:\Program Files (x86)\Windows Live [30/10/2015 11:24:24] - |D| - [5961728] - C:\Program Files (x86)\Windows Mail [30/10/2015 11:24:24] - |D| - [3342927] - C:\Program Files (x86)\Windows Media Player [30/10/2015 11:24:24] - |D| - [220064] - C:\Program Files (x86)\Windows Multimedia Platform [30/10/2015 11:24:24] - |D| - [7575610] - C:\Program Files (x86)\Windows NT [30/10/2015 11:24:24] - |D| - [5484224] - C:\Program Files (x86)\Windows Photo Viewer [30/10/2015 11:24:24] - |D| - [220064] - C:\Program Files (x86)\Windows Portable Devices [30/10/2015 11:24:24] - |SHD| - [0] - C:\Program Files (x86)\Windows Sidebar [30/10/2015 11:24:24] - |SD| - [2685232] - C:\Program Files (x86)\WindowsPowerShell [16/11/2015 00:46:44] - |AD| - [7233255] - C:\Program Files (x86)\ZHPFix ---------- | C:\Program Files [06/06/2015 21:32:09] - |D| - [2177293095] - C:\Program Files\Autodesk [08/09/2012 15:06:46] - |D| - [1302034179] - C:\Program Files\AVAST Software [08/03/2014 16:07:05] - |AD| - [613967] - C:\Program Files\Bonjour [15/06/2012 22:15:31] - |D| - [14494963] - C:\Program Files\Broadcom [30/10/2015 10:28:30] - |D| - [525009102] - C:\Program Files\Common Files [12/03/2016 19:22:00] - |D| - [36356551] - C:\Program Files\DAEMON Tools Lite [30/10/2015 11:24:28] - |ASH| - [174] - C:\Program Files\desktop.ini [14/07/2009 09:32:38] - |D| - [0] - C:\Program Files\DVD Maker [05/09/2012 15:30:21] - |SHD| - [525009102] - C:\Program Files\Fichiers communs [08/09/2012 15:10:07] - |D| - [0] - C:\Program Files\Google [13/10/2011 04:57:12] - |AD| - [12403764] - C:\Program Files\Hewlett-Packard [10/06/2016 19:55:28] - |AD| - [84596346] - C:\Program Files\IDT [15/06/2012 22:08:52] - |D| - [37808639] - C:\Program Files\Intel [30/10/2015 11:24:24] - |D| - [2777305] - C:\Program Files\Internet Explorer [21/09/2014 15:47:43] - |D| - [2324203] - C:\Program Files\iPod [21/09/2014 15:47:43] - |D| - [3008688] - C:\Program Files\iTunes [02/12/2015 18:08:43] - |D| - [66182747] - C:\Program Files\Microsoft Analysis Services [14/07/2009 09:32:38] - |D| - [2680] - C:\Program Files\Microsoft Games [02/12/2015 18:07:01] - |AD| - [1483457069] - C:\Program Files\Microsoft Office [18/03/2013 16:47:15] - |AD| - [55717262] - C:\Program Files\Microsoft Silverlight [02/12/2015 18:51:38] - |D| - [2966976] - C:\Program Files\Microsoft SQL Server Compact Edition [02/12/2015 18:51:38] - |D| - [1014647] - C:\Program Files\Microsoft Sync Framework [02/12/2015 18:52:12] - |D| - [326800] - C:\Program Files\Microsoft Synchronization Services [10/06/2016 22:36:53] - |D| - [25757] - C:\Program Files\MSBuild [15/06/2012 22:10:43] - |D| - [502241807] - C:\Program Files\NVIDIA Corporation [24/02/2012 18:09:26] - |RD| - [600788] - C:\Program Files\Online Services [28/08/2013 19:01:12] - |D| - [32498961] - C:\Program Files\Plants vs. Zombies [10/06/2016 22:36:53] - |D| - [36850857] - C:\Program Files\Reference Assemblies [10/06/2016 19:56:59] - |D| - [152555558] - C:\Program Files\Synaptics [27/04/2016 09:43:31] - |HD| - [0] - C:\Program Files\Uninstall Information [15/06/2012 22:14:16] - |AD| - [24986650] - C:\Program Files\Validity Sensors [15/06/2012 22:16:07] - |D| - [229931962] - C:\Program Files\WIDCOMM [30/10/2015 11:24:24] - |D| - [11400666] - C:\Program Files\Windows Defender [27/04/2016 09:29:00] - |D| - [8974456] - C:\Program Files\Windows Journal [24/02/2012 18:06:34] - |D| - [7916031] - C:\Program Files\Windows Live [30/10/2015 11:24:24] - |D| - [6322176] - C:\Program Files\Windows Mail [30/10/2015 11:24:24] - |D| - [5394547] - C:\Program Files\Windows Media Player [30/10/2015 11:24:24] - |D| - [258280] - C:\Program Files\Windows Multimedia Platform [30/10/2015 11:24:24] - |D| - [7862330] - C:\Program Files\Windows NT [30/10/2015 11:24:24] - |D| - [6381248] - C:\Program Files\Windows Photo Viewer [30/10/2015 11:24:24] - |D| - [258280] - C:\Program Files\Windows Portable Devices [30/10/2015 11:24:24] - |SHD| - [14257] - C:\Program Files\Windows Sidebar [30/10/2015 11:24:24] - |HD| - [1199157227] - C:\Program Files\WindowsApps [30/10/2015 11:24:24] - |SD| - [2856133] - C:\Program Files\WindowsPowerShell ---------- | C:\Program Files (x86)\Common Files [24/02/2012 18:08:12] - |AD| - [19305826] - C:\Program Files (x86)\Common Files\Adobe [08/03/2014 16:06:30] - |D| - [128520206] - C:\Program Files (x86)\Common Files\Apple [19/12/2013 14:44:07] - |AD| - [7435840] - C:\Program Files (x86)\Common Files\AuthenTec [06/06/2015 21:17:43] - |AD| - [243204021] - C:\Program Files (x86)\Common Files\Autodesk Shared [03/12/2015 21:10:46] - |D| - [1545889] - C:\Program Files (x86)\Common Files\AV [04/01/2014 21:08:37] - |D| - [1155061] - C:\Program Files (x86)\Common Files\InstallShield [15/06/2012 22:10:10] - |D| - [121765362] - C:\Program Files (x86)\Common Files\Intel [15/06/2012 22:24:11] - |D| - [10997] - C:\Program Files (x86)\Common Files\Intel Corporation [17/11/2015 00:36:36] - |D| - [1957520] - C:\Program Files (x86)\Common Files\Java [30/10/2015 11:24:24] - |AD| - [134274235] - C:\Program Files (x86)\Common Files\Microsoft Shared [15/06/2012 22:08:36] - |D| - [193516] - C:\Program Files (x86)\Common Files\postureAgent [14/09/2013 16:27:55] - |AD| - [51029850] - C:\Program Files (x86)\Common Files\Research In Motion [30/10/2015 11:24:24] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [07/04/2016 13:25:10] - |AD| - [2399872] - C:\Program Files (x86)\Common Files\Skype [10/06/2016 20:05:10] - |D| - [41095079] - C:\Program Files (x86)\Common Files\SpeechEngines [08/09/2012 16:40:17] - |D| - [0] - C:\Program Files (x86)\Common Files\Symantec Shared [30/10/2015 11:24:24] - |D| - [10246283] - C:\Program Files (x86)\Common Files\System [24/02/2012 18:06:08] - |D| - [291457372] - C:\Program Files (x86)\Common Files\Windows Live [14/09/2013 16:41:29] - |D| - [48151590] - C:\Program Files (x86)\Common Files\XCPCSync.OEM ---------- | C:\Program Files\Common files [08/03/2014 16:07:32] - |D| - [8228510] - C:\Program Files\Common files\Apple [19/12/2013 14:44:06] - |AD| - [8936960] - C:\Program Files\Common files\AuthenTec [06/06/2015 21:32:10] - |AD| - [196236599] - C:\Program Files\Common files\Autodesk Shared [29/07/2015 19:21:02] - |D| - [1545889] - C:\Program Files\Common files\AV [05/12/2015 01:51:35] - |AD| - [99992] - C:\Program Files\Common files\DESIGNER [01/02/2013 23:27:59] - |D| - [136576] - C:\Program Files\Common files\EPSON [15/06/2012 22:10:10] - |D| - [16903686] - C:\Program Files\Common files\Intel [06/06/2015 21:39:44] - |D| - [1357387] - C:\Program Files\Common files\Macrovision Shared [30/10/2015 11:24:24] - |AD| - [279859894] - C:\Program Files\Common files\microsoft shared [30/10/2015 11:24:24] - |D| - [2702] - C:\Program Files\Common files\Services [10/06/2016 20:05:01] - |D| - [599040] - C:\Program Files\Common files\SpeechEngines [30/10/2015 11:24:24] - |D| - [11101867] - C:\Program Files\Common files\System ---------- | Tasks [MD5.AD150BA061C6DF5F08CEFDB549119941] - [24/02/2012 17:57:15] - |A| - [1002] - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [MD5.BB968A17B4C4A1FBB686BFBC8E313561] - [08/12/2015 00:52:10] - |A| - [1178] - C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job [MD5.3FE8381C7073BF8995C9504B3A41F40D] - [08/12/2015 00:52:15] - |A| - [1182] - C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job [MD5.825AED2B5127BABBDE5EB259E33421DE] - [19/02/2014 02:04:52] - |A| - [902] - C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2532391380-2442022221-794288624-1001Core.job [MD5.E5F1C4054E79113D67C419E12F563BA0] - [19/02/2014 02:04:54] - |A| - [924] - C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2532391380-2442022221-794288624-1001UA.job [MD5.C02648EA9150DA61A63FD608F77494F0] - [08/09/2012 15:07:48] - |A| - [1060] - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [MD5.C95490BA9B7691E59F2D4965189FC039] - [08/09/2012 15:07:49] - |A| - [1064] - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [MD5.CFE0BD407DC43ECF672DCDEAF3993C70] - [02/11/2012 17:18:46] - |A| - [342] - C:\WINDOWS\Tasks\HPCeeScheduleForTHEO-HP$.job [MD5.61CED2F9459EF19292C6D0F4EAF380B3] - [26/05/2016 21:19:02] - |A| - [344] - C:\WINDOWS\Tasks\HPCeeScheduleFortheo.job [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [27/04/2016 09:43:15] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.F8B5E20524D0B920F11B7EB23D9DC37D] - [24/02/2012 17:57:15] - |A| - [3976] - C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater : C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.00000000000000000000000000000000] - [08/03/2014 16:08:14] - |D| - [3538] - C:\WINDOWS\System32\Tasks\Apple [MD5.00000000000000000000000000000000] - [29/07/2015 19:21:18] - |D| - [0] - C:\WINDOWS\System32\Tasks\AVAST Software [MD5.4067DE4F215E8D49B38B287CBAE30EBF] - [08/09/2012 15:07:22] - |A| - [4278] - C:\WINDOWS\System32\Tasks\avast! Emergency Update : C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [MD5.77BA685F3DD16197C2BAD2616317D2BA] - [08/12/2015 00:52:10] - |A| - [4036] - C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore : C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [MD5.ADAD04F9417D50DEC918137657B77A45] - [08/12/2015 00:52:15] - |A| - [4288] - C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA : C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [MD5.50354B3D4D2F548E11194C3C4C216700] - [19/02/2014 02:04:52] - |A| - [3640] - C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2532391380-2442022221-794288624-1001Core : C:\Users\theo\AppData\Local\Facebook\Update\FacebookUpdate.exe [MD5.7BA4E718B3BD3C05393FD2457E7EA3E2] - [19/02/2014 02:04:54] - |A| - [4008] - C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2532391380-2442022221-794288624-1001UA : C:\Users\theo\AppData\Local\Facebook\Update\FacebookUpdate.exe [MD5.ADE45F72D2E06F6F5EAC4D491CC33260] - [08/09/2012 15:07:48] - |A| - [3918] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.C1E6B31D03E2691A9A5EB7AB4D690FF5] - [08/09/2012 15:07:49] - |A| - [4170] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.00000000000000000000000000000000] - [24/02/2012 18:11:26] - |D| - [21574] - C:\WINDOWS\System32\Tasks\Hewlett-Packard [MD5.E65977CCA94961A68717D9699A28170B] - [26/05/2016 21:19:06] - |A| - [3232] - C:\WINDOWS\System32\Tasks\HPCeeScheduleFortheo : C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [MD5.6407985B31FC7B1ABA81C89333DECD3D] - [02/11/2012 17:18:47] - |A| - [3244] - C:\WINDOWS\System32\Tasks\HPCeeScheduleForTHEO-HP$ : C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [MD5.00000000000000000000000000000000] - [30/10/2015 11:24:25] - |D| - [551216] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.98B293F4DF448A63AF155E6CDCCCE443] - [05/06/2016 17:16:56] - |A| - [3272] - C:\WINDOWS\System32\Tasks\MirageAgent : C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [MD5.00000000000000000000000000000000] - [08/09/2012 22:08:17] - |D| - [4502] - C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform [MD5.FBE36FCC56E801D095ADB46EE5C51F63] - [14/07/2016 13:34:19] - |A| - [4030] - C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1468488844 : C:\Program Files\AVAST Software\SZBrowser\launcher.exe [MD5.1A7739E180037461F05B75F483C1878E] - [05/09/2012 15:42:00] - |A| - [4158] - C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3B621811-7C55-46B6-BA18-4BAECB3973F8} : C:\Windows\system32\msfeedssync.exe [MD5.00000000000000000000000000000000] - [14/07/2009 09:09:57] - |D| - [4472] - C:\WINDOWS\System32\Tasks\WPD [MD5.C8712E0701F9B1EB208E3AE10518E0BD] - [17/06/2015 20:04:04] - |A| - [3330] - C:\WINDOWS\System32\Tasks\{469B39D9-AEBC-47DC-A037-35709BA21D2B} : C:\Windows\system32\pcalua.exe [MD5.2752D197F3C3064A9779F85ED67BC63D] - [15/05/2016 17:20:26] - |A| - [3188] - C:\WINDOWS\System32\Tasks\{B4BEFF7D-A282-4744-AC1A-D6E48DA9D0B6} : C:\Windows\system32\pcalua.exe [MD5.D32F3838CE8A2AB95CE9CC823A325538] - [09/06/2014 21:17:45] - |A| - [3114] - C:\WINDOWS\System32\Tasks\{DC7830B9-5945-494B-9F20-D970F114D1A9} : C:\Program Files (x86)\Mozilla Firefox\firefox.exe [MD5.00000000000000000000000000000000] - [30/10/2015 11:24:25] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "vm-monitoring-dcom"=v2.0|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=135|App=%SystemRoot%\system32\svchost.exe|Svc=RpcSs|Name=@icsvc.dll,-709|Desc=@icsvc.dll,-710|EmbedCtxt=@icsvc.dll,-700| "vm-monitoring-icmpv4"=v2.0|Action=Allow|Active=FALSE|Dir=In|Protocol=1|Name=@icsvc.dll,-701|Desc=@icsvc.dll,-702|EmbedCtxt=@icsvc.dll,-700| "vm-monitoring-icmpv6"=v2.0|Action=Allow|Active=FALSE|Dir=In|Protocol=58|Name=@icsvc.dll,-703|Desc=@icsvc.dll,-704|EmbedCtxt=@icsvc.dll,-700| "vm-monitoring-nb-session"=v2.0|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=139|Name=@icsvc.dll,-705|Desc=@icsvc.dll,-706|EmbedCtxt=@icsvc.dll,-700| "vm-monitoring-rpc"=v2.0|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\system32\svchost.exe|Svc=Schedule|Name=@icsvc.dll,-707|Desc=@icsvc.dll,-708|EmbedCtxt=@icsvc.dll,-700| "Wininit-Shutdown-In-Rule-TCP-RPC"=v2.25|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36753|Desc=@firewallapi.dll,-36754|EmbedCtxt=@firewallapi.dll,-36751| "Wininit-Shutdown-In-Rule-TCP-RPC-EPMapper"=v2.25|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC-EPMap|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36755|Desc=@firewallapi.dll,-36756|EmbedCtxt=@firewallapi.dll,-36751| "DeliveryOptimization-TCP-In"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "DeliveryOptimization-UDP-In"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "Netlogon-NamedPipe-In"=v2.25|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "Netlogon-TCP-RPC-In"=v2.25|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010| "WirelessDisplay-In-TCP"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-UDP"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "MDNS-In-UDP"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort2_24=mDNS|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37303|Desc=@%SystemRoot%\system32\firewallapi.dll,-37304|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302| "MDNS-Out-UDP"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|LPort=5353|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37305|Desc=@%SystemRoot%\system32\firewallapi.dll,-37306|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302| "{629348E5-CDC8-4292-A55A-DAD5C073A069}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Desc=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-1910091885-1573563583-1104941280-2418270861-3411158377-2822700936-2990310272|EmbedCtxt=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{5A07F8F0-955F-41D3-B41C-79D22E3819EE}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Desc=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-1910091885-1573563583-1104941280-2418270861-3411158377-2822700936-2990310272|EmbedCtxt=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{19E2A71E-EBEF-4CBA-B436-D5DAEFA86D2A}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Desc=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-2434737943-167758768-3180539153-984336765-1107280622-3591121930-2677285773|EmbedCtxt=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Platform=2:6:2|Platform2=GTEQ| "{4EB9BBDD-83BC-417B-B3B5-4D359A2B3C6A}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Desc=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-2434737943-167758768-3180539153-984336765-1107280622-3591121930-2677285773|EmbedCtxt=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Platform=2:6:2|Platform2=GTEQ| "{6DF546D6-13B7-49E3-905D-4085106A6941}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Desc=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/ProductDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742|EmbedCtxt=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{B8E0DBED-B67B-48FA-9B6A-EF831417E300}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Desc=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/ProductDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742|EmbedCtxt=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{69A97E02-59FD-4B31-8CE4-1F782FFD8BD1}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.AccountsControl_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.AccountsControl/Resources/DisplayName}|Desc=@{Microsoft.AccountsControl_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.AccountsControl/Resources/DisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-969871995-3242822759-583047763-1618006129-3578262429-3647035748-2471858633|EmbedCtxt=@{Microsoft.AccountsControl_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.AccountsControl/Resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{C11F23A4-E612-4A92-B0CB-EF189E94F9BE}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}|Desc=@{Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-2758101530-1321080646-1475665648-4066602542-2880396197-3643791541-2654759312|EmbedCtxt=@{Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{450BE8AE-0C01-44D7-AD1B-861F5E647148}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Desc=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194|EmbedCtxt=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Platform=2:6:2|Platform2=GTEQ| "{DB1064A4-2825-4B1C-B215-7E08C38DC2F6}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Desc=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194|EmbedCtxt=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Platform=2:6:2|Platform2=GTEQ| "{09B000D0-7580-4EC2-A155-E59399F5D0AF}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.ContentDeliveryManager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ContentDeliveryManager/resources/AppDisplayName}|Desc=@{Microsoft.Windows.ContentDeliveryManager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ContentDeliveryManager/resources/AppDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723|EmbedCtxt=@{Microsoft.Windows.ContentDeliveryManager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ContentDeliveryManager/resources/AppDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{31261360-34F0-41C6-98D6-30332DCF692A}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Desc=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795|EmbedCtxt=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{E750CCAC-6146-4D54-BCCA-0E162E42B966}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Desc=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795|EmbedCtxt=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{731CB1ED-9F8D-400A-80AB-FA5ADF8A74CF}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.ParentalControls_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ParentalControls/resources/DisplayName}|Desc=@{Microsoft.Windows.ParentalControls_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ParentalControls/resources/DisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-3072599432-1607568789-957273504-856596282-71567818-1546726304-1084662928|EmbedCtxt=@{Microsoft.Windows.ParentalControls_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ParentalControls/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{A269953B-88E2-4968-9B2E-C9B4DA28D2B7}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.WindowsFeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.WindowsFeedback/FeedbackApp.Resources/AppName/Text}|Desc=@{Microsoft.WindowsFeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.WindowsFeedback/FeedbackApp.Resources/AppName/Text}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-1322174799-1054373777-2441082058-564842223-2721992343-4124100487-3261661085|EmbedCtxt=@{Microsoft.WindowsFeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.WindowsFeedback/FeedbackApp.Resources/AppName/Text}|Platform=2:6:2|Platform2=GTEQ| "{26FC50B4-CB17-44C8-93F7-8F1C6E63C5BD}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.XboxGameCallableUI_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxGameCallableUI/resources/PkgDisplayName}|Desc=@{Microsoft.XboxGameCallableUI_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxGameCallableUI/resources/PkgDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-957941444-2271171641-4049211970-804197638-2225746618-2474488012-4131196493|EmbedCtxt=@{Microsoft.XboxGameCallableUI_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxGameCallableUI/resources/PkgDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{1EA5358A-1A66-456F-A605-7381197C5572}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.XboxIdentityProvider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxIdentityProvider/Resources/PkgDisplayName}|Desc=@{Microsoft.XboxIdentityProvider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxIdentityProvider/Resources/PkgDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-3833609522-3861047620-3675164185-1739081557-594447883-3111017752-456581032|EmbedCtxt=@{Microsoft.XboxIdentityProvider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxIdentityProvider/Resources/PkgDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{DD42B476-E606-4D97-BED6-1D2F7C3AD43D}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Desc=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-735366590-2037340711-2578745391-3096723288-1660081568-2625366440-3369012008|EmbedCtxt=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{8CA78F31-F83A-430E-AF55-21D92EE34BC2}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Desc=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-735366590-2037340711-2578745391-3096723288-1660081568-2625366440-3369012008|EmbedCtxt=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{86BF0ED6-88D4-470E-BC70-A8B944E9A86B}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.PurchaseDialog/resources/DisplayName}|Desc=@{Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.PurchaseDialog/resources/Description}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-3137318289-415437605-3491609480-3741388289-878520165-689859088-69748861|EmbedCtxt=@{Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.PurchaseDialog/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{D8BE1351-722D-446D-B30B-18041C5855BA}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-21-2532391380-2442022221-794288624-500|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "MSMQ-In-TCP"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=%systemroot%\system32\mqsvc.exe|Name=@mqutil.dll,-11189|Desc=@mqutil.dll,-11189|EmbedCtxt=@mqutil.dll,-6102| "MSMQ-Out-TCP"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=%systemroot%\system32\mqsvc.exe|Name=@mqutil.dll,-11190|Desc=@mqutil.dll,-11190|EmbedCtxt=@mqutil.dll,-6102| "MSMQ-In-UDP"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=%systemroot%\system32\mqsvc.exe|Name=@mqutil.dll,-11191|Desc=@mqutil.dll,-11191|EmbedCtxt=@mqutil.dll,-6102| "MSMQ-Out-UDP"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=%systemroot%\system32\mqsvc.exe|Name=@mqutil.dll,-11192|Desc=@mqutil.dll,-11192|EmbedCtxt=@mqutil.dll,-6102| "IIS-WebServerRole-HTTP-In-TCP"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=80|App=System|Name=@%windir%\system32\inetsrv\iisres.dll,-30500|Desc=@%windir%\system32\inetsrv\iisres.dll,-30510|EmbedCtxt=@%windir%\system32\inetsrv\iisres.dll,-30501| "IIS-WebServerRole-HTTPS-In-TCP"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=443|App=System|Name=@%windir%\system32\inetsrv\iisres.dll,-30502|Desc=@%windir%\system32\inetsrv\iisres.dll,-30512|EmbedCtxt=@%windir%\system32\inetsrv\iisres.dll,-30503| "WCF-NetTcpActivator-In-TCP-64bit"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=808|Svc=NetTcpActivator|Name=@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll,-2000|Desc=@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll,-2001|EmbedCtxt=@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll,-2002| "{9A0C5F70-00A4-477C-8DD0-E30510E32195}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Mozilla Firefox\firefox.exe|Name=Firefox (C:\Program Files (x86)\Mozilla Firefox)| "{190CD925-AF13-461F-9BE5-19EC4ED8F388}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Mozilla Firefox\firefox.exe|Name=Firefox (C:\Program Files (x86)\Mozilla Firefox)| "{DF145258-FC76-49B9-BAD3-0C8FE68C9DCA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IHeeaWA\IHeeaWA\bin\IHeeaWA_server.exe|Name=Chrome Server|Desc=Chrome Server| "{82DC124A-8709-408C-A6F0-DB3BA828A270}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IHeeaWA\IHeeaWA\chrome.exe|Name=Chrome Browser|Desc=Chrome Browser| "UDP Query User{41331512-2B83-483B-9502-378A0EB88F71}C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe|Name=cacaoweb.exe|Desc=cacaoweb.exe| "TCP Query User{AE7B917B-FA7A-47BC-A7FD-8B8727E9FD8E}C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe|Name=cacaoweb.exe|Desc=cacaoweb.exe| "{3A97623D-AE3B-4F09-A36F-31CCECFCD4A5}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe|Name=HP Device Detection| "UDP Query User{F6C4FD70-94BE-4548-AC24-379270A0D6AD}C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe|Name=cacaoweb.exe|Desc=cacaoweb.exe|Defer=User| "TCP Query User{3FD6B5D1-EF99-4D91-88EA-4675EECC3E51}C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\theo\appdata\roaming\cacaoweb\cacaoweb.exe|Name=cacaoweb.exe|Desc=cacaoweb.exe|Defer=User| "UDP Query User{7AD88EAD-C127-4968-9798-EB1FBE8E96DF}C:\users\theo\appdata\local\akamai\netsession_win.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\theo\appdata\local\akamai\netsession_win.exe|Name=netsession_win.exe|Desc=netsession_win.exe| "TCP Query User{E2237DA4-51E3-4166-82BA-5F13B9D2FF79}C:\users\theo\appdata\local\akamai\netsession_win.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\theo\appdata\local\akamai\netsession_win.exe|Name=netsession_win.exe|Desc=netsession_win.exe| "{BB5F5424-0F10-4BC9-8E89-BD01F736BE7C}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Domain|Profile=Private|LPort=50248|Name=Autodesk Content Service| "UDP Query User{21D26D19-6860-478F-B0FC-5348B80F81F5}C:\users\theo\appdata\local\akamai\netsession_win.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\theo\appdata\local\akamai\netsession_win.exe|Name=netsession_win.exe|Desc=netsession_win.exe|Defer=User| "TCP Query User{FEDE5200-AED8-4F14-ACB3-45955F743FF1}C:\users\theo\appdata\local\akamai\netsession_win.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\theo\appdata\local\akamai\netsession_win.exe|Name=netsession_win.exe|Desc=netsession_win.exe|Defer=User| "UDP Query User{5E072ABF-13CC-40B7-9316-565323B5C9E8}C:\users\theo\appdata\local\popcorn time\node-webkit\popcorn time.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\theo\appdata\local\popcorn time\node-webkit\popcorn time.exe|Name=popcorn time.exe|Desc=popcorn time.exe|Defer=User| "TCP Query User{75805983-C06B-4875-ADAE-09FE9018C569}C:\users\theo\appdata\local\popcorn time\node-webkit\popcorn time.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\theo\appdata\local\popcorn time\node-webkit\popcorn time.exe|Name=popcorn time.exe|Desc=popcorn time.exe|Defer=User| "{F2F10788-82EF-4A78-8595-35E7072D3EE9}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\theo\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe|Name=Facebook Video Calling Plugin|Edge=TRUE| "{CA873711-7E0F-4BF4-94ED-3BE1458BEABE}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Bonjour\mDNSResponder.exe|Name=Service Bonjour| "{FC5D9FCB-593D-434A-811C-709470F56758}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Bonjour\mDNSResponder.exe|Name=Service Bonjour| "{843E6CF6-D6E5-4861-89B1-1B98958F6D87}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files\Bonjour\mDNSResponder.exe|Name=Service Bonjour| "{A3A52E26-6303-4985-A563-A2D7637E1ECA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files\Bonjour\mDNSResponder.exe|Name=Service Bonjour| "{4BDAB11C-2EB1-407F-A2A0-FC69E889F731}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=808|App=C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe|Svc=NetTcpActivator|Name=@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2000|Desc=@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2001|EmbedCtxt=@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2002| "{1C830A75-18DF-4FAA-8848-5E3DFE05B64F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|LPort=4482|RA4=LocalSubnet|RA6=LocalSubnet|Name=BlackBerry Desktop Software Wireless Music Sync discovery| "{A02784E6-9B26-4B66-990B-B7352C162C84}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|LPort=4482|RA4=LocalSubnet|RA6=LocalSubnet|Name=BlackBerry Desktop Software Wireless Music Sync data transfer| "{8600EEE8-6FA9-43BC-9C75-C39031BB81B0}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|LPort=4481|RA4=LocalSubnet|RA6=LocalSubnet|Name=BlackBerry Desktop Software Wireless Music Sync discovery| "{7897F46C-1B1B-4F36-A4FA-6A87BE91EC86}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|LPort=4481|RA4=LocalSubnet|RA6=LocalSubnet|Name=BlackBerry Desktop Software Wireless Music Sync data transfer| "{515665AB-3263-47E3-9C6C-178391ACDACF}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe|Name=BlackBerry Desktop Software| "{9C7AB6B2-67CD-4E7D-8797-BB6EE97D7999}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe|Name=BlackBerry Desktop Software| "{43480BF3-B68E-4C59-A0F8-0D2543F7DC22}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\EasyBits For Kids\ezDesktop.exe|Name=EasyBits Magic Desktop|Edge=TRUE|Defer=App| "{8276BB40-590D-4745-B151-C33499E133D2}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Windows\system32\ezSharedSvcHost.exe|Name=EasyBits Magic Desktop Services|Edge=TRUE|Defer=App| "{C9C25A18-D202-4F86-84B1-2F39C62DC349}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe|Name=Daemonu.exe| "{85D83084-3A6A-49DF-926C-D41FC1384086}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe|Name=Daemonu.exe| "{72A4DE87-6887-42BD-8984-4E8FAC55EEFE}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Mesh\MOE.exe|Name=Windows Live Mesh|Edge=TRUE| "{576A048B-525B-48AA-BF1F-8D0C47A3E6FC}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe|Name=Windows Live Messenger|Edge=TRUE| "{9C718DFF-6D25-4050-98F9-5CA9CA9179EC}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (SSDP)| "{B63EC7E0-A710-4037-B965-516C00F484D3}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (UPnP)| "{6494E80F-6616-460C-A408-6D4349CAF47A}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe|Name=Windows Live Communications Platform|Edge=TRUE| "{2F576477-1AEC-4426-90E6-CCFA18825EC7}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Skype\Phone\Skype.exe|Name=Skype| "{7BE6C762-A27A-4D91-B9FB-4BE14206B940}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-18|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{B94906F2-8C8D-4CC5-BAB2-2CDC746FE753}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Desc=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1910091885-1573563583-1104941280-2418270861-3411158377-2822700936-2990310272|EmbedCtxt=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{A06995D4-E9CE-4E53-8E0A-1F7D4B333391}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Desc=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1910091885-1573563583-1104941280-2418270861-3411158377-2822700936-2990310272|EmbedCtxt=@{Microsoft.AAD.BrokerPlugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{C9BE794B-532C-4037-9328-380DB11B8FCE}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Desc=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2434737943-167758768-3180539153-984336765-1107280622-3591121930-2677285773|EmbedCtxt=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Platform=2:6:2|Platform2=GTEQ| "{6F2A0826-35BC-4802-8432-54A66AAAE658}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Desc=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2434737943-167758768-3180539153-984336765-1107280622-3591121930-2677285773|EmbedCtxt=@{Microsoft.Windows.CloudExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}|Platform=2:6:2|Platform2=GTEQ| "{7C841652-A54C-4214-877B-E26EC71380C9}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Desc=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/ProductDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742|EmbedCtxt=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{DF6A6113-7E66-4C38-AB16-6068B43CE269}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Desc=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/ProductDescription}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742|EmbedCtxt=@{Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Cortana/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{FEE9CD89-BA42-4FF2-81F1-1C1A29497312}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.AccountsControl_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.AccountsControl/Resources/DisplayName}|Desc=@{Microsoft.AccountsControl_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.AccountsControl/Resources/DisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-969871995-3242822759-583047763-1618006129-3578262429-3647035748-2471858633|EmbedCtxt=@{Microsoft.AccountsControl_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.AccountsControl/Resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{F71B2F9D-9894-4B9A-A033-625E90555EB3}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}|Desc=@{Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2758101530-1321080646-1475665648-4066602542-2880396197-3643791541-2654759312|EmbedCtxt=@{Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{66F07D2F-33A3-4EBC-A481-F90BBE552595}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Desc=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194|EmbedCtxt=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Platform=2:6:2|Platform2=GTEQ| "{12EA3247-159F-4DB3-8162-4DD2AA15BBDA}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Desc=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194|EmbedCtxt=@{Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}|Platform=2:6:2|Platform2=GTEQ| "{C801D2AE-B126-48CD-8C90-EB45741CBF94}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.ContentDeliveryManager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ContentDeliveryManager/resources/AppDisplayName}|Desc=@{Microsoft.Windows.ContentDeliveryManager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ContentDeliveryManager/resources/AppDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723|EmbedCtxt=@{Microsoft.Windows.ContentDeliveryManager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ContentDeliveryManager/resources/AppDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{89E79A24-EA27-47FC-8214-44A9225004FF}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Desc=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795|EmbedCtxt=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{AEC3338E-BCC6-4938-9A1D-CDB3CDAEE397}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Desc=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795|EmbedCtxt=@{Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.FeatureOnDemand.InsiderHub/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{A3BB35EE-3EF1-42A6-9DD1-F32E816088D3}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.ParentalControls_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ParentalControls/resources/DisplayName}|Desc=@{Microsoft.Windows.ParentalControls_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ParentalControls/resources/DisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3072599432-1607568789-957273504-856596282-71567818-1546726304-1084662928|EmbedCtxt=@{Microsoft.Windows.ParentalControls_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ParentalControls/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{0A98E9E1-951E-4209-9DA2-E89D8B3A6F09}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.WindowsFeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.WindowsFeedback/FeedbackApp.Resources/AppName/Text}|Desc=@{Microsoft.WindowsFeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.WindowsFeedback/FeedbackApp.Resources/AppName/Text}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1322174799-1054373777-2441082058-564842223-2721992343-4124100487-3261661085|EmbedCtxt=@{Microsoft.WindowsFeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.WindowsFeedback/FeedbackApp.Resources/AppName/Text}|Platform=2:6:2|Platform2=GTEQ| "{09C46FEA-8077-4132-96C0-A52D271536F2}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.XboxGameCallableUI_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxGameCallableUI/resources/PkgDisplayName}|Desc=@{Microsoft.XboxGameCallableUI_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxGameCallableUI/resources/PkgDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-957941444-2271171641-4049211970-804197638-2225746618-2474488012-4131196493|EmbedCtxt=@{Microsoft.XboxGameCallableUI_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxGameCallableUI/resources/PkgDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{5E45DB15-9D34-4C5D-BF42-0EA835F88872}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.XboxIdentityProvider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxIdentityProvider/Resources/PkgDisplayName}|Desc=@{Microsoft.XboxIdentityProvider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxIdentityProvider/Resources/PkgDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3833609522-3861047620-3675164185-1739081557-594447883-3111017752-456581032|EmbedCtxt=@{Microsoft.XboxIdentityProvider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.XboxIdentityProvider/Resources/PkgDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{7FB6A6C8-630F-4922-9812-3268DFA5B9FA}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Desc=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-735366590-2037340711-2578745391-3096723288-1660081568-2625366440-3369012008|EmbedCtxt=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Platform=2:6:2|Platform2=GTEQ| "{B69011B6-F6CE-420B-A7D3-ACE2C5BDD922}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Desc=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-735366590-2037340711-2578745391-3096723288-1660081568-2625366440-3369012008|EmbedCtxt=@{Windows.ContactSupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.ContactSupport/Resources/appDisplayName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{1E4117B4-2F2D-4828-9E93-4FFCD979BB74}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.PurchaseDialog/resources/DisplayName}|Desc=@{Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.PurchaseDialog/resources/Description}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3137318289-415437605-3491609480-3741388289-878520165-689859088-69748861|EmbedCtxt=@{Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.PurchaseDialog/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{C795EB33-66A4-4384-A552-A02E28D1B602}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.Appconnector/Resources/ConnectorStubTitle}|Desc=@{Microsoft.Appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.Appconnector/Resources/ConnectorStubTitle}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3232211935-909325347-210818523-1333736584-3758124246-283266685-1557978965|EmbedCtxt=@{Microsoft.Appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.Appconnector/Resources/ConnectorStubTitle}|Platform=2:6:2|Platform2=GTEQ| "{81DFF08D-54A4-4217-94C1-B64F6AF92124}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.ConnectivityStore_1.1604.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ConnectivityStore/MSWifiResources/AppStoreName}|Desc=@{Microsoft.ConnectivityStore_1.1604.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ConnectivityStore/MSWifiResources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1485202841-4094060947-262313417-955497226-1243708313-1027065603-2694978511|EmbedCtxt=@{Microsoft.ConnectivityStore_1.1604.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ConnectivityStore/MSWifiResources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{698B132F-0DA9-4200-B1BA-7D3A53C20AA0}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.Messaging/Microsoft.Apps.Messaging.Skype/SkypeMessaging.Resources/Skype_AppStoreName}|Desc=@{Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.Messaging/Microsoft.Apps.Messaging.Skype/SkypeMessaging.Resources/Skype_AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-421345033-1710570203-969709436-2809900243-2023987463-1056701467-1672618525|EmbedCtxt=@{Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.Messaging/Microsoft.Apps.Messaging.Skype/SkypeMessaging.Resources/Skype_AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{A7E3E80D-C28E-4831-B934-2B6301314335}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.Messaging/Microsoft.Apps.Messaging.Skype/SkypeMessaging.Resources/Skype_AppStoreName}|Desc=@{Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.Messaging/Microsoft.Apps.Messaging.Skype/SkypeMessaging.Resources/Skype_AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-421345033-1710570203-969709436-2809900243-2023987463-1056701467-1672618525|EmbedCtxt=@{Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.Messaging/Microsoft.Apps.Messaging.Skype/SkypeMessaging.Resources/Skype_AppStoreName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{3714D22A-AEF6-491A-94BB-340DFB999DFB}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}|Desc=@{Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2226957697-3030467180-2301525-4248967783-2024719031-2325529081-2915787518|EmbedCtxt=@{Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{47A949D0-65A6-4872-8E23-3482F2ECE2C5}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}|Desc=@{Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2226957697-3030467180-2301525-4248967783-2024719031-2325529081-2915787518|EmbedCtxt=@{Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{BF0BFBB5-FCDD-4C1E-AB6F-40E3C5FA7100}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.CommsPhone_2.17.27003.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CommsPhone/Resources/AppStoreName}|Desc=@{Microsoft.CommsPhone_2.17.27003.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CommsPhone/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3502142457-1175083276-1468359876-1514580144-2717768582-2562788200-3268064651|EmbedCtxt=@{Microsoft.CommsPhone_2.17.27003.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CommsPhone/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{535DC7B5-15E3-4C00-B20B-930ADF07FAEB}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.CommsPhone_2.17.27003.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CommsPhone/Resources/AppStoreName}|Desc=@{Microsoft.CommsPhone_2.17.27003.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CommsPhone/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3502142457-1175083276-1468359876-1514580144-2717768582-2562788200-3268064651|EmbedCtxt=@{Microsoft.CommsPhone_2.17.27003.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CommsPhone/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{C0C02303-3260-460A-A163-5A4A91D27A43}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsStore/Resources/StoreTitle}|Desc=@{Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsStore/Resources/StoreTitle}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157|EmbedCtxt=@{Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsStore/Resources/StoreTitle}|Platform=2:6:2|Platform2=GTEQ| "{C458B357-9F00-4589-A73C-94C1889262B0}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsStore/Resources/StoreTitle}|Desc=@{Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsStore/Resources/StoreTitle}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157|EmbedCtxt=@{Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsStore/Resources/StoreTitle}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{BA60266A-2F55-4129-A21A-A05F7AB54F5F}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=WindowsDVDPlayer|Desc=@{Microsoft.WindowsDVDPlayer_3.6.13291.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsDVDPlayer/resources/IDS_DVDPLAYER_APP_DESCRIPTION}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-494306191-403223751-685396099-4274694484-3538043412-2548233107-2872311217|EmbedCtxt=WindowsDVDPlayer|Platform=2:6:2|Platform2=GTEQ| "{21F1A077-2610-4A25-B2B6-46BF45984EC6}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox|Desc=Xbox|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-4153522205-3718366397-1353898457-1332184198-1210887116-3116787857-2103916698|EmbedCtxt=Xbox|Platform=2:6:2|Platform2=GTEQ| "{9B158A1E-FFDD-49C9-A3E1-80F2ABAA2BBC}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox|Desc=Xbox|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-4153522205-3718366397-1353898457-1332184198-1210887116-3116787857-2103916698|EmbedCtxt=Xbox|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{EC7A74C0-C30D-4810-9912-95EDD0256770}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.WindowsMaps_5.1606.1670.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsMaps/Resources/AppStoreName}|Desc=@{Microsoft.WindowsMaps_5.1606.1670.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsMaps/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1239072475-3687740317-1842961305-3395936705-4023953123-1525404051-2779347315|EmbedCtxt=@{Microsoft.WindowsMaps_5.1606.1670.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsMaps/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{057F07A0-8610-4356-BCA4-8832E63C74E8}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Candy Crush Soda Saga|Desc=Candy Crush Soda Saga|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3055884410-2067824683-223899546-422323478-2359388318-2114876276-1379654078|EmbedCtxt=Candy Crush Soda Saga|Platform=2:6:2|Platform2=GTEQ| "{ACD4CA85-5DE9-40D0-801C-F3E287489171}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.WindowsPhone_10.1605.1661.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsPhone/Resources/AppStoreName}|Desc=@{Microsoft.WindowsPhone_10.1605.1661.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsPhone/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1227535392-783678415-19788749-859698564-2515149781-2716591593-3518111838|EmbedCtxt=@{Microsoft.WindowsPhone_10.1605.1661.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsPhone/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{A1555824-F3AD-4827-9D1C-22DAADE4E694}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.Getstarted_3.11.1.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Getstarted/Resources/AppStoreName}|Desc=@{Microsoft.Getstarted_3.11.1.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Getstarted/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1930852602-715273891-2259524165-1460409268-4224052142-2029744616-1797406285|EmbedCtxt=@{Microsoft.Getstarted_3.11.1.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Getstarted/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{A80137C5-6CBA-412B-A1EC-D72343F79773}C:\Users\theo\Pas important\Downloads\QuickDiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\theo\Pas important\Downloads\QuickDiag.exe|Name=QuickDiag|Desc=QuickDiag|Defer=User| "UDP Query User{8086F52E-78FA-489A-B2C4-2168ADE624EB}C:\Users\theo\Pas important\Downloads\QuickDiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\theo\Pas important\Downloads\QuickDiag.exe|Name=QuickDiag|Desc=QuickDiag|Defer=User| "TCP Query User{ADC4ADA4-5BDB-4192-B368-B105DEB5600A}C:\users\theo\pas important\downloads\quickdiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\theo\pas important\downloads\quickdiag.exe|Name=quickdiag.exe|Desc=quickdiag.exe|Defer=User| "UDP Query User{6A6E5B8C-C23F-4555-8457-98DB2E548EEA}C:\users\theo\pas important\downloads\quickdiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\theo\pas important\downloads\quickdiag.exe|Name=quickdiag.exe|Desc=quickdiag.exe|Defer=User| "TCP Query User{A80137C5-6CBA-412B-A1EC-D72343F79773}C:\Users\theo\Desktop\QuickDiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\theo\Desktop\QuickDiag.exe|Name=QuickDiag|Desc=QuickDiag|Defer=User| "UDP Query User{8086F52E-78FA-489A-B2C4-2168ADE624EB}C:\Users\theo\Desktop\QuickDiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\theo\Desktop\QuickDiag.exe|Name=QuickDiag|Desc=QuickDiag|Defer=User| "TCP Query User{C154E343-A28C-4A15-BD10-EA992DD5C4AC}C:\users\theo\desktop\quickdiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\theo\desktop\quickdiag.exe|Name=quickdiag.exe|Desc=quickdiag.exe|Defer=User| "UDP Query User{F0B995FD-F8BF-4BB1-BB80-B2412525FC91}C:\users\theo\desktop\quickdiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\theo\desktop\quickdiag.exe|Name=quickdiag.exe|Desc=quickdiag.exe|Defer=User| "{13E71A7C-2D73-46BA-81D6-039E6FA2CC85}"=v2.25|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe|Name=Update service| "TCP Query User{A8064AE8-6CBA-412B-A1EC-D72343F79773}C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|LPort=19844|App=C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe|Name=AdsFix|Desc=AdsFix|Enable=yes|Defer=User| "UDP Query User{8012CD5F-78FA-489A-B2C4-2168ADE624EB}C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=19844|App=C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe|Name=AdsFix|Desc=AdsFix|Enable=yes|Defer=User| "{0D15B902-7265-429D-8C6F-C7B8DEDBC59F}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingNews/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingNews/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257|EmbedCtxt=@{Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingNews/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{CDFB9C9C-2EC9-462D-9E1A-A1D00967C402}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingNews/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingNews/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257|EmbedCtxt=@{Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingNews/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{0B6929ED-5968-465C-A52C-B89FC6B01C5A}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.BingFinance_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingFinance/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingFinance_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingFinance/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3492598633-4112760462-2134878185-2430567730-3345539238-3072415288-217264472|EmbedCtxt=@{Microsoft.BingFinance_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingFinance/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{FE5222D7-531F-4DD9-B48C-BDC76722FA44}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.BingFinance_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingFinance/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingFinance_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingFinance/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3492598633-4112760462-2134878185-2430567730-3345539238-3072415288-217264472|EmbedCtxt=@{Microsoft.BingFinance_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingFinance/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{202E9876-9CCB-4E9D-8EB6-99537C538134}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.BingSports_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingSports/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingSports_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingSports/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1457613951-1028716704-1089715812-858319886-3420779130-1191463368-1428868892|EmbedCtxt=@{Microsoft.BingSports_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingSports/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{B9377579-7845-4043-93E1-1C44C142EA22}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.BingSports_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingSports/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingSports_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingSports/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1457613951-1028716704-1089715812-858319886-3420779130-1191463368-1428868892|EmbedCtxt=@{Microsoft.BingSports_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingSports/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{DC63ECBC-38ED-4E92-A7D8-F49410DE2D99}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.BingWeather_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingWeather_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2040986369-264322980-3882385089-1970153872-3662121739-3363227934-2464603330|EmbedCtxt=@{Microsoft.BingWeather_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{03E8439C-FB61-4239-81C6-77D8BB4830C9}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.BingWeather_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}|Desc=@{Microsoft.BingWeather_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2040986369-264322980-3882385089-1970153872-3662121739-3363227934-2464603330|EmbedCtxt=@{Microsoft.BingWeather_4.11.156.0_x86__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}|Platform=2:6:2|Platform2=GTEQ| "{D582A488-9F45-4039-84C1-98874987C3FF}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Sway|Desc=Microsoft Sway|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-584073948-3292409011-2882754242-2237763630-1999038865-1049037702-4080706152|EmbedCtxt=Sway|Platform=2:6:2|Platform2=GTEQ| "{2559B2E0-D9EB-4B5A-B250-E2DE56CD4454}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Sway|Desc=Microsoft Sway|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-584073948-3292409011-2882754242-2237763630-1999038865-1049037702-4080706152|EmbedCtxt=Sway|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{C9BA6775-10B9-4015-833D-81AC5BE69B38}"=v2.25|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe|Name=Dropbox| "{4EDD8ABB-D80B-4F2A-87C9-BFDF29F422E1}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Twitter|Desc=Twitter|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1063257880-1914585122-1954150059-946145533-116938067-416079064-1690466945|EmbedCtxt=Twitter|Platform=2:6:2|Platform2=GTEQ| "{E486A3FB-81A3-4A35-BB8E-83DD6562483A}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{DD5096CD-9A10-4EAF-A031-87BE5A3FC52F}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{413F3F3D-462E-44DD-B1EE-09C0B6165847}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/resources/IDS_MANIFEST_MUSIC_APP_NAME}|Desc=@{Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/resources/IDS_MANIFEST_MUSIC_APP_DESCRIPTION}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3132517012-1571311091-3263739450-2968124769-4061529133-2106415361-233808003|EmbedCtxt=@{Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/resources/IDS_MANIFEST_MUSIC_APP_NAME}|Platform=2:6:2|Platform2=GTEQ| "{3AA5B442-07A0-4335-96D5-B26863749B39}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/resources/IDS_MANIFEST_MUSIC_APP_NAME}|Desc=@{Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/resources/IDS_MANIFEST_MUSIC_APP_DESCRIPTION}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3132517012-1571311091-3263739450-2968124769-4061529133-2106415361-233808003|EmbedCtxt=@{Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/resources/IDS_MANIFEST_MUSIC_APP_NAME}|Platform=2:6:2|Platform2=GTEQ| "{01364DB7-E5E0-44B4-93FD-E635F880C010}"=v2.25|Action=Allow|Active=TRUE|Dir=In|App=C:\ProgramData\IHeeaWA\protect\protect.exe|Name=Protect Service| "{ADF70B15-E414-4A1B-9001-B3102F614EBD}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.ZuneVideo_3.6.22501.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_NAME}|Desc=@{Microsoft.ZuneVideo_3.6.22501.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_DESCRIPTION}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2967553933-3217682302-2494645345-2077017737-3805576244-585965800-1797614741|EmbedCtxt=@{Microsoft.ZuneVideo_3.6.22501.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_NAME}|Platform=2:6:2|Platform2=GTEQ| "{F57658BB-8FF6-4224-9B6F-53CE95481592}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{Microsoft.ZuneVideo_3.6.22501.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_NAME}|Desc=@{Microsoft.ZuneVideo_3.6.22501.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_DESCRIPTION}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2967553933-3217682302-2494645345-2077017737-3805576244-585965800-1797614741|EmbedCtxt=@{Microsoft.ZuneVideo_3.6.22501.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_NAME}|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{A8064AE8-6CBA-412B-A1EC-D72343F79773}C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|LPort=19844|App=C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe|Name=AdsFix|Desc=AdsFix|Enable=yes|Defer=User| "UDP Query User{8012CD5F-78FA-489A-B2C4-2168ADE624EB}C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=19844|App=C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe|Name=AdsFix|Desc=AdsFix|Enable=yes|Defer=User| "{30EBF06C-127B-4AD4-9D30-03B80586F378}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{9C873D7A-0F08-48D1-9F92-CD4878897C02}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{AC383AE9-2860-4B74-B476-67A9A9E51687}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.3DBuilder_11.1.9.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.3DBuilder/resources/AppStoreName}|Desc=@{Microsoft.3DBuilder_11.1.9.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.3DBuilder/resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3995430443-3719053022-3339397951-2895237338-2437516106-1575886070-2755610054|EmbedCtxt=@{Microsoft.3DBuilder_11.1.9.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.3DBuilder/resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| "{1CF03152-EF4F-4A44-8220-B6E3CF3BFD52}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/AppManifest_OutlookDesktop_DisplayName}|Desc=@{microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/AppManifest_OutlookDesktop_Description}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433|EmbedCtxt=@{microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/AppManifest_OutlookDesktop_DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{83B70AA4-73EE-4C53-90EA-CB66E197FCD8}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/AppManifest_OutlookDesktop_DisplayName}|Desc=@{microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/AppManifest_OutlookDesktop_Description}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433|EmbedCtxt=@{microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/AppManifest_OutlookDesktop_DisplayName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{79FFBFAF-E171-491C-87CC-691026028210}"=v2.25|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Firefox\bin\FirefoxCommand.exe|Name=Command service| "{F5D70C1B-24F6-4A0B-B9A0-8AE34318674D}"=v2.25|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Firefox\firefox.exe|Name=Firefox browser| "{308F574D-BFB9-4649-A58C-32F25D49632B}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.People/Resources/AppStoreName}|Desc=@{Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.People/Resources/AppStoreName}|LUOwn=S-1-5-21-2532391380-2442022221-794288624-1001|AppPkgId=S-1-15-2-3981118486-977731610-4260702232-2292029000-2544493239-2660358776-1526570402|EmbedCtxt=@{Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.People/Resources/AppStoreName}|Platform=2:6:2|Platform2=GTEQ| [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\standardprofile\authorizedapplications\list] "C:\Users\theo\Pas important\Downloads\QuickDiag.exe"=C:\Users\theo\Pas important\Downloads\QuickDiag.exe:*:Enabled:QuickDiag "C:\Users\theo\Desktop\QuickDiag.exe"=C:\Users\theo\Desktop\QuickDiag.exe:*:Enabled:QuickDiag "C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe"=C:\Users\theo\Desktop\adsfix_3_30.06.2016.2.exe:*:Enabled:adsfix_3_30.06.2016.2 "C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe"=C:\Users\theo\Desktop\adsfix_3_16.07.2016.1.exe:*:Enabled:adsfix_3_16.07.2016.1 ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{03F52937-1FD6-44FB-82C6-FE988F1B1D61}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{04A83FC2-2AE2-4C88-B45F-E9707B377636}] : (aswHwid) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{17fdd8f0-53df-406f-8287-8c38f6fc9bcc}] : (RIMUSBBB) [] -> BlackBerry [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{24619924-aa9e-486f-99f9-847a5986b6be}] : (Biometric) [] -> @oem20.inf,%ClassName%;Biometric Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{24A0C840-2C3D-4410-8236-8B40816C7B90}] : (aswVmm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (Security Accelerator) [] -> @c_sslaccel.inf,%ClassName%;Security Accelerator [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @%SystemRoot%\system32\McxDriv.dll,-100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4532C9EB-FEF9-43AC-83DA-D5DE1F9A2BFF}] : (nvpciflt) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @%SystemRoot%\System32\StorProp.dll,-17000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @%SystemRoot%\System32\DispCI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (fdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (hdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{522119B9-1B9A-498A-AC52-148B533EFD50}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{59F44B03-CCD2-460B-ACD8-53CBF375D174}] : (GEARAspiWDM) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @%SystemRoot%\System32\SysClass.Dll,-3007 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{81C87465-DE07-4EFC-9D93-61E891D52FD2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87C077B2-3D3B-4156-938A-EA51B451D6C6}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8AE85550-832C-4A9B-81BB-2A49DBEE72B4}] : (aswRvrt) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9d6d66a6-0b0c-4563-9077-a0e9a7955ae4}] : (Ramdisk) [] -> @ramdisk.inf,%ClassName%;RAM Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A73C93F1-9727-4D1D-ACE1-0E333BA4E7DB}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{B95B836B-234E-4857-A1F8-D0D9A9BEC1C5}] : (vmbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{C4A06E97-ED42-47B9-83E1-F12299B286A5}] : (aswRdr) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{FB58BE68-EA9E-4803-847F-2CE814E7B159}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [// ::] - (0.0.0.0) - ( -) - C:\WINDOWS\System32\drivers\whaqqb.sys [24/09/2012 16:40:56] - (4.2.9.1) - (Hewlett-Packard Company - HP Disk Filter - SATA/RAID) - C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [23/07/2015 04:02:12] - (10.18.13.5362) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 353.62) - C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [23/07/2015 04:02:12] - (10.18.13.5362) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 353.62) - C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [14/10/2011 08:37:44] - (19.0.12.98) - (Synaptics Incorporated - Synaptics Touchpad Win64 Driver) - C:\WINDOWS\system32\DRIVERS\SynTP.sys [08/03/2014 16:10:43] - (2.2.3.0) - (GEAR Software Inc. - CD DVD Filter) - C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [11/06/2016 12:55:08] - (19.0.12.98) - (Synaptics Incorporated - Synaptics SMBus Driver) - C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [24/09/2012 16:40:56] - (4.2.9.1) - (Hewlett-Packard Company - HP Accelerometer) - C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [12/03/2016 19:24:06] - (3.4.0.0) - (Disc Soft Ltd - DAEMON Tools Lite Virtual USB Bus Driver) - C:\WINDOWS\System32\drivers\dtliteusbbus.sys [06/05/2016 20:01:38] - (2.6.2.3143) - (Huawei Technologies Co., Ltd. - ew_jubusenum Driver) - C:\WINDOWS\System32\drivers\ew_jubusenum.sys [12/03/2016 19:22:11] - (5.28.0.0) - (Disc Soft Ltd - DAEMON Tools Lite Virtual SCSI Bus Driver) - C:\WINDOWS\System32\drivers\dtlitescsibus.sys [14/09/2013 16:42:54] - (2.3.0.11) - (Research in Motion Ltd - RIM Virtual Serial Driver) - C:\WINDOWS\system32\DRIVERS\RimSerial_AMD64.sys [10/10/2013 19:44:54] - (6.10.6418.0) - (IDT, Inc. - IDT PC Audio) - C:\WINDOWS\system32\DRIVERS\stwrt64.sys ---------- | LoadOrderGroup Name: System Reserved - DriverEnabled: True - GroupOrder: 1 - Status: OK Name: EMS - DriverEnabled: True - GroupOrder: 2 - Status: OK Name: WdfLoadGroup - DriverEnabled: True - GroupOrder: 3 - Status: OK Name: Boot Bus Extender - DriverEnabled: True - GroupOrder: 4 - Status: OK Name: System Bus Extender - DriverEnabled: True - GroupOrder: 5 - Status: OK Name: SCSI miniport - DriverEnabled: True - GroupOrder: 6 - Status: OK Name: Port - DriverEnabled: True - GroupOrder: 7 - Status: OK Name: Primary Disk - DriverEnabled: True - GroupOrder: 8 - Status: OK Name: SCSI Class - DriverEnabled: True - GroupOrder: 9 - Status: OK Name: SCSI CDROM Class - DriverEnabled: True - GroupOrder: 10 - Status: OK Name: FSFilter Infrastructure - DriverEnabled: True - GroupOrder: 11 - Status: OK Name: FSFilter System - DriverEnabled: True - GroupOrder: 12 - Status: OK Name: FSFilter Bottom - DriverEnabled: True - GroupOrder: 13 - Status: OK Name: FSFilter Copy Protection - DriverEnabled: True - GroupOrder: 14 - Status: OK Name: FSFilter Security Enhancer - DriverEnabled: True - GroupOrder: 15 - Status: OK Name: FSFilter Open File - DriverEnabled: True - GroupOrder: 16 - Status: OK Name: FSFilter Physical Quota Management - DriverEnabled: True - GroupOrder: 17 - Status: OK Name: FSFilter Virtualization - DriverEnabled: True - GroupOrder: 18 - Status: OK Name: FSFilter Encryption - DriverEnabled: True - GroupOrder: 19 - Status: OK Name: FSFilter Compression - DriverEnabled: True - GroupOrder: 20 - Status: OK Name: FSFilter Imaging - DriverEnabled: True - GroupOrder: 21 - Status: OK Name: FSFilter HSM - DriverEnabled: True - GroupOrder: 22 - Status: OK Name: FSFilter Cluster File System - DriverEnabled: True - GroupOrder: 23 - Status: OK Name: FSFilter System Recovery - DriverEnabled: True - GroupOrder: 24 - Status: OK Name: FSFilter Quota Management - DriverEnabled: True - GroupOrder: 25 - Status: OK Name: FSFilter Content Screener - DriverEnabled: True - GroupOrder: 26 - Status: OK Name: FSFilter Continuous Backup - DriverEnabled: True - GroupOrder: 27 - Status: OK Name: FSFilter Replication - DriverEnabled: True - GroupOrder: 28 - Status: OK Name: FSFilter Anti-Virus - DriverEnabled: True - GroupOrder: 29 - Status: OK Name: FSFilter Undelete - DriverEnabled: True - GroupOrder: 30 - Status: OK Name: FSFilter Activity Monitor - DriverEnabled: True - GroupOrder: 31 - Status: OK Name: FSFilter Top - DriverEnabled: True - GroupOrder: 32 - Status: OK Name: Filter - DriverEnabled: True - GroupOrder: 33 - Status: OK Name: Boot File System - DriverEnabled: True - GroupOrder: 34 - Status: OK Name: Base - DriverEnabled: True - GroupOrder: 35 - Status: OK Name: Pointer Port - DriverEnabled: True - GroupOrder: 36 - Status: OK Name: Keyboard Port - DriverEnabled: True - GroupOrder: 37 - Status: OK Name: Pointer Class - DriverEnabled: True - GroupOrder: 38 - Status: OK Name: Keyboard Class - DriverEnabled: True - GroupOrder: 39 - Status: OK Name: Video Init - DriverEnabled: True - GroupOrder: 40 - Status: OK Name: Video - DriverEnabled: True - GroupOrder: 41 - Status: OK Name: Video Save - DriverEnabled: True - GroupOrder: 42 - Status: OK Name: File System - DriverEnabled: True - GroupOrder: 43 - Status: OK Name: Streams Drivers - DriverEnabled: True - GroupOrder: 44 - Status: OK Name: NDIS Wrapper - DriverEnabled: True - GroupOrder: 45 - Status: OK Name: COM Infrastructure - DriverEnabled: True - GroupOrder: 46 - Status: OK Name: Event Log - DriverEnabled: True - GroupOrder: 47 - Status: OK Name: ProfSvc_Group - DriverEnabled: True - GroupOrder: 48 - Status: OK Name: AudioGroup - DriverEnabled: True - GroupOrder: 49 - Status: OK Name: UIGroup - DriverEnabled: True - GroupOrder: 50 - Status: OK Name: MS_WindowsLocalValidation - DriverEnabled: True - GroupOrder: 51 - Status: OK Name: PlugPlay - DriverEnabled: True - GroupOrder: 52 - Status: OK Name: Cryptography - DriverEnabled: True - GroupOrder: 53 - Status: OK Name: PNP_TDI - DriverEnabled: True - GroupOrder: 54 - Status: OK Name: NDIS - DriverEnabled: True - GroupOrder: 55 - Status: OK Name: TDI - DriverEnabled: True - GroupOrder: 56 - Status: OK Name: iSCSI - DriverEnabled: True - GroupOrder: 57 - Status: OK Name: NetBIOSGroup - DriverEnabled: True - GroupOrder: 58 - Status: OK Name: ShellSvcGroup - DriverEnabled: True - GroupOrder: 59 - Status: OK Name: SchedulerGroup - DriverEnabled: True - GroupOrder: 60 - Status: OK Name: SpoolerGroup - DriverEnabled: True - GroupOrder: 61 - Status: OK Name: SmartCardGroup - DriverEnabled: True - GroupOrder: 62 - Status: OK Name: NetworkProvider - DriverEnabled: True - GroupOrder: 63 - Status: OK Name: MS_WindowsRemoteValidation - DriverEnabled: True - GroupOrder: 64 - Status: OK Name: NetDDEGroup - DriverEnabled: True - GroupOrder: 65 - Status: OK Name: Parallel arbitrator - DriverEnabled: True - GroupOrder: 66 - Status: OK Name: Extended Base - DriverEnabled: True - GroupOrder: 67 - Status: OK Name: PCI Configuration - DriverEnabled: True - GroupOrder: 68 - Status: OK Name: MS Transactions - DriverEnabled: True - GroupOrder: 69 - Status: OK Name: Core - DriverEnabled: False - GroupOrder: 70 - Status: OK Name: PnP Filter - DriverEnabled: False - GroupOrder: 71 - Status: OK Name: Network - DriverEnabled: False - GroupOrder: 72 - Status: OK Name: NetworkService - DriverEnabled: False - GroupOrder: 73 - Status: OK Name: _Early-Launch - DriverEnabled: False - GroupOrder: 74 - Status: OK Name: Core Security Extensions - DriverEnabled: False - GroupOrder: 75 - Status: OK Name: LocalService - DriverEnabled: False - GroupOrder: 76 - Status: OK ---------- | LoadOrderGroupServiceDependencies LoadOrderGroup.Name="NetBIOSGroup" - Service.Name="RemoteAccess" LoadOrderGroup.Name="SCSI CDROM Class" - SystemDriver.Name="cdfs" ---------- | LoadOrderGroupServiceMembers LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="AppIDSvc" LoadOrderGroup.Name="AudioGroup" - Service.Name="AudioEndpointBuilder" LoadOrderGroup.Name="AudioGroup" - Service.Name="Audiosrv" LoadOrderGroup.Name="ShellSvcGroup" - Service.Name="avast! Antivirus" LoadOrderGroup.Name="NetworkProvider" - Service.Name="BFE" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="BrokerInfrastructure" LoadOrderGroup.Name="NetworkProvider" - Service.Name="Browser" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="DcomLaunch" LoadOrderGroup.Name="PlugPlay" - Service.Name="DeviceInstall" LoadOrderGroup.Name="TDI" - Service.Name="Dhcp" LoadOrderGroup.Name="TDI" - Service.Name="Dnscache" LoadOrderGroup.Name="TDI" - Service.Name="dot3svc" LoadOrderGroup.Name="Event Log" - Service.Name="EventLog" LoadOrderGroup.Name="AudioGroup" - Service.Name="FontCache" LoadOrderGroup.Name="Base" - Service.Name="FPLService" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="gpsvc" LoadOrderGroup.Name="UIGroup" - Service.Name="hpsrv" LoadOrderGroup.Name="TDI" - Service.Name="icssvc" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="igfxCUIService1.0.0.0" LoadOrderGroup.Name="NetworkProvider" - Service.Name="LanmanWorkstation" LoadOrderGroup.Name="TDI" - Service.Name="lmhosts" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="LSM" LoadOrderGroup.Name="NetworkService" - Service.Name="MapsBroker" LoadOrderGroup.Name="NetworkProvider" - Service.Name="MpsSvc" LoadOrderGroup.Name="iSCSI" - Service.Name="MSiSCSI" LoadOrderGroup.Name="MS_WindowsRemoteValidation" - Service.Name="Netlogon" LoadOrderGroup.Name="Cryptography" - Service.Name="NgcCtnrSvc" LoadOrderGroup.Name="Cryptography" - Service.Name="NgcSvc" LoadOrderGroup.Name="Video" - Service.Name="nvsvc" LoadOrderGroup.Name="PlugPlay" - Service.Name="PlugPlay" LoadOrderGroup.Name="Plugplay" - Service.Name="Power" LoadOrderGroup.Name="profsvc_group" - Service.Name="ProfSvc" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="RpcEptMapper" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="RpcSs" LoadOrderGroup.Name="MS_WindowsLocalValidation" - Service.Name="SamSs" LoadOrderGroup.Name="SmartCardGroup" - Service.Name="SCardSvr" LoadOrderGroup.Name="SchedulerGroup" - Service.Name="Schedule" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="SENS" LoadOrderGroup.Name="ShellSvcGroup" - Service.Name="ShellHWDetection" LoadOrderGroup.Name="SpoolerGroup" - Service.Name="Spooler" LoadOrderGroup.Name="AudioGroup" - Service.Name="STacSV" LoadOrderGroup.Name="PlugPlay" - Service.Name="TabletInputService" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="Themes" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="TrustedInstaller" LoadOrderGroup.Name="SmartCardGroup" - Service.Name="WbioSrvc" LoadOrderGroup.Name="TDI" - Service.Name="Wcmsvc" LoadOrderGroup.Name="NetworkProvider" - Service.Name="WebClient" LoadOrderGroup.Name="SchedulerGroup" - Service.Name="winzipersvc" LoadOrderGroup.Name="TDI" - Service.Name="WlanSvc" LoadOrderGroup.Name="LocalService" - Service.Name="workfolderssvc" LoadOrderGroup.Name="PlugPlay" - Service.Name="wudfsvc" LoadOrderGroup.Name="TDI" - Service.Name="WwanSvc" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="3ware" LoadOrderGroup.Name="Base" - SystemDriver.Name="Accelerometer" LoadOrderGroup.Name="Core" - SystemDriver.Name="ACPI" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="acpiex" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="acpitime" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="ADP80XX" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="AFD" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="agp440" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AmdK8" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AmdPPM" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdsata" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdsbs" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdxata" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="arcsas" LoadOrderGroup.Name="Keyboard Port" - SystemDriver.Name="aswKbd" LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="aswMonFlt" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="aswRdr" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="aswRvrt" LoadOrderGroup.Name="FSFilter Virtualization" - SystemDriver.Name="aswSnx" LoadOrderGroup.Name="FSFilter Security Enhancer" - SystemDriver.Name="aswSP" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="aswStm" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="aswVmm" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="atapi" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="b06bdrv" LoadOrderGroup.Name="Video" - SystemDriver.Name="BasicDisplay" LoadOrderGroup.Name="Video" - SystemDriver.Name="BasicRender" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="BCM43XX" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="bcmfn" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="bcmfn2" LoadOrderGroup.Name="Base" - SystemDriver.Name="Beep" LoadOrderGroup.Name="Network" - SystemDriver.Name="bowser" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="BthAvrcpTg" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="BthHFEnum" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="BthPan" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="BTHPORT" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="BTHUSB" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="cdfs" LoadOrderGroup.Name="SCSI CDROM Class" - SystemDriver.Name="cdrom" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="circlass" LoadOrderGroup.Name="Filter" - SystemDriver.Name="CLFS" LoadOrderGroup.Name="Core" - SystemDriver.Name="CNG" LoadOrderGroup.Name="Base" - SystemDriver.Name="cnghwassist" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="CompositeBus" LoadOrderGroup.Name="Base" - SystemDriver.Name="condrv" LoadOrderGroup.Name="Network" - SystemDriver.Name="Dfsc" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="dtlitescsibus" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="dtliteusbbus" LoadOrderGroup.Name="Video Init" - SystemDriver.Name="DXGKrnl" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="ebdrv" LoadOrderGroup.Name="SCSI Class" - SystemDriver.Name="EhStorClass" LoadOrderGroup.Name="SCSI Class" - SystemDriver.Name="EhStorTcgDrv" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="ErrDev" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="exfat" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="fastfat" LoadOrderGroup.Name="FSFilter Encryption" - SystemDriver.Name="FileCrypt" LoadOrderGroup.Name="FSFilter Bottom" - SystemDriver.Name="FileInfo" LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="Filetrace" LoadOrderGroup.Name="FSFilter Infrastructure" - SystemDriver.Name="FltMgr" LoadOrderGroup.Name="FSFilter Top" - SystemDriver.Name="FsDepends" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="fvevol" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="gagp30kx" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="GEARAspiWDM" LoadOrderGroup.Name="Base" - SystemDriver.Name="genericusbfn" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="GPIOClx0101" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="HDAudBus" LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidBth" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hidi2c" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hidinterrupt" LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidIr" LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidUsb" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="hpdskflt" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="HpSAMD" LoadOrderGroup.Name="Base" - SystemDriver.Name="huawei_enumerator" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hyperkbd" LoadOrderGroup.Name="Video" - SystemDriver.Name="HyperVideo" LoadOrderGroup.Name="Keyboard Port" - SystemDriver.Name="i8042prt" LoadOrderGroup.Name="Base" - SystemDriver.Name="iai2c" LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSS2i_I2C" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iaLPSSi_GPIO" LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSSi_I2C" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="iaStorAV" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="iaStorV" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="ibbus" LoadOrderGroup.Name="Video" - SystemDriver.Name="igfx" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="intelide" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="intelppm" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="isapnp" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="iusb3hcs" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iwdbus" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="kdnic" LoadOrderGroup.Name="Base" - SystemDriver.Name="KSecDD" LoadOrderGroup.Name="Cryptography" - SystemDriver.Name="KSecPkg" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="ksthunk" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="lltdio" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS2i" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS3i" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SSS" LoadOrderGroup.Name="FSFilter Virtualization" - SystemDriver.Name="luafv" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasas" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasr" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MEIx64" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="mlx4_bus" LoadOrderGroup.Name="Extended base" - SystemDriver.Name="Modem" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="mountmgr" LoadOrderGroup.Name="network" - SystemDriver.Name="mpsdrv" LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb" LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb10" LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb20" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="MsBridge" LoadOrderGroup.Name="File system" - SystemDriver.Name="Msfs" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="msgpiowin32" LoadOrderGroup.Name="Base" - SystemDriver.Name="mshidumdf" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="msisadrv" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSKSSRV" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="MsLldp" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSPCLOCK" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSPQM" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSTEE" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MTConfig" LoadOrderGroup.Name="Network" - SystemDriver.Name="Mup" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="mvumis" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NativeWifiP" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="ndfltr" LoadOrderGroup.Name="NDIS Wrapper" - SystemDriver.Name="NDIS" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NdisCap" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NdisTapi" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="Ndisuio" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="ndiswanlegacy" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="ndproxy" LoadOrderGroup.Name="NetBIOSGroup" - SystemDriver.Name="NetBIOS" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="NetBT" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="netvsc" LoadOrderGroup.Name="File system" - SystemDriver.Name="Npfs" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="NTFS" LoadOrderGroup.Name="Base" - SystemDriver.Name="Null" LoadOrderGroup.Name="Video" - SystemDriver.Name="nvlddmkm" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="nvraid" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="nvstor" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="nv_agp" LoadOrderGroup.Name="Parallel arbitrator" - SystemDriver.Name="Parport" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="partmgr" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="pci" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="pciide" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="pcmcia" LoadOrderGroup.Name="System Reserved" - SystemDriver.Name="pcw" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="pdc" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="percsas2i" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="percsas3i" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="Processor" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="Psched" LoadOrderGroup.Name="Streams Drivers" - SystemDriver.Name="RasAcd" LoadOrderGroup.Name="Network" - SystemDriver.Name="rdbss" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="rdyboost" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="ReFSv1" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="RFCOMM" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="rspndr" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="rt640x64" LoadOrderGroup.Name="Video" - SystemDriver.Name="s3cap" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="scfilter" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="sdbus" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="Serenum" LoadOrderGroup.Name="Extended base" - SystemDriver.Name="Serial" LoadOrderGroup.Name="Pointer Port" - SystemDriver.Name="sermouse" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="SiSRaid2" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="SiSRaid4" LoadOrderGroup.Name="Base" - SystemDriver.Name="SmbDrv" LoadOrderGroup.Name="Base" - SystemDriver.Name="SmbDrvI" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="spaceport" LoadOrderGroup.Name="Network" - SystemDriver.Name="srv" LoadOrderGroup.Name="Network" - SystemDriver.Name="srv2" LoadOrderGroup.Name="Network" - SystemDriver.Name="srvnet" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="stexstor" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="storahci" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="storflt" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="stornvme" LoadOrderGroup.Name="FSFilter Quota Management" - SystemDriver.Name="storqosflt" LoadOrderGroup.Name="Base" - SystemDriver.Name="storvsc" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="swenum" LoadOrderGroup.Name="Video Init" - SystemDriver.Name="Synth3dVsc" LoadOrderGroup.Name="Pointer Port" - SystemDriver.Name="SynTP" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="Tcpip" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="tdx" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="terminpt" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="TPM" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="TsUsbGD" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="uagp35" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UcmCx0101" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="Ucx01000" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="udfs" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="Ufx01000" LoadOrderGroup.Name="Base" - SystemDriver.Name="UfxChipidea" LoadOrderGroup.Name="Base" - SystemDriver.Name="ufxsynopsys" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="uliagpkx" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="umbus" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="UmPass" LoadOrderGroup.Name="Base" - SystemDriver.Name="UrsChipidea" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UrsCx01000" LoadOrderGroup.Name="Base" - SystemDriver.Name="UrsSynopsys" LoadOrderGroup.Name="Base" - SystemDriver.Name="USBAAPL64" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbccgp" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="usbcir" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbehci" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbhub" LoadOrderGroup.Name="Base" - SystemDriver.Name="USBHUB3" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbohci" LoadOrderGroup.Name="extended base" - SystemDriver.Name="usbprint" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbuhci" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="vdrvroot" LoadOrderGroup.Name="WdfLoadGroup" - SystemDriver.Name="VerifierExt" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="vhdmp" LoadOrderGroup.Name="Base" - SystemDriver.Name="vhf" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="vmbus" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="VMBusHID" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="volmgr" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="volmgrx" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="vpci" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="vsmraid" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="VSTXRAID" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="vwififlt" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="vwifimp" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WacomPen" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wanarp" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wanarpv6" LoadOrderGroup.Name="_Early-Launch" - SystemDriver.Name="WdBoot" LoadOrderGroup.Name="WdfLoadGroup" - SystemDriver.Name="Wdf01000" LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="WdFilter" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="WFPLWFS" LoadOrderGroup.Name="FSFilter Infrastructure" - SystemDriver.Name="WIMMount" LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="WindowsTrustedRT" LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="WindowsTrustedRTProxy" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="WinMad" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="WinVerbs" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WmiAcpi" LoadOrderGroup.Name="FSFilter Compression" - SystemDriver.Name="Wof" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wpcfltr" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="WpdUpFltr" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="ws2ifsl" LoadOrderGroup.Name="base" - SystemDriver.Name="WudfPf" LoadOrderGroup.Name="base" - SystemDriver.Name="WUDFRd" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="xboxgip" LoadOrderGroup.Name="Base" - SystemDriver.Name="xinputhid" ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service S0 - 3ware () -> System32\drivers\3ware.sys R0 - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys R0 - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys S0 - ADP80XX () -> System32\drivers\ADP80XX.SYS S0 - agp440 (@machine.inf,%agp440_svcdesc%;Intel AGP Bus Filter) -> System32\drivers\agp440.sys S0 - amdsata () -> System32\drivers\amdsata.sys S0 - amdsbs () -> System32\drivers\amdsbs.sys S0 - amdxata () -> System32\drivers\amdxata.sys S0 - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys R0 - aswRvrt (avast! Revert) -> (?) R0 - aswVmm (avast! VM Monitor) -> (?) S0 - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys S0 - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II VBD) -> System32\drivers\bxvbda.sys R0 - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys R0 - CNG () -> System32\Drivers\cng.sys R0 - disk (@disk.inf,%disk_ServiceDesc%;Pilote de disque) -> System32\drivers\disk.sys S0 - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys S0 - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys S0 - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys R0 - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys R0 - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys S0 - Fs_Rec () -> (?) R0 - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys S0 - gagp30kx (@agp.inf,%gagp30kx_svcdesc%;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms) -> System32\drivers\gagp30kx.sys R0 - hpdskflt (@oem37.inf,%service_desc%;HP Filter) -> system32\DRIVERS\hpdskflt.sys S0 - HpSAMD () -> System32\drivers\HpSAMD.sys S0 - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys R0 - iaStorAV (@iastorav.inf,%iaStorAV.DeviceDesc%;Intel(R) SATA RAID Controller Windows) -> System32\drivers\iaStorAV.sys S0 - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys S0 - intelide () -> System32\drivers\intelide.sys S0 - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys S0 - isapnp () -> System32\drivers\isapnp.sys R0 - iusb3hcs (@oem36.inf,%XHCI_svcdesc%;Pilote de commutateur de contrôleur d'hôte Intel(R) USB 3.0) -> System32\drivers\iusb3hcs.sys R0 - KSecDD () -> System32\Drivers\ksecdd.sys R0 - KSecPkg () -> System32\Drivers\ksecpkg.sys S0 - LSI_SAS () -> System32\drivers\lsi_sas.sys S0 - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys S0 - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys S0 - LSI_SSS () -> System32\drivers\lsi_sss.sys S0 - megasas () -> System32\drivers\megasas.sys S0 - megasr () -> System32\drivers\megasr.sys R0 - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys R0 - msisadrv () -> System32\drivers\msisadrv.sys R0 - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys S0 - mvumis () -> System32\drivers\mvumis.sys R0 - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys R0 - nvpciflt () -> system32\DRIVERS\nvpciflt.sys S0 - nvraid () -> System32\drivers\nvraid.sys S0 - nvstor () -> System32\drivers\nvstor.sys S0 - nv_agp (@machine.inf,%agpnvidia_svcdesc%;NVIDIA nForce AGP Bus Filter) -> System32\drivers\nv_agp.sys R0 - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys R0 - pci (@pci.inf,%pci_svcdesc%;Pilote de bus PCI) -> System32\drivers\pci.sys S0 - pciide () -> System32\drivers\pciide.sys S0 - pcmcia () -> System32\drivers\pcmcia.sys R0 - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys R0 - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys S0 - percsas2i () -> System32\drivers\percsas2i.sys S0 - percsas3i () -> System32\drivers\percsas3i.sys R0 - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys S0 - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys S0 - SiSRaid2 () -> System32\drivers\SiSRaid2.sys S0 - SiSRaid4 () -> System32\drivers\sisraid4.sys R0 - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys S0 - stexstor () -> System32\drivers\stexstor.sys S0 - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys S0 - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys S0 - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys S0 - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys S0 - storvsc () -> System32\drivers\storvsc.sys R0 - Tcpip (@%SystemRoot%\system32\drivers\tcpip.sys,-10001) -> System32\drivers\tcpip.sys S0 - uagp35 (@agp.inf,%uagp35_svcdesc%;Microsoft AGPv3.5 Filter) -> System32\drivers\uagp35.sys S0 - uliagpkx (@machine.inf,%uliagpkx_svcdesc%;Uli AGP Bus Filter) -> System32\drivers\uliagpkx.sys R0 - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys S0 - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys R0 - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys R0 - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys R0 - volsnap (@volume.inf,%VolumeClassName%;Storage volumes) -> System32\drivers\volsnap.sys S0 - vsmraid () -> System32\drivers\vsmraid.sys S0 - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys R0 - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys R0 - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys R0 - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys R0 - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys R0 - Wof (Windows Overlay File System Filter Driver) -> (?) R1 - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys R1 - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys R1 - aswKbd (aswKbd) -> \SystemRoot\system32\drivers\aswKbd.sys R1 - aswRdr (aswRdr) -> \SystemRoot\system32\drivers\aswRdr2.sys R1 - aswSnx (aswSnx) -> \SystemRoot\system32\drivers\aswSnx.sys R1 - aswSP (aswSP) -> \SystemRoot\system32\drivers\aswSP.sys R1 - BasicDisplay () -> \SystemRoot\System32\drivers\BasicDisplay.sys R1 - BasicRender () -> \SystemRoot\System32\drivers\BasicRender.sys R1 - Beep (Beep) -> (?) R1 - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys S1 - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys R1 - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys R1 - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys R1 - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys R1 - Msfs () -> (?) R1 - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys R1 - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys R1 - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys R1 - Npfs () -> (?) R1 - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys R1 - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys R1 - Null () -> (?) R1 - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys R1 - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys R1 - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys R1 - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys R2 - AdAppMgrSvc (Autodesk Application Manager Service) -> "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe" R2 - AdobeARMservice (Adobe Acrobat Update Service) -> "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" R2 - AppHostSvc (@%windir%\system32\inetsrv\iisres.dll,-30011) -> %windir%\system32\svchost.exe -k apphost R2 - Apple Mobile Device (Apple Mobile Device) -> "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" R2 - aswHwid (avast! HardwareID) -> \SystemRoot\system32\drivers\aswHwid.sys R2 - aswMonFlt (aswMonFlt) -> \SystemRoot\system32\drivers\aswMonFlt.sys R2 - aswStm (aswStm) -> \SystemRoot\system32\drivers\aswStm.sys R2 - AudioEndpointBuilder (@%SystemRoot%\system32\AudioEndpointBuilder.dll,-204) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R2 - Audiosrv (@%SystemRoot%\system32\audiosrv.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted S2 - Autodesk Content Service (Autodesk Content Service) -> "C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe" R2 - avast! Antivirus (Avast Antivirus) -> "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" R2 - BcmBtRSupport (@oem40.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service) -> %SystemRoot%\system32\BtwRSupportService.exe R2 - BFE (@%SystemRoot%\system32\bfe.dll,-1001) -> %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork S2 - BITS (@%SystemRoot%\system32\qmgr.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k netsvcs R2 - Bonjour Service (Service Bonjour) -> "C:\Program Files\Bonjour\mDNSResponder.exe" R2 - BrokerInfrastructure (@%windir%\system32\bisrv.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - c2cautoupdatesvc (Skype Click to Call Updater) -> "C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service R2 - c2cpnrsvc (Skype Click to Call PNR Service) -> "C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service R2 - CommandHandler (Command Service(CommandHandler)) -> "C:\Program Files (x86)\Firefox\bin\FirefoxCommand.exe" R2 - CoreMessagingRegistrar (@%SystemRoot%\system32\coremessaging.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork R2 - CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k NetworkService R2 - dbupdate (Service Mise à jour Dropbox (dbupdate)) -> "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /svc R2 - DcomLaunch (@combase.dll,-5012) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S2 - DeskTop_F (DeskTop DispalyName) -> C:\ProgramData\desktopfind\desktop154.exe R2 - DeviceAssociationService (@%SystemRoot%\system32\das.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - Dhcp (@%SystemRoot%\system32\dhcpcore.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted R2 - DiagTrack (@%SystemRoot%\system32\diagtrack.dll,-3001) -> %SystemRoot%\System32\svchost.exe -k utcsvc R2 - Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101) -> %SystemRoot%\system32\svchost.exe -k NetworkService R2 - DoSvc (@%systemroot%\system32\dosvc.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - DPS (@%systemroot%\system32\dps.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork R2 - EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - EventSystem (@comres.dll,-2450) -> %SystemRoot%\system32\svchost.exe -k LocalService R2 - ezSharedSvc (Easybits Services for Windows) -> C:\Windows\System32\ezSharedSvcHost.exe R2 - FirefoxU (Update Service(FirefoxU)) -> "C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe" R2 - FontCache (@%systemroot%\system32\FntCache.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService R2 - FPLService (TrueSuiteService) -> "C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe" S2 - gpsvc (@gpapi.dll,-112) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - gupdate (Service Google Update (gupdate)) -> "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc R2 - HPAuto (HP Auto) -> "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" R2 - HPClientSvc (HP Client Services) -> "C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe" R2 - hpsrv (@oem37.inf,%hpservice_desc%;HP Service) -> %SystemRoot%\system32\Hpservice.exe R2 - HPSupportSolutionsFrameworkService (HP Support Solutions Framework Service) -> "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" R2 - HPWMISVC (HPWMISVC) -> C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe R2 - HWDeviceService64.exe (HWDeviceService64.exe) -> "C:\ProgramData\DatacardService\HWDeviceService64.exe" -/service R2 - igfxCUIService1.0.0.0 (Intel(R) HD Graphics Control Panel Service) -> %SystemRoot%\system32\igfxCUIService.exe S2 - IHeeaWA_protect (Protect Service(IHeeaWA_protect)) -> "C:\ProgramData\IHeeaWA\protect\protect.exe" R2 - Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) -> "C:\Program Files\Intel\iCLS Client\HeciServer.exe" R2 - Intel(R) ME Service (Intel(R) ME Service) -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe R2 - iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500) -> %SystemRoot%\System32\svchost.exe -k NetSvcs R2 - jhi_service (Intel(R) Dynamic Application Loader Host Interface Service) -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe R2 - LanmanServer (@%systemroot%\system32\srvsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k NetworkService R2 - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys R2 - LMS (Intel(R) Management and Security Application Local Management Service) -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe R2 - LSM (@%windir%\system32\lsm.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys S2 - MapsBroker (@%SystemRoot%\System32\moshost.dll,-100) -> %SystemRoot%\System32\svchost.exe -k NetworkService R2 - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys R2 - MpsSvc (@%SystemRoot%\system32\FirewallAPI.dll,-23090) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork R2 - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys R2 - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys R2 - MSMQ (@mqutil.dll,-6102) -> %systemroot%\system32\mqsvc.exe R2 - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys R2 - NetMsmqActivator (@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195) -> "%systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator S2 - NetPipeActivator (@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197) -> %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe S2 - NetTcpActivator (@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199) -> %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe R2 - NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k NetworkService R2 - nsi (@%SystemRoot%\system32\nsisvc.dll,-200) -> %systemroot%\system32\svchost.exe -k LocalService R2 - nvsvc (NVIDIA Display Driver Service) -> "C:\WINDOWS\system32\nvvsvc.exe" R2 - nvUpdatusService (NVIDIA Update Service Daemon) -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe S2 - OneSyncSvc (@%SystemRoot%\system32\APHostRes.dll,-10002) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup R2 - OneSyncSvc_2b66c (Hôte de synchronisation_2b66c) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S2 - OneSyncSvc_3af07 (Hôte de synchronisation_3af07) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S2 - OneSyncSvc_4095b (Hôte de synchronisation_4095b) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S2 - OneSyncSvc_5ffd1 (Hôte de synchronisation_5ffd1) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup R2 - PcaSvc (@%SystemRoot%\system32\pcasvc.dll,-1) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys R2 - Power (@%SystemRoot%\system32\umpo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - ProfSvc (@%systemroot%\system32\profsvc.dll,-300) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k RPCSS R2 - RpcSs (@combase.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k rpcss R2 - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys R2 - SamSs (@%SystemRoot%\system32\samsrv.dll,-1) -> %SystemRoot%\system32\lsass.exe R2 - Schedule (@%SystemRoot%\system32\schedsvc.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - SENS (@%SystemRoot%\system32\Sens.dll,-200) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288) -> %SystemRoot%\System32\svchost.exe -k netsvcs S2 - SkypeUpdate (Skype Updater) -> "C:\Program Files (x86)\Skype\Updater\Updater.exe" R2 - Spooler (@%systemroot%\system32\spoolsv.exe,-1) -> %SystemRoot%\System32\spoolsv.exe S2 - sppsvc (@%SystemRoot%\system32\sppsvc.exe,-101) -> %SystemRoot%\system32\sppsvc.exe R2 - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys R2 - STacSV (@%SystemRoot%\system32\stlang64.dll,-10101) -> C:\Program Files\IDT\WDM\STacSV64.exe R2 - stisvc (@%SystemRoot%\system32\wiaservc.dll,-9) -> %SystemRoot%\system32\svchost.exe -k imgsvc R2 - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys R2 - SynTPEnhService (SynTPEnh Caller Service) -> "C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe" R2 - SysMain (@%SystemRoot%\system32\sysmain.dll,-1000) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - SystemEventsBroker (@%windir%\system32\SystemEventsBrokerServer.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys R2 - TDataSvr (TDataSvr) -> C:\Program Files (x86)\TData\TData.exe R2 - Themes (@%SystemRoot%\System32\themeservice.dll,-8192) -> %SystemRoot%\System32\svchost.exe -k netsvcs R2 - tiledatamodelsvc (@%SystemRoot%\system32\tileobjserver.dll,-1) -> %systemroot%\system32\svchost.exe -k appmodel R2 - TrkWks (@%SystemRoot%\system32\trkwks.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R2 - UNS (Intel(R) Management and Security Application User Notification Service) -> "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" R2 - UserManager (@%systemroot%\system32\usermgr.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - W3SVC (@%windir%\system32\inetsrv\iisres.dll,-30003) -> %windir%\system32\svchost.exe -k iissvcs R2 - wanarp (@%systemroot%\system32\rascfg.dll,-32011) -> System32\DRIVERS\wanarp.sys R2 - WbioSrvc (@%systemroot%\system32\wbiosrvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k WbioSvcGroup R2 - Wcmsvc (@%SystemRoot%\System32\wcmsvc.dll,-4097) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted R2 - Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - winzipersvc (WinZiper service) -> C:\Program Files (x86)\WinZipper\winzipersvc.exe R2 - WlanSvc (@%SystemRoot%\System32\wlansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - wscsvc (@%SystemRoot%\System32\wscsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - WSearch (@%systemroot%\system32\SearchIndexer.exe,-103) -> %systemroot%\system32\SearchIndexer.exe /Embedding S2 - YSearchUtilSvc (YSearchUtilSvc) -> "C:\Program Files (x86)\Yahoo!\yset\{43DBDB4F-A370-7A47-B34A-E8F679FBA4A9}\YSearchUtilSvc.exe" S3 - 1394ohci (@1394.inf,%PCI\CC_0C0010.DeviceDesc%;1394 OHCI Compliant Host Controller) -> \SystemRoot\System32\drivers\1394ohci.sys R3 - Accelerometer (@oem37.inf,%accelerometer_desc%;HP Mobile Data Protection Sensor) -> \SystemRoot\system32\DRIVERS\Accelerometer.sys S3 - acpipagr (@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver) -> \SystemRoot\System32\drivers\acpipagr.sys S3 - AcpiPmi (@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver) -> \SystemRoot\System32\drivers\acpipmi.sys S3 - acpitime (@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver) -> \SystemRoot\System32\drivers\acpitime.sys S3 - AdobeFlashPlayerUpdateSvc (Adobe Flash Player Update Service) -> C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe S3 - AJRouter (@%SystemRoot%\system32\AJRouter.dll,-2) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - ALG (@%SystemRoot%\system32\Alg.exe,-112) -> %SystemRoot%\System32\alg.exe S3 - AmdK8 (@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver) -> \SystemRoot\System32\drivers\amdk8.sys S3 - AmdPPM (@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver) -> \SystemRoot\System32\drivers\amdppm.sys S3 - AppID (@%systemroot%\system32\srpapi.dll,-100) -> system32\drivers\appid.sys S3 - AppIDSvc (@%systemroot%\system32\appidsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted R3 - Appinfo (@%systemroot%\system32\appinfo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - AppReadiness (@%SystemRoot%\System32\AppReadiness.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k AppReadiness S3 - AppXSvc (@%SystemRoot%\system32\appxdeploymentserver.dll,-1) -> %systemroot%\system32\svchost.exe -k wsappx S3 - AsyncMac (@%systemroot%\system32\rascfg.dll,-32000) -> \SystemRoot\System32\drivers\asyncmac.sys S3 - AxInstSV (@%SystemRoot%\system32\AxInstSV.dll,-103) -> %SystemRoot%\system32\svchost.exe -k AxInstSVGroup R3 - bcbtums (@oem40.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter) -> \SystemRoot\system32\drivers\bcbtums.sys R3 - BCM43XX (@oem22.inf,%BCM43XX_Service_DispName%;Pilote pour carte réseau Broadcom 802.11) -> \SystemRoot\system32\DRIVERS\bcmwl664.sys S3 - bcmfn (@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service) -> \SystemRoot\System32\drivers\bcmfn.sys S3 - bcmfn2 (@bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service) -> \SystemRoot\System32\drivers\bcmfn2.sys S3 - BDESVC (@%SystemRoot%\system32\bdesvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs R3 - BlackBerry Device Manager (BlackBerry Device Manager) -> "C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe" R3 - bowser (@%systemroot%\system32\browser.dll,-102) -> system32\DRIVERS\bowser.sys R3 - Browser (@%systemroot%\system32\browser.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - BthAvrcpTg (@bthaudhid.inf,%BthAvrcpTg_SvcDesc%;Bluetooth Audio/Video Remote Control HID) -> \SystemRoot\System32\drivers\BthAvrcpTg.sys R3 - BthEnum (@bth.inf,%BthEnum.SVCDESC%;Service d’énumérateur Bluetooth) -> \SystemRoot\System32\drivers\BthEnum.sys S3 - BthHFEnum (@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio and Call Control HID Enumerator) -> \SystemRoot\System32\drivers\bthhfenum.sys S3 - bthhfhid (@bthaudhid.inf,%BthAudioHFHid.SVCDESC%;Bluetooth Hands-Free Call Control HID) -> \SystemRoot\System32\drivers\BthHFHid.sys S3 - BthHFSrv (@%SystemRoot%\System32\BthHFSrv.dll,-103) -> %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation R3 - BthLEEnum (@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver) -> \SystemRoot\System32\drivers\BthLEEnum.sys S3 - BTHMODEM (@mdmbtmdm.inf,%BthModem.DisplayName%;Pilote de communications modem Bluetooth) -> \SystemRoot\System32\drivers\bthmodem.sys R3 - BthPan (@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network)) -> \SystemRoot\System32\drivers\bthpan.sys S3 - BTHPORT (@bth.inf,%BTHPORT.SvcDesc%;Pilote de port Bluetooth) -> \SystemRoot\System32\drivers\BTHport.sys R3 - bthserv (@%SystemRoot%\System32\bthserv.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalService R3 - BTHUSB (@bth.inf,%BTHUSB.SvcDesc%;Pilote USB radio Bluetooth) -> \SystemRoot\System32\drivers\BTHUSB.sys S3 - btwampfl (@oem40.inf,%btwampfl.ServiceName%;btwampfl) -> \SystemRoot\system32\DRIVERS\btwampfl.sys S3 - buttonconverter (@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices) -> \SystemRoot\System32\drivers\buttonconverter.sys S3 - CapImg (@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen) -> \SystemRoot\System32\drivers\capimg.sys S3 - CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - circlass (@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices) -> \SystemRoot\System32\drivers\circlass.sys S3 - ClipSVC (@%SystemRoot%\system32\ClipSVC.dll,-103) -> %SystemRoot%\System32\svchost.exe -k wsappx R3 - CmBatt (@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver) -> \SystemRoot\System32\drivers\CmBatt.sys R3 - CompositeBus (@compositebus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver) -> \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_912dfdedc3d2f520\CompositeBus.sys S3 - COMSysApp (@comres.dll,-947) -> %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} R3 - condrv (Console Driver) -> System32\drivers\condrv.sys R3 - cphs (Intel(R) Content Protection HECI Service) -> %SystemRoot%\SysWow64\IntelCpHeciSvc.exe S3 - dbupdatem (Service Mise à jour Dropbox (dbupdatem)) -> "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /medsvc S3 - DcpSvc (@%SystemRoot%\system32\dcpsvc.dll,-3001) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - defragsvc (@%SystemRoot%\system32\defragsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k defragsvc S3 - DeviceInstall (@%SystemRoot%\system32\umpnpmgr.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S3 - DevQueryBroker (@%SystemRoot%\system32\DevQueryBroker.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - diagnosticshub.standardcollector.service (@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000) -> %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe R3 - Disc Soft Lite Bus Service (Disc Soft Lite Bus Service) -> "C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe" S3 - DmEnrollmentSvc (@%systemroot%\system32\Windows.Internal.Management.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - dmvsc () -> \SystemRoot\System32\drivers\dmvsc.sys S3 - dmwappushservice (@%SystemRoot%\system32\dmwappushsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - dot3svc (@%systemroot%\system32\dot3svc.dll,-1102) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - drmkaud (@wdmaudio.inf,%drmkaud.SvcDesc%;Microsoft Trusted Audio Drivers) -> \SystemRoot\System32\drivers\drmkaud.sys S3 - DsmSvc (@%SystemRoot%\system32\DeviceSetupManager.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - DsSvc (@%SystemRoot%\system32\dssvc.dll,-10003) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R3 - dtlitescsibus (@oem53.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus) -> \SystemRoot\System32\drivers\dtlitescsibus.sys R3 - dtliteusbbus (@oem7.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus) -> \SystemRoot\System32\drivers\dtliteusbbus.sys R3 - DXGKrnl (LDDM Graphics Subsystem) -> \SystemRoot\System32\drivers\dxgkrnl.sys S3 - Eaphost (@%systemroot%\system32\eapsvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - EFS (@%SystemRoot%\system32\efssvc.dll,-100) -> %SystemRoot%\System32\lsass.exe S3 - embeddedmode (@%SystemRoot%\system32\embeddedmodesvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - EntAppSvc (@EnterpriseAppMgmtSvc.dll,-1) -> %systemroot%\system32\svchost.exe -k appmodel S3 - ErrDev (@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver) -> \SystemRoot\System32\drivers\errdev.sys S3 - exfat (exFAT File System Driver) -> (?) R3 - fastfat (FAT12/16/32 File System Driver) -> (?) S3 - Fax (@%systemroot%\system32\fxsresm.dll,-118) -> %systemroot%\system32\fxssvc.exe S3 - fdc (@fdc.inf,%fdc_ServiceDesc%;Floppy Disk Controller Driver) -> \SystemRoot\System32\drivers\fdc.sys R3 - fdPHost (@%systemroot%\system32\fdPHost.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService R3 - FDResPub (@%systemroot%\system32\fdrespub.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - fhsvc (@%systemroot%\system32\fhsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - Filetrace (@%SystemRoot%\system32\drivers\filetrace.sys,-10001) -> system32\drivers\filetrace.sys S3 - FlexNet Licensing Service 64 (FlexNet Licensing Service 64) -> "C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe" S3 - flpydisk (@flpydisk.inf,%floppy_ServiceDesc%;Floppy Disk Driver) -> \SystemRoot\System32\drivers\flpydisk.sys R3 - FontCache3.0.0.0 (@%SystemRoot%\system32\PresentationHost.exe,-3309) -> %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe S3 - FsDepends (@%SystemRoot%\system32\drivers\fsdepends.sys,-10001) -> System32\drivers\FsDepends.sys S3 - GamesAppService (GamesAppService) -> "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" R3 - GEARAspiWDM (GEAR ASPI Filter Driver) -> system32\DRIVERS\GEARAspiWDM.sys S3 - gencounter (@wgencounter.inf,%GenCounter.SVCDESC%;Microsoft Hyper-V Generation Counter) -> \SystemRoot\System32\drivers\vmgencounter.sys S3 - genericusbfn (@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class) -> \SystemRoot\System32\drivers\genericusbfn.sys S3 - GPIOClx0101 (Microsoft GPIO Class Extension Driver) -> System32\Drivers\msgpioclx.sys S3 - gupdatem (Service Google Update (gupdatem)) -> "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc R3 - HDAudBus (@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio) -> \SystemRoot\System32\drivers\HDAudBus.sys S3 - HidBatt (@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver) -> \SystemRoot\System32\drivers\HidBatt.sys S3 - HidBth (@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport) -> \SystemRoot\System32\drivers\hidbth.sys S3 - hidi2c (@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver) -> \SystemRoot\System32\drivers\hidi2c.sys S3 - hidinterrupt (@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts) -> \SystemRoot\System32\drivers\hidinterrupt.sys S3 - HidIr (@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver) -> \SystemRoot\System32\drivers\hidir.sys S3 - hidserv (@%SystemRoot%\System32\hidserv.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - HidUsb (@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver) -> \SystemRoot\System32\drivers\hidusb.sys S3 - HomeGroupListener (@%SystemRoot%\System32\ListSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R3 - HomeGroupProvider (@%SystemRoot%\System32\provsvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R3 - hpqwmiex (HP Software Framework Service) -> "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" R3 - HTTP (@%SystemRoot%\system32\drivers\http.sys,-1) -> system32\drivers\HTTP.sys R3 - huawei_enumerator () -> \SystemRoot\System32\drivers\ew_jubusenum.sys S3 - hyperkbd () -> \SystemRoot\System32\drivers\hyperkbd.sys S3 - HyperVideo () -> \SystemRoot\system32\DRIVERS\HyperVideo.sys R3 - i8042prt (@msmouse.inf,%i8042prt.SvcDesc%;Pilote de port clavier et souris PS/2) -> \SystemRoot\System32\drivers\i8042prt.sys S3 - iai2c (@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller) -> \SystemRoot\System32\drivers\iai2c.sys S3 - iaLPSS2i_I2C (@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_I2C.sys S3 - iaLPSSi_GPIO (@ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Controller Driver) -> \SystemRoot\System32\drivers\iaLPSSi_GPIO.sys S3 - iaLPSSi_I2C (@ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel(R) Serial IO I2C Controller Driver) -> \SystemRoot\System32\drivers\iaLPSSi_I2C.sys S3 - ibbus (@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver)) -> \SystemRoot\System32\drivers\ibbus.sys S3 - icssvc (@%SystemRoot%\System32\tetheringservice.dll,-4097) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - idsvc () -> (?) S3 - IEEtwCollectorService (@%SystemRoot%\system32\ieetwcollectorres.dll,-1000) -> %SystemRoot%\system32\IEEtwCollector.exe /V R3 - igfx () -> \SystemRoot\system32\DRIVERS\igdkmd64.sys S3 - IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - intaud_WaveExtensible (@oem59.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device) -> \SystemRoot\system32\drivers\intelaud.sys R3 - IntcDAud (@oem66.inf,%IntcDAud.SvcDesc%;Son Intel(R) pour écrans) -> \SystemRoot\system32\DRIVERS\IntcDAud.sys R3 - intelppm (@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver) -> \SystemRoot\System32\drivers\intelppm.sys S3 - IoQos (@%SystemRoot%\system32\drivers\ioqos.sys,-100) -> system32\drivers\ioqos.sys S3 - IpFilterDriver (@%systemroot%\system32\rascfg.dll,-32013) -> system32\DRIVERS\ipfltdrv.sys S3 - IPMIDRV () -> \SystemRoot\System32\drivers\IPMIDrv.sys S3 - IPNAT (IP Network Address Translator) -> System32\drivers\ipnat.sys R3 - iPod Service (Service de l’iPod) -> "C:\Program Files\iPod\bin\iPodService.exe" S3 - IRENUM (@%SystemRoot%\system32\drivers\irenum.sys,-100) -> system32\drivers\irenum.sys S3 - iScsiPrt (@iscsi.inf,%iScsiPortName%;iScsiPort Driver) -> \SystemRoot\System32\drivers\msiscsi.sys R3 - iwdbus (@oem60.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator) -> \SystemRoot\System32\drivers\iwdbus.sys R3 - kbdclass (@keyboard.inf,%kbdclass.SvcDesc%;Pilote de la classe Clavier) -> \SystemRoot\System32\drivers\kbdclass.sys S3 - kbdhid (@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver) -> \SystemRoot\System32\drivers\kbdhid.sys R3 - kdnic (@kdnic.inf,%KdNic.Service.DispName%;Microsoft Kernel Debug Network Miniport (NDIS 6.20)) -> \SystemRoot\System32\drivers\kdnic.sys R3 - KeyIso (@keyiso.dll,-100) -> %SystemRoot%\system32\lsass.exe R3 - ksthunk (Kernel Streaming Thunks) -> \SystemRoot\system32\drivers\ksthunk.sys S3 - KtmRm (@comres.dll,-2946) -> %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation R3 - lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k netsvcs R3 - LicenseManager (@%SystemRoot%\system32\licensemanagersvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - lltdsvc (@%SystemRoot%\system32\lltdres.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalService R3 - lmhosts (@%SystemRoot%\system32\lmhsvc.dll,-101) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R3 - MEIx64 (@oem51.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface) -> \SystemRoot\System32\drivers\HECIx64.sys S3 - MessagingService (@%SystemRoot%\system32\MessagingService.dll,-100) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - MessagingService_2b66c (MessagingService_2b66c) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - MessagingService_3af07 (MessagingService_3af07) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - MessagingService_4095b (MessagingService_4095b) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - MessagingService_5ffd1 (MessagingService_5ffd1) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - Microsoft SharePoint Workspace Audit Service (Microsoft SharePoint Workspace Audit Service) -> "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice S3 - mlx4_bus (@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator) -> \SystemRoot\System32\drivers\mlx4_bus.sys S3 - Modem () -> system32\drivers\modem.sys R3 - monitor (@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service) -> \SystemRoot\System32\drivers\monitor.sys R3 - mouclass (@msmouse.inf,%mouclass.SvcDesc%;Pilote de la classe Souris) -> \SystemRoot\System32\drivers\mouclass.sys S3 - mouhid (@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver) -> \SystemRoot\System32\drivers\mouhid.sys S3 - MozillaMaintenance (Mozilla Maintenance Service) -> "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" R3 - mpsdrv (@%SystemRoot%\system32\drivers\mpsdrv.sys,-23092) -> System32\drivers\mpsdrv.sys R3 - MQAC (@mqutil.dll,-6101) -> system32\drivers\mqac.sys S3 - MRxDAV (@%systemroot%\system32\webclnt.dll,-104) -> \SystemRoot\system32\drivers\mrxdav.sys R3 - mrxsmb (@%systemroot%\system32\wkssvc.dll,-1002) -> system32\DRIVERS\mrxsmb.sys R3 - mrxsmb20 (@%systemroot%\system32\wkssvc.dll,-1006) -> system32\DRIVERS\mrxsmb20.sys S3 - MsBridge (@%SystemRoot%\system32\bridgeres.dll,-1) -> System32\drivers\bridge.sys S3 - MSDTC (@comres.dll,-2797) -> %SystemRoot%\System32\msdtc.exe S3 - msgpiowin32 (@msgpiowin32.inf,%GPIO.SvcDesc%;Common Driver for Buttons, DockMode and Laptop/Slate Indicator) -> \SystemRoot\System32\drivers\msgpiowin32.sys S3 - mshidkmdf () -> \SystemRoot\System32\drivers\mshidkmdf.sys S3 - mshidumdf (@%SystemRoot%\system32\drivers\mshidumdf.sys,-100) -> \SystemRoot\System32\drivers\mshidumdf.sys S3 - MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - msiserver (@%SystemRoot%\system32\msimsg.dll,-27) -> %systemroot%\system32\msiexec.exe /V S3 - MSKSSRV (@ksfilter.inf,%MSKSSRV.DeviceDesc%;Microsoft Streaming Service Proxy) -> \SystemRoot\system32\DRIVERS\MSKSSRV.sys S3 - MSPCLOCK (@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Microsoft Streaming Clock Proxy) -> \SystemRoot\system32\DRIVERS\MSPCLOCK.sys S3 - MSPQM (@ksfilter.inf,%MSPQM.DeviceDesc%;Microsoft Streaming Quality Manager Proxy) -> \SystemRoot\system32\DRIVERS\MSPQM.sys S3 - MsRPC () -> (?) S3 - MSTEE (@ksfilter.inf,%MSTEE.DeviceDesc%;Microsoft Streaming Tee/Sink-to-Sink Converter) -> \SystemRoot\system32\DRIVERS\MSTEE.sys S3 - MTConfig (@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver) -> \SystemRoot\System32\drivers\MTConfig.sys R3 - NativeWifiP (@%SystemRoot%\System32\drivers\nwifi.sys,-101) -> system32\DRIVERS\nwifi.sys S3 - NcaSvc (@%SystemRoot%\system32\ncasvc.dll,-3009) -> %SystemRoot%\System32\svchost.exe -k NetSvcs R3 - NcbService (@%SystemRoot%\system32\ncbservice.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R3 - NcdAutoSetup (@%SystemRoot%\system32\NcdAutoSetup.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork S3 - ndfltr (@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service) -> \SystemRoot\System32\drivers\ndfltr.sys S3 - NdisCap (@%SystemRoot%\System32\drivers\ndiscap.sys,-5000) -> System32\drivers\ndiscap.sys S3 - NdisImPlatform (@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501) -> System32\drivers\NdisImPlatform.sys S3 - NdisTapi (@%systemroot%\system32\rascfg.dll,-32001) -> System32\DRIVERS\ndistapi.sys R3 - Ndisuio (NDIS Usermode I/O Protocol) -> system32\drivers\ndisuio.sys R3 - NdisVirtualBus (@%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200) -> \SystemRoot\System32\drivers\NdisVirtualBus.sys S3 - NdisWan (@%systemroot%\system32\rascfg.dll,-32002) -> \SystemRoot\System32\drivers\ndiswan.sys S3 - ndiswanlegacy (@%systemroot%\system32\rascfg.dll,-32014) -> System32\DRIVERS\ndiswan.sys S3 - ndproxy (@%SystemRoot%\system32\drivers\todo.sys,-101;NDIS Proxy) -> System32\DRIVERS\NDProxy.sys S3 - Netlogon (@%SystemRoot%\System32\netlogon.dll,-102) -> %systemroot%\system32\lsass.exe R3 - Netman (@%SystemRoot%\system32\netman.dll,-109) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R3 - netprofm (@%SystemRoot%\system32\netprofmsvc.dll,-202) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - NetSetupSvc (@%SystemRoot%\system32\NetSetupSvc.dll,-3) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - netvsc () -> \SystemRoot\System32\drivers\netvsc.sys S3 - NgcCtnrSvc (@%SystemRoot%\System32\NgcCtnrSvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - NgcSvc (@%SystemRoot%\System32\ngcsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R3 - NTFS () -> (?) R3 - nvlddmkm () -> \SystemRoot\system32\DRIVERS\nvlddmkm.sys S3 - ose64 (Office 64 Source Engine) -> "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" S3 - osppsvc (Office Software Protection Platform) -> "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" S3 - p2pimsvc (@%SystemRoot%\system32\pnrpsvc.dll,-8004) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - p2psvc (@%SystemRoot%\system32\p2psvc.dll,-8006) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - Parport (@msports.inf,%Parport.SVCDESC%;Parallel port driver) -> \SystemRoot\System32\drivers\parport.sys S3 - PerfHost (@%systemroot%\sysWow64\perfhost.exe,-2) -> %SystemRoot%\SysWow64\perfhost.exe S3 - PhoneSvc (@%SystemRoot%\system32\PhoneserviceRes.dll,-10000) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - PimIndexMaintenanceSvc (@%SystemRoot%\system32\UserDataAccessRes.dll,-15001) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - PimIndexMaintenanceSvc_2b66c (Données de contacts_2b66c) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - PimIndexMaintenanceSvc_3af07 (Données de contacts_3af07) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - PimIndexMaintenanceSvc_4095b (Données de contacts_4095b) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - PimIndexMaintenanceSvc_5ffd1 (Données de contacts_5ffd1) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - pla (@%systemroot%\system32\pla.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork R3 - PlugPlay (@%SystemRoot%\system32\umpnpmgr.dll,-200) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S3 - PNRPAutoReg (@%SystemRoot%\system32\pnrpauto.dll,-8002) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - PNRPsvc (@%SystemRoot%\system32\pnrpsvc.dll,-8000) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet R3 - PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted S3 - PptpMiniport (@%systemroot%\system32\rascfg.dll,-32006) -> \SystemRoot\System32\drivers\raspptp.sys S3 - PrintNotify (@C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll,-1) -> %SystemRoot%\system32\svchost.exe -k print S3 - Processor (@cpu.inf,%Processor.SvcDesc%;Processor Driver) -> \SystemRoot\System32\drivers\processr.sys S3 - QWAVE (@%SystemRoot%\system32\qwave.dll,-1) -> %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - QWAVEdrv (@%SystemRoot%\system32\drivers\qwavedrv.sys,-1) -> \SystemRoot\system32\drivers\qwavedrv.sys S3 - RasAcd (Remote Access Auto Connection Driver) -> System32\DRIVERS\rasacd.sys S3 - RasAgileVpn (@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2)) -> \SystemRoot\System32\drivers\AgileVpn.sys S3 - RasAuto (@%Systemroot%\system32\rasauto.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - Rasl2tp (@%systemroot%\system32\rascfg.dll,-32005) -> \SystemRoot\System32\drivers\rasl2tp.sys S3 - RasMan (@%Systemroot%\system32\rasmans.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - RasPppoe (@%systemroot%\system32\rascfg.dll,-32007) -> \SystemRoot\System32\drivers\raspppoe.sys S3 - RasSstp (@%systemroot%\system32\sstpsvc.dll,-202) -> \SystemRoot\System32\drivers\rassstp.sys R3 - rdpbus (@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver) -> \SystemRoot\System32\drivers\rdpbus.sys S3 - RDPDR (@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100) -> System32\drivers\rdpdr.sys S3 - RdpVideoMiniport (Remote Desktop Video Miniport Driver) -> System32\drivers\rdpvideominiport.sys S3 - ReFSv1 () -> (?) S3 - RetailDemo (@%SystemRoot%\System32\RDXService.dll,-256) -> %SystemRoot%\System32\svchost.exe -k netsvcs R3 - RFCOMM (@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI)) -> \SystemRoot\System32\drivers\rfcomm.sys R3 - RimVSerPort (@oem11.inf,%RimVSerPort%;RIM Virtual Serial Port v2) -> \SystemRoot\system32\DRIVERS\RimSerial_AMD64.sys S3 - RpcLocator (@%systemroot%\system32\Locator.exe,-2) -> %SystemRoot%\system32\locator.exe S3 - RSP2STOR (@oem25.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2) -> \SystemRoot\system32\DRIVERS\RtsP2Stor.sys R3 - rt640x64 (@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver) -> \SystemRoot\System32\drivers\rt640x64.sys S3 - s3cap () -> \SystemRoot\System32\drivers\vms3cap.sys S3 - ScDeviceEnum (@%SystemRoot%\System32\ScDeviceEnum.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - scfilter (@%SystemRoot%\System32\drivers\scfilter.sys,-11) -> System32\DRIVERS\scfilter.sys S3 - SCPolicySvc (@%SystemRoot%\System32\certprop.dll,-13) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - sdbus () -> \SystemRoot\System32\drivers\sdbus.sys R3 - SDRSVC (@%SystemRoot%\system32\sdrsvc.dll,-107) -> %SystemRoot%\system32\svchost.exe -k SDRSVC S3 - sdstor (@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver) -> \SystemRoot\System32\drivers\sdstor.sys S3 - seclogon (@%SystemRoot%\system32\seclogon.dll,-7001) -> %windir%\system32\svchost.exe -k netsvcs S3 - SensorDataService (@%SystemRoot%\system32\SensorDataService.exe,-101) -> %SystemRoot%\System32\SensorDataService.exe S3 - SensorService (@%SystemRoot%\System32\sensorservice.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - SensrSvc (@%SystemRoot%\System32\sensrsvc.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - SerCx (Serial UART Support Library) -> system32\drivers\SerCx.sys S3 - SerCx2 (Serial UART Support Library) -> system32\drivers\SerCx2.sys S3 - Serenum (@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver) -> \SystemRoot\System32\drivers\serenum.sys S3 - Serial (@msports.inf,%Serial.SVCDESC%;Serial port driver) -> \SystemRoot\System32\drivers\serial.sys S3 - sermouse (@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver) -> \SystemRoot\System32\drivers\sermouse.sys S3 - SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - sfloppy (@flpydisk.inf,%sfloppy_devdesc%;High-Capacity Floppy Disk Drive) -> \SystemRoot\System32\drivers\sfloppy.sys S3 - SharedAccess (@%SystemRoot%\system32\ipnathlp.dll,-106) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - SmbDrv () -> \SystemRoot\system32\DRIVERS\Smb_driver.sys R3 - SmbDrvI () -> \SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys S3 - smphost (@%SystemRoot%\System32\smphost.dll,-102) -> %SystemRoot%\System32\svchost.exe -k smphost S3 - SmsRouter (@%SystemRoot%\System32\SmsRouterSvc.dll,-10001) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - SNMPTRAP (@%SystemRoot%\system32\snmptrap.exe,-3) -> %SystemRoot%\System32\snmptrap.exe S3 - SpbCx (Simple Peripheral Bus Support Library) -> system32\drivers\SpbCx.sys R3 - srv2 (@%systemroot%\system32\srvsvc.dll,-104) -> System32\DRIVERS\srv2.sys R3 - srvnet () -> System32\DRIVERS\srvnet.sys R3 - SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - SstpSvc (@%SystemRoot%\system32\sstpsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService R3 - StateRepository (@%SystemRoot%\system32\windows.staterepository.dll,-1) -> %SystemRoot%\system32\svchost.exe -k appmodel R3 - STHDA (@%SystemRoot%\system32\stlang64.dll,-10306) -> \SystemRoot\system32\DRIVERS\stwrt64.sys S3 - StorSvc (@%SystemRoot%\System32\StorSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - svsvc (@%SystemRoot%\system32\svsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R3 - swenum (@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver) -> \SystemRoot\System32\drivers\swenum.sys S3 - swprv (@%SystemRoot%\System32\swprv.dll,-103) -> %SystemRoot%\System32\svchost.exe -k swprv S3 - Synth3dVsc () -> \SystemRoot\System32\drivers\Synth3dVsc.sys R3 - SynTP (@oem19.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver) -> \SystemRoot\system32\DRIVERS\SynTP.sys R3 - TabletInputService (@%SystemRoot%\system32\TabSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - TapiSrv (@%SystemRoot%\system32\tapisrv.dll,-10100) -> %SystemRoot%\System32\svchost.exe -k NetworkService S3 - Tcpip6 (@todo.dll,-100;Microsoft IPv6 Protocol Driver) -> System32\drivers\tcpip.sys S3 - terminpt (@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver) -> \SystemRoot\System32\drivers\terminpt.sys S3 - TermService (@%SystemRoot%\System32\termsrv.dll,-268) -> %SystemRoot%\System32\svchost.exe -k NetworkService S3 - TieringEngineService (@%SystemRoot%\system32\TieringEngineService.exe,-702) -> %SystemRoot%\system32\TieringEngineService.exe R3 - TimeBroker (@%windir%\system32\TimeBrokerServer.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - TPM (@tpm.inf,%TPM%;TPM) -> \SystemRoot\System32\drivers\tpm.sys S3 - TrueService (TrueAPI Service component) -> "C:\Program Files\Common Files\AuthenTec\TrueService.exe" S3 - TrustedInstaller (@%SystemRoot%\servicing\TrustedInstaller.exe,-100) -> %SystemRoot%\servicing\TrustedInstaller.exe S3 - tsusbflt (@%SystemRoot%\system32\drivers\tsusbflt.sys,-1000) -> System32\drivers\TsUsbFlt.sys S3 - TsUsbGD (@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device) -> \SystemRoot\System32\drivers\TsUsbGD.sys S3 - UASPStor (@uaspstor.inf,%UASPortName%;USB Attached SCSI (UAS) Driver) -> \SystemRoot\System32\drivers\uaspstor.sys S3 - UcmCx0101 (USB Connector Manager KMDF Class Extension) -> System32\Drivers\UcmCx.sys S3 - UcmUcsi (@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client) -> \SystemRoot\System32\drivers\UcmUcsi.sys R3 - Ucx01000 (USB Host Support Library) -> system32\drivers\ucx01000.sys S3 - UdeCx (USB Device Emulation Support Library) -> system32\drivers\udecx.sys S3 - UEFI (@uefi.inf,%UEFI.SvcDesc%;Microsoft UEFI Driver) -> \SystemRoot\System32\drivers\UEFI.sys S3 - Ufx01000 (USB Function Class Extension) -> system32\drivers\ufx01000.sys S3 - UfxChipidea (@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller) -> \SystemRoot\System32\drivers\UfxChipidea.sys S3 - ufxsynopsys (@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller) -> \SystemRoot\System32\drivers\ufxsynopsys.sys S3 - UI0Detect (@%SystemRoot%\system32\ui0detect.exe,-101) -> %SystemRoot%\system32\UI0Detect.exe R3 - umbus (@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver) -> \SystemRoot\System32\drivers\umbus.sys S3 - UmPass (@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver) -> \SystemRoot\System32\drivers\umpass.sys S3 - UmRdpService (@%SystemRoot%\system32\umrdp.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - UnistoreSvc (@%SystemRoot%\system32\UserDataAccessRes.dll,-10003) -> %SystemRoot%\System32\svchost.exe -k UnistackSvcGroup S3 - UnistoreSvc_2b66c (Stockage des données utilisateur_2b66c) -> C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup S3 - UnistoreSvc_3af07 (Stockage des données utilisateur_3af07) -> C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup S3 - UnistoreSvc_4095b (Stockage des données utilisateur_4095b) -> C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup S3 - UnistoreSvc_5ffd1 (Stockage des données utilisateur_5ffd1) -> C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup S3 - upnphost (@%systemroot%\system32\upnphost.dll,-213) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - UrsChipidea (@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver) -> \SystemRoot\System32\drivers\urschipidea.sys S3 - UrsCx01000 (USB Role-Switch Support Library) -> system32\drivers\urscx01000.sys S3 - UrsSynopsys (@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver) -> \SystemRoot\System32\drivers\urssynopsys.sys S3 - USBAAPL64 (@oem10.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver) -> \SystemRoot\System32\Drivers\usbaapl64.sys R3 - usbccgp (@usb.inf,%GenericParent.SvcDesc%;Pilote parent générique USB Microsoft) -> \SystemRoot\System32\drivers\usbccgp.sys S3 - usbcir (@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR)) -> \SystemRoot\System32\drivers\usbcir.sys R3 - usbehci (@usbport.inf,%EHCIMP.SvcDesc%;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0) -> \SystemRoot\System32\drivers\usbehci.sys R3 - usbhub (@usbport.inf,%ROOTHUB.SvcDesc%;Microsoft USB Standard Hub Driver) -> \SystemRoot\System32\drivers\usbhub.sys R3 - USBHUB3 (@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub) -> \SystemRoot\System32\drivers\UsbHub3.sys S3 - usbohci (@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbohci.sys S3 - usbprint (@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class) -> \SystemRoot\System32\drivers\usbprint.sys S3 - usbser (@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver) -> \SystemRoot\System32\drivers\usbser.sys R3 - USBSTOR (@usbstor.inf,%USBSTOR.SvcDesc%;Pilote de stockage de masse USB) -> \SystemRoot\System32\drivers\USBSTOR.SYS S3 - usbuhci (@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbuhci.sys R3 - usbvideo (@usbvideo.inf,%USBVideo.SvcDesc%;Périphérique vidéo USB (WDM)) -> \SystemRoot\System32\Drivers\usbvideo.sys R3 - USBXHCI (@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller) -> \SystemRoot\System32\drivers\USBXHCI.SYS S3 - UserDataSvc (@%SystemRoot%\system32\UserDataAccessRes.dll,-14001) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - UserDataSvc_2b66c (Accès aux données utilisateur_2b66c) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - UserDataSvc_3af07 (Accès aux données utilisateur_3af07) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - UserDataSvc_4095b (Accès aux données utilisateur_4095b) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - UserDataSvc_5ffd1 (Accès aux données utilisateur_5ffd1) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - UsoSvc (@%systemroot%\system32\usocore.dll,-102) -> %systemroot%\system32\svchost.exe -k netsvcs R3 - VaultSvc (@%SystemRoot%\system32\vaultsvc.dll,-1003) -> %SystemRoot%\system32\lsass.exe S3 - vds (@%SystemRoot%\system32\vds.exe,-100) -> %SystemRoot%\System32\vds.exe S3 - VerifierExt (@%SystemRoot%\system32\drivers\VerifierExt.sys,-1000) -> system32\drivers\VerifierExt.sys S3 - vhdmp () -> \SystemRoot\System32\drivers\vhdmp.sys S3 - vhf (@%SystemRoot%\system32\drivers\vhf.sys,-100) -> \SystemRoot\System32\drivers\vhf.sys S3 - VMBusHID () -> \SystemRoot\System32\drivers\VMBusHID.sys S3 - vmicguestinterface (@%systemroot%\system32\icsvc.dll,-801) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmicheartbeat (@%systemroot%\system32\icsvc.dll,-101) -> %systemroot%\system32\svchost.exe -k ICService S3 - vmickvpexchange (@%systemroot%\system32\icsvc.dll,-201) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmicrdv (@%systemroot%\system32\icsvc.dll,-601) -> %systemroot%\system32\svchost.exe -k ICService S3 - vmicshutdown (@%systemroot%\system32\icsvc.dll,-301) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmictimesync (@%systemroot%\system32\icsvc.dll,-401) -> %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - vmicvmsession (@%systemroot%\system32\icsvc.dll,-901) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmicvss (@%systemroot%\system32\icsvc.dll,-501) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vpci (@wvpci.inf,%vpci.SVCDESC%;Microsoft Hyper-V Virtual PCI Bus) -> \SystemRoot\System32\drivers\vpci.sys S3 - VSS (@%systemroot%\system32\vssvc.exe,-102) -> %systemroot%\system32\vssvc.exe R3 - vwifibus (@%SystemRoot%\System32\drivers\vwifibus.sys,-257) -> \SystemRoot\System32\drivers\vwifibus.sys R3 - vwifimp (@%SystemRoot%\System32\drivers\vwifimp.sys,-261) -> \SystemRoot\System32\drivers\vwifimp.sys S3 - W32Time (@%SystemRoot%\system32\w32time.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - w3logsvc (@%windir%\system32\inetsrv\iisres.dll,-30014) -> %windir%\system32\svchost.exe -k apphost S3 - WacomPen (@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver) -> \SystemRoot\System32\drivers\wacompen.sys S3 - WalletService (@%SystemRoot%\System32\WalletService.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k appmodel S3 - wanarpv6 (@%systemroot%\system32\rascfg.dll,-32012) -> System32\DRIVERS\wanarp.sys R3 - WAS (@%windir%\system32\inetsrv\iisres.dll,-30001) -> %windir%\system32\svchost.exe -k iissvcs S3 - wbengine (@%systemroot%\system32\wbengine.exe,-104) -> "%systemroot%\system32\wbengine.exe" S3 - wcncsvc (@%SystemRoot%\system32\wcncsvc.dll,-3) -> %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation S3 - WcsPlugInService (@%SystemRoot%\system32\WcsPlugInService.dll,-200) -> %SystemRoot%\system32\svchost.exe -k wcssvc S3 - WdBoot (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390) -> \SystemRoot\system32\drivers\WdBoot.sys S3 - WdFilter (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330) -> \SystemRoot\system32\drivers\WdFilter.sys R3 - WdiServiceHost (@%systemroot%\system32\wdi.dll,-502) -> %SystemRoot%\System32\svchost.exe -k LocalService R3 - WdiSystemHost (@%systemroot%\system32\wdi.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - wdiwifi (WDI Driver Framework) -> system32\DRIVERS\wdiwifi.sys S3 - WdNisDrv (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-370) -> system32\Drivers\WdNisDrv.sys S3 - WdNisSvc (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320) -> "%ProgramFiles%\Windows Defender\NisSrv.exe" S3 - WebClient (@%systemroot%\system32\webclnt.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - Wecsvc (@%SystemRoot%\system32\wecsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k NetworkService S3 - WEPHOSTSVC (@%systemroot%\system32\wephostsvc.dll,-100) -> %systemroot%\system32\svchost.exe -k WepHostSvcGroup S3 - wercplsupport (@%SystemRoot%\System32\wercplsupport.dll,-101) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - WerSvc (@%SystemRoot%\System32\wersvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k WerSvcGroup S3 - WiaRpc (@%SystemRoot%\system32\wiarpc.dll,-2) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - WIMMount (WIMMount) -> system32\drivers\wimmount.sys S3 - WinDefend (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310) -> "%ProgramFiles%\Windows Defender\MsMpEng.exe" R3 - WinHttpAutoProxySvc (@%SystemRoot%\system32\winhttp.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - WinMad (@mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service) -> \SystemRoot\System32\drivers\winmad.sys S3 - WinRM (@%Systemroot%\system32\wsmsvc.dll,-101) -> %SystemRoot%\System32\svchost.exe -k NetworkService R3 - WINUSB (@winusb.inf,%WINUSB_SvcDesc%;WinUsb Driver) -> \SystemRoot\System32\drivers\WinUSB.SYS S3 - WinVerbs (@mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service) -> \SystemRoot\System32\drivers\winverbs.sys S3 - wlidsvc (@%SystemRoot%\system32\wlidsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs R3 - WmiAcpi (@wmiacpi.inf,%WMIMAP.SvcDesc%;Microsoft Windows Management Interface for ACPI) -> \SystemRoot\System32\drivers\wmiacpi.sys S3 - wmiApSrv (@%Systemroot%\system32\wbem\wmiapsrv.exe,-110) -> %systemroot%\system32\wbem\WmiApSrv.exe S3 - WMPNetworkSvc (@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101) -> "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" S3 - workfolderssvc (@%systemroot%\system32\workfolderssvc.dll,-102) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - wpcfltr (Family Safety Filter Driver) -> system32\DRIVERS\wpcfltr.sys S3 - wpcsvc () -> (?) S3 - WPDBusEnum (@%SystemRoot%\system32\wpdbusenum.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - WpdUpFltr (@%systemroot%\System32\drivers\WpdUpFltr.sys,-100) -> System32\drivers\WpdUpFltr.sys S3 - WpnService (@%SystemRoot%\system32\wpnservice.dll,-1) -> %systemroot%\system32\svchost.exe -k wswpnservice S3 - WSService (@%SystemRoot%\system32\WSService.dll,-103) -> %SystemRoot%\System32\svchost.exe -k wsappx S3 - wuauserv (@%systemroot%\system32\wuaueng.dll,-105) -> %systemroot%\system32\svchost.exe -k netsvcs R3 - WudfPf (@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000) -> system32\drivers\WudfPf.sys R3 - WUDFRd (@%SystemRoot%\system32\drivers\WudfRd.sys,-1000) -> \SystemRoot\System32\drivers\WUDFRd.sys R3 - wudfsvc (@%SystemRoot%\system32\wudfsvc.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R3 - WUDFWpdFs () -> \SystemRoot\system32\DRIVERS\WUDFRd.sys R3 - WUDFWpdMtp () -> \SystemRoot\system32\DRIVERS\WUDFRd.sys S3 - WwanSvc (@%SystemRoot%\System32\wwansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork S3 - XblAuthManager (@%systemroot%\system32\XblAuthManager.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - XblGameSave (@%systemroot%\system32\XblGameSave.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - xboxgip (@xboxgip.inf,%XBOXGIP_Desc%;Xbox Game Input Protocol Driver) -> \SystemRoot\System32\drivers\xboxgip.sys S3 - XboxNetApiSvc (@%systemroot%\system32\XboxNetApiSvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - xinputhid (@xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver) -> \SystemRoot\System32\drivers\xinputhid.sys S4 - aspnet_state (@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1) -> %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe S4 - cdfs (CD/DVD File System Reader) -> system32\DRIVERS\cdfs.sys S4 - CDPSvc (@%SystemRoot%\system32\cdpsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S4 - cnghwassist (@%SystemRoot%\system32\drivers\cnghwassist.sys,-100) -> System32\DRIVERS\cnghwassist.sys S4 - NetTcpPortSharing (@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201) -> %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe S4 - RemoteAccess (@%Systemroot%\system32\mprdim.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs S4 - RemoteRegistry (@regsvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k localService S4 - SCardSvr (@%SystemRoot%\System32\SCardSvr.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S4 - tzautoupdate (@%SystemRoot%\system32\tzautoupdate.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService S4 - udfs (udfs) -> system32\DRIVERS\udfs.sys S4 - wlcrasvc (Windows Live Mesh remote connections service) -> "C:\Program Files\Windows Live\Mesh\wlcrasvc.exe" S4 - ws2ifsl (@%systemroot%\System32\drivers\ws2ifsl.sys,-1000) -> \SystemRoot\system32\drivers\ws2ifsl.sys ---------- | System files (Microsoft Files whitelisted) [MD5.2C5B3035B86770ADD2FE9BFBAF5B35A4] - [30/10/2015 11:17:22] - (.Copyright (c) 2011 LSI - LSI 3ware SCSI Storport Driver.) - [104.84 Ko] - (5.1.0.51) - C:\WINDOWS\System32\Drivers\3ware.sys [MD5.899B7E724BF19F17978B6A37B864A277] - [24/09/2012 16:40:56] - (.© Copyright 2001-2011 Hewlett-Packard Development Company, L.P. - HP Accelerometer.) - [42.81 Ko] - (4.2.9.1) - C:\WINDOWS\System32\Drivers\Accelerometer.sys [MD5.F7D0CD345D2DA42E7042ABCD73662403] - [30/10/2015 11:17:22] - (.Copyright (C) PMC-Sierra 2001-2014 - PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller.) - [1108.84 Ko] - (1.3.0.10769) - C:\WINDOWS\System32\Drivers\adp80xx.sys [MD5.5B30BCFE6E02E45D3EE268FF001BC5E0] - [30/10/2015 11:17:22] - (.Copyright © 2008-2015 AMD, Inc. - AHCI 1.3 Device Driver.) - [81.34 Ko] - (1.1.3.277) - C:\WINDOWS\System32\Drivers\amdsata.sys [MD5.F20B30F35A5C7888441B4DCA001ECF8E] - [30/10/2015 11:17:22] - (.2012 Advanced Micro Devices, Inc. - AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform.) - [253.34 Ko] - (3.7.1540.43) - C:\WINDOWS\System32\Drivers\amdsbs.sys [MD5.AFE838D7576C581D6483529621AB10CC] - [30/10/2015 11:17:22] - (.Copyright © 2008-2015 AMD, Inc. - Storage Filter Driver.) - [26.34 Ko] - (1.1.3.277) - C:\WINDOWS\System32\Drivers\amdxata.sys [MD5.E3FE8F610B1CC12BC3B2E6BC43DC97E2] - [30/10/2015 11:17:22] - (.Copyright 2014 PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) - [128.84 Ko] - (7.5.0.32048) - C:\WINDOWS\System32\Drivers\arcsas.sys [MD5.A629E4799D4CD6361D1B5D573EA5C2CD] - [14/08/2015 22:45:31] - (.Copyright (c) 2014 AVAST Software - avast! HWID.) - [36.77 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswHwid.sys [MD5.97F952A9050CAD88681F5F0F46B8D5A5] - [21/10/2012 23:28:24] - (.Copyright (c) 2014 AVAST Software - avast! Keyboard Filter Driver.) - [36.27 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswKbd.sys [MD5.9C6C17C495E960E52EDE5D038EE92AE1] - [08/09/2012 15:07:23] - (.Copyright (c) 2014 AVAST Software - avast! File System Minifilter for Windows 2003/Vista.) - [105.77 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswMonFlt.sys [MD5.8F492911129B1B32818BF894DC0C2C73] - [08/09/2012 15:07:31] - (.Copyright (c) 2014 AVAST Software - avast! WFP Redirect Driver.) - [100.65 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswRdr2.sys [MD5.4ABDD84A67378E866BC15DDC9916BA71] - [20/09/2013 23:35:54] - (.Copyright (c) 2014 AVAST Software - avast! Revert.) - [72.8 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswRvrt.sys [MD5.409CDD1400B404F655EEC1B5850FD3BE] - [08/09/2012 15:07:28] - (.Copyright (c) 2014 AVAST Software - avast! Virtualization Driver.) - [1045.8 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswSnx.sys [MD5.CDB1BE967AFF65D8395B6DF2EA8CBCCF] - [08/09/2012 15:07:38] - (.Copyright (c) 2014 AVAST Software - avast! self protection module.) - [462.49 Ko] - (12.1.3076.7) - C:\WINDOWS\System32\Drivers\aswsp.sys [MD5.F6B5E463A0BB934C26FB319EDC726F65] - [14/08/2015 22:45:37] - (.Copyright (c) 2014 AVAST Software - Stream Filter.) - [159.09 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswStm.sys [MD5.DA7B392FB478EB42BE925433D27940F8] - [20/09/2013 23:35:54] - (.Copyright (c) 2014 AVAST Software - avast! VM Monitor.) - [283.29 Ko] - (12.1.3076.0) - C:\WINDOWS\System32\Drivers\aswVmm.sys [MD5.2299302FBD11ADCF992DC1F59FC81C47] - [01/10/2015 19:25:12] - (.Copyright (C) 2000-2012, Broadcom Corporation. - Broadcom Bluetooth Firmware Download Filter.) - [203.3 Ko] - (12.0.1.410) - C:\WINDOWS\System32\Drivers\bcbtums.sys [MD5.3F5523DCEFE42B385659C5CB46A6B810] - [30/10/2015 11:17:22] - (.© Broadcom Corporation. - BCM Function 2 Device Driver.) - [9.5 Ko] - (6.3.9477.0) - C:\WINDOWS\System32\Drivers\bcmfn.sys [MD5.0B750A6A6D847E73CA48ADD7A0F5A393] - [30/10/2015 11:17:22] - (.© Broadcom Corporation. - BCM Function 2 Device Driver.) - [9.5 Ko] - (6.3.9391.6) - C:\WINDOWS\System32\Drivers\bcmfn2.sys [MD5.D41E6CCB9752F551049D2E0C437DD03D] - [15/06/2012 22:15:31] - (.1998-2010, Broadcom Corp. All Rights Rsvd - Broadcom 802.11 Network Adapter wireless driver.) - [4636.56 Ko] - (5.100.82.139) - C:\WINDOWS\System32\Drivers\BCMWL664.SYS [MD5.E1D4A8F545C4361C278007F61195A6F6] - [01/10/2015 19:25:12] - (.Copyright (C) 2000-2012, Broadcom Corporation. - Broadcom Bluetooth USB AMP Filter.) - [217.8 Ko] - (12.0.1.410) - C:\WINDOWS\System32\Drivers\btwampfl.sys [MD5.6447BA6FA709514B6C803D159B4C7D1E] - [30/10/2015 11:17:22] - (.(c) COPYRIGHT 2001-2012 Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) - [518.84 Ko] - (7.4.14.0) - C:\WINDOWS\System32\Drivers\bxvbda.sys [MD5.679FF716052109392D870F6A6C4A3535] - [12/03/2016 19:22:11] - (.Copyright (C) 2000-2015 - DAEMON Tools Lite Virtual SCSI Bus Driver.) - [29.55 Ko] - (5.28.0.0) - C:\WINDOWS\System32\Drivers\dtlitescsibus.sys [MD5.E23FDD696839A4790682CA66C48D3F2F] - [12/03/2016 19:24:06] - (.Copyright (C) 2000-2015 - DAEMON Tools Lite Virtual USB Bus Driver.) - [46.55 Ko] - (3.4.0.0) - C:\WINDOWS\System32\Drivers\dtliteusbbus.sys [MD5.491275B864B704B54EC08168344E0F38] - [30/10/2015 11:17:22] - (.(c) COPYRIGHT 2014-2015 QLogic Corporation - QLogic 10 GigE VBD.) - [3356.34 Ko] - (7.12.2.3) - C:\WINDOWS\System32\Drivers\evbda.sys [MD5.F572B7467B5CB4FA8FB6319575902E41] - [06/05/2016 20:02:03] - (.Copyright (C), 1988-2010, Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) - [32 Ko] - (1.0.0.2) - C:\WINDOWS\System32\Drivers\ewdcsc.sys [MD5.4216386DA9622C9AD330AA749C1E6517] - [06/05/2016 20:02:03] - (.Copyright (C) Huawei Technologies Co., Ltd. 2004-2011. - USB Modem/Serial Device Driver.) - [220.75 Ko] - (2.0.6.720) - C:\WINDOWS\System32\Drivers\ewusbmdm.sys [MD5.AE2808DB3338ED24650F8BC7A861ACA5] - [06/05/2016 20:02:03] - (.Copyright (C) Huawei Technologies Co., Ltd. 2004-2011. - USB NDIS Miniport Driver.) - [445 Ko] - (6.0.1.330) - C:\WINDOWS\System32\Drivers\ewusbwwan.sys [MD5.CACBDF30051DFB383E24B3E731D82BDE] - [06/05/2016 20:02:03] - (.Huawei Technologies Co., Ltd. Copyright @2010 - ew_hwupgrade Driver.) - [21.5 Ko] - (1.0.0.2) - C:\WINDOWS\System32\Drivers\ew_hwupgrade.sys [MD5.6196072AB259D45261619FA1230D6E1A] - [06/05/2016 20:01:38] - (.Huawei Technologies Co., Ltd. Copyright @2010-2013 - ew_jubusenum Driver.) - [89.5 Ko] - (2.6.2.3143) - C:\WINDOWS\System32\Drivers\ew_jubusenum.sys [MD5.9FF1915F672AACA0E241A11F7E0BB677] - [06/05/2016 20:02:03] - (.Huawei Technologies Co., Ltd. Copyright @2010-2013 - ew_jucdcndis Driver.) - [240.5 Ko] - (2.6.2.3151) - C:\WINDOWS\System32\Drivers\ew_juwwanecm.sys [MD5.8E98D21EE06192492A5671A6144D092F] - [08/03/2014 16:10:43] - (.Copyright (C) GEAR Software Inc. 1997-2012 - CD DVD Filter.) - [32.46 Ko] - (2.2.3.0) - C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [MD5.6B01B7414A105B9E51652089A03027CF] - [10/11/2011 13:04:00] - (.Copyright © 2006-2011, Intel Corporation. - Intel(R) Management Engine Interface.) - [58.77 Ko] - (8.0.0.1262) - C:\WINDOWS\System32\Drivers\HECIx64.sys [MD5.D104FF402FC3DDB686E6DEF00334DB26] - [24/09/2012 16:40:56] - (.© Copyright 2001-2011 Hewlett-Packard Development Company, L.P. - HP Disk Filter - SATA/RAID.) - [30.31 Ko] - (4.2.9.1) - C:\WINDOWS\System32\Drivers\hpdskflt.sys [MD5.FF442DCDCE1F6E9FAA9C8AD0CD1D199B] - [30/10/2015 11:17:22] - (.Copyright (c) 2004-2011 Hewlett-Packard Development Company, L.P. - Smart Array SAS/SATA Controller Media Driver.) - [62.84 Ko] - (8.0.4.0) - C:\WINDOWS\System32\Drivers\HpSAMD.sys [MD5.9A2A2F3C69B9A30B6E78536F6D258BAD] - [30/10/2015 11:17:18] - (.Copyright (C) 2013. - Intel(R) Serial IO I2C Driver.) - [79.5 Ko] - (604.10146.2643.2818) - C:\WINDOWS\System32\Drivers\iai2c.sys [MD5.59A20F5AD9F4AE54098154359519408E] - [30/10/2015 11:17:18] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO I2C Driver v2.) - [162 Ko] - (30.63.1519.7) - C:\WINDOWS\System32\Drivers\iaLPSS2i_I2C.sys [MD5.16A10CCEDCF5AC4CAAE43DC9FC40392F] - [30/10/2015 11:17:18] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO GPIO Controller Driver.) - [37.23 Ko] - (1.1.250.0) - C:\WINDOWS\System32\Drivers\iaLPSSi_GPIO.sys [MD5.EB82A11613326691508D9ED9A4FE29E7] - [30/10/2015 11:17:18] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO I2C Controller Driver.) - [110.5 Ko] - (1.1.253.0) - C:\WINDOWS\System32\Drivers\iaLPSSi_I2C.sys [MD5.6B0029A0253098CCE28EACCFDB9E7208] - [30/10/2015 11:17:22] - (.Copyright (C), Intel Corporation. - Intel(R) Rapid Storage Technology driver (inbox) - x64.) - [657.34 Ko] - (13.2.0.1022) - C:\WINDOWS\System32\Drivers\iaStorAV.sys [MD5.9652E1E35A92D8C75710C17A63B15796] - [30/10/2015 11:17:22] - (.Copyright(C) Intel Corporation 1994-2008 - Intel Matrix Storage Manager driver - x64.) - [402.34 Ko] - (8.6.2.1019) - C:\WINDOWS\System32\Drivers\iaStorV.sys [MD5.FFADF691F7BF727AF5C863454A372723] - [30/10/2015 11:17:23] - (.Copyright© 2009 Mellanox Technologies Ltd - InfiniBand Fabric Bus Driver.) - [414.84 Ko] - (4.91.10730.0) - C:\WINDOWS\System32\Drivers\ibbus.sys [MD5.9CE4D3A79D3180AC5A141E2F7E7137F4] - [30/07/2015 22:45:32] - (.Copyright (c) 1998-2012 Intel Corporation. - Intel Graphics Kernel Mode Driver.) - [3721.96 Ko] - (10.18.10.4358) - C:\WINDOWS\System32\Drivers\igdkmd64.sys [MD5.87871AB7AC797F922A6F3D4C874CED96] - [21/08/2015 11:50:48] - (.Intel(R) Corporation. - Intel(R) Display Audio Driver.) - [452.26 Ko] - (6.16.0.3154) - C:\WINDOWS\System32\Drivers\IntcDAud.sys [MD5.41CD73C13FCAEA4942F0CF7608B7530F] - [27/06/2015 00:54:13] - (.Copyright © 2013-2013, Intel Corporation. - Intel® WiDi Solution.) - [48.98 Ko] - (4.5.71.0) - C:\WINDOWS\System32\Drivers\intelaud.sys [MD5.DC0DBA5164F657DE2AE94B9D1FF75DA4] - [05/12/2011 14:13:00] - (.(C) 2010-2011 Intel Corporation - Intel(R) USB 3.0 Host Controller Switch Driver.) - [15.77 Ko] - (1.0.0.199) - C:\WINDOWS\System32\Drivers\iusb3hcs.sys [MD5.48B904D31F2369D7B0122617038D3F5B] - [27/06/2015 00:54:13] - (.Copyright © 2013-2013, Intel Corporation. - Intel® WiDi Solution.) - [37.98 Ko] - (4.5.71.0) - C:\WINDOWS\System32\Drivers\iwdbus.sys [MD5.961F28D879D345BFA50AF51285C90F2E] - [30/10/2015 11:17:23] - (.Copyright © LSI Corporation 2010 - LSI Fusion-MPT SAS Driver (StorPort).) - [106.34 Ko] - (1.34.3.83) - C:\WINDOWS\System32\Drivers\lsi_sas.sys [MD5.6BFB8D1B3407518BE06B6F81F92FA0F5] - [30/10/2015 11:17:23] - (.Copyright © LSI Corporation 2012 - LSI SAS Gen2 Driver (StorPort).) - [102.34 Ko] - (2.0.76.80) - C:\WINDOWS\System32\Drivers\lsi_sas2i.sys [MD5.BE0E47988D78F731DEC2C0CB03E765CB] - [30/10/2015 11:17:23] - (.Copyright © Avago Technologies 2015 - Avago SAS Gen3 Driver (StorPort).) - [96.84 Ko] - (2.50.96.80) - C:\WINDOWS\System32\Drivers\lsi_sas3i.sys [MD5.F99BF02BE9219986817BF094981EEB18] - [30/10/2015 11:17:23] - (.Copyright © LSI Corporation 2012 - LSI SSS PCIe/Flash Driver (StorPort).) - [80.84 Ko] - (2.10.61.81) - C:\WINDOWS\System32\Drivers\lsi_sss.sys [MD5.78BFF5425E044086E74E78650A359FBB] - [15/11/2015 20:41:07] - (.© Malwarebytes. - Malwarebytes Anti-Malware.) - [26.38 Ko] - (0.1.16.0) - C:\WINDOWS\System32\Drivers\mbam.sys [MD5.1239597BAB7EED2BB16D035AF87E65D9] - [15/11/2015 20:41:07] - (.© Malwarebytes. - Malwarebytes Chameleon Protection Driver.) - [137.38 Ko] - (1.1.22.0) - C:\WINDOWS\System32\Drivers\mbamchameleon.sys [MD5.78488AF2AB2111D67B3C4044707A519B] - [15/11/2015 20:41:43] - (.© Malwarebytes. - Malwarebytes Anti-Malware.) - [187.71 Ko] - (0.3.0.4) - C:\WINDOWS\System32\Drivers\MBAMSwissArmy.sys [MD5.2ED29B635F35E31A1C0D3DDB7DD2AD03] - [30/10/2015 11:17:23] - (.Copyright © Avago Technologies2013 - MEGASAS RAID Controller Driver for Windows.) - [58.34 Ko] - (6.706.6.0) - C:\WINDOWS\System32\Drivers\megasas.sys [MD5.22E3CB85870879CBAE13C5095A8B12E3] - [30/10/2015 11:17:23] - (.Copyright (C) 2007 LSI Corporation. - LSI MegaRAID Software RAID Driver.) - [562.34 Ko] - (15.2.2013.129) - C:\WINDOWS\System32\Drivers\megasr.sys [MD5.D41920FBFFF2BBCBBC69A5B383AD022E] - [30/10/2015 11:17:23] - (.Copyright© 2009 Mellanox Technologies Ltd - MLX4 Bus Driver.) - [688.84 Ko] - (4.91.10730.0) - C:\WINDOWS\System32\Drivers\mlx4_bus.sys [MD5.15E399875C850B54FC253A2323AD8021] - [06/05/2016 20:02:03] - (.Copyright (C) 2001 DiBcom SA - DiBcom AVSTREAM BDA driver.) - [978 Ko] - (4.0.3.2) - C:\WINDOWS\System32\Drivers\mod7700.sys [MD5.218705233D02776AE4D19CC37D985C1B] - [30/10/2015 11:17:23] - (.Copyright (c) Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) - [62.34 Ko] - (1.0.5.1016) - C:\WINDOWS\System32\Drivers\mvumis.sys [MD5.898415AC0B5F1D2A9A48ABCB68A6DC4B] - [15/11/2015 20:41:07] - (.© Malwarebytes Corporation. - Malwarebytes Web Access Control.) - [63.88 Ko] - (1.0.6.0) - C:\WINDOWS\System32\Drivers\mwac.sys [MD5.B57CE307DA101C739885B7CC0678077F] - [30/10/2015 11:17:23] - (.Copyright© 2009 Mellanox Technologies Ltd - NetworkDirect Support Filter Driver.) - [74.34 Ko] - (4.91.10730.0) - C:\WINDOWS\System32\Drivers\ndfltr.sys [MD5.DF0BB2C179476D312B7BC0056CEC50A6] - [23/07/2015 04:02:12] - (.(C) 2015 NVIDIA Corporation. - NVIDIA Windows Kernel Mode Driver, Version 353.62.) - [10881.82 Ko] - (10.18.13.5362) - C:\WINDOWS\System32\Drivers\nvlddmkm.sys [MD5.2328DC3622412EE112868645DA013075] - [23/07/2015 04:02:12] - (.(C) 2015 NVIDIA Corporation. - NVIDIA Windows Kernel Mode Driver, Version 353.62.) - [30.64 Ko] - (10.18.13.5362) - C:\WINDOWS\System32\Drivers\nvpciflt.sys [MD5.604D27CC38CC23493F218D0BB834B3FF] - [30/10/2015 11:17:23] - (.Copyright(C) 2001-2011 NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) - [146.84 Ko] - (10.6.0.23) - C:\WINDOWS\System32\Drivers\nvraid.sys [MD5.8B50D897657AB4A15FD9E251BBF7D107] - [30/10/2015 11:17:23] - (.Copyright(C) 2001-2011 NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) - [162.34 Ko] - (10.6.0.23) - C:\WINDOWS\System32\Drivers\nvstor.sys [MD5.1398A85E59698067CBBE1D66A9C13ADF] - [30/10/2015 11:17:23] - (.Copyright © LSI Corporation 2014 - MEGASAS RAID Controller Driver for Windows.) - [56.84 Ko] - (6.803.21.0) - C:\WINDOWS\System32\Drivers\percsas2i.sys [MD5.35F7C7AD709D909D618D9EDF987FC3ED] - [30/10/2015 11:17:23] - (.Copyright © Avago Technologies2013 - MEGASAS RAID Controller Driver for Windows.) - [57.34 Ko] - (6.602.12.0) - C:\WINDOWS\System32\Drivers\percsas3i.sys [MD5.344604E6913BD6E4EAEC34AF2E0943D7] - [14/09/2013 16:42:54] - (.Copyright (c) 2011 Research in Motion Ltd - RIM Virtual Serial Driver.) - [43.5 Ko] - (2.3.0.11) - C:\WINDOWS\System32\Drivers\RimSerial_AMD64.sys [MD5.FBEFF38DE03450E03E6CD9E8E37A8C74] - [30/10/2015 11:17:23] - (.Copyright (C) 2015 Realtek Semiconductor Corporation. All Right Reserved. - Realtek 8136/8168/8169 NDIS 6.40 64-bit Driver .) - [576 Ko] - (9.1.402.2015) - C:\WINDOWS\System32\Drivers\rt640x64.sys [MD5.7F324DFFCA5318EEF040DBE351D038D8] - [15/06/2012 22:12:42] - (.Copyright (C) Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vista/Win7.) - [253.6 Ko] - (6.1.7601.29005) - C:\WINDOWS\System32\Drivers\RtsP2Stor.sys [MD5.ABBE803FE0BDAE0E5BE74DDEFBE62F23] - [30/10/2015 11:17:23] - (.Copyright (c) SiS Corp. 2000-2010 - SiS RAID Stor Miniport Driver.) - [43.84 Ko] - (5.1.1039.2600) - C:\WINDOWS\System32\Drivers\sisraid2.sys [MD5.6043DF55CFE3C7ACF477645FA64DEA98] - [30/10/2015 11:17:23] - (.Copyright (c) SiS Corp. 2007-2013 - SiS AHCI Stor-Miniport Driver.) - [79.84 Ko] - (5.1.1039.3600) - C:\WINDOWS\System32\Drivers\sisraid4.sys [MD5.8AF2546861B179E2517EB02748B4FAB7] - [14/10/2011 08:37:42] - (.Copyright (C) Synaptics Incorporated 1996-2011 - Synaptics SMBus Driver.) - [19.55 Ko] - (15.3.29.0) - C:\WINDOWS\System32\Drivers\Smb_driver.sys [MD5.DBE58734165B4ACE92D80F10D766F17A] - [28/04/2016 00:53:48] - (.Copyright (C) Synaptics Incorporated 1996-2015 - Synaptics SMBus Driver.) - [51.16 Ko] - (19.0.12.98) - C:\WINDOWS\System32\Drivers\Smb_driver_AMDASF_Aux.sys [MD5.C67697A38E6D646F97EFF462DED68CF3] - [11/06/2016 12:55:08] - (.Copyright (C) Synaptics Incorporated 1996-2015 - Synaptics SMBus Driver.) - [51.66 Ko] - (19.0.12.98) - C:\WINDOWS\System32\Drivers\Smb_driver_Intel.sys [MD5.C67697A38E6D646F97EFF462DED68CF3] - [28/04/2016 00:53:48] - (.Copyright (C) Synaptics Incorporated 1996-2015 - Synaptics SMBus Driver.) - [51.66 Ko] - (19.0.12.98) - C:\WINDOWS\System32\Drivers\Smb_driver_Intel_Aux.sys [MD5.CCDA497C880AD16D87EDFAEFCFB2EDF5] - [30/10/2015 11:17:23] - (.© Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) - [30.34 Ko] - (5.1.0.10) - C:\WINDOWS\System32\Drivers\stexstor.sys [MD5.7E89F65EB250463EE8665CFE19566FC3] - [10/10/2013 19:44:54] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [527.5 Ko] - (6.10.6418.0) - C:\WINDOWS\System32\Drivers\stwrt64.sys [MD5.46062E452891A8D6D3B96DCAADDCC084] - [14/10/2011 08:37:44] - (.Copyright (C) Synaptics Incorporated 1996-2015 - Synaptics Touchpad Win64 Driver.) - [608.19 Ko] - (19.0.12.98) - C:\WINDOWS\System32\Drivers\SynTP.sys [MD5.5C3BE22E485B9BF11FCEFDC676C728D0] - [28/07/2014 16:52:00] - (.© Apple, Inc. - Apple Mobile Device USB Driver.) - [53.5 Ko] - (1.65.0.0) - C:\WINDOWS\System32\Drivers\usbaapl64.sys [MD5.D48ED0A08BD2FD25A833E6AC99623091] - [30/10/2015 11:17:23] - (.Copyright (C) VIA Technologies 1992-2007 - VIA RAID DRIVER FOR AMD-X86-64.) - [162.84 Ko] - (7.0.9600.6352) - C:\WINDOWS\System32\Drivers\vsmraid.sys [MD5.6990D4AFDF545669D4E6C232F26DE1FB] - [30/10/2015 11:17:23] - (.Copyright (C) 2008 VIA Corporation - VIA StorX RAID Controller Driver.) - [298.34 Ko] - (8.0.9200.8110) - C:\WINDOWS\System32\Drivers\VSTXRAID.SYS [MD5.4A53441C1C4D2878BEF27E381138BB2D] - [30/10/2015 11:17:23] - (.Copyright© 2009 Mellanox Technologies Ltd - Kernel WinMad.) - [26.34 Ko] - (4.91.10730.0) - C:\WINDOWS\System32\Drivers\winmad.sys [MD5.40A3E8D729F458B2C9A8BD9380FF83D5] - [30/10/2015 11:17:23] - (.Copyright© 2009 Mellanox Technologies Ltd - Kernel WinVerbs.) - [57.84 Ko] - (4.91.10730.0) - C:\WINDOWS\System32\Drivers\winverbs.sys ---------- | Uninstall [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\9a83c7154017fe19] : (Fleex player.-.fleex SAS) -> rundll32.exe dfshim.dll,ShArpMaintain Fleex player.application, Culture=neutral, PublicKeyToken=22fb91d707410980, processorArchitecture=msil [HKU\S-1-5-21-2532391380-2442022221-794288624-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CodeBlocks] : (CodeBlocks.-.The Code::Blocks Team) -> C:\Program Files (x86)\CodeBlocks\uninstall.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AutoCAD 2015 - Français (French)] : (Autodesk AutoCAD 2015 - Français (French).-.Autodesk) -> C:\Program Files\Autodesk\AutoCAD 2015\Setup\fr-fr\Setup\Setup.exe /P {5783F2D7-E001-0000-0102-0060B0CE6BBA} /M ACAD /language fr-FR [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Autodesk ReCap] : (Autodesk ReCap.-.Autodesk) -> C:\Program Files\Autodesk\Autodesk ReCap\Setup\Setup.exe /P {31ABA3F2-0000-1033-0102-111D43815377} /M Autodesk_ReCap /LANG en-US [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Broadcom 802.11 Wireless LAN Adapter] : (Broadcom 802.11 Wireless LAN Adapter.-.Broadcom Corporation) -> "C:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Broadcom\Broadcom 802.11\Driver" driver [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DAEMON Tools Lite] : (DAEMON Tools Lite.-.Disc Soft Ltd) -> C:\Program Files\DAEMON Tools Lite\uninst.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\EPSON SX535WD Series] : (EPSON SX535WD Series Printer Uninstall.-.SEIKO EPSON Corporation) -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YINSHTE.EXE /R /APD /P:"EPSON SX535WD Series" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SynTPDeinstKey] : (Synaptics Pointing Device Driver.-.Synaptics Incorporated) -> rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}] : (HP Client Services.-.Hewlett-Packard) -> MsiExec.exe /I{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{31ABA3F2-0000-1033-0102-111D43815377}] : (Autodesk ReCap.-.Autodesk) -> [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{5783F2D7-E001-0000-0102-0060B0CE6BBA}] : (AutoCAD 2015 - Français (French).-.Autodesk) -> C:\Program Files\Autodesk\AutoCAD 2015\Setup\fr-fr\Setup\Setup.exe /P {5783F2D7-E001-0000-0102-0060B0CE6BBA} /M ACAD /language fr-FR [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{5783F2D7-E001-040C-1102-0060B0CE6BBA}] : (AutoCAD 2015 Language Pack - Français (French).-.Autodesk) -> [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{5783F2D7-E001-040C-2102-0060B0CE6BBA}] : (AutoCAD 2015 - Français (French).-.Autodesk) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{5A847522-375C-4D05-BD3D-88C450CC047F}] : (HP Launch Box.-.Hewlett-Packard Company) -> MsiExec.exe /I{5A847522-375C-4D05-BD3D-88C450CC047F} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}] : (Intel® Trusted Connect Service Client.-.Intel Corporation) -> MsiExec.exe /I{6199B534-A1B6-46ED-873B-97B0ECF8F81E} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}] : (Bonjour.-.Apple Inc.) -> MsiExec.exe /X{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}] : (Broadcom Bluetooth Software.-.Broadcom Corporation) -> MsiExec.exe /X{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9D589081-AFC2-4932-9071-AC585AC1EA83}] : (Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit.-.Autodesk) -> MsiExec.exe /X{9D589081-AFC2-4932-9071-AC585AC1EA83} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel] : (Panneau de configuration NVIDIA 353.62.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver] : (NVIDIA Pilote graphique 353.62.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.Driver [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus] : (NVIDIA Optimus Update 10.4.0.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update] : (Mises à jour NVIDIA 10.4.0.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.Update [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update] : (NVIDIA Update Components.-.NVIDIA Corporation) -> [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core] : (NVIDIA Update Core.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B678797F-DF38-4556-8A31-8B818E261868}] : (Apple Mobile Device Support.-.Apple Inc.) -> MsiExec.exe /I{B678797F-DF38-4556-8A31-8B818E261868} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}] : (HP Auto.-.Hewlett-Packard Company) -> MsiExec.exe /I{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{DA83578A-7DB2-4CF6-9453-CF24C7917AB8}] : (Validity WBF DDK.-.Validity Sensors, Inc.) -> MsiExec.exe /X{DA83578A-7DB2-4CF6-9453-CF24C7917AB8} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{EBC0CC3F-B7A1-4FC8-8014-4C7BFD3925E8}] : (AuthenTec TrueAPI 64-bit.-.AuthenTec, Inc.) -> MsiExec.exe /I{EBC0CC3F-B7A1-4FC8-8014-4C7BFD3925E8} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F46AA0F1-E284-4878-A462-5F11B9166C0E}] : (iTunes.-.Apple Inc.) -> MsiExec.exe /I{F46AA0F1-E284-4878-A462-5F11B9166C0E} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F9DF0B5D-554B-45D2-8698-7C467FAF4BCA}] : (HP Security Assistant.-.Hewlett-Packard Company) -> MsiExec.exe /I{F9DF0B5D-554B-45D2-8698-7C467FAF4BCA} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F9E399CB-046F-45FD-A67F-CF399E2128E4}] : (HP 3D DriveGuard.-.Hewlett-Packard Company) -> MsiExec.exe /X{F9E399CB-046F-45FD-A67F-CF399E2128E4} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AbiWord2] : (AbiWord 2.9.4.-.AbiSource Developers) -> C:\Program Files (x86)\AbiWord\UninstallAbiWord2.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] : (Adobe Flash Player 22 NPAPI.-.Adobe Systems Incorporated) -> C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_22_0_0_209_Plugin.exe -maintain plugin [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Shockwave Player] : (Adobe Shockwave Player 11.6.-.Adobe Systems, Inc.) -> "C:\Windows\SysWOW64\Adobe\Shockwave 11\uninstaller.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Autodesk Application Manager] : (Autodesk Application Manager.-.Autodesk) -> C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\removeAdAppMgr.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Autodesk Content Service] : (Autodesk Content Service.-.Autodesk) -> C:\Program Files (x86)\Autodesk\Content Service\Setup\Setup.exe /P {A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F} /M ContentService /LANG fr-FR [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Autodesk Material Library 2015] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Autodesk Material Library Base Resolution Image Library 2015] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\avast] : (Avast Antivirus Gratuit.-.AVAST Software) -> C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Dropbox] : (Dropbox.-.Dropbox, Inc.) -> "C:\Program Files (x86)\Dropbox\Client\DropboxUninstaller.exe" /InstallType:MACHINE [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EasyBits Magic Desktop] : (Magic Desktop.-.EasyBits Software AS) -> C:\Windows\system32\ezMDUninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EW : Cossacks] : (Cossacks - European Wars.-.) -> C:\Windows\uncsetup.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\gedit_is1] : (gedit 2.30.1.-.GNOME) -> "C:\Program Files (x86)\gedit\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Google Chrome] : (Google Chrome.-.Google Inc.) -> "C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\setup.exe" --uninstall --multi-install --chrome --system-level --verbose-logging [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}] : (CyberLink YouCam.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1] : (Malwarebytes Anti-Malware version 2.2.1.1043.-.Malwarebytes) -> "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Mozilla Firefox 46.0.1 (x86 fr)] : (Mozilla Firefox 46.0.1 (x86 fr).-.Mozilla) -> "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MozillaMaintenanceService] : (Mozilla Maintenance Service.-.Mozilla) -> "C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Parametres SFR 3G] : (Parametres SFR 3G.-.Huawei Technologies Co.,Ltd) -> C:\Program Files (x86)\Parametres SFR 3G\uninst.exe [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SafeZone 1.48.2066.114] : (SafeZone Stable 1.48.2066.114.-.Avast Software) -> "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SumatraPDF] : (SumatraPDF.-.Krzysztof Kowalczyk) -> "C:\Program Files (x86)\SumatraPDF\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Test Simulator] : (Test Simulator.-.) -> "C:\Program Files (x86)\Test Simulator\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Uninstall dam] : (yessearches Uninstall.-.) -> "C:\Program Files (x86)\SearchesToYesbnd\unIns.exe" /cf={A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Usbfix] : (UsbFix.-.El Desaparecido - www.usb-antivirus.com - www.sosvirus.net) -> C:\UsbFix\Un-UsbFix.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VLC media player] : (VLC media player 2.0.3.-.VideoLAN) -> C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wi-Fi Modem] : (Wi-Fi Modem.-.Huawei Technologies Co.,Ltd) -> C:\Program Files (x86)\Wi-Fi Modem\uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangent hp Master Uninstall] : (HP Games.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-genres] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Game Explorer Categories - genres\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-main] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Game Explorer Categories - main\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-bals] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Build-A-Lot Metropolis\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-battlestargalacticaonline] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Battlestar Galactica Online\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-clubpenguin] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Club Penguin\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-darkorbit] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Dark Orbit\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-gunbros] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Gun Bros\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-itgirl] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - It Girl!\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-mahjonggdarkdimensions] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Mahjongg Dark Dimensions\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-oddmanor] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Odd Manor\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-organizedcrime] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Organized Crime\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-penguinworldsocial] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Penguin World\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-polarbowlerfacebook] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Polar Bowler Strike!\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-salonstreetsocial] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Salon Street\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-seafight] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Seafight\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-shaiya] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - Shaiya\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-hp-worldofwarcraft] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\HP Games\Web Link - World of Warcraft\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WinZip] : (WinZip.-.Winzipper Pvt Ltd.) -> C:\Program Files (x86)\WinZipper\wzUninstall.exe [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-1c151d6c-bd26-4777-8b76-db84421e42ef] : (Jewel Quest II.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Jewel Quest II\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-1c8aac74-709e-4ed7-bccc-42ae1c67e506] : (Farm Frenzy.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Farm Frenzy\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-29639670-a2fb-46f9-987d-01551aa2b695] : (Cradle of Rome 2.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Cradle of Rome 2\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-313fa4aa-5f5f-4145-81a7-425b738cb0e5] : (Virtual Families.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Virtual Families\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-3de479f0-f95d-4c3c-bc7d-071634ecfb32] : (Cake Mania.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Cake Mania\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-42832894-76bc-4c9b-a691-f8bae8050959] : (Wedding Dash.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Wedding Dash\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-43f03b5d-4876-491c-b428-3b6e2b051331] : (Farmscapes.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Farmscapes\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-75868758-b6c7-4bab-b9c0-4cab7c70fea0] : (Mahjongg Artifacts.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Mahjongg Artifacts\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-7aa0cd8e-2d26-4a80-bbc9-c3578db8b980] : (Jewel Match 3.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Jewel Match 3\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-8307bf80-c432-4274-b93b-d1948f42ace7] : (Fishdom (TM) 2.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Fishdom (TM) 2\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-85c2f8c1-e598-46c7-8b21-a7eda5a31aaa] : (Final Drive Fury.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Final Drive Fury\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-8bab3d0f-1561-4c74-af61-2f3f2d068ede] : (Bejeweled 3.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Bejeweled 3\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-8c1106af-94e3-49ca-b390-d66ab9dfdd44] : (Zuma's Revenge.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Zumas Revenge\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-998ec54c-aa1d-404d-bbc6-20b1c5581513] : (Chuzzle Deluxe.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Chuzzle Deluxe\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-bbc5a9eb-75cd-4b9e-8948-6c7a26a8e461] : (FATE.-.WildTangent) -> "C:\Program Files (x86)\HP Games\FATE\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-bf8fc2fe-79fa-4613-861a-ee4b5dfad6ca] : (Jewel Quest Solitaire 2.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Jewel Quest Solitaire 2\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-c12ac195-1b21-42da-915a-0bbabe7be0f3] : (Virtual Villagers 4 - The Tree of Life.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Virtual Villagers 4 - The Tree of Life\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-c6a20d67-3f9c-474f-b13d-792ae38ef9de] : (Insaniquarium Deluxe.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Insaniquarium Deluxe\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-d6a66fa9-ae6f-4be8-957b-386b649cf64c] : (Torchlight.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Torchlight\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-e8dcfed9-24cf-4b41-8a01-5a7c4ba9a061] : (Polar Bowler.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Polar Bowler\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-f4810285-02bb-4a51-9954-1c5324326b85] : (Plants vs. Zombies - Game of the Year.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Plants vs Zombies - Game of the Year\uninstall\uninstaller.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-f72245c7-937b-40c3-a5c5-f7af637b0af3] : (Mystery of Mortlake Mansion.-.WildTangent) -> "C:\Program Files (x86)\HP Games\Mystery of Mortlake Mansion\uninstall\uninstaller.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Yahoo! SearchSet] : (Yahoo Search Set.-.Yahoo Inc.) -> C:\Program Files (x86)\Yahoo!\yset\{43DBDB4F-A370-7A47-B34A-E8F679FBA4A9}\unset.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ZHPFix_is1] : (ZHPFix 2015.-.Nicolas Coolman) -> "C:\Program Files (x86)\ZHPFix\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{00DEB00E-B24F-4FB8-BC31-6853979FBCC8}] : (The Great Escape.-.) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{00DEB00E-B24F-4FB8-BC31-6853979FBCC8}\setup.exe" -l0x40c [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{01FB4998-33C4-4431-85ED-079E3EEFE75D}] : (CyberLink YouCam.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE}] : (BlackBerry Device Software Updater.-.Research In Motion Ltd) -> MsiExec.exe /X{06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{07FA4960-B038-49EB-891B-9F95930AA544}] : (HP Customer Experience Enhancements.-.Hewlett-Packard) -> MsiExec.exe /X{07FA4960-B038-49EB-891B-9F95930AA544} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{099218A5-A723-43DC-8DB5-6173656A1E94}] : (Dropbox Update Helper.-.Dropbox, Inc.) -> MsiExec.exe /I{099218A5-A723-43DC-8DB5-6173656A1E94} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0E2C6C50-A909-462E-9586-ADF103881BBF}] : (Secure Download Manager.-.e-academy Inc.) -> MsiExec.exe /I{0E2C6C50-A909-462E-9586-ADF103881BBF} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}] : (HP CoolSense.-.Hewlett-Packard Company) -> MsiExec.exe /I{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2091F234-EB58-4B80-8C96-8EB78C808CF7}] : (Facebook Video Calling 3.1.0.521.-.Skype Limited) -> MsiExec.exe /X{2091F234-EB58-4B80-8C96-8EB78C808CF7} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}] : (Intel(R) USB 3.0 eXtensible Host Controller Driver.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Uninstall\setup.exe -uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218060F0}] : (Java 8 Update 60.-.Oracle Corporation) -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83218060F0} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App] : (Update Installer for WildTangent Games App.-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\App\Uninstall.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}] : (opensource.-.Your Company Name) -> MsiExec.exe /I{3677D4D8-E5E0-49FC-B86E-06541CF00BBE} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{427F733F-4D6C-45BC-9324-EB743104C321}] : (Autodesk Material Library 2015.-.Autodesk) -> MsiExec.exe /I{427F733F-4D6C-45BC-9324-EB743104C321} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}] : (Java Auto Updater.-.Oracle Corporation) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268}] : (HP SimplePass.-.Hewlett-Packard) -> MsiExec.exe /X{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610}] : (BlackBerry Device Manager 7.0.-.Research In Motion Ltd.) -> MsiExec.exe /X{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{53B17A98-5BF0-40BC-AAFF-850A357975AC}] : (HP Quick Launch.-.Hewlett-Packard Company) -> MsiExec.exe /I{53B17A98-5BF0-40BC-AAFF-850A357975AC} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{612C34C7-5E90-47D8-9B5C-0F717DD82726}] : (swMSM.-.Adobe Systems, Inc) -> MsiExec.exe /I{612C34C7-5E90-47D8-9B5C-0F717DD82726} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{63EA6400-F30C-4C5C-8E64-6A448D1E9310}] : (HP Software Framework.-.Hewlett-Packard Company) -> MsiExec.exe /X{63EA6400-F30C-4C5C-8E64-6A448D1E9310} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}] : (Intel(R) Management Engine Components.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}] : (Hewlett-Packard ACLM.NET v1.2.2.3.-.Hewlett-Packard Company) -> MsiExec.exe /I{6F340107-F9AA-47C6-B54C-C3A19F11553F} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp] : (WildTangent Games App (HP Games).-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\Touchpoints\hp\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{768A6276-5822-489C-8A2B-67190F745655}] : (ESU for Microsoft Windows 7 SP1.-.Hewlett-Packard) -> MsiExec.exe /I{768A6276-5822-489C-8A2B-67190F745655} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{76B1B1F2-F96E-4FDF-A135-28099607575F}_is1] : (DetMinero_v1.2.-.Mehdi MIMOUNE © 2009) -> "c:\DETMINERO\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{78002155-F025-4070-85B3-7C0453561701}] : (Apple Application Support.-.Apple Inc.) -> MsiExec.exe /I{78002155-F025-4070-85B3-7C0453561701} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}] : (Apple Software Update.-.Apple Inc.) -> MsiExec.exe /I{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}] : (HP Support Assistant.-.Hewlett-Packard Company) -> "C:\Program Files (x86)\InstallShield Installation Information\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}\setup.exe" -runfromtemp -l0x0409 -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{85735431-6CD3-4B16-BEC8-95332034E53B}] : (Autodesk AutoCAD Performance Feedback Tool Version 1.2.2.-.Autodesk) -> MsiExec.exe /X{85735431-6CD3-4B16-BEC8-95332034E53B} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}] : (Realtek Ethernet Controller Driver.-.Realtek) -> C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8CE152BA-1D16-11E1-867D-984BE15F174E}] : (Evernote v. 4.5.2.-.Evernote Corp.) -> MsiExec.exe /X{8CE152BA-1D16-11E1-867D-984BE15F174E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8D5D54B8-3D29-4AB4-8DA8-1868DAF941D8}] : (OpenOffice 4.0.1.-.Apache Software Foundation) -> MsiExec.exe /I{8D5D54B8-3D29-4AB4-8DA8-1868DAF941D8} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8ED5A2F1-338F-4608-8AF7-BCD1ADC1E1F7}_is1] : (Free Alarm Clock.-.Comfort Software Group) -> "C:\Program Files (x86)\FreeAlarmClock\unins000.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}] : (Autodesk Content Service.-.Autodesk) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}] : (Autodesk Content Service Language Pack.-.Autodesk) -> MsiExec.exe /X{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}] : (Google Update Helper.-.Google Inc.) -> MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}] : (Autodesk Material Library Base Resolution Image Library 2015.-.Autodesk) -> MsiExec.exe /I{ABE2F70B-8D94-44E9-AA04-F0DB35063D62} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}] : (Adobe Reader X (10.1.5) MUI.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-FFFF-7B44-AA0000000001} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AE856388-AFAD-4753-81DF-D96B19D0A17C}] : (HP Setup Manager.-.Hewlett-Packard Company) -> MsiExec.exe /I{AE856388-AFAD-4753-81DF-D96B19D0A17C} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B288E426-9954-451C-B811-B0F234CF0EDD}] : (HP Documentation.-.Hewlett-Packard) -> MsiExec.exe /X{B288E426-9954-451C-B811-B0F234CF0EDD} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}] : (BlackBerry Desktop Software 7.1.-.Research In Motion Ltd.) -> MsiExec.exe /I{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C1594429-8296-4652-BF54-9DBE4932A44C}] : (Realtek PCIE Card Reader.-.Realtek Semiconductor Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C1594429-8296-4652-BF54-9DBE4932A44C}\setup.exe" -runfromtemp -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C403E867-FCF1-432B-BCC1-8FFD40A10A6E}] : (Importation de SketchUp.-.Autodesk) -> MsiExec.exe /X{C403E867-FCF1-432B-BCC1-8FFD40A10A6E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C8125548-F2D5-4059-823F-1F3C5BBD9F19}] : (Autodesk App Manager.-.Autodesk) -> MsiExec.exe /X{C8125548-F2D5-4059-823F-1F3C5BBD9F19} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C9EF1AAF-B542-41C8-A537-1142DA5D4AEC}] : (HP Customer Experience Enhancements.-.Hewlett-Packard) -> MsiExec.exe /X{C9EF1AAF-B542-41C8-A537-1142DA5D4AEC} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DBCD5E64-7379-4648-9444-8A6558DCB614}] : (HP Recovery Manager.-.Hewlett-Packard) -> MsiExec.exe /I{DBCD5E64-7379-4648-9444-8A6558DCB614} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}] : (IDT Audio.-.IDT) -> "C:\Program Files (x86)\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\Setup.exe" -remove -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ED1BD69A-07E3-418C-91F1-D856582581BF}] : (HP On Screen Display.-.Hewlett-Packard Company) -> MsiExec.exe /I{ED1BD69A-07E3-418C-91F1-D856582581BF} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ED5CE45D-842B-4C18-A002-87E16EA39BB3}] : (HP Support Solutions Framework.-.Hewlett-Packard Company) -> MsiExec.exe /X{ED5CE45D-842B-4C18-A002-87E16EA39BB3} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EDDEE94B-214D-4B07-9727-A3E46F3E379A}] : (Applications recommandées Autodesk.-.Autodesk) -> MsiExec.exe /X{EDDEE94B-214D-4B07-9727-A3E46F3E379A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}] : (Intel(R) Processor Graphics.-.Intel Corporation) -> "C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe" -uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}] : (HP Setup.-.Hewlett-Packard Company) -> MsiExec.exe /I{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{f761359c-9ced-45ae-9a51-9d6605cd55c4}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FC965A47-4839-40CA-B618-18F486F042C6}] : (Skype™ 7.25.-.Skype Technologies S.A.) -> MsiExec.exe /X{FC965A47-4839-40CA-B618-18F486F042C6} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}] : (Intel(R) OpenCL CPU Runtime.-.Intel Corporation) -> C:\Program Files (x86)\Intel\OpenCL SDK\2.0\Uninstall\setup.exe -uninstall ---------- | Ports ---------- | Microsoft Specifications CheckID: SetupControllerFiles0{90140000-0100-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: OSetupController0{90140000-0100-040C-1000-0000000FF1CE} - CLICK2RUN -> OSetupController CheckID: SetupControllerFiles0{90140000-0101-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0011-0000-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: OSetupController0{90140000-0011-0000-1000-0000000FF1CE} - CLICK2RUN -> OSetupController CheckID: SetupControllerFiles0{90140000-00A1-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-00A1-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0043-0000-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0043-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0043-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0044-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0044-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-00B4-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-00B4-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0015-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0015-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0115-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-00B5-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: OSetupController0{90140000-00B5-040C-1000-0000000FF1CE} - CLICK2RUN -> OSetupController CheckID: SetupControllerFiles0{90140000-0016-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0016-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0017-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0117-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0018-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0018-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0019-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-0019-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001A-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001A-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-00BA-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-00BA-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001B-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001B-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-003B-0000-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: OSetupController0{90140000-003B-0000-1000-0000000FF1CE} - CLICK2RUN -> OSetupController CheckID: SetupControllerFiles0{90140000-002C-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-002C-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-006E-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: OSetupControllerIntl_10330{90140000-006E-0409-1000-0000000FF1CE} - CLICK2RUN -> OSetupControllerIntl_1033 CheckID: SetupControllerFiles0{90140000-006E-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: OSetupControllerIntl_10360{90140000-006E-040C-1000-0000000FF1CE} - CLICK2RUN -> OSetupControllerIntl_1036 CheckID: SetupControllerFiles0{90140000-001F-0401-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001F-0413-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001F-0407-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001F-0409-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001F-0C0A-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: SetupControllerFiles0{90140000-001F-040C-1000-0000000FF1CE} - CLICK2RUN -> SetupControllerFiles CheckID: AI32BitFiles1{63EA6400-F30C-4C5C-8E64-6A448D1E9310} - VersionNT64 -> AI32BitFiles CheckID: USBDrivers999{06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE} - VersionNT64 -> USBDrivers CheckID: USBDrivers641{06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE} - VersionNT64 AND (NOT Intel64) -> USBDrivers64 CheckID: LtNts4200{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - SY_TRN_LTNTS4=0 -> LtNts4 CheckID: MSOE200{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - SY_TRN_MSOE=0 -> MSOE CheckID: MSOl200{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - SY_TRN_MSOL=0 -> MSOl CheckID: WinVista200{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - SY_TRN_WINVISTA=0 -> WinVista CheckID: Modem_Drivers_32999{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - VersionNT64 -> Modem_Drivers_32 CheckID: Modem_Drivers_641{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - VersionNT64 AND (NOT Intel64) -> Modem_Drivers_64 CheckID: USB_Drivers_32999{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - VersionNT64 -> USB_Drivers_32 CheckID: USB_Drivers_641{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} - VersionNT64 AND (NOT Intel64) -> USB_Drivers_64 CheckID: XPerf64Feature0{85735431-6CD3-4B16-BEC8-95332034E53B} - NOT VersionNT64 -> XPerf64Feature CheckID: VSTA_Runtime_CLR350{9495AEB4-AB97-39DE-8C42-806EEF75ECA7} - (NOT NETFX35_INSTALLED) AND (NOT NETCLIENT35_INSTALLED) -> VSTA_Runtime_CLR35 CheckID: VSTA_Runtime_CLR400{9495AEB4-AB97-39DE-8C42-806EEF75ECA7} - (NOT NETFX40_INSTALLED) AND (NOT NETCLIENT40_INSTALLED) -> VSTA_Runtime_CLR40 CheckID: VSTO_Runtime_CLR350{9495AEB4-AB97-39DE-8C42-806EEF75ECA7} - (NOT NETFX35_INSTALLED) AND (NOT NETCLIENT35_INSTALLED) -> VSTO_Runtime_CLR35 CheckID: VSTO_Runtime_CLR400{9495AEB4-AB97-39DE-8C42-806EEF75ECA7} - (NOT NETFX40_INSTALLED) AND (NOT NETCLIENT40_INSTALLED) -> VSTO_Runtime_CLR40 CheckID: CASL999{79C54A05-F146-4EA0-8A70-D4EFE6181E52} - INSTALLCASL=false -> CASL CheckID: SearchAndIndex0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_SEARCH5="YES" -> SearchAndIndex CheckID: MultimediaPlugin0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_MULTIMEDIA="YES" -> MultimediaPlugin CheckID: ReaderBrowserIntegration0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_BROWSER_INTEGRATION="YES" -> ReaderBrowserIntegration CheckID: ReaderPDFIntegration0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_PDF_INTEGRATION="YES" -> ReaderPDFIntegration CheckID: Accessibility_Plugins0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_ACCESSIBILITY="YES" -> Accessibility_Plugins CheckID: Atmosphere_3D0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_3D="YES" -> Atmosphere_3D CheckID: AdobeCommonLinguistics_Big0{AC76BA86-7AD7-FFFF-7B44-AA0000000001} - DISABLE_LINGUISTICS="YES" -> AdobeCommonLinguistics_Big CheckID: VSTAR_res_CLR350{8D0A0EC6-9A3C-354F-9BFC-A61E96BE1846} - (NOT NETFX35_INSTALLED) AND (NOT NETCLIENT35_INSTALLED) -> VSTAR_res_CLR35 CheckID: VSTOR_res_CLR350{8D0A0EC6-9A3C-354F-9BFC-A61E96BE1846} - (NOT NETFX35_INSTALLED) AND (NOT NETCLIENT35_INSTALLED) -> VSTOR_res_CLR35 CheckID: VSTOR_res_CLR400{8D0A0EC6-9A3C-354F-9BFC-A61E96BE1846} - (NOT NETFX40_INSTALLED) AND (NOT NETCLIENT40_INSTALLED) -> VSTOR_res_CLR40 CheckID: Registry_Feature1{5783F2D7-E001-0000-0102-0060B0CE6BBA} - 1 -> Registry_Feature CheckID: System_Files1{5783F2D7-E001-0000-0102-0060B0CE6BBA} - 1 -> System_Files CheckID: Express_Tools3{5783F2D7-E001-0000-0102-0060B0CE6BBA} - ACADLANGABBREV="enu" -> Express_Tools CheckID: LTU1{5783F2D7-E001-0000-0102-0060B0CE6BBA} - ACADSTANDALONENETWORKTYPE="3" -> LTU CheckID: Registry_Feature1{5783F2D7-E001-040C-1102-0060B0CE6BBA} - 1 -> Registry_Feature CheckID: System_Files1{5783F2D7-E001-040C-1102-0060B0CE6BBA} - 1 -> System_Files CheckID: Express_Tools3{5783F2D7-E001-040C-1102-0060B0CE6BBA} - ACADLANGABBREV="enu" -> Express_Tools CheckID: LTU1{5783F2D7-E001-040C-1102-0060B0CE6BBA} - ACADSTANDALONENETWORKTYPE="3" -> LTU CheckID: Registry_Feature1{5783F2D7-E001-040C-2102-0060B0CE6BBA} - 1 -> Registry_Feature CheckID: System_Files1{5783F2D7-E001-040C-2102-0060B0CE6BBA} - 1 -> System_Files CheckID: Express_Tools3{5783F2D7-E001-040C-2102-0060B0CE6BBA} - ACADLANGABBREV="enu" -> Express_Tools CheckID: LTU1{5783F2D7-E001-040C-2102-0060B0CE6BBA} - ACADSTANDALONENETWORKTYPE="3" -> LTU CheckID: TrueAPI200{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268} - VersionNT64<>"" -> TrueAPI CheckID: TrueSuite64_Files200{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268} - VersionNT64="" -> TrueSuite64_Files CheckID: FTRE_ChromeExt0{6D1221A9-17BF-4EC0-81F2-27D30EC30701} - NOT CHROME_IS_INSTALLED -> FTRE_ChromeExt CheckID: FTRE_FFAddOn0{6D1221A9-17BF-4EC0-81F2-27D30EC30701} - NOT FF_IS_INSTALLED -> FTRE_FFAddOn CheckID: FTRE_IEAddOn0{6D1221A9-17BF-4EC0-81F2-27D30EC30701} - NOT IE_IS_INSTALLED -> FTRE_IEAddOn CheckID: USB_Driver999{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610} - VersionNT64 -> USB_Driver CheckID: USB_Driver641{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610} - VersionNT64 AND (NOT Intel64) -> USB_Driver64 CheckID: USB_Serial_Driver999{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610} - VersionNT64 -> USB_Serial_Driver CheckID: USB_Serial_Driver641{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610} - VersionNT64 AND (NOT Intel64) -> USB_Serial_Driver64 ---------- | CLSID [HKCR\CLSID\{08A6AF6A-8FF2-4a3b-BECF-C2FAC8630BBF}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{0A25C695-3765-4B37-9455-4B1C113C2C04}] - (.© 2003-2014 Apple Inc. - iTunes Outlook Add-in.) - C:\Program Files (x86)\iTunes\iTunesOutlookAddIn.dll [01/09/2014 06:47:54] [HKCR\CLSID\{0A9FA806-6F90-4AF3-9316-1469717E7E3C}] - (.EasyBits Software AS -.) - C:\PROGRA~2\EASYBI~1\Programs\EASYLE~1\ELPROG~1.OCX [16/03/2011 14:00:00] [HKCR\CLSID\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}] - (.License: MPL 2 -.) - C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll [23/05/2016 20:50:23] [HKCR\CLSID\{11E4D223-C650-43F9-AB90-AB3AE4FB38F0}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{15FD01A3-6E5D-4ECD-9EBD-1813CB3887A1}] - (.-.) - %windir%\system32\btpanui.dll [HKCR\CLSID\{179F3D56-1B0B-42B2-A962-59B7EF59FE1B}] - (.-.) - C:\Windows\SysWOW64\speech_onecore\engines\tts\MSTTSEngine_OneCore.dll [30/10/2015 11:18:29] [HKCR\CLSID\{1965FEA3-3896-438B-B789-F5981797E7E7}] - (.-.) - C:\Windows\SysWOW64\MapsBtSvcProxy.dll [HKCR\CLSID\{1CEBDE3E-6B91-484A-AF48-5E4F4ED6B1E1}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{20347534-760B-464D-B572-285E6B618257}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{20ADDA11-8287-44D0-8C63-27CDA87ACC46}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{262E45B9-36DA-43ac-ABF4-C546A7EA3BFC}] - (.-.) - C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxClient-x86.dll [HKCR\CLSID\{26445657-50E1-4C9F-8378-FF028FD26816}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{2B445657-7159-42A1-84F0-538E82EE5DE9}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{2BE1981C-CCF9-4D8B-8DA2-E217287AD983}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{2C5F9B72-7148-4D97-BFC9-68A0E076BEBD}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{2FE8F810-B2A5-11d0-A787-0000F803ABFC}] - (.-.) - C:\WINDOWS\system32\dplayx.dll [HKCR\CLSID\{3018609E-CDBC-47E8-A255-809D46BAA319}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{326787D9-37B9-47A6-B539-EE13E7B04B8B}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Properties.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll [17/06/2013 16:46:14] [HKCR\CLSID\{343D770D-7788-47c2-B62A-B7C4CED925CB}] - (.-.) - C:\Windows\SysWOW64\wpcmig.dll [HKCR\CLSID\{37B05236-FFB5-4D42-B0C8-4A36CBF1BE62}] - (.-.) - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MUOPTIN.DLL [HKCR\CLSID\{3A445657-23E2-4E1E-82AB-D1836874C536}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{3EC569DC-6FB5-45D1-8B46-E122D27962E9}] - (.-.) - C:\WINDOWS\system32\CoreUIComponents.dll [13/07/2016 20:51:59] [HKCR\CLSID\{3F052B8E-512B-419D-9E06-9B9ADDC7118C}] - (.-.) - C:\Windows\SysWOW64\MapsCSP.dll [HKCR\CLSID\{4062C116-0270-11D3-8BCB-00600893B1B6}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{4108FA85-3586-11D3-8BD7-00600893B1B6}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{41445657-4118-4689-B300-E7F1EB61FF7B}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{4516EC43-8F20-11D0-9B6D-0000C0781BC3}] - (.-.) - C:\WINDOWS\system32\d3dxof.dll [HKCR\CLSID\{455c3e04-bfe9-4089-8622-f2464ec3fddb}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{47F64EC4-1AD6-4168-9D4C-00F3842F7CFB}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Properties.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll [17/06/2013 16:46:14] [HKCR\CLSID\{4EE17959-931E-49E4-A2C6-977ECF3628F3}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}] - (.-.) - %windir%\system32\acppage.dll [HKCR\CLSID\{52C550C6-067F-4BC8-98B2-0F0E91C10261}] - (.-.) - %windir%\system32\inetsrv\w3ctrlps.dll [HKCR\CLSID\{53DBCD97-3FDF-4B60-975B-2596B57482EF}] - (.© 2001-2012 Research In Motion Limited. - BlackBerry WebSL Browser Plug-In.) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\BBWebSLLauncher.dll [09/07/2013 17:52:50] [HKCR\CLSID\{572D5281-4E8C-4F82-A8E1-26E786B6B5B3}] - (.-.) - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\OPTINPS.DLL [HKCR\CLSID\{5A57485B-151F-4868-945B-FBB95B574075}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{5DE7918B-BFD7-4C1E-B4E0-B16D0A3EA76B}] - (.-.) - C:\Windows\SysWOW64\AuthHostProxy.dll [HKCR\CLSID\{62A560B8-09DB-4cc6-AE1B-9D8F7ADDB8F3}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{63530157-314D-473F-BB48-9B1B18908300}] - (.© 2003-2014 Apple Inc. - iTunes Outlook Add-in.) - C:\Program Files (x86)\iTunes\iTunesOutlookAddIn.dll [01/09/2014 06:47:54] [HKCR\CLSID\{640167b4-59b0-47a6-b335-a6b3c0695aea}] - (.-.) - C:\WINDOWS\system32\audiodev.dll [HKCR\CLSID\{669F39F0-33C6-404F-A7AE-2F2215CF81E7}] - (.EasyBits Software AS -.) - C:\PROGRA~2\EASYBI~1\ezDeskAX.ocx [15/09/2011 14:00:00] [HKCR\CLSID\{6C2589C3-96F8-4863-A511-9C33EB2C7E2A}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{70061822-CF33-46CD-BE75-9D8FCC1D6FD6}] - (.EasyBits Software AS -.) - C:\PROGRA~2\EASYBI~1\Programs\EASYLE~1\ELCOUR~1.OCX [16/03/2011 14:00:00] [HKCR\CLSID\{71A1A612-F7B4-4092-8E0F-C79C8FB0391D}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{73D320C0-FACA-4553-9D5F-070F9E4DC5C8}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Properties.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll [17/06/2013 16:46:14] [HKCR\CLSID\{79BA9E00-B6EE-11D1-86BE-00C04FBF8FEF}] - (.-.) - C:\WINDOWS\System32\dmband.dll [HKCR\CLSID\{7C7E6C99-BB8D-4718-AAA9-70C4320010DE}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{810B5013-E88D-11D2-8BC1-00600893B1B6}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{82D1C283-A637-4A07-B1EC-8C7AE661EAF1}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Properties.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll [17/06/2013 16:46:14] [HKCR\CLSID\{88445657-4A4E-4949-8FED-72B831C7C662}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{898F8BC2-C6E3-4CD7-B04A-72E5B490B4C6}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{8A90343C-B07A-45B6-A3F5-6B6498B90C55}] - (.EasyBits Software AS -.) - C:\PROGRA~2\EASYBI~1\EZCTRL~1.OCX [15/09/2011 14:00:00] [HKCR\CLSID\{8CD1B98D-D8D5-4B51-9564-48B12A98698F}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{90A1998A-EB21-4F61-872F-F4DFDE1065D6}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceoledb35.dll [HKCR\CLSID\{93445657-12CA-4B80-AB18-9996D7293EC6}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{9E7E2CCE-3F1F-4891-892C-AC8B486D03B2}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{9FD542D2-61C4-4E9F-A8E2-E6B8C7F64CBF}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{A4445657-BCB6-476E-8336-3A2ACD96E299}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{A4AB08B7-35EE-4f75-BE0A-D8F9630D755E}] - (.-.) - C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxClient-x86.dll [HKCR\CLSID\{A6098E79-9C50-4F87-8973-5FB4532C93D8}] - (.-.) - %windir%\system32\btpanui.dll [HKCR\CLSID\{A861C6E2-FCFC-11D2-8BC9-00600893B1B6}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{A9D3060D-3526-4538-B13A-1913568DAA0D}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{AAF322D7-795E-4485-A92F-3D3F39269EDE}] - (.-.) - C:\Windows\SysWOW64\Windows.Perception.Stub.dll [30/10/2015 11:18:31] [HKCR\CLSID\{AD046C04-9CC6-4424-A8E2-1F8BB9D0B29D}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Proxy.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManagerps.dll [17/06/2013 16:46:16] [HKCR\CLSID\{B2445657-090D-11e4-AEDA-B4B52FE06611}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{B2D2142A-9055-4C37-B3FA-EEFDD4C1DC59}] - (.-.) - C:\Windows\SysWOW64\ConnectedStorageService.ProxyStub.dll [HKCR\CLSID\{B8445657-C149-4F95-8CFF-49D39B615F27}] - (.-.) - C:\Windows\SysWOW64\mtf.dll [11/06/2016 12:50:36] [HKCR\CLSID\{B8DF592B-DE05-49f5-BB21-084F548F12A9}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{C5621364-87CC-4731-8947-929CAE75323E}] - (.-.) - %windir%\system32\F12\msdbg2.dll [HKCR\CLSID\{C64501F6-E6E6-451f-A150-25D0839BC510}] - (.-.) - C:\Windows\SysWOW64\speech\engines\tts\MSTTSEngine.dll [30/10/2015 11:18:27] [HKCR\CLSID\{C70EB77F-EFD4-4678-A27B-BF1648F30D04}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{C8992C14-DF59-4518-808F-CCFBB5850282}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Properties.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll [17/06/2013 16:46:14] [HKCR\CLSID\{CABAFF81-DCD7-4404-9167-FF58307B632E}] - (.EasyBits Software AS -.) - C:\PROGRA~2\EASYBI~1\Programs\Gamepad\EZGAME~1.OCX [16/03/2011 14:00:00] [HKCR\CLSID\{D1EB6D20-8923-11d0-9D97-00A0C90A43CB}] - (.-.) - C:\WINDOWS\system32\dplayx.dll [HKCR\CLSID\{D2AC2894-B39B-11D1-8704-00600893B1BD}] - (.-.) - C:\WINDOWS\System32\dmband.dll [HKCR\CLSID\{D3075F87-A7BD-4231-9F6A-60C5E07374A7}] - (.-.) - %windir%\system32\acppage.dll [HKCR\CLSID\{D6FCA954-F7AE-4EAC-8783-85F5E4ABD840}] - (.-.) - %windir%\system32\F12\pdmproxy100.dll [HKCR\CLSID\{D719897A-B07A-4C0C-AEA9-9B663A28DFCB}] - (.© 2003-2008 Apple Inc. - ITDetector Module.) - C:\Program Files (x86)\iTunes\ITDetector.ocx [06/05/2014 06:13:10] [HKCR\CLSID\{D73D05A6-07E5-4B70-8198-6F556D46F6BE}] - (.EasyBits Software AS -.) - C:\PROGRA~2\EASYBI~1\Programs\EASYLE~1\ELARIT~1.OCX [16/03/2011 14:00:00] [HKCR\CLSID\{DFA14C43-F385-4170-99CC-1B7765FA0E4A}] - (.-.) - C:\Windows\SysWOW64\wpcumi.dll [HKCR\CLSID\{E54729E8-BB3D-4270-9D49-7389EA579090}] - (.EasyBits Software Corp. - EasyBits Security Shield component.) - C:\Windows\SysWOW64\ezUPBHook.dll [15/06/2012 22:22:40] [HKCR\CLSID\{e8cc4cbe-fdff-11d0-b865-00a0c9081c1d}] - (.-.) - C:\Program Files\Common Files\System\Ole DB\msdaora.dll [HKCR\CLSID\{e8cc4cbf-fdff-11d0-b865-00a0c9081c1d}] - (.-.) - C:\Program Files\Common Files\System\Ole DB\msdaora.dll [HKCR\CLSID\{E9D58BF1-0070-4fcd-B722-A0EE5A3ABCD6}] - (.© 2003-2014 Apple Inc. - iTunes Administrative DLL.) - C:\Program Files (x86)\iTunes\iTunesAdmin.dll [01/09/2014 06:47:52] [HKCR\CLSID\{EA91E968-EF93-4FF1-86F3-75CC93416DF2}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll [HKCR\CLSID\{EB59852D-B38E-4A4C-94BA-6731836E5538}] - (.© 2002-2012 Research In Motion Limited. - RIM Handheld Communications Manager Properties.) - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll [17/06/2013 16:46:14] [HKCR\CLSID\{EBF2320A-2502-11D3-8BD1-00600893B1B6}] - (.-.) - C:\WINDOWS\System32\dmscript.dll [HKCR\CLSID\{F49C559D-E9E5-467C-8C18-3326AAE4EBCC}] - (.-.) - C:\Program Files (x86)\Microsoft SQL Server Compact Edition\v3.5\sqlceoledb35.dll [HKCR\CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}] - (.-.) - %windir%\system32\amsi.dll ---------- | Listing No Microsoft signed files | system32 (Not necessary Malwares) [MD5.1AF5C2DF252F0572BBB34A913A5E5663] - |D| - [14/07/2009 08:45:49] - (.-.) - [30.73 Ko] - (0.0.0.0) - C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [MD5.1AF5C2DF252F0572BBB34A913A5E5663] - |D| - [14/07/2009 08:45:49] - (.-.) - [30.73 Ko] - (0.0.0.0) - C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [MD5.C65F3DD5C512B0E73984DB406B5512F7] - |D| - [30/10/2015 11:17:53] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@edptoastimage.png [MD5.373CF57FF3DAAEEB629F90CE7226B30D] - |D| - [30/10/2015 11:18:12] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@language_notification_icon.png [MD5.373CF57FF3DAAEEB629F90CE7226B30D] - |D| - [30/10/2015 11:18:10] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@optionalfeatures.png [MD5.9971B035154F5C54948B73A86D6C6874] - |D| - [30/10/2015 11:18:14] - (.-.) - [0.12 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@TileEmpty1x1Image.png [MD5.7AC3EA1A5175106ED6467FF0C5315541] - |D| - [30/10/2015 11:17:39] - (.-.) - [14.75 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@WiFiNotificationIcon.png [MD5.5DAB32D5C7C77C021B94D15FD79CA0CF] - |D| - [07/02/2014 14:02:35] - (.Copyright 2014 by Autodesk, Inc. - AutoCAD component.) - [35.32 Ko] - (20.0.51.0) - C:\WINDOWS\system32\AcSignExt.dll [MD5.ADBBDDDA29FD0A8B36267EC8EBE0A898] - |D| - [14/02/2014 04:18:46] - (.Copyright 2014 by Autodesk, Inc. - AutoCAD component.) - [17.82 Ko] - (20.0.51.0) - C:\WINDOWS\system32\AcSignExtRes.dll [MD5.4220B98E5159A10C7562DF04999A0AF4] - |D| - [07/02/2014 14:02:36] - (.Copyright 2014 by Autodesk, Inc. - AutoCAD component.) - [46.82 Ko] - (20.0.51.0) - C:\WINDOWS\system32\AcSignIcon.dll [MD5.9F07CB347E986D271A63950577437050] - |D| - [07/02/2014 14:02:35] - (.Copyright 2014 by Autodesk, Inc. - AutoCAD component.) - [425.82 Ko] - (20.0.51.0) - C:\WINDOWS\system32\AcSignOpt.exe [MD5.926C753C058B5E589CF38AAC72166702] - |D| - [30/10/2015 11:17:41] - (.-.) - [404.84 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ApnDatabase.xml [MD5.9B034D049D1C6EC9BED55D2F27D86ED9] - |D| - [11/06/2016 12:50:35] - (.-.) - [2.13 Ko] - (0.0.0.0) - C:\WINDOWS\system32\AppxProvisioning.xml [MD5.4E118AC95A15BD14B8C1E49C5B4CD79B] - |D| - [14/07/2016 10:49:30] - (.Copyright (c) 2014 AVAST Software - avast! start-up scanner.) - [381.82 Ko] - (12.1.3076.0) - C:\WINDOWS\system32\aswBoot.exe [MD5.D638E3AD81E149A75EEF59E9C743E27C] - |D| - [30/10/2015 11:24:33] - (.-.) - [0.38 Ko] - (0.0.0.0) - C:\WINDOWS\system32\AutoWorkplace.exe.config [MD5.1CD28D4B4EA91CE7FAC80578E87B6A68] - |D| - [15/06/2012 22:12:28] - (.-.) - [57.72 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Balen&Yeats.xml [MD5.06AB6C6F8CB4195D459C7EE4B825236C] - |D| - [10/06/2016 19:55:51] - (.-.) - [41.49 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Balen&Yeats_dv7.xml [MD5.84512088476EDBC06B0F0A99EE57AD89] - |D| - [15/06/2012 22:15:31] - (.-.) - [6.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\bcmwlrc.dll [MD5.4DB832701EA2D47F325ED11F012F7338] - |D| - [10/06/2016 19:55:51] - (.-.) - [3.69 Ko] - (0.0.0.0) - C:\WINDOWS\system32\bltinmic.ico [MD5.22D9945B4AAE36DD59620A918F2E65F4] - |D| - [30/10/2015 11:17:46] - (.-.) - [3096 Ko] - (0.0.0.0) - C:\WINDOWS\system32\boot.sdi [MD5.405E1EF8E3C88E9BCD2853382BB12430] - |D| - [30/10/2015 11:19:28] - (.-.) - [22.45 Ko] - (0.0.0.0) - C:\WINDOWS\system32\bopomofo.uce [MD5.6EC6A5D8C388FCE5792805DC8C736E87] - |D| - [30/10/2015 11:17:40] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [92 Ko] - (1.0.0.1) - C:\WINDOWS\system32\BthpanContextHandler.dll [MD5.6E5DAEBB08D93B3630F2DA9B4FACC05B] - |D| - [30/10/2015 11:18:10] - (.Copyright (C) 2008 - Application ContextH.) - [54 Ko] - (1.0.0.1) - C:\WINDOWS\system32\BWContextHandler.dll [MD5.CCEAEFAA4DF2F399E9A179D942FEB23C] - |D| - [30/10/2015 11:18:01] - (.-.) - [163.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\chs_singlechar_pinyin.dat [MD5.EC98366AD462383659681BDFFD384CED] - |D| - [14/07/2009 05:20:28] - (.Copyright CANON INC. 2008 All Rights Reserved - Canon Inkjet Printer Driver.) - [261.5 Ko] - (0.3.1536.1) - C:\WINDOWS\system32\CNBLM4.DLL [MD5.EC55351788F229C98BCD657ED0B46893] - |D| - [22/05/2007 02:00:00] - (.Copyright CANON INC. 2000-2007 All Rights Reserved - IJ Language Monitor.) - [252.5 Ko] - (0.3.0.1) - C:\WINDOWS\system32\CNMLM94.DLL [MD5.B2241C7E71A7CA5B4CE86FB28FA97373] - |D| - [30/10/2015 11:18:07] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-appcmd.searchconnector-ms [MD5.2B405BCB2A2BDEC47D35D0A921E5B10B] - |D| - [30/10/2015 11:18:06] - (.-.) - [0.52 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-contacts.searchconnector-ms [MD5.8A063B4755E352DD772D43D5E8123BBB] - |D| - [30/10/2015 11:18:06] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-history.searchconnector-ms [MD5.A727FC8376E18F7506A6BB6BC389E602] - |D| - [30/10/2015 11:18:07] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-music.searchconnector-ms [MD5.80CC9D3D6A70AAA255C0FEDB4C7BB692] - |D| - [30/10/2015 11:18:06] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-paths.searchconnector-ms [MD5.1420FE34B31CBD3B81011E03ACAD94F2] - |D| - [30/10/2015 11:18:07] - (.-.) - [0.52 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-protocol.searchconnector-ms [MD5.E7B53AF004BEE5112F787A6E5B04D737] - |D| - [30/10/2015 11:18:06] - (.-.) - [10.85 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms [MD5.ACB02726235DF588BF8D5A4FF54379DF] - |D| - [30/10/2015 11:18:06] - (.-.) - [7.6 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-suggestions.searchconnector-ms [MD5.0E3D116A4DC1D2ABDD0692C6173E09E6] - |D| - [30/10/2015 11:18:06] - (.-.) - [6.98 Ko] - (0.0.0.0) - C:\WINDOWS\system32\connectedsearch-zeroinput.searchconnector-ms [MD5.A71D446195E2B8090621C884D5DC3532] - |D| - [13/07/2016 20:51:59] - (.-.) - [2594.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\CoreUIComponents.dll [MD5.59075B2A63DF6A568123218BF4DC2696] - |D| - [11/07/2015 00:46:24] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\CustomModeApp.exe.config [MD5.899E708E589C09700BFF1C73CB7D7002] - |D| - [11/07/2015 00:46:24] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\CustomModeAppv2_0.exe.config [MD5.306B90493D00011EB635E161C6C024B8] - |D| - [30/10/2015 11:17:57] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DefaultHrtfs.bin [MD5.664AA698FC0106A2B075A641E8DC6302] - |D| - [30/10/2015 11:24:34] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DefaultQuestions.json [MD5.F938469DAF278EE42E32CE2ED5400172] - |D| - [30/10/2015 11:17:46] - (.-.) - [90.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DiskSnapshot.conf [MD5.0E2B7D35E3DDD21AF04FB4D98C2BCF7F] - |D| - [30/12/2015 23:52:34] - (.-.) - [308.83 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DisplayAudiox64.cab [MD5.59075B2A63DF6A568123218BF4DC2696] - |D| - [11/07/2015 00:46:26] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DPTopologyApp.exe.config [MD5.899E708E589C09700BFF1C73CB7D7002] - |D| - [11/07/2015 00:46:26] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DPTopologyAppv2_0.exe.config [MD5.8C6F56F4CDDE6A1FD01F4FCF2773298E] - |D| - [30/10/2015 11:24:34] - (.-.) - [210.88 Ko] - (0.0.0.0) - C:\WINDOWS\system32\dssec.dat [MD5.30B4EC182373056C7AE758B72B83E8D5] - |D| - [30/10/2015 11:17:52] - (.-.) - [166.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\EditionUpgradeHelper.dll [MD5.33D9CB37446952603C170F80B2C897BB] - |D| - [30/10/2015 11:17:52] - (.-.) - [28 Ko] - (0.0.0.0) - C:\WINDOWS\system32\efsext.dll [MD5.F9DB048B202876AABFEFD4ABE9D3111A] - |D| - [10/06/2016 20:27:43] - (.-.) - [22.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\emptyregdb.dat [MD5.93E76CF7B04EC33A1E9E0FD7546D3603] - |D| - [30/10/2015 11:17:45] - (.-.) - [17.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\EventViewer_EventDetails.xsl [MD5.BAC5074667751F72A9CE48CDC31BAC48] - |D| - [01/02/2013 23:27:42] - (.Copyright (C) 2007 SEIKO EPSON CORP. - E_GCINST.) - [10.5 Ko] - (1.0.0.6) - C:\WINDOWS\system32\E_GCINST.DLL [MD5.28D7498FC2EEFB421602A115B11A949C] - |D| - [01/02/2013 23:27:40] - (.Copyright (C) SEIKO EPSON CORPORATION 2005-2010. - ECBTEGB AMD64.) - [81.5 Ko] - (3.2.0.0) - C:\WINDOWS\system32\E_YD4BHTE.DLL [MD5.6FE91BDE1F8B9FD1A49D434643DE1370] - |D| - [01/02/2013 23:27:40] - (.Copyright (C) SEIKO EPSON CORPORATION 2005-2010. - EPSON Bi-directional Monitor AMD64.) - [116 Ko] - (3.1.0.0) - C:\WINDOWS\system32\E_YLMHTE.DLL [MD5.BEF27B179426A8D21C94B92B12791DF8] - |D| - [27/04/2016 00:39:15] - (.-.) - [433.29 Ko] - (0.0.0.0) - C:\WINDOWS\system32\FNTCACHE.DAT [MD5.7EB29DBB6CB2CACD1C7027B8E050DED8] - |D| - [30/10/2015 11:18:09] - (.-.) - [24.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\GamePanelExternalHook.dll [MD5.0FEE8DB559981D7F06E26042ECD8D671] - |D| - [30/10/2015 11:17:39] - (.-.) - [73.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\gatherNetworkInfo.vbs [MD5.4FDED87068052EEB9B72A97FDBC141DB] - |D| - [30/10/2015 11:19:28] - (.-.) - [23.44 Ko] - (0.0.0.0) - C:\WINDOWS\system32\gb2312.uce [MD5.5C7B8533FEC9E65368D14965EC4C9D8A] - |D| - [21/08/2012 16:01:20] - (.Copyright © 2000-2012 GEAR Software Inc. - GEARAspi.) - [122.92 Ko] - (2.1.3.1) - C:\WINDOWS\system32\GEARAspi64.dll [MD5.899E708E589C09700BFF1C73CB7D7002] - |D| - [11/07/2015 00:46:28] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Gfxv2_0.exe.config [MD5.59075B2A63DF6A568123218BF4DC2696] - |D| - [11/07/2015 00:46:30] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Gfxv4_0.exe.config [MD5.E3F76DF0119A00413579025C0CB319B6] - |D| - [10/06/2016 19:55:51] - (.-.) - [67.83 Ko] - (0.0.0.0) - C:\WINDOWS\system32\hpbeats.ico [MD5.1A4695BDC5017B37E6D23A88CFEC0760] - |D| - [24/02/2012 17:54:09] - (.Copyright (C) 2011 -.) - [114.5 Ko] - (1.3.0.0) - C:\WINDOWS\system32\HPMUIDir.exe [MD5.65264A0B35149AB00AF1A856B4E63035] - |D| - [10/06/2016 19:55:52] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [219 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\HPToneCtrls64.dll [MD5.D41D8CD98F00B204E9800998ECF8427E] - |D| - [06/12/2012 19:43:34] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt [MD5.E635EEC491CBD436095B4300C3E9C4C9] - |D| - [30/10/2015 11:17:57] - (.-.) - [340.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\HrtfApo.dll [MD5.69EA6698680C130BB37C7CE74B70E583] - |D| - [03/05/2016 23:30:46] - (.-.) - [109.01 Ko] - (0.0.0.0) - C:\WINDOWS\system32\IccLibDll_x64.dll [MD5.ECD81B99477AB4A93D7838EB40B870D0] - |D| - [30/10/2015 11:24:35] - (.-.) - [8.59 Ko] - (0.0.0.0) - C:\WINDOWS\system32\icrav03.rat [MD5.038F6AD6CEE43585D814CDBC7CDFD3EC] - |D| - [30/10/2015 11:19:28] - (.-.) - [59.04 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ideograf.uce [MD5.75B6DE8FC5B4BFF7620A3D9FE1D02539] - |D| - [10/06/2016 19:55:51] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [1778.5 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\IDTNC64.cpl [MD5.5FCF790D74A047E6F44BD5607B7205C7] - |D| - [10/06/2016 19:55:51] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [7799 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\IDTNGUI.exe [MD5.E4BD542524F562379967C79E87B69F7B] - |D| - [10/06/2016 19:55:51] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [7503.5 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\IDTNHP.dll [MD5.9292C0A715703B5624B34EFDC8B046EB] - |D| - [10/06/2016 19:55:51] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [247 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\IDTNJ.exe [MD5.7FD170CC1F4FB6670777CC78D2E274AA] - |D| - [10/06/2016 19:55:51] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [2160 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\IDTNX.dll [MD5.6B31D08801D3A3F51B59FB1DB14E4A01] - |D| - [30/10/2015 11:18:41] - (.-.) - [3.38 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ieuinit.inf [MD5.B6E428E02148357877B157CC0639DA9E] - |D| - [03/05/2016 23:30:44] - (.-.) - [175.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igdail64.dll [MD5.3E492F4CC8B2A725C51B68086593CCA1] - |D| - [03/05/2016 23:30:46] - (.-.) - [233.01 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igdde64.dll [MD5.8D48192378591B7020555BE0F2053F7D] - |D| - [03/05/2016 23:30:46] - (.Copyright (C) 2012-2013 - MDF(CM) Runtime DX11 Dynamic Link Library.) - [197.51 Ko] - (3.0.0.1284) - C:\WINDOWS\system32\igfx11cmrt64.dll [MD5.99381DBFE7D1EC55EBFFC818D5B4C261] - |D| - [03/05/2016 23:30:46] - (.Copyright (C) 2010 - 2013 - MDF(CM) JIT Dynamic Link Library.) - [1996.51 Ko] - (3.0.0.1284) - C:\WINDOWS\system32\igfxcmjit64.dll [MD5.FA1BC8B5D88A67BF5893BEB18729E0D8] - |D| - [03/05/2016 23:31:28] - (.Copyright (C) 2010 - 2013 - MDF(CM) Runtime Dynamic Link Library.) - [204.73 Ko] - (3.0.0.1284) - C:\WINDOWS\system32\igfxcmrt64.dll [MD5.BE8148B25062A0008741050DDC831CD3] - |D| - [03/05/2016 23:30:46] - (.-.) - [266.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igfxCPL.cpl [MD5.A93B4E0D9F460480D6273A3D77CBC41B] - |D| - [03/05/2016 23:30:46] - (.-.) - [101.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igfxCUIServicePS.dll [MD5.2645C797FA81819282FFA26F1B1743B2] - |D| - [03/05/2016 23:30:46] - (. - .) - [75.51 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxDHLib.dll [MD5.78D2D935BE4765FDB8161552F2522181] - |D| - [03/05/2016 23:30:46] - (. - .) - [85.01 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxDHLibv2_0.dll [MD5.C6B5714EE703CE75BF4CC2F0A068C7C2] - |D| - [03/05/2016 23:30:46] - (. - .) - [27.51 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxDILib.dll [MD5.B4607D004BAC24D0204FB60FC5A28D48] - |D| - [03/05/2016 23:30:46] - (. - .) - [27.51 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxDILibv2_0.dll [MD5.BDB7715B7121BAC65B49ED1A20EB4762] - |D| - [03/05/2016 23:30:46] - (. - .) - [27.01 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxEMLib.dll [MD5.DC09F79852DFE9A957ADC4A917AAE29D] - |D| - [03/05/2016 23:30:46] - (. - .) - [27.01 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxEMLibv2_0.dll [MD5.CE12AB540A39C6D695DD556118150A2D] - |D| - [03/05/2016 23:30:46] - (. - .) - [22.01 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxLHMLib.dll [MD5.26D5D96A154CA199F3F11DCE1242B29F] - |D| - [03/05/2016 23:30:46] - (. - .) - [22.01 Ko] - (1.0.0.0) - C:\WINDOWS\system32\igfxLHMLibv2_0.dll [MD5.6C0F36ABFE80433B352FA7748ED887BF] - |D| - [11/07/2015 00:29:50] - (.-.) - [2748 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxa64.cpa [MD5.2FCCF7939D4D3F392AB3C0F5F40039DD] - |D| - [11/07/2015 00:29:50] - (.-.) - [1.1 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxa64.vp [MD5.B226B85123619EF1394339C1B5EB5A8D] - |D| - [11/07/2015 00:29:50] - (.-.) - [42.47 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxc64.vp [MD5.55C71EDC47B57E5115B40095EEC9E205] - |D| - [11/07/2015 00:29:50] - (.-.) - [42.79 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxc64_dev.vp [MD5.94ED4F871997E5DFC610DC1649C38911] - |D| - [11/07/2015 00:29:50] - (.-.) - [42.24 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxg64.vp [MD5.04590E9E52E13EF34B2AA02C7EA2431B] - |D| - [11/07/2015 00:29:50] - (.-.) - [42.28 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxg64_dev.vp [MD5.3B6EF4F03F2DE75A3B7DDF627A3EC146] - |D| - [11/07/2015 00:29:50] - (.-.) - [42.99 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxo64.vp [MD5.715DBDBED4599E798F94EDF6003F75B6] - |D| - [11/07/2015 00:29:50] - (.-.) - [41.09 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxo64_dev.vp [MD5.6E9392C7BC5A96AAC89882D910A6F2AD] - |D| - [30/12/2015 23:52:52] - (.-.) - [2.52 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxs64.vp [MD5.AAA0C03BF54FC8A4E895B576861A9848] - |D| - [21/11/2010 07:07:41] - (.-.) - [29.12 Ko] - (0.0.0.0) - C:\WINDOWS\system32\InstallPackage_ETW.Log [MD5.3FF007DCE48038E858DA50353324D50D] - |D| - [03/05/2016 23:30:46] - (.Copyright © The Khronos Group Inc 2011 - OpenCL Client DLL.) - [79.51 Ko] - (1.2.11.0) - C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll [MD5.652C6CF73BE7AD53D8EECB92D37F3EDE] - |D| - [30/10/2015 11:18:01] - (.-.) - [181.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ism32k.dll [MD5.7C0C25F4BA1084C4ABBEEA2C74194C5F] - |D| - [30/10/2015 11:19:28] - (.-.) - [6.79 Ko] - (0.0.0.0) - C:\WINDOWS\system32\kanji_1.uce [MD5.529BBD63519BBD654EF328454019693F] - |D| - [30/10/2015 11:19:28] - (.-.) - [8.29 Ko] - (0.0.0.0) - C:\WINDOWS\system32\kanji_2.uce [MD5.7A7A04370A6030B9B0E8178DAD4A6E41] - |D| - [30/10/2015 11:19:28] - (.-.) - [12.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\korean.uce [MD5.251C002837808A2F421A73CB9F8E2239] - |D| - [30/10/2015 11:17:36] - (.Copyright © 1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS - MPEG Layer-3 Audio Codec for MSACM.) - [85 Ko] - (1.9.0.401) - C:\WINDOWS\system32\l3codeca.acm [MD5.9C0B73FE241261A8C447407DDA4EC7F3] - |D| - [30/10/2015 11:17:36] - (.Copyright © 2004 Fraunhofer IIS - MPEG Audio Layer-3 Codec for MSACM.) - [180 Ko] - (3.4.0.0) - C:\WINDOWS\system32\l3codecp.acm [MD5.050BC9351A3386458B696F8BCA78B27B] - |D| - [30/10/2015 11:17:57] - (.-.) - [145.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\LargeRoom.bin [MD5.531FE5A2634D87A078017259F21D9736] - |D| - [30/10/2015 11:18:19] - (.-.) - [206.97 Ko] - (0.0.0.0) - C:\WINDOWS\system32\lcphrase.tbl [MD5.D3C85593F8C4576FCF9B42AC48CA4368] - |D| - [30/10/2015 11:18:19] - (.-.) - [23.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\lcptr.tbl [MD5.10B2D2D402319E647C90A2E1908C8DBB] - |D| - [10/06/2016 20:47:08] - (.-.) - [49.47 Ko] - (0.0.0.0) - C:\WINDOWS\system32\license.rtf [MD5.E89C001FB4D9E08CC7072CE774CDB999] - |D| - [21/11/2010 06:52:07] - (.-.) - [0.01 Ko] - (0.0.0.0) - C:\WINDOWS\system32\LocalGroupAdminAdd.log [MD5.563C3703A9B57CC9B370A76D6173D09C] - |D| - [21/11/2010 06:52:08] - (.-.) - [0.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Local_LLU.log [MD5.BC74BDA8DC53F722C2CA686071600AE2] - |D| - [30/10/2015 11:17:57] - (.-.) - [107.45 Ko] - (0.0.0.0) - C:\WINDOWS\system32\MediumRoom.bin [MD5.ED434A3EBE29070A7E0138C42482EB93] - |D| - [30/10/2015 11:18:14] - (.-.) - [657.31 Ko] - (0.0.0.0) - C:\WINDOWS\system32\mlang.dat [MD5.18403DE4979A328F21279DECB2E4298F] - |D| - [30/10/2015 11:18:42] - (.-.) - [3.32 Ko] - (0.0.0.0) - C:\WINDOWS\system32\msmqpub.mof [MD5.E0640DE5407EEE4C6E16D839243B71F9] - |D| - [30/10/2015 11:18:42] - (.-.) - [8.88 Ko] - (0.0.0.0) - C:\WINDOWS\system32\msmqtrc.mof [MD5.3ED9AC3EE11EE2C16E2E41F0DC4BAD42] - |D| - [30/10/2015 11:18:42] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\msmqtrcRemove.mof [MD5.AB416599057FFDC84E28BBB6DA69EADC] - |D| - [11/06/2016 12:50:36] - (.-.) - [229.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\MTF.dll [MD5.72534830694CCABA9A5CBA33F9771C63] - |D| - [27/04/2016 09:16:33] - (.-.) - [254.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\MTFServer.dll [MD5.937CF6954D64AF5811EC1BE4ECBF60E8] - |D| - [10/06/2016 19:55:51] - (.-.) - [13.62 Ko] - (0.0.0.0) - C:\WINDOWS\system32\nbspkrsbeats.ico [MD5.3DDE8AC5E84FD43735194C0AADED443C] - |D| - [15/06/2012 22:21:46] - (.-.) - [0.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ndCPrepLog [MD5.86166DAA04A6C154826508304CC6D4AC] - |D| - [30/10/2015 11:17:40] - (.-.) - [0.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NdfEventView.xml [MD5.AC5F8EAE44B2E34FFA8B86A0EB8C576B] - |D| - [10/06/2016 19:53:45] - (.-.) - [29.41 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NetSetupMig.log [MD5.C146E873B22C3B300B21A859FE66C27A] - |D| - [30/10/2015 11:17:39] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NetTrace.PLA.Diagnostics.xml [MD5.8E24A7BCAEF2045DA1FF29217622843E] - |D| - [21/11/2010 06:52:07] - (.-.) - [0.04 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Network_LLU.log [MD5.79BD0E63A9E54ED8AFFD19F43B5B83F2] - |D| - [27/04/2016 09:16:33] - (.Copyright (C) Nokia 2013 - master branch.) - [258 Ko] - (8.1.0.65535) - C:\WINDOWS\system32\NmaDirect.dll [MD5.DE78E0C57BC478D47CC2F470B68E1A45] - |D| - [30/10/2015 11:24:36] - (.-.) - [0.72 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NOISE.DAT [MD5.B071773BB3252D6921B85D313D45F3B2] - |D| - [23/07/2015 04:02:12] - (.-.) - [41728.82 Ko] - (0.0.0.0) - C:\WINDOWS\system32\nvcompiler.dll [MD5.40E604813893D9F9E04711089F5A6E16] - |D| - [15/06/2012 22:11:39] - (.-.) - [5001.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\nvcoproc.bin [MD5.5555A3D9F21DF390DA76A3EDF702B53B] - |D| - [23/07/2015 04:02:12] - (.-.) - [31.23 Ko] - (0.0.0.0) - C:\WINDOWS\system32\nvinfo.pb [MD5.5D27362AF3BCAA75A418F5416A35934E] - |D| - [30/10/2015 11:17:55] - (.-.) - [0.26 Ko] - (0.0.0.0) - C:\WINDOWS\system32\odbcconf.rsp [MD5.8027CE5492ECE1AAFA04B482F71D1A8D] - |D| - [15/06/2012 22:15:51] - (.-.) - [1046.09 Ko] - (0.0.0.0) - C:\WINDOWS\system32\oem21.inf [MD5.3371F9C04BC57D048DBD5DBAC4A7C2B6] - |D| - [10/06/2016 19:55:21] - (.-.) - [1063.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\oem22.inf [MD5.3371F9C04BC57D048DBD5DBAC4A7C2B6] - |D| - [11/04/2014 23:39:44] - (.-.) - [1063.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\oem47.inf [MD5.DE4FA2E0FBF5D7CAF54977DE21949EC2] - |D| - [30/10/2015 11:24:36] - (.-.) - [15.33 Ko] - (0.0.0.0) - C:\WINDOWS\system32\OEMDefaultAssociations.xml [MD5.2901049544FDF863362FABA2363EB647] - |D| - [30/10/2015 11:17:50] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\system32\onlinesetup.cmd [MD5.3FF007DCE48038E858DA50353324D50D] - |D| - [10/06/2016 21:14:21] - (.Copyright © The Khronos Group Inc 2011 - OpenCL Client DLL.) - [79.51 Ko] - (1.2.11.0) - C:\WINDOWS\system32\OpenCL.dll [MD5.42D2360079B1DF3230024AE920737367] - |D| - [30/10/2015 11:17:57] - (.-.) - [45.81 Ko] - (0.0.0.0) - C:\WINDOWS\system32\OutdoorAudioEnvironment.bin [MD5.66D58077CC739E4B8166E33AB0BA4639] - |D| - [30/10/2015 11:18:09] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\pcl.sep [MD5.399A37832E558EAD8CD2CFC00173946F] - |D| - [30/10/2015 11:26:16] - (.-.) - [169.33 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfc009.dat [MD5.DA3517D2FF4B43F96509FBC02E6549F1] - |D| - [27/04/2016 09:12:16] - (.-.) - [194.85 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfc00C.dat [MD5.32BC2E0CC95E2DCEE25B15BFB82D07B8] - |D| - [30/10/2015 11:26:16] - (.-.) - [32.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfd009.dat [MD5.AA180E09E4990FF71FBEAC8C4455CF47] - |D| - [27/04/2016 09:12:16] - (.-.) - [39.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfd00C.dat [MD5.ECE18A83AA778BD528DBB15565505378] - |D| - [30/10/2015 11:26:16] - (.-.) - [811.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfh009.dat [MD5.94CC2C2886901514CF20DF00EDC22970] - |D| - [27/04/2016 09:12:16] - (.-.) - [914.54 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfh00C.dat [MD5.E3224A3E1F41815D246737757A935F09] - |D| - [10/06/2016 20:00:08] - (.-.) - [2089.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\PerfStringBackup.INI [MD5.A3D81AC71FA806EB9A95A257F5A00CCE] - |D| - [14/02/2014 04:19:42] - (.Copyright 2014 Autodesk, Inc. - Autodesk Hardcopy component.) - [2630.82 Ko] - (12.0.51.0) - C:\WINDOWS\system32\plotman.cpl [MD5.C09741B9886EF0D15EC3B1443352FB62] - |D| - [30/10/2015 11:18:09] - (.-.) - [0.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\pscript.sep [MD5.007893E8374C766471239EB291BA8C17] - |D| - [30/10/2015 11:17:45] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\psmodulediscoveryprovider.mof [MD5.3A77C18665A4C8428768CE186A5BC1EF] - |D| - [30/10/2015 11:17:39] - (.-.) - [1.78 Ko] - (0.0.0.0) - C:\WINDOWS\system32\rasctrnm.h [MD5.45B13DCD38BD8D5400FCAD7488B3A776] - |D| - [30/12/2015 23:53:10] - (.-.) - [161.07 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resARA.cui [MD5.6659852D082515116691907217EE12CF] - |D| - [30/12/2015 23:53:10] - (.-.) - [145.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resCHS.cui [MD5.4C753D32EE16231059379157A5F13EB2] - |D| - [30/12/2015 23:53:10] - (.-.) - [146.41 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resCHT.cui [MD5.7EE04EA51220641630C60B6C1D381766] - |D| - [30/12/2015 23:53:10] - (.-.) - [152.47 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resCSY.cui [MD5.7500547A42B144BAECCF3FB2F8C394AC] - |D| - [30/12/2015 23:53:10] - (.-.) - [149.44 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resDAN.cui [MD5.90B669D2378C6C604C66E7A3EF10A30E] - |D| - [30/12/2015 23:53:10] - (.-.) - [154.19 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resDEU.cui [MD5.02233DAB3FA1D7E0D29E4A92E39B27EA] - |D| - [30/12/2015 23:53:10] - (.-.) - [179.18 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resELL.cui [MD5.2A494F1A69642804A69EEC07B1961DDA] - |D| - [30/12/2015 23:53:10] - (.-.) - [148.13 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resENU.cui [MD5.93BFE18055C725BE62F326BF21A8BBEE] - |D| - [30/12/2015 23:53:10] - (.-.) - [153.88 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resESN.cui [MD5.D2DC0F286A18CD604D614796EEF43DD7] - |D| - [30/12/2015 23:53:10] - (.-.) - [151.82 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resFIN.cui [MD5.DF222231EEB1A30C571C939E8D093B3E] - |D| - [30/12/2015 23:53:10] - (.-.) - [155.97 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resFRA.cui [MD5.6CFDEC7F925B4FB7B790691604CB45D8] - |D| - [30/12/2015 23:53:10] - (.-.) - [160.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resHEB.cui [MD5.7D71A8DA29E4793E4903A69F7E1904DB] - |D| - [30/12/2015 23:53:10] - (.-.) - [151.43 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resHRV.cui [MD5.2E20C34A1C4187F74B595095E588B661] - |D| - [30/12/2015 23:53:10] - (.-.) - [155.99 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resHUN.cui [MD5.C4635F995A560E940CB53D856C4C2262] - |D| - [30/12/2015 23:53:10] - (.-.) - [154.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resITA.cui [MD5.0B3FF7F09EE2F2CB46E5A6666295E8F4] - |D| - [30/12/2015 23:53:10] - (.-.) - [160.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resJPN.cui [MD5.7A746D9E4CE17816EF79A9D281549C9C] - |D| - [30/12/2015 23:53:10] - (.-.) - [154.3 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resKOR.cui [MD5.F437178473513F674448DDD563E21EC6] - |D| - [30/12/2015 23:53:10] - (.-.) - [153.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resNLD.cui [MD5.C0E4A8CD76BAF7E34DD884C2B11F9157] - |D| - [30/12/2015 23:53:10] - (.-.) - [149.91 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resNOR.cui [MD5.8DA2EE8AF3BA9795D5858A03419E2582] - |D| - [30/12/2015 23:53:10] - (.-.) - [153.46 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resPLK.cui [MD5.226BBC4490EA49B69B407742A85A2D92] - |D| - [30/10/2015 11:19:26] - (.-.) - [8.72 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ResPriHMImageList [MD5.7153DD25B2D727B7281780A3DF33C877] - |D| - [30/10/2015 11:19:26] - (.-.) - [8.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ResPriImageList [MD5.7FF2CC47007D028C70D260CD3BE3A3E9] - |D| - [30/12/2015 23:53:10] - (.-.) - [152.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resPTB.cui [MD5.53BC9C2E21EFB2F6383316B8F7E49B5E] - |D| - [30/12/2015 23:53:10] - (.-.) - [152.29 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resPTG.cui [MD5.DD636076410053695210D7FE335B4612] - |D| - [30/12/2015 23:53:10] - (.-.) - [153.97 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resROM.cui [MD5.D49A6F32AF0C0CACD3E28011752CD7BB] - |D| - [30/12/2015 23:53:10] - (.-.) - [175.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resRUS.cui [MD5.BE427823C85F7356B08F87D7A3652A0F] - |D| - [30/12/2015 23:53:10] - (.-.) - [153.33 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resSKY.cui [MD5.790ABA99CCCA436A7F14BED99054676C] - |D| - [30/12/2015 23:53:10] - (.-.) - [150.86 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resSLV.cui [MD5.B61D17AB060B76EF699D5C561DF5937D] - |D| - [30/12/2015 23:53:10] - (.-.) - [151 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resSVE.cui [MD5.43E7D0AB6A8564F5BF375FBF0934FAD1] - |D| - [30/10/2015 11:17:50] - (.-.) - [0.7 Ko] - (0.0.0.0) - C:\WINDOWS\system32\RestartManager.mof [MD5.3F75A221A01F68D6CE67FE99A868BD8F] - |D| - [30/10/2015 11:17:50] - (.-.) - [0.17 Ko] - (0.0.0.0) - C:\WINDOWS\system32\RestartManagerUninstall.mof [MD5.F92CD71D1F33737C1B44520A4FA46F41] - |D| - [30/12/2015 23:53:10] - (.-.) - [186.39 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resTHA.cui [MD5.6811F7D1D1DD791AD5EF4B34021DDA41] - |D| - [30/12/2015 23:53:10] - (.-.) - [152.46 Ko] - (0.0.0.0) - C:\WINDOWS\system32\resTRK.cui [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |D| - [30/10/2015 11:19:26] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ScavengeSpace.xml [MD5.00E5FCFD833151F7CBDE607E2F7AFEB4] - |D| - [30/10/2015 11:19:28] - (.-.) - [5.66 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SecurityAndMaintenance.png [MD5.5719BFC9CFDA7A9C059A71A47A0E6383] - |D| - [30/10/2015 11:19:28] - (.-.) - [2.56 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SecurityAndMaintenance_Alert.png [MD5.099BA37F81C044F6B2609537FDB7D872] - |D| - [30/10/2015 11:19:28] - (.-.) - [6.72 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SecurityAndMaintenance_Error.png [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |D| - [30/10/2015 11:17:43] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\system32\settings.dat [MD5.8CA32E9D986FA76F60EFBCFCD9D80A58] - |D| - [30/10/2015 11:19:28] - (.-.) - [16.35 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ShiftJIS.uce [MD5.612C713CF5E2224213BD03FF9D7B3545] - |D| - [10/06/2016 19:55:51] - (.(c) 2010 SRS Labs, Inc. - SRS APO COM Interface.) - [453.5 Ko] - (1.1.3.0) - C:\WINDOWS\system32\slapoi64.dll [MD5.3903BCAB32A4A853DFA54962112D4D02] - |D| - [30/10/2015 11:17:53] - (.-.) - [139.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\slmgr.vbs [MD5.1C6F12AA3D178A0A953E8005B3CD4CDE] - |D| - [30/10/2015 11:17:57] - (.-.) - [68.14 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SmallRoom.bin [MD5.C1AA14DBA23EB5AE5044727DF182FE5C] - |D| - [30/10/2015 11:17:46] - (.-.) - [54.8 Ko] - (0.0.0.0) - C:\WINDOWS\system32\srms.dat [MD5.98A46D5F20447697C11E6FECBE7C01B8] - |D| - [10/10/2013 19:44:48] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [249.5 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\staco64.dll [MD5.D1A4C41AC2E15B2BC54AE3A120FB9C4C] - |D| - [10/10/2013 19:44:49] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [641.5 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\stapi64.dll [MD5.AF4A205229B7755088B5038F6A6BAAC8] - |D| - [10/10/2013 19:44:49] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [1941.5 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\stapo64.dll [MD5.B59958CD06C9F89C39281FB12F1BB233] - |D| - [30/10/2015 11:18:42] - (.-.) - [513.74 Ko] - (0.0.0.0) - C:\WINDOWS\system32\staticurllist.bin [MD5.FE2ED28D793B13D278CC2AEBC2E9D912] - |D| - [10/10/2013 19:44:50] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [439.5 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\stcplx64.dll [MD5.923657D22AF581ACA6225239B9575B8E] - |D| - [10/06/2016 19:55:51] - (.Copyright © 2004 - 2009 IDT, Inc. - IDT PC Audio.) - [5943 Ko] - (1.0.6418.0) - C:\WINDOWS\system32\stlang64.dll [MD5.1B150412BDA69981A1740E90DEB265C1] - |D| - [14/02/2014 04:19:48] - (.Copyright 2014 Autodesk, Inc. - Autodesk Hardcopy component.) - [2630.82 Ko] - (12.0.51.0) - C:\WINDOWS\system32\styleman.cpl [MD5.30F5568679A54042F99CA9EC1102EBCD] - |D| - [30/10/2015 11:19:28] - (.-.) - [91.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SubRange.uce [MD5.D69ED8FF3D054122060A411601BBB37A] - |D| - [14/10/2011 08:35:00] - (.Copyright (C) Synaptics Incorporated 1996-2015 - SynCOM.) - [754.01 Ko] - (19.0.12.98) - C:\WINDOWS\system32\SynCOM.dll [MD5.45E7155675477D71380490AB3BE8246A] - |D| - [14/10/2011 08:35:02] - (.Copyright (C) Synaptics Incorporated 1996-2011 - SynCtrl.) - [271.29 Ko] - (15.3.29.0) - C:\WINDOWS\system32\SynCtrl.dll [MD5.2111EFF8E2DFD04C0E25041DD6392E4F] - |D| - [15/09/2011 06:11:16] - (.-.) - [1024 Ko] - (0.0.0.0) - C:\WINDOWS\system32\syndata.bin [MD5.8C31C7742FBA26B4AC0EF9878288CFF4] - |D| - [14/10/2011 08:35:08] - (.Copyright (C) Synaptics Incorporated 1996-2015 - SynTPAPI.) - [268.52 Ko] - (19.0.12.98) - C:\WINDOWS\system32\SynTPAPI.dll [MD5.D4F925B962863266B965A43972521943] - |D| - [28/04/2016 00:53:50] - (.Copyright (C) Synaptics Incorporated 1996-2015 - Synaptics Pointing Device Driver Co-Installer.) - [261.17 Ko] - (19.0.12.98) - C:\WINDOWS\system32\SynTPCo31-1.dll [MD5.D1535BE8D27B89216D397022E9C37C77] - |D| - [14/10/2011 08:35:08] - (.Copyright (C) Synaptics Incorporated 1996-2011 - Synaptics Pointing Device Driver Co-Installer.) - [145.29 Ko] - (15.3.29.0) - C:\WINDOWS\system32\SynTPCo9.dll [MD5.81B14F1AD906AC1CF9102796C97A54FE] - |D| - [30/10/2015 11:18:09] - (.-.) - [3.24 Ko] - (0.0.0.0) - C:\WINDOWS\system32\sysprint.sep [MD5.58A67EC6B00A54A69DC364194CA171E0] - |D| - [30/10/2015 11:18:09] - (.-.) - [3.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\sysprtj.sep [MD5.31B010EF50D54D548B4B8B211F421318] - |D| - [30/10/2015 11:18:10] - (.-.) - [1.63 Ko] - (0.0.0.0) - C:\WINDOWS\system32\tcpbidi.xml [MD5.D602CA245CC6774A0981B607F0675609] - |D| - [30/10/2015 11:18:09] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\tcpmon.ini [MD5.6D21D0A95286DCD09E354B612F592EB7] - |D| - [30/10/2015 11:24:37] - (.-.) - [1.94 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ticrf.rat [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |D| - [30/10/2015 11:17:47] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WdsUnattendTemplate.xml [MD5.039C8233D4FCE424F5CA9427EF771942] - |D| - [30/10/2015 11:18:19] - (.-.) - [213.34 Ko] - (0.0.0.0) - C:\WINDOWS\system32\weretw.dll [MD5.D87FB0D2599BAE25F3A6D29589AF0D98] - |D| - [30/10/2015 11:17:49] - (.-.) - [2.22 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WimBootCompress.ini [MD5.2BA7DF05213968EFC98867E03687CEDB] - |D| - [30/10/2015 11:17:59] - (.-.) - [401.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Windows.Perception.Stub.dll [MD5.E0974EE3F592223A950B3B0C04797212] - |D| - [30/10/2015 11:19:39] - (.-.) - [1.61 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WindowsCodecsRaw.txt [MD5.7EF8F3CADE2DE177F96B5A5B581D73FF] - |D| - [30/10/2015 11:17:43] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\system32\winrm.cmd [MD5.9D7684F978EBD77E6A3EA7EF1330B946] - |D| - [30/10/2015 11:17:43] - (.-.) - [199.32 Ko] - (0.0.0.0) - C:\WINDOWS\system32\winrm.vbs [MD5.965E1F4E54E12010DDDC7F71950C9C53] - |D| - [30/10/2015 11:17:50] - (.http://www.sqlite.org/copyright.html - SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - [642.46 Ko] - (3.8.8.3) - C:\WINDOWS\system32\winsqlite3.dll [MD5.C30C621748C66CE751B19B2788559A3E] - |D| - [30/10/2015 11:18:42] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wpcmon.png [MD5.F1DF7849450DBC5D5C3A464E8A791C8C] - |D| - [30/10/2015 11:18:42] - (.-.) - [1485.18 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WpcNBModel.bin [MD5.B6B479B04C64AF5EF36C24EBDF278302] - |D| - [30/10/2015 11:18:03] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wpr.config.xml [MD5.930423065AB3F5DB52D5726C7FC66385] - |D| - [30/10/2015 11:17:43] - (.-.) - [4.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wsmanconfig_schema.xml [MD5.D6CBFA113B69C491DE370E85EBAC80E9] - |D| - [30/10/2015 11:17:43] - (.-.) - [1.52 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WsmPty.xsl [MD5.B2EDF82825D979928AE07CBE9C7A2160] - |D| - [30/10/2015 11:17:43] - (.-.) - [2.37 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WsmTxt.xsl [MD5.9D6B8FC71167D22849424084F0F3D9E9] - |D| - [30/10/2015 11:19:41] - (.-.) - [74.28 Ko] - (0.0.0.0) - C:\WINDOWS\system32\xpsrchvw.xml [MD5.684DDBD6ED4066B10660A3A06655B59A] - |D| - [30/10/2015 11:17:42] - (.-.) - [3.92 Ko] - (0.0.0.0) - C:\WINDOWS\system32\xwizard.dtd [MD5.CB136B267569A62EF63D798BC90ABD5A] - |D| - [17/06/2016 22:30:20] - (.-.) - [0.14 Ko] - (0.0.0.0) - C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat [MD5.9F45771914360A925252A1B7226EC7EC] - |D| - [12/06/2016 13:09:55] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat ---------- | Installer [HKCR\Installer\Products\0046AE36C03FC5C4E846A644D8E13901] : HP Software Framework -> C:\Windows\Installer\{63EA6400-F30C-4C5C-8E64-6A448D1E9310}\app_1.exe [HKCR\Installer\Products\03115A601D9CFB64F8750EFE3EBDEFED] : BlackBerry Device Software Updater -> C:\Windows\Installer\{06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0540B5EBBCCD9EF4392EB3838DA847B5] : BlackBerry Desktop Software 7.1 -> C:\Windows\Installer\{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0694AF70830BBE9498B1F95939A05A44] : HP Customer Experience Enhancements -> C:\Windows\Installer\{07FA4960-B038-49EB-891B-9F95930AA544}\ARPPRODUCTICON.exe [HKCR\Installer\Products\134537583DC661B4EB8C593302435EB3] : Autodesk AutoCAD Performance Feedback Tool Version 1.2.2 [HKCR\Installer\Products\1F0AA64F482E87844A26F5119B61C6E0] : iTunes -> C:\Windows\Installer\{F46AA0F1-E284-4878-A462-5F11B9166C0E}\Installer.ico [HKCR\Installer\Products\225748A5C57350D4DBD3884C05CC40F7] : HP Launch Box -> C:\Windows\Installer\{5A847522-375C-4D05-BD3D-88C450CC047F}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\2B0163E6D0340BE4183EB2758E9BEDD8] : Bonjour -> C:\Windows\Installer\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}\Bonjour.ico [HKCR\Installer\Products\2C1A65825C073CE4FA7F5E5BE155032A] : HP Client Services -> C:\Windows\Installer\{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}\ARPPRODUCTICON.exe [HKCR\Installer\Products\2F3ABA1300003301102011D134183577] : Autodesk ReCap -> C:\Windows\Installer\{31ABA3F2-0000-1033-0102-111D43815377}\AutodeskReCapIcon [HKCR\Installer\Products\3AC4F7E6ED2BC3147A1A34AAB51EE91A] : Broadcom Bluetooth Software -> C:\Windows\Installer\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\435B99166B1ADE6478B3790BCE8F8FE1] : Intel® Trusted Connect Service Client [HKCR\Installer\Products\46B5A9879DD95AB419A50FCFA0B1B7EF] : Apple Software Update -> C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\Installer.ico [HKCR\Installer\Products\46E5DCBD973784644944A85685CD6B41] : HP Recovery Manager -> C:\Windows\Installer\{DBCD5E64-7379-4648-9444-8A6558DCB614}\_6FEFF9B68218417F98F549.exe [HKCR\Installer\Products\4EA42A62D9304AC4784BF2381208060F] : Java 8 Update 60 -> C:\Program Files (x86)\Java\jre1.8.0_60\\bin\javaws.exe [HKCR\Installer\Products\50A45C97641F0AE4A8074DFE6E81E125] : HP Support Assistant -> C:\Windows\Installer\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}\ARPPRODUCTICON.exe [HKCR\Installer\Products\52744B0D6663D294EB6F85A741DBB99D] : MSVCRT_amd64 [HKCR\Installer\Products\55120087520F0704583BC74035657110] : Apple Application Support -> C:\Windows\Installer\{78002155-F025-4070-85B3-7C0453561701}\WinInstall.ico [HKCR\Installer\Products\5A812990327ACD34D85B163756A6E149] : Dropbox Update Helper [HKCR\Installer\Products\6116D6C8427B0184F8D20D746E7B6DE8] : Mesh Runtime [HKCR\Installer\Products\624E882B4599C1548B110B2F43FCE0DD] : HP Documentation -> C:\Windows\Installer\{B288E426-9954-451C-B811-B0F234CF0EDD}\NotebookDocs.exe [HKCR\Installer\Products\68AB67CA7DA7FFFFB744AA0000000010] : Adobe Reader X (10.1.5) MUI -> C:\Windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico [HKCR\Installer\Products\69A9FA1138D6B3C4D8BC61AEA253E8F3] : HP CoolSense -> C:\Windows\Installer\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\701043F6AA9F6C745BC43C1AF91155F3] : Hewlett-Packard ACLM.NET v1.2.2.3 -> C:\Windows\Installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\74A569CF9384AC046B81814F680F246C] : Skype™ 7.25 -> C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe [HKCR\Installer\Products\7B65D4CC81F6B0747843BADC57CB4F1F] : HP Auto -> C:\Windows\Installer\{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\7BD4C90EC03660F46A13E87A329932FA] : D3DX10 [HKCR\Installer\Products\7C43C21609E58D74B9C5F017D78D7262] : swMSM -> C:\Windows\Installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726}\ARPPRODUCTICON.exe [HKCR\Installer\Products\7D2F3875100E0000102000060BECB6AB] : AutoCAD 2015 - Français (French) [HKCR\Installer\Products\7D2F3875100EC040112000060BECB6AB] : AutoCAD 2015 Language Pack - Français (French) [HKCR\Installer\Products\7D2F3875100EC040122000060BECB6AB] : AutoCAD 2015 - Français (French) [HKCR\Installer\Products\7E0BA6F1DDC839B4A832AAE92BEFCF4E] : Junk Mail filter update [HKCR\Installer\Products\85BDC73A8EAA0000C8310E7FABBCD0F5] : Autodesk Content Service -> C:\Windows\Installer\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}\appicon.ico [HKCR\Installer\Products\85BDC73A8EAA1000C8310E7FABBCD0F5] : Autodesk Content Service Language Pack [HKCR\Installer\Products\883658EADAFA357418FD9DB6910D1AC7] : HP Setup Manager -> C:\Windows\Installer\{AE856388-AFAD-4753-81DF-D96B19D0A17C}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8994BF104C33134458DE70E9E3FE7ED5] : YouCam -> C:\Windows\Installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\ARPPRODUCTICON.exe [HKCR\Installer\Products\89A71B350FB5CB04AAFF58A0539757CA] : HP Quick Launch -> C:\Windows\Installer\{53B17A98-5BF0-40BC-AAFF-850A357975AC}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\8B3ACAB4A36FDE44A9D8844B0DA22D86] : HP SimplePass -> C:\Windows\Installer\{4BACA3B8-F63A-44ED-9A8D-48B4D02AD268}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8B45D5D892D34BA4D88A8186AD9F148D] : OpenOffice 4.0.1 -> C:\Windows\Installer\{8D5D54B8-3D29-4AB4-8DA8-1868DAF941D8}\soffice.ico [HKCR\Installer\Products\8D4D77630E5ECF948BE66045C10FB0EB] : opensource -> C:\Windows\Installer\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}\ARPPRODUCTICON.exe [HKCR\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E] : Google Update Helper [HKCR\Installer\Products\9A1221D6FB710CE4182F723DE03C7010] : Skype Click to Call -> C:\Windows\Installer\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}\ICON_PRODUCT [HKCR\Installer\Products\9B5ECB8DFC76F3F439EAA3CC57C427BE] : HP Power Manager -> C:\Windows\Installer\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\9EE49AF494B4A9C4B8A8232BCEA56301] : BlackBerry Device Manager 7.0 -> C:\Windows\Installer\{4FA94EE9-4B49-4C9A-8B8A-32B2EC5A3610}\ARPPRODUCTICON.exe [HKCR\Installer\Products\A6C64DD86500CEF47BA082BB611A1FF1] : MSVCRT [HKCR\Installer\Products\A87538AD2BD76FC44935FC427C19A78B] : Validity WBF DDK -> C:\Windows\Installer\{DA83578A-7DB2-4CF6-9453-CF24C7917AB8}\ValidityLogo.ico [HKCR\Installer\Products\A96DB1DE3E70C814191F8D65855218FB] : HP On Screen Display -> C:\Windows\Installer\{ED1BD69A-07E3-418C-91F1-D856582581BF}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\AB251EC861D11E1168D789B41EF571E4] : Evernote v. 4.5.2 -> C:\Windows\Installer\{8CE152BA-1D16-11E1-867D-984BE15F174E}\Evernote.ico [HKCR\Installer\Products\B07F2EBA49D89E44AA400FBD5360D326] : Autodesk Material Library Base Resolution Image Library 2015 -> C:\Windows\Installer\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}\ARPPRODUCTICON.exe [HKCR\Installer\Products\BC993E9FF640DF546AF7FC93E912824E] : HP 3D DriveGuard -> C:\Windows\Installer\{F9E399CB-046F-45FD-A67F-CF399E2128E4}\controlPanelIcon.exe [HKCR\Installer\Products\D54EC5DEB24881C40A20781EE63AB93B] : HP Support Solutions Framework -> C:\Windows\Installer\{ED5CE45D-842B-4C18-A002-87E16EA39BB3}\icon.ico [HKCR\Installer\Products\D5B0FD9FB4552D546889C764F7FAB4AC] : HP Security Assistant -> C:\Windows\Installer\{F9DF0B5D-554B-45D2-8698-7C467FAF4BCA}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\F337F724C6D4CB543942BE4713403C12] : Autodesk Material Library 2015 -> C:\Windows\Installer\{427F733F-4D6C-45BC-9324-EB743104C321}\ARPPRODUCTICON.exe [HKCR\Installer\Products\F3CC0CBE1A7B8CF40841C4B7DF93528E] : AuthenTec TrueAPI 64-bit -> C:\Windows\Installer\{EBC0CC3F-B7A1-4FC8-8014-4C7BFD3925E8}\appicon [HKCR\Installer\Products\F60730A4A66673047777F5728467D401] : Java Auto Updater [HKCR\Installer\Products\F797876B83FD6554A813B818E8628186] : Apple Mobile Device Support -> C:\Windows\Installer\{B678797F-DF38-4556-8A31-8B818E261868}\Installer.ico [HKCR\Installer\Products\FA9D7E5F6F0603A4783EE49AD423C21E] : HP Setup -> C:\Windows\Installer\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\FAA1FE9C245B8C145A731124ADD5A4CE] : HP Customer Experience Enhancements -> C:\Windows\Installer\{C9EF1AAF-B542-41C8-A537-1142DA5D4AEC}\ARPPRODUCTICON.exe ---------- | ADS ---------- | Drives Disk: 0 Size=610G Pos MBRndx Type/Name Size Active Hide Start Sector Sectors --- ------ ---------- ---- ------ ---- ------------ ------------ 0 0 07-NTFS 199M Yes No 2,048 407,552 1 1 07-NTFS 588G No No 409,600 203,695,616 2 2 07-NTFS 22G No No 204,105,216 45,944,832 3 3 0C-FAT32X 103M No No 250,050,048 210,944 ---------- | MBR Windows Version: Windows Information: (build 9200), 64-bit Base Board Manufacturer: Hewlett-Packard BIOS Manufacturer: Insyde System Manufacturer: Hewlett-Packard System Product Name: HP Pavilion dv7 Notebook PC Logical Drives Mask: 0x0000009c Analysis of file "C:\QuickDiag\MBR.bin": Windows 7 MBR code detected 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog Nom de l’application défaillante Microsoft.Photos.exe, version : 16.526.11240.0, horodatage : 0x574744f3 Nom du module défaillant : ntdll.dll, version : 10.0.10586.306, horodatage : 0x571af2eb Code d’exception : 0xc0000005 Décalage d’erreur : 0x0000000000015a7e ID du processus défaillant : 0xd0 Heure de début de l’application défaillante : 0x01d1e42a152c71fa Chemin d’accès de l’application défaillante : C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : e59c4520-f3b4-47c6-ac9e-d5b43cf98596 Nom complet du package défaillant : Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante WinStore.Mobile.exe, version : 11602.1.26.0, horodatage : 0x5721ad5a Nom du module défaillant : ntdll.dll, version : 10.0.10586.306, horodatage : 0x571af2eb Code d’exception : 0xc0000005 Décalage d’erreur : 0x0000000000015a62 ID du processus défaillant : 0x2ca0 Heure de début de l’application défaillante : 0x01d1e426a0b4c8d6 Chemin d’accès de l’application défaillante : C:\Program Files\WindowsApps\Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : 6aa139b2-ffba-43fc-9e21-3bf739697aa5 Nom complet du package défaillant : Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante Microsoft.Photos.exe, version : 16.526.11240.0, horodatage : 0x574744f3 Nom du module défaillant : ntdll.dll, version : 10.0.10586.306, horodatage : 0x571af2eb Code d’exception : 0xc0000005 Décalage d’erreur : 0x0000000000015ead ID du processus défaillant : 0x2c0c Heure de début de l’application défaillante : 0x01d1e4262f465d04 Chemin d’accès de l’application défaillante : C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : 1c314d04-b10c-4738-91b5-ad5edfad668f Nom complet du package défaillant : Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante SearchUI.exe, version : 10.0.10586.494, horodatage : 0x5775e69a Nom du module défaillant : SearchUI.exe, version : 10.0.10586.494, horodatage : 0x5775e69a Code d’exception : 0xc000027b Décalage d’erreur : 0x00000000001b05b7 ID du processus défaillant : 0x2a64 Heure de début de l’application défaillante : 0x01d1e426184af8fe Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe ID de rapport : 7a1a0581-e9bd-423c-a61c-b217e285a5e9 Nom complet du package défaillant : Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : CortanaUI ------------ Nom de l’application défaillante ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Nom du module défaillant : ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Code d’exception : 0xc000027b Décalage d’erreur : 0x0000000000085831 ID du processus défaillant : 0x2958 Heure de début de l’application défaillante : 0x01d1e42616696bc9 Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe ID de rapport : 6428dc91-dec0-47ce-9218-12af4aad3958 Nom complet du package défaillant : Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante SearchUI.exe, version : 10.0.10586.494, horodatage : 0x5775e69a Nom du module défaillant : SearchUI.exe, version : 10.0.10586.494, horodatage : 0x5775e69a Code d’exception : 0xc000027b Décalage d’erreur : 0x00000000001b05b7 ID du processus défaillant : 0x284c Heure de début de l’application défaillante : 0x01d1e42614632de3 Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe ID de rapport : 89d7f7c7-8af8-4e3b-865c-9fcb4133a7a5 Nom complet du package défaillant : Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : CortanaUI ------------ Nom de l’application défaillante ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Nom du module défaillant : ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Code d’exception : 0xc000027b Décalage d’erreur : 0x0000000000085831 ID du processus défaillant : 0xb84 Heure de début de l’application défaillante : 0x01d1e426124ae6bf Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe ID de rapport : 3097c034-a952-4586-b8d0-46fd54350cb5 Nom complet du package défaillant : Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Nom du module défaillant : ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Code d’exception : 0xc000027b Décalage d’erreur : 0x0000000000085831 ID du processus défaillant : 0x1880 Heure de début de l’application défaillante : 0x01d1e424e9429c2e Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe ID de rapport : f058ac2a-6981-4a2f-8b52-67aa6261b46d Nom complet du package défaillant : Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Nom du module défaillant : ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Code d’exception : 0xc000027b Décalage d’erreur : 0x0000000000085831 ID du processus défaillant : 0x25a8 Heure de début de l’application défaillante : 0x01d1e424959c0f7a Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe ID de rapport : 005cb471-b466-40e4-b57f-69b6db553863 Nom complet du package défaillant : Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : App ------------ Nom de l’application défaillante plugin-container.exe, version : 47.0.0.6025, horodatage : 0x577496dc Nom du module défaillant : mozglue.dll, version : 47.0.0.6025, horodatage : 0x5774961b Code d’exception : 0x80000003 Décalage d’erreur : 0x0000268d ID du processus défaillant : 0x1c30 Heure de début de l’application défaillante : 0x01d1e2b574c12716 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Firefox\plugin-container.exe Chemin d’accès du module défaillant: C:\Program Files (x86)\Firefox\mozglue.dll ID de rapport : df260fe7-3c1c-460a-ac4f-9ed0a3a64af0 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Nom de l’application défaillante SyncServer.exe, version : 17.669.22.68, horodatage : 0x52fa24ee Nom du module défaillant : MSVCR100.dll, version : 10.0.40219.325, horodatage : 0x4df2be1e Code d’exception : 0xc0000005 Décalage d’erreur : 0x00002561 ID du processus défaillant : 0xe58 Heure de début de l’application défaillante : 0x01d1e4239f29c010 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\MSVCR100.dll ID de rapport : dea0d4c7-86af-481e-b8ac-50339800ab52 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Nom de l’application défaillante ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Nom du module défaillant : ShellExperienceHost.exe, version : 10.0.10586.494, horodatage : 0x5775e94c Code d’exception : 0xc000027b Décalage d’erreur : 0x0000000000085831 ID du processus défaillant : 0x25f4 Heure de début de l’application défaillante : 0x01d1e42313520f55 Chemin d’accès de l’application défaillante : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Chemin d’accès du module défaillant: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe ID de rapport : 50877dfb-b27b-465f-8ca6-9aab23336ace Nom complet du package défaillant : Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : App ------------ Task Scheduling Error: m->NextScheduledSPRetry 68573063 ------------ Task Scheduling Error: m->NextScheduledEvent 68573063 ------------ Task Scheduling Error: Continuously busy for more than a second ------------ Task Scheduling Error: m->NextScheduledSPRetry 3766 ------------ Task Scheduling Error: m->NextScheduledEvent 3766 ------------ Task Scheduling Error: Continuously busy for more than a second ------------ Task Scheduling Error: m->NextScheduledSPRetry 2516 ------------ ----------( EOF)---------- - 10524 | 19:11:02