--------------- QuickDiag | g3n-h@ckm@n | 2_12.08.2016.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 23/08/2016 20:45:55 Updated 12/08/2016 | 12.00 by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [Jean-Marie (Administrator)] - [LFS_ULTRA] (S-1-5-21-3042704910-407304991-3750219112-1001) System: Microsoft Windows 10 Professionnel - - (10.0.14393) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Professionnel|C:\WINDOWS|\Device\Harddisk0\Partition4 Boot : SafeMode with network PC: CQ2904EF - Hewlett-Packard - IdNumber: 4CH3100VPJ - UUID: 2C238515-5AA2-7984-51F0-370493363EDB Processor : X64 - 1397 Mhz - AMD E1-1200 APU with Radeon(tm) HD Graphics 8.17 - fra - AMI - S/N: 4CH3100VPJ - 8.17 - HPQOEM - 1072009 CoreTemp : ? Celsius ----------| Extended ---------- | SoundDevice Realtek High Definition Audio - Status: Unknown - Manufacturer: Realtek - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0662&SUBSYS_103C2AE3&REV_1001\4&2070A159&0&0001 HD Webcam C310 - Status: Unknown - Manufacturer: Logitech - PNPDeviceID: USB\VID_046D&PID_081B&MI_02\9&4D0A220&0&0002 ---------- | Video AMD Radeon HD 7310 Graphics - Resolution: x - Colors: - RefreshRate: - Bits Per Pixel - DeviceID: VideoController1 - Drivers: aticfx64.dll,aticfx64.dll,aticfx64.dll,aticfx32,aticfx32,aticfx32,atiumd64.dll,atidxx64.dll,atidxx64.dll,atiumdag,atidxx32,atidxx32,atiumdva,atiumd6a.cap,atitmm64.dll - PNPDeviceID: PCI\VEN_1002&DEV_9809&SUBSYS_2AE3103C&REV_00\3&11583659&0&08 - AdapterCompatibility: Advanced Micro Devices, Inc. - RAM: 402653184 Inegrated Video Chipset DeviceName: AMD Radeon HD 7310 Graphics - DriverVersion: 8.14.01.6463 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35696 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25352 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 87040 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34640 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\prodad-codec.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 607256 - Manufacturer: proDAD GmbH - Status: OK c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 54272 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 27648 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42936 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\lvcod64.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 175392 - Manufacturer: Logitech Inc. - Status: OK ---------- | CPU CPU #1 value:0 % CPU #2 value:0 % Total Overall CPU Usage value:0 % ---------- | Network Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30) - Ethernet 802.3 - Qualcomm Atheros - Status: - PnPID : PCI\VEN_1969&DEV_2062&SUBSYS_2AE3103C&REV_C1\4&186C6B44&0&00A9 Microsoft Kernel Debug Network Adapter - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000 Microsoft ISATAP Adapter - - - Status: - PnPID : Microsoft Teredo Tunneling Adapter - - - Status: - PnPID : ---------- | Memory RAM = Total (MB) : 3748 | Free (MB) : 2224 Pagefile = Total (MB) : 4157 | Free (MB) : 2759 Virtual = Total (MB) : 4194 | Free (MB) : 3995 Physical Memory 0 : Capacity: 4294967296 - A1_DIMM0 - Posit.: 0 - Manufacturer: Micron - PartNumber: 8JTF51264AZ-1G6E1 - S/N: DEA02E9 ---------- | SID Users Administrateur : [S-1-5-21-3042704910-407304991-3750219112-500] DefaultAccount : [S-1-5-21-3042704910-407304991-3750219112-503] GFIDIRECTORY_ADMIN : [S-1-5-21-3042704910-407304991-3750219112-1009] HomeGroupUser$ : [S-1-5-21-3042704910-407304991-3750219112-1005] Invité : [S-1-5-21-3042704910-407304991-3750219112-501] Jean-Marie : [S-1-5-21-3042704910-407304991-3750219112-1001] LANGUARD_12_USER : [S-1-5-21-3042704910-407304991-3750219112-1008] Administrateurs : [S-1-5-32-544] Administrateurs Hyper-V : [S-1-5-32-578] Duplicateurs : [S-1-5-32-552] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] Opérateurs d'assistance de contrôle d'accès : [S-1-5-32-579] Opérateurs de chiffrement : [S-1-5-32-569] Opérateurs de configuration réseau : [S-1-5-32-556] Opérateurs de sauvegarde : [S-1-5-32-551] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs avec pouvoir : [S-1-5-32-547] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du Bureau à distance : [S-1-5-32-555] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] AMD FUEL : [S-1-5-21-3042704910-407304991-3750219112-1006] HomeUsers : [S-1-5-21-3042704910-407304991-3750219112-1004] SQLServer2005SQLBrowserUser$LFS_ULTRA : [S-1-5-21-3042704910-407304991-3750219112-1007] WinRMRemoteWMIUsers__ : [S-1-5-21-3042704910-407304991-3750219112-1000] ---------- | Drives Y:\ -> [Removable] | [USB DISK] | Total : 15 Go | Free : 12.07 Go -> FAT32 [USB] X:\ -> [Removable] | [UUI] | Total : 7.26 Go | Free : 0.29 Go -> FAT32 [USB] V:\ -> [Fixed] | [My Passport] | Total : 2794.49 Go | Free : 453.9 Go -> NTFS [USB] U:\ -> [Removable] | [NO NAME] | Total : 59.48 Go | Free : 17.33 Go -> FAT32 [USB] Q:\ -> [Removable] | [FramaLive] | Total : 14.41 Go | Free : 9.68 Go -> FAT32 [USB] P:\ -> [Removable] | [stylo espio] | Total : 3.69 Go | Free : 0.95 Go -> FAT32 [USB] O:\ -> [Removable] | [MONTRE ESPI] | Total : 7.42 Go | Free : 0.87 Go -> FAT32 [USB] N:\ -> [Removable] | [] | Total : 30.02 Go | Free : 2.07 Go -> FAT32 [USB] M:\ -> [CDROM] | [Paragon] | Total : 0.12 Go | Free : 0 Go -> CDFS [USB] K:\ -> [Removable] | [HITMANPRO] | Total : 1.86 Go | Free : 1.7 Go -> FAT32 [USB] I:\ -> [Removable] | [FRAMAKEY SA] | Total : 28.78 Go | Free : 23.22 Go -> FAT32 [USB] H:\ -> [Removable] | [FRAMAKEY UB] | Total : 57.64 Go | Free : 53.58 Go -> FAT32 [USB] G:\ -> [Removable] | [] | Total : 3.67 Go | Free : 0.06 Go -> FAT32 [USB] D:\ -> [Fixed] | [Recovery Image] | Total : 13.06 Go | Free : 1.6 Go -> NTFS [SATA] C:\ -> [Fixed] | [OS] | Total : 916.54 Go | Free : 858.47 Go -> NTFS [SATA] Disk Usage Information [18 total Physical Disks] Physical Drive #0 [C:, D:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [G:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #2 [H:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #3 [I:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #4 [J:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #5 [K:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #6 [Q:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #7 [N:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #8 [O:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #9 [P:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, R:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, S:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, T:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, U:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, V:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, X:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, Y:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #1 [, L:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Overall - Read Maximum:0 bytes/sec, Write Maximum:0 bytes/sec DeviceID: \\.\PHYSICALDRIVE2 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_VERBATIM&PROD_STORE_N_GO&REV_5.00\070B559AA120B087&0 DeviceID: \\.\PHYSICALDRIVE1 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_GENERIC-&PROD_MULTI-CARD&REV_1.00\20071114173400000&0 DeviceID: \\.\PHYSICALDRIVE14 - Status: OK - USB - External hard disk media - 4 Part. - PnPID : USBSTOR\DISK&VEN_WD&PROD_MY_PASSPORT_0827&REV_1012\575831314438354450483744&0 DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 5 Part. - PnPID : SCSI\DISK&VEN_WDC&PROD_WD10EZEX-60ZF5A0\4&32E8E4A0&0&000000 DeviceID: \\.\PHYSICALDRIVE8 - Status: OK - USB - Removable Media - 1 Part. - PnPID : USBSTOR\DISK&VEN_GENPLUS&PROD_USB-MSDC_DISK_A&REV_1.00\9&368B17D4&0 DeviceID: \\.\PHYSICALDRIVE15 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_KINGSTON&PROD_DATATRAVELER_2.0&REV_PMAP\001BFC3653BCBFC0698F7C35&0 DeviceID: \\.\PHYSICALDRIVE16 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_GENERAL&PROD_USB_FLASH_DISK&REV_1100\0340915030009803&0 DeviceID: \\.\PHYSICALDRIVE4 - Status: OK - USB - - 0 Part. - PnPID : USBSTOR\DISK&VEN_GENERIC&PROD_STORAGE_DEVICE&REV_9451\7&18D61DD&0 DeviceID: \\.\PHYSICALDRIVE11 - Status: OK - USB - - 0 Part. - PnPID : USBSTOR\DISK&VEN_SONY&PROD_CARD_R/W__-SM/XD&REV_2.10\50000007EDC1&1 DeviceID: \\.\PHYSICALDRIVE13 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_SONY&PROD_CARD_R/W__-MS&REV_2.10\50000007EDC1&3 DeviceID: \\.\PHYSICALDRIVE12 - Status: OK - USB - - 0 Part. - PnPID : USBSTOR\DISK&VEN_SONY&PROD_CARD_R/W__-SD&REV_2.10\50000007EDC1&2 DeviceID: \\.\PHYSICALDRIVE17 - Status: OK - USB - - 0 Part. - PnPID : USBSTOR\DISK&VEN_MASS&PROD_STORAGE_DEVICE&REV_1.00\121220130416&0 DeviceID: \\.\PHYSICALDRIVE6 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_KINGSTON&PROD_DATATRAVELER_3.0&REV_PMAP\AC220B280C8CB030D9732DE0&0 DeviceID: \\.\PHYSICALDRIVE9 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_GENPLUS&PROD_USB-MSDC_DISK_A&REV_1.00\9&311F417B&0 DeviceID: \\.\PHYSICALDRIVE10 - Status: OK - USB - - 0 Part. - PnPID : USBSTOR\DISK&VEN_SONY&PROD_CARD_R/W__-CF&REV_2.10\50000007EDC1&0 DeviceID: \\.\PHYSICALDRIVE7 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_GENERAL&PROD_USB_FLASH_DISK&REV_1100\0116000000008682&0 DeviceID: \\.\PHYSICALDRIVE5 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_&PROD_FIXMESTICK&REV_8.07\D2BF4C401E2763FP1289&0 DeviceID: \\.\PHYSICALDRIVE3 - Status: OK - USB - Removable Media - 4 Part. - PnPID : USBSTOR\DISK&VEN_VERBATIM&PROD_STORE_N_GO&REV_PMAP\071055D329387500&0 ---------- | Windows updates No detected update !!! ---------- | Browsers IE : 11.0.14393.0 (© Microsoft Corporation. Tous droits réservés.) Default : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 ---------- | FlashPlayer FlashPlayer ActiveX : 22.0.0.209 FlashPlayer Plugin : 22.0.0.209 ---------- | Security AV : Windows Defender Enabled AS : Windows Defender Enabled FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Auto(2)] = stopped AS: Windows Defender [Auto(2)] = Running WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 408 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.14393.0) = C:\Windows\System32\smss.exe [16/07/2016 13:42:27] CPU Usage:0 % 560 | [Owner : | Parent : 496() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.14393.0) = C:\Windows\System32\wininit.exe [16/07/2016 13:42:27] CPU Usage:0 % 644 | [Owner : | Parent : 552() | ?????] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.14393.0) = C:\Windows\System32\winlogon.exe [16/07/2016 13:42:20] CPU Usage:0 % 664 | [Owner : | Parent : 560(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.14393.0) = C:\Windows\System32\services.exe [16/07/2016 13:42:27] CPU Usage:0 % 672 | [Owner : | Parent : 560(wininit.exe) | ?????] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.14393.0) = C:\Windows\System32\lsass.exe [16/07/2016 13:42:27] CPU Usage:0 % 768 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 820 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1004 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 312 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 428 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 652 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 484 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1064 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1100 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1184 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1412 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1420 | [Owner : | Parent : 664(services.exe) | ?????] - (.Microsoft Corporation - Antimalware Service Executable.) - (4.10.14393.0) = C:\Program Files\Windows Defender\MsMpEng.exe [16/07/2016 13:43:04] CPU Usage:0 % 1920 | [Owner : Jean-Marie | Parent : 428(svchost.exe) | 19.45 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.14393.0) = C:\Windows\System32\sihost.exe [16/07/2016 13:42:09] CPU Usage:0 % 2036 | [Owner : Jean-Marie | Parent : 1988() | 84.96 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.14393.0) = C:\Windows\explorer.exe [16/07/2016 13:42:40] CPU Usage:0 % 1460 | [Owner : Jean-Marie | Parent : 2036(explorer.exe) | 10.49 Mo] - (.Microsoft Corporation - Chargeur CTF.) - (10.0.14393.0) = C:\Windows\System32\ctfmon.exe [16/07/2016 13:42:43] CPU Usage:0 % 2072 | [Owner : Jean-Marie | Parent : 768(svchost.exe) | 59.8 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.14393.0) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe [16/07/2016 13:42:02] CPU Usage:0 % 2248 | [Owner : Jean-Marie | Parent : 768(svchost.exe) | 88.44 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.14393.51) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe [14/08/2016 10:43:20] CPU Usage:0 % 2260 | [Owner : Jean-Marie | Parent : 768(svchost.exe) | 12.57 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.14393.0) = C:\Windows\System32\dllhost.exe [16/07/2016 13:42:27] CPU Usage:0 % 2384 | [Owner : Jean-Marie | Parent : 768(svchost.exe) | 16.89 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.14393.0) = C:\Windows\System32\RuntimeBroker.exe [16/07/2016 13:42:05] CPU Usage:0 % 2656 | [Owner : Jean-Marie | Parent : 768(svchost.exe) | 20.28 Mo] - (.Microsoft Corporation - Aide et support Microsoft.) - (10.0.14393.0) = C:\Windows\HelpPane.exe [16/07/2016 13:42:20] CPU Usage:0 % 3288 | [Owner : Jean-Marie | Parent : 768(svchost.exe) | 24.77 Mo] - (.Microsoft Corporation - SmartScreen.) - (10.0.14393.0) = C:\Windows\System32\smartscreen.exe [16/07/2016 13:42:05] CPU Usage:0 % 3492 | [Owner : Jean-Marie | Parent : 2036(explorer.exe) | 28.51 Mo] - (.SosVirus - QuickDiag.) - (12.8.2016.1) = C:\Users\Jean-Marie\Desktop\quickdiag_2_12.08.2016.1 (1).exe [23/08/2016 20:39:45] CPU Usage:0 % ---------- | MD5 [MD5.05181A5AC4197D6C5C02ACE6070AF234] - [16/07/2016 13:42:40] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4563.77 Ko] - (10.0.14393.0) : C:\WINDOWS\Explorer.exe [MD5.F4F684066175B77E0C3A000549D2922C] - [16/07/2016 13:42:36] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [227.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\cmd.exe [MD5.77DBC745D957B4F0404ABABC10696784] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Processus d’exécution client-serveur.) - [17.72 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\csrss.exe [MD5.DA63852A2B0340E94D74EAF0CD444979] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. - COM Surrogate.) - [20.84 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\dllhost.exe [MD5.6955067712F2F4752CA12192B08EF860] - [16/07/2016 13:42:16] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [683.48 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Kernel32.dll [MD5.FD0FC10A8CFD7AFEC58BBBE649BAA470] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. - Local Security Authority Process.) - [56.05 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\lsass.exe [MD5.7BD259FC59CF9C2AE1B979564B374CC6] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. - Distributed COM Services.) - [867.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\rpcss.dll [MD5.C7645D43451C6D94D87F4D07BDE59C89] - [16/07/2016 13:42:42] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [68 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\rundll32.exe [MD5.133390D061D94917125DC666DA67ECD0] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [443.95 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\services.exe [MD5.36F670D89040709013F6A460176767EC] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [43.45 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\svchost.exe [MD5.958AD14CDF4EBB6BADDB13F8B39A97CF] - [14/08/2016 10:43:19] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de l’API uilisateur de Windows multi-utilisateurs.) - [1426.95 Ko] - (10.0.14393.5) : C:\WINDOWS\System32\user32.dll [MD5.C1B1FFC800BE2F31EB2CF8CB40629C69] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Userinit.) - [32.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\userinit.exe [MD5.99A19C9A74E2F9820E501DCE77F84F70] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [297.11 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Wininit.exe [MD5.770DB86BF679CA34FC927F25FBAA350C] - [16/07/2016 13:42:20] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Windows.) - [658.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Winlogon.exe [MD5.983266DA83FFF73DBDDD3730A4712228] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de fonction connexe pour WinSock.) - [569.84 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\afd.sys [MD5.A10F989A812B57B9695F6C305907C9C6] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [27.84 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\atapi.sys [MD5.65DEB05FC234BFF207379F06F0754402] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [187.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\ataport.sys [MD5.F8FB51B9EF6372610E9B31A1D86B62FC] - [16/07/2016 13:42:35] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [90 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\cdfs.sys [MD5.613D0137C269187FA298A157E3D14A18] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [169 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\cdrom.sys [MD5.7EAFDEF51136E8F2452CEBD8D084F108] - [16/07/2016 13:42:23] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [141 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\dfsc.sys [MD5.10E3515FE5DBA6656FA62C29342EC4A1] - [16/07/2016 13:41:52] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [81.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\hdaudbus.sys [MD5.B54B30992620C97230013A74461C8517] - [16/07/2016 13:41:54] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [111.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\i8042prt.sys [MD5.F1DAECC3B3D6399875D4F10529D6A77C] - [16/07/2016 13:42:39] - (.© Microsoft Corporation. - IP Network Address Translator.) - [207.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\ipnat.sys [MD5.C9BB4E2FCAB693FEB00CF940060D94F4] - [16/07/2016 13:42:23] - (.© Microsoft Corporation. Tous droits réservés. - Minirdr SMB Windows NT.) - [438.84 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\mrxsmb.sys [MD5.36DD2C614720EC2970CB5E870BA69D8D] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - NDIS (Network Driver Interface Specification).) - [1154.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\ndis.sys [MD5.6FEBB0A847FFD5F057B9AC8889F1B9A7] - [16/07/2016 13:42:35] - (.© Microsoft Corporation. - MBT Transport driver.) - [272.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\netbt.sys [MD5.D1AF837A1555990602A51A3ED238EC80] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [2204.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\ntfs.sys [MD5.6B81BF7853D161DB8AC62CD8B9C2DE6B] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [94.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\parport.sys [MD5.17E565710172ED71B8531D8822E1C5D1] - [16/07/2016 13:42:39] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [102.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\rasl2tp.sys [MD5.7135785C21CA79D270D11037C43D3F19] - [16/07/2016 13:44:03] - (.© Microsoft Corporation. Tous droits réservés. - Redirecteur de périphérique de Microsoft RDP.) - [173 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\rdpdr.sys [MD5.172B5A199F917B4BACB38F13BCAA11CB] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [2479.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\tcpip.sys [MD5.9D2DD64A0B51C56285512DC9454340F6] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. - TDI Translation Driver.) - [115.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\tdx.sys [MD5.BF2546583BB75F01DDA60A7921DFB230] - [16/07/2016 13:42:35] - (.© Microsoft Corporation. - Volume Shadow Copy driver.) - [382.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\volsnap.sys ---------- | Locked Applications ---------- | Explorer.exe component call (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\CoreUIComponents.dll (.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.12.2.0) -- C:\WINDOWS\System32\winsqlite3.dll (.Acronis.-.Acronis True Image Shell Extensions.) - (19.0.0.3104) -- C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (.Nero AG.-.Nero Burning ROM Shell Extension.) - (17.0.8.0) -- C:\Program Files (x86)\Common Files\Nero\NeroShellExt\x64\NeroShellExt.dll (.Nero AG.-.Nero Solution Explorer Dynamic Link Library.) - (17.0.0.3) -- C:\Program Files (x86)\Common Files\Nero\NeroShellExt\x64\SolutionExplorer.dll (.ArcticLine Software.-.Shell extension for FileMarker.NET.) - (1.0.1.0) -- C:\Program Files (x86)\FileMarker.NET\FileMarkerShlExt64.dll (.Cyberlink.-.Cyberlink Shell Extension dynamic link library.) - (10.0.0.1409) -- C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt10_20160822_18_48_24.dll ---------- | Svchost.exe component call (Microsoft Files Whitelisted) ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up OneDrive - ("C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\...\Run]) - User: LFS_ULTRA\Jean-Marie uTorrent - ("V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\portableapps N° 3 100% Sécurisé Finalis\PortableApps\uTorrentPortable\App\uTorrent\uTorrent.exe" /MINIMIZED [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\...\Run]) - User: LFS_ULTRA\Jean-Marie Power2GoExpress10 - ("C:\Program Files (x86)\CyberLink\Power2Go10\Power2GoExpress10.exe" /Startup [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\...\Run]) - User: LFS_ULTRA\Jean-Marie Acronis Scheduler2 Service - ("C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [HKLM\...\Run]) - User: Public WindowsDefender - ("%ProgramFiles%\Windows Defender\MSASCuiL.exe" [HKLM\...\Run]) - User: Public [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background "uTorrent"="V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\portableapps N° 3 100% Sécurisé Finalis\PortableApps\uTorrentPortable\App\uTorrent\uTorrent.exe" /MINIMIZED "Power2GoExpress10"="C:\Program Files (x86)\CyberLink\Power2Go10\Power2GoExpress10.exe" /Startup [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"=C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64" [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU] "a"=notepad\1 "MRUList"=acb "b"="V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\PortableApps\FirefoxPortable\FirefoxPortable.exe"\1 "c"=C:\Users\Jean-Marie\Desktop\quickdiag_2_12.08.2016.1.exe\1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "Acronis Scheduler2 Service"="C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" "WindowsDefender"="%ProgramFiles%\Windows Defender\MSASCuiL.exe" [HKLM\Software\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun "Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [14/08/2016 07:37:54] "BingDesktop"=C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey "InstantBurn"=C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe [14/08/2016 21:32:26] "PowerDVD16Agent"="C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe" "CLMLServer_For_P2G10"="C:\Program Files (x86)\CyberLink\Power2Go10\CLMLSvc_P2G10.exe" "DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [08/08/2016 08:08:08] "AcronisTibMounterMonitor"=C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [25/04/2016 21:44:56] "TrueImageMonitor.exe"=C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [10/05/2016 16:23:20] [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 ---------- | Startings up registry ¦ Folder ---------- | Other keys [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "RailShowallNotifyIcons"=1 "RDPVGCInstalled"=1 "InstanceID"=ae778103-b8cb-4eff-aedc-4e68445 "GlassSessionId"=1 [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "ResourceTimeoutCount"=648000 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=AcrSch2Svc UsoSvc gpsvc trustedinstaller "WaitToKillServiceTimeout"=200 "SystemStartOptions"= FLIGHTSIGNING NOEXECUTE=OPTIN SAFEBOOT:NETWORK NOGUIBOOT BOOTLOGO "SystemBootDevice"=multi(0)disk(0)rdisk(4)partition(4) "FirmwareBootDevice"=multi(0)disk(0)rdisk(4)partition(2) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=6 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Notification Packages"=scecli "Authentication Packages"=msv1_0 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "LsaPid"=672 "ProductType"=6 "restrictanonymous"=0 "restrictanonymoussam"=1 "SamConnectedAccountsExist"=1 "SecureBoot"=1 "Security Packages"=kerberos msv1_0 schannel wdigest tspkg pku2u livessp ---------- | .LNK C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\SendTo\Destinataire de télécopie.lnk (/SendTo) C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk (page=SettingsPagePCSystemDevices) C:\Users\Jean-Marie\Desktop\Pre_Scan_Donate.lnk (https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=S3AQ8V3XRWWYN) C:\Users\Jean-Marie\Desktop\Pre_Scan_Restore.lnk (C:\Pre_Scan) C:\ProgramData\Microsoft\Windows\GameExplorer\{000d96f5-8034-4b74-a429-b6f0b04c75f4}\PlayTasks\0\provider.lnk (/id=000d96f5-8034-4b74-a429-b6f0b04c75f4 /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{227680FF-28CE-48EE-AADF-8D009B2813A9}\PlayTasks\0\web.lnk (/src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{22A975C0-D22F-482C-A387-637EEC15870F}\PlayTasks\0\web.lnk (/src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{26352374-af55-4b53-b07b-6b0288ed97df}\PlayTasks\0\provider.lnk (/id=26352374-af55-4b53-b07b-6b0288ed97df /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{2D080D0F-37EF-433E-90F1-CE36EB0205F6}\PlayTasks\0\web.lnk (/src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{3eda1e54-8889-41f5-a649-5a306789b7ef}\PlayTasks\0\provider.lnk (/id=3eda1e54-8889-41f5-a649-5a306789b7ef /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{5f828e7a-066c-4d4a-ada6-8b2494b859db}\PlayTasks\0\web.lnk (/src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{c3c636e0-1b04-11de-8c30-0800200c9a66}\PlayTasks\0\provider.lnk (/id=c3c636e0-1b04-11de-8c30-0800200c9a66 /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{d58eecb0-0816-11de-8c30-0800200c9a66}\PlayTasks\0\provider.lnk (/id=d58eecb0-0816-11de-8c30-0800200c9a66 /src gameexploreroem) C:\ProgramData\Microsoft\Windows\GameExplorer\{e923cba5-ed90-4670-bf07-064d14a1cd55}\PlayTasks\0\web.lnk (/src gameexploreroem) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk (-SpeechUX) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\Activate Acronis Startup Recovery Manager.lnk (/asz_recovery_manager) L �I.>I�>.R�A�TrueImageHomer2����H�q TRUEIM~4.EXEV ᆰH�qI5>.� C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\Add New Disk.lnk (/add_new_disk) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\Clone Disk.lnk (/clone_disk) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\DriveCleanser.lnk (/drive_cleanser) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\Manage Acronis Secure Zone.lnk (/manage_asz) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\System Clean-up.lnk (/system_cleanup) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Tools and Utilities\Try&Decide.lnk (/tnd_tool) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk (/res) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\Help.lnk (Start Help -help) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite\CyberLink MediaEspresso 7.5\CyberLink MediaEspresso 7.5 Gadget.lnk (gadget) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX\Chercher les mises à jour.lnk (/start=update) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX\Enregistrez.lnk (/start=registration) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX\Réglages du Codec.lnk (/start=decoder) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\WSG.lnk (P004H7B2 WSG) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\OPS.lnk (P004GZB2 OPS) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\SCG.lnk (P004GZB2 SCG) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\SRI.lnk (P004GZB2 SRI) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\TMG.lnk (P004GZB2 TMG) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2012\Configuration Tools\SQL Server Configuration Manager.lnk (/32 c:\WINDOWS\SysWOW64\SQLServerManager11.msc) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk (/7) ---------- | AppCertDlls | AppInit_DLLs ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallPaper"=C:\Users\Jean-Marie\AppData\Local\Microsoft\BingDesktop\themes\2016-08-23.jpg [23/08/2016 11:16:09] "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "ScreenSaveActive"=1 "UserPreferencesMask"=0x9E3E078012000000 "AutoColorization"=1 "MaxVirtualDesktopDimension"=1280 "MaxMonitorDimension"=1280 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC301006F3A0A0080070000B004000013728FFC1EFDD10143003A005C00550073006500720073005C004A00650061006E002D004D0061007200690065005C0041007000700044006100740061005C004C006F00630061006C005C004D006900630072006F0073006F00660074005C00420069006E0067004400650073006B0074006F0070005C007400680065006D00650073005C0032003000310036002D00300038002D00320033002E006A007000670000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ImageColor"=2941022717 "Win8DpiScaling"=0 "DpiScalingVer"=4096 "ScreenSaverIsSecure"=1 "WaitToKillAppTimeout"=200 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "ShellState"=0x240000003E28000000000000000000000000000001000000130000000000000063000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "GlobalAssocChangedCounter"=94 "TelemetrySalt"=5 "FirstRunTelemetryComplete"=1 "AppReadinessLogonComplete"=1 "SlowContextMenuEntries"=0x40C7A47B819ECF1199D300AA004AE837C06A00000114020000000000C000000000000046F52D00006024B221EA3A6910A2DC08002B30309D6E75000066D59EB119D40B47B1113C89040BC027D67600005D54A9A2C2A0B4429708A0B2BADD77C877E10000 "Browse For Folder Width"=347 "Browse For Folder Height"=328 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=0 "ShowCompColor"=1 "HideFileExt"=0 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=0 "SeparateProcess"=1 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StartMenuInit"=13 "TaskbarSizeMove"=0 "DisablePreviewDesktop"=0 "TaskbarGlomLevel"=0 "ReindexedProfile"=1 "StoreAppsOnTaskbar"=1 "EnableStartMenu"=1 "TaskbarStateLastRun"=0x5C67B95700000000 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "EnableLinkedConnections"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=0 "NoActiveDesktopChanges"=0 "NoRecentDocsHistory"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=0 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=0 "{871C5380-42A0-1069-A2EA-08002B30309D}"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=0 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD} "SmartScreenEnabled"=RequireAdmin "GlobalAssocChangedCounter"=25 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "EnableLinkedConnections"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=0 "NoActiveDesktopChanges"=0 "NoRecentDocsHistory"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=0 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=0 "{871C5380-42A0-1069-A2EA-08002B30309D}"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=0 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD} "GlobalAssocChangedCounter"=55 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s ---------- | Winlogon [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=14393 "FirstLogon"=0 "PUUActive"=0xC98DF9E8010004001800430014A90100E5C001009FE70600D100000002001F007AFB96960E8A0700678307006C800000D96A00007417000000000000375107002A160000BC01000057E1F3E56DFDD10114A90100000000000100000000000000 "ParseAutoexec"=1 "AutoRestartShell"=1 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DefaultDomainName"= "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "LastLogOffEndTimePerfCounter"=2784065184 "ShutdownFlags"=2147484711 "Userinit"=C:\Windows\system32\userinit.exe, "scremoveoption"=0 "AutoAdminLogon"=0 "DefaultUserName"=MicrosoftAccount\jean-marie.carribon@wanadoo.fr "ShutdownWithoutLogon"=0 "DisableCad"=1 "EnableFirstLogonAnimation"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "EnableSIHostIntegration"=1 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "userinit"=C:\WINDOWS\SYSWOW64\userinit.exe, "AutoRestartShell"=1 ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Internet Explorer\iexplore.exe" [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\Clients\StartMenuInternet\Vivaldi\Shell\open\Command] ""="C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe" [HKLM\Software\Clients\StartMenuInternet\Vivaldi\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Internet Explorer\iexplore.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Vivaldi\Shell\open\Command] ""="C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Vivaldi\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe" --make-default-browser ---------- | AppcompatFlags [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Users\Jean-Marie\AppData\Local\Temp\nsu4D22.tmp\DivXSetup.exe"=1 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "SIGN.MEDIA=772E50 setup.exe"=0x5341435001000000000000000700000028000000C03A0100691C020001000000000000000000020600210000647CA60EA56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000007599E700000000000100000001000000 "C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C03802000BA5020001000000000000000000000A002100006A920CE5B7BAD0010000000100000000 "C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8BA020001D3020001000000000000000000000A002100006A920CE5B7BAD0010000000100000000 "SIGN.MEDIA=1090E298 Backup data\Windows10Upgrade28084.exe"=0x5341435001000000000000000700000028000000805D5800B4CA580001000000000000000000000A002100006A920CE5B7BAD0010000000000000000 "C:\Windows10Upgrade\Windows10UpgraderApp.exe"=0x5341435001000000000000000700000028000000C8D2120060B1130001000000000000000000000A7122000033504C2B57DFD1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000023E26600000000000300000003000000 "G:\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x53414350010000000000000007000000280000005006020013610200010000000000000000000306710200006A920CE5B7BAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000040340300000000000100000001000000 "G:\PowerCam\Norton_Removal_Tool.exe"=0x5341435001000000000000000700000028000000989E0E003A6F0F00010000000000000000000106000100006A920CE5B7BAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000ACF85800000000000100000001000000 "G:\barrow 2 & widen 100% sécurisé\efm du musée de l'homme & power2go 11 essentials managers\filmora_setup_full1084.exe"=0x5341435001000000000000000700000028000000906812003E4D130001000000000000000000000A002100006A920CE5B7BAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000020440600000000000100000001000000 "G:\LFS Ultra & 100% Sécurisé\hidefolder\hide_pro\LFS Ultra & 100% Sécurisé\LFS Ultra - 100% Sécurisé - Cewbé Suite\on squatte sur les voitures\ashampoo_privacy_protector_e1.0.2_sm.exe"=0x5341435001000000000000000700000028000000F0085901ACBD590101000000000000000000000A002100006A920CE5B7BAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000F5BA0300000000000100000001000000 "G:\LFS Ultra & 100% Sécurisé\ashampoo_privacy_protector_2015_19866.exe"=0x5341435001000000000000000700000028000000188F4B019A244C0101000000000000000000000A002100006A920CE5B7BAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000E1860700000000000100000001000000 "G:\barrow 2 & widen 100% sécurisé\efm du musée de l'homme & power2go 11 essentials managers\filmora_resource.exe"=0x5341435001000000000000000700000028000000C066511643475216010000000000000000000106000100006A920CE5B7BAD0010000000000000000020000002800000000000000000000000000000000000000000000000000000022AF0200000000000100000001000000 "G:\BingDesktopSetup.exe"=0x5341435001000000000000000700000028000000D86AA00040A2A000010000000000000000000105710000006A920CE5B7BAD001000000000000000002000000280000000000000080090040000000000000000000000000000000008CC60000000000000100000001000000 "C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8BA020001D3020001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "G:\PortableApps\FirefoxPortable\FirefoxPortable.exe"=0x5341435001000000000000000700000028000000683703008E1404000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000584B1900000000000200000002000000 "G:\UsbFix_Basic\UsbFix_Basic.exe"=0x534143500100000000000000070000002800000040052F007ACA2F000100000000000000000000067100000033504C2B57DFD1010000000000000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\PortableApps\FirefoxPortable\FirefoxPortable.exe"=0x5341435001000000000000000700000028000000683703008E1404000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000002EBBE700000000000100000001000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\Start Emergency Kit Scanner.exe"=0x534143500100000000000000070000002800000028883900B0A7390001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000AD22AE00000000000100000001000000 "C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe"=0x5341435001000000000000000700000028000000C0342400BB6724000100000000000000000003067102000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000090F36100000000000100000001000000 "G:\PortableApps\IObitUninstallerPortable\IObitUninstallerPortable.exe"=0x534143500100000000000000070000002800000060870300A90004000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000004DDF1F00000000000100000001000000 "SIGN.MEDIA=413AA92C SoftR3_Cryptex_TX.exe"=0x534143500100000000000000070000002800000000E01200BD9913000100000000000000000000067120000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000065800800000000000200000002000000 "G:\PortableApps\7-ZipPortable\7-ZipPortable.exe"=0x5341435001000000000000000700000028000000A08603006DFB03000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000200000000000000000000000000AE0F2B00000000000200000002000000 "G:\PortableApps\PeaZipPortable\PeaZipPortable.exe"=0x534143500100000000000000070000002800000028800200052A03000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000002E8D0300000000000100000001000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\chan final le 100% séc séc fach mc flu de luchon peacock a le brulog noemie\nous f la c de la l de dem\ME_mailessentials.exe"=0x5341435001000000000000000700000028000000B28C500099CCBB1001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000E08B0100000000000100000001000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\chan final le 100% séc séc fach mc flu de luchon peacock a le brulog noemie\nous f la c de la l de dem\WEBMONNET_gfiwebmonitor_net_x64.exe"=0x534143500100000000000000070000002800000088A0B6068B77B7060100000000000000000000067102000033504C2B57DFD1010000000000000000020000002800000000000000800100400000000000000000000000000000000068DB0400000000000100000001000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\cadeau-ammorce finalisation 100% sécurisé (& lfs ultra)\WJSSetup.exe"=0x5341435001000000000000000700000028000000A01A220055FD22000100000000000000000003060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000001F7D0000000000000100000001000000 "C:\Program Files\GFI\WebMonitor\SplashScreen.exe"=0x5341435001000000000000000700000028000000882E0A00C9B10A0001000000000000000000000AF122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000C7180000000000000100000001000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000519D1C00000000000100000001000000 "G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\finalisation 100% sécurisé (& lfs ultra)\roguekiller premium, rebrand with logo tom\RogueKillerX64.exe"=0x534143500100000000000000070000002800000048E882013777830101000000000000000000000A00210000D5B3B31A57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000000E111900000000000100000001000000 "G:\avanquest achats 05_08_2016\FI_PRO_14.0.34.73_FRA.exe"=0x5341435001000000000000000700000028000000289E8603923D87030100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000002970300000000000100000001000000 "G:\avanquest achats 05_08_2016\AutoSaveEssentialsFR.exe"=0x5341435001000000000000000700000028000000700AE6009439E6000100000000000000000001057100000033504C2B57DFD10100000000000000000200000028000000000000000008004000000000000000000000000000000000210D0300000000000100000001000000 "C:\Users\Jean-Marie\Downloads\avanquest achats 05_08_2016\tvc_setup_2.0.0.145_ML.exe"=0x534143500100000000000000070000002800000038B63403E71A350301000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000006DA0300000000000100000001000000 "G:\resizer-free\resizer-free-1\resizer-free.exe"=0x5341435001000000000000000700000028000000FEB53D00000000000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000008E230500000000000100000001000000 "G:\PortableApps\RufusPortable\RufusPortable.exe"=0x5341435001000000000000000700000028000000585402009C2403000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000A4641E00000000000100000001000000 "G:\CyberLinkMediaSuite14.0_Ultimate_MES160511-03_TR160627-004.part1.exe"=0x5341435001000000000000000700000028000000807F843E82C0843E0100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000080000000000000000000000000000000000000004C714B00000000000100000001000000 "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe"=0x534143500100000000000000070000002800000050491300C18313000100000000000000000002067122000033504C2B57DFD1010000008000000000020000002800000000000000000000000000000000000000000000000000000008F72300000000000100000001000000 "G:\LFS Ultra & 100% Sécurisé\hidefolder\hide_pro\LFS Ultra & 100% Sécurisé\LFS Ultra - 100% Sécurisé - Cewbé Suite\on squatte sur les voitures\1_CyberLink_Power2Go10_Platinum_Upgrade_P2G150522-04.exe"=0x534143500100000000000000070000002800000020EB1E0D444B1F0D0100000000000000000001060001000033504C2B57DFD1010000000000000000 "C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000C0723C01E3C13C0101000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C0AC02007050030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\CyberLink\Power2Go10\OLRSubmission\OLRStateCheck.exe"=0x5341435001000000000000000700000028000000B89D0100203F02000100000000000000000003067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000CB1A0000000000001300000013000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000008F9D7500000000000100000001000000 "C:\Program Files (x86)\DivX\DivX Control Panel\DivXControlPanelLauncher.exe"=0x534143500100000000000000070000002800000060B9050034A206000100000000000000000002067120000033504C2B57DFD1010000000000000000020000002800000000000000800000000000000000000000000000000000000040530000000000000100000001000000 "V:\DivXInstaller.exe"=0x5341435001000000000000000700000028000000C8FD24009201250001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000DF621400000000000100000001000000 "C:\ProgramData\BVRP Software\LiveUpdate\LiveUpdate\Temp\setup.exe"=0x534143500100000000000000070000002800000000E50500D01406000100000000000000000001060021000033504C2B57DFD10100000080000000000200000028000000000000000000004000000000000000000000000000000000513E0000000000000100000001000000 "C:\Program Files (x86)\DivX\DivX Converter\DivXConverter.exe"=0x5341435001000000000000000700000028000000E08B0500E768060001000000000000000000000A7122000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000029920100000000000200000002000000 "C:\Program Files (x86)\DivX\DivX Player\DivX Player.exe"=0x5341435001000000000000000700000028000000E0BD1C00EB901D0001000000000000000000000A7120000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000084740000000000000200000002000000 "C:\Program Files (x86)\CyberLink\Media Suite\PS.exe"=0x534143500100000000000000070000002800000018DF0800A839090001000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000006046D702000000000400000004000000 "V:\Like New PC - final paid\LikeNEWPCSetup.exe"=0x5341435001000000000000000700000028000000587E3B007F903B0001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000061520100000000000100000001000000 "V:\PortableApps\PortableApps.com\PortableAppsPlatform.exe"=0x534143500100000000000000070000002800000000D1290044D9290001000000000000000000000A0021000033504C2B57DFD1010000000000000000 "C:\Users\Jean-Marie\Downloads\RogueKillerX64_old.exe"=0x5341435001000000000000000700000028000000481AC200ACC1C20001000000000000000000000A00210000D5B3B31A57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000FF3E5500000000000100000001000000 "V:\PortableApps\FirefoxPortable\FirefoxPortable.exe"=0x5341435001000000000000000700000028000000683703008E1404000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000006B91A600000000000700000007000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\cadeaux de finalisation 100% sécurisé finalis (& de lfs ultra)\Nero2016-17.0.04500.exe"=0x5341435001000000000000000700000028000000C8F51610F03B17100100000000000000000001067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000E9AD2300000000000100000001000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\cadeaux de finalisation 100% sécurisé finalis (& de lfs ultra)\nero2016contentpack_17.0.00200.nsx.exe"=0x53414350010000000000000007000000280000004863ED2F5C85ED2F0100000000000000000001067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000A26C1100000000000100000001000000 "C:\ProgramData\IObit\ASCDownloader\un6\Smart Defrag.exe"=0x5341435001000000000000000700000028000000B0B1AD00A85CAE0001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000800000000000000000000000000000000038462001000000000100000001000000 "V:\TeraCopy\TeraCopy.exe"=0x534143500100000000000000070000002800000040EA1300310714000100000000000000000002067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000100000000000000000000000000000C55F6E03000000000100000001000000 "V:\Fix-It_Professional_ENU_signed.exe"=0x53414350010000000000000007000000280000000017A0039348A0030100000000000000000001060001000033504C2B57DFD1010000000000000000 "C:\Program Files (x86)\EaseUS\EaseUS Todo PCTrans\bin\PCTrans.exe"=0x534143500100000000000000070000002800000010A92000E5E5200001000000000000000000000A7122000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000B11D3D00000000000200000002000000 "C:\Program Files (x86)\EaseUS\EaseUS Partition Recovery 8.5\bin\EprDrwLoader.exe"=0x534143500100000000000000070000002800000060B0090078C809000100000000000000000001067102000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000054FD0500000000000100000001000000 "C:\Users\Jean-Marie\Downloads\PCKeeper Installer.exe"=0x5341435001000000000000000700000028000000D0D4150052C315000100000000000000000001060001000033504C2B57DFD1010000000000000000 "C:\Users\Jean-Marie\Downloads\spybot_1154288655.exe"=0x5341435001000000000000000700000028000000867B0E000000000001000000000000000000000A0021000033504C2B57DFD1010000000000000000 "C:\Users\Jean-Marie\Downloads\setup.exe"=0x5341435001000000000000000700000028000000D0B03E001BAC3F0001000000000000000000000A0021000033504C2B57DFD1010000000000000000 "SIGN.MEDIA=306062D Data\Documents\roguekiller avec nouveau logo franprix\RogueKillerX64.exe"=0x534143500100000000000000070000002800000048088301514B830101000000000000000000000A00210000D5B3B31A57DFD1010000000000000000 "SIGN.MEDIA=3061C28 Data\Documents\roguekiller avec ancien logo franprix\RogueKillerX64.exe"=0x534143500100000000000000070000002800000048088301514B830101000000000000000000000A00210000D5B3B31A57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000F3340500000000000200000002000000 "C:\Users\Jean-Marie\Desktop\pre-scan_6_20.07.2016.1.exe"=0x5341435001000000000000000700000028000000A8B53400683B350001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000084180501000000000100000001000000 "C:\Program Files (x86)\Internet Explorer\iexplore.exe"=0x5341435001000000000000000700000028000000C0980C0045340D0001000000010000000000000A0021000033504C2B57DFD1010000000000000000 "V:\barrow 2 & widen 100% sécurisé\PortableApps\PortableApps.com\PortableAppsPlatform.exe"=0x534143500100000000000000070000002800000000D1290044D9290001000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000003E111200000000000100000001000000 "C:\Users\Jean-Marie\Desktop\UsbFix_2016_8.248.exe"=0x53414350010000000000000007000000280000002CAD2F00000000000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000B16A0000000000000100000001000000 "C:\Users\Jean-Marie\Desktop\UsbFix_8.261.exe"=0x5341435001000000000000000700000028000000C9892F00000000000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000095E94F00000000000200000002000000 "C:\Users\Jean-Marie\Desktop\EJmiB6N87eh_SFTGC.exe"=0x534143500100000000000000070000002800000000A21400D8BE140001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000A7220100000000000100000001000000 "C:\Pre_Scan\Pre_Scan_Restore.exe"=0x534143500100000000000000070000002800000010D613009C80140001000000000000000000000A0021000033504C2B57DFD101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000006D430100000000000700000007000000 "SIGN.MEDIA=214E33 Download\Diagnostic_PC_Gratuit.exe"=0x5341435001000000000000000700000028000000A8AB1401A343150101000000000000000000000A7120000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000048341500000000000100000001000000 "SIGN.MEDIA=3498BEC Download\vivaldi_1-3-551-30_fr_431419_32.exe"=0x5341435001000000000000000700000028000000786C5102C35A520201000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000031E0100000000000100000001000000 "C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe"=0x534143500100000000000000070000002800000078E015004A70160001000000000000000000000A0021000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000E2561C00000000000800000008000000 "SIGN.MEDIA=3498BEC Download\refresh-windows-tool_1-0_fr_433221.exe"=0x5341435001000000000000000700000028000000D036050099E805000100000000000000000000067100000033504C2B57DFD1010000000000000000050000001000000000000000000000000000000080010000020000002800000000000000800100000010000000000000000000000000000005860E00000000000100000001000000 "V:\AcronisTrueImage2016_web.exe"=0x53414350010000000000000007000000280000009869530030DA53000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000A56B2200000000000100000001000000 "C:\Program Files (x86)\Nero\Nero 2016\Nero Launcher\NeroLauncher.exe"=0x5341435001000000000000000700000028000000F0F335013C78360101000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000008000000000000000000000000000000000000000183E1600000000000300000003000000 "C:\Users\Jean-Marie\AppData\Local\Temp\557F68BB-09CD-449C-BABC-DA9D27D94F21\securezone_upgrade_standard.exe"=0x534143500100000000000000070000002800000060E98800D44989000100000000000000000001060001000033504C2B57DFD101000000800000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000003BEB0000000000000100000001000000 "C:\Program Files (x86)\Nero\Nero 2016\Nero Vision\NeroVision.exe"=0x5341435001000000000000000700000028000000D0B1160091C7160001000000000000000000000AF122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000A1BA0100000000000100000001000000 "C:\Program Files\Wondershare\Filmora\Filmora.exe"=0x534143500100000000000000070000002800000090003101F122310101000000000000000000000A73220000D5B3B31A57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000006CE90200000000000100000001000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\finalisation 100% sécurisé (& lfs ultra)\tentative lfs ultra finalis mars 2016 - watermark software\video-watermark-pro.exe"=0x534143500100000000000000070000002800000040230001319F000101000000000000000000000A6120000033504C2B57DFD101000000000000000002000000280000000000000000000000400000000000000000000000000000005D6A1500000000000100000001000000 "V:\barrow 2 & widen 100% sécurisé\sosvirus app for stop all power2go 11 process for facilite iobit unlocker work\processclose_1.0.0.3.exe"=0x534143500100000000000000070000002800000000140F0001DC0F0001000000000000000000000A0021000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000A74D2000000000000700000002000000000000000000008000000000000000000000000000000000364D0000000000000100000000000000 "C:\Users\Jean-Marie\Desktop\quickdiag_2_12.08.2016.1.exe"=0x5341435001000000000000000700000028000000A81D240084AC240001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000050000000000000000000004000000000000000000000000000000000EE4D0400000000000200000002000000000000000000000000000000000000000000000000000000071E0000000000000100000000000000 "C:\Users\Jean-Marie\Documents\AoaoPhoto Digital Studio\Video Watermark Pro\VideoWatermark.exe"=0x5341435001000000000000000700000028000000D0BE1D0098841E0001000000000000000000000A6120000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000006F9C0D00000000000100000001000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\finalisation 100% sécurisé (& lfs ultra)\tentative lfs ultra finalis mars 2016 - watermark software\video-to-gif.exe"=0x534143500100000000000000070000002800000068D0C4000CF4C4000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000006B732400000000000100000001000000 "V:\ashampoo_hdd_control_2017_24209.exe"=0x534143500100000000000000070000002800000070B4D000B054D10001000000000000000000000A0021000033504C2B57DFD1010000000000000000 "V:\events nouveau logo blini\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000051E90B00000000000100000001000000 "V:\PortableApps\ThunderbirdPortable\ThunderbirdPortable.exe"=0x534143500100000000000000070000002800000008C104009D8C05000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000007C2B0200000000000100000001000000 "C:\Program Files (x86)\Wondershare\TidyMyMusic\TidyMyMusic.exe"=0x5341435001000000000000000700000028000000386D0D0047C80D0001000000000000000000000AF122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000753C3300000000000300000003000000 "V:\filemarker net pro 1 0\FileMarkerNETPro10\FileMarker.NET Pro.exe"=0x53414350010000000000000007000000280000000F032A00000000000100000000000000000003060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000EA270000000000000100000001000000 "C:\Users\Jean-Marie\Downloads\FileMarker.NET_Pro.exe"=0x534143500100000000000000070000002800000040E22600767027000100000000000000000003060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000001C660000000000000100000001000000 "C:\Users\Jean-Marie\Downloads\ZHPCleaner.exe"=0x534143500100000000000000070000002800000000D42300CDBB24000100000000000000000003060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000F5101100000000000100000001000000 "C:\Users\Jean-Marie\Pictures\aspsetup.exe"=0x534143500100000000000000070000002800000020F068002AFF680001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000DE822700000000000100000001000000 "C:\Program Files\CyberLink\PhotoDirector7\PhotoDirector7.exe"=0x5341435001000000000000000700000028000000186102008882020001000000000000000000000A00210000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000C1180800000000000100000001000000 "C:\Program Files (x86)\CyberLink\Power2Go10\Power2Go10.exe"=0x5341435001000000000000000700000028000000B8F75C0064415D0001000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000005BF60900000000000100000001000000 "C:\Program Files\CyberLink\PowerDirector14\PDR.exe"=0x5341435001000000000000000700000028000000189D4A000FE24A0001000000000000000000000A00210000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000F7FC0800000000000100000001000000 "C:\Program Files (x86)\CyberLink\MediaShow6\MediaShow6.exe"=0x5341435001000000000000000700000028000000185F0700D0D0070001000000000000000000000A7122000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000080640800000000000100000001000000 "C:\Program Files (x86)\CyberLink\WaveEditor\WaveEditor.exe"=0x534143500100000000000000070000002800000018870F0088900F000100000000000000000003067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000CD261800000000000100000001000000 "C:\Users\Jean-Marie\Desktop\JRT.exe"=0x534143500100000000000000070000002800000040931800A3DF18000100000000000000000001067102000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000084490500000000000100000001000000 "C:\Users\Jean-Marie\Desktop\adwcleaner_6.000.exe"=0x534143500100000000000000070000002800000040BE3900DB9C3A0001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000090061200000000000200000002000000 "V:\barrow 2 & widen 100% sécurisé\data copy tool for power2go 11 by portableapps\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000003B2E0200000000000100000001000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\PortableApps\FirefoxPortable\FirefoxPortable.exe"=0x534143500100000000000000070000002800000068370300E32A04000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000BBCB8502000000000200000002000000 "V:\barrow 2 & widen 100% sécurisé\portableapps N° 2 Barrow 2 & Widen\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD1010000000000000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\portableapps N° 3 100% Sécurisé Finalis\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD1010000000000000000 "C:\Users\Jean-Marie\Desktop\FRST64.exe"=0x5341435001000000000000000700000028000000009224005441250001000000000000000000000A00210000D5B3B31A57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000E7F90F00000000000400000004000000 "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageLauncher.exe"=0x5341435001000000000000000700000028000000B05F030088C9030001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000008000004000000000000000000000000000000000552D0100000000000100000001000000 "V:\LFS Ultra & 100% Sécurisé\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x534143500100000000000000070000002800000050060200136102000100000000000000000003067102000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000009C934700000000000200000002000000 "V:\LFS Ultra & 100% Sécurisé\hidefolder\hide_pro\LFS Ultra & 100% Sécurisé\LFS Ultra\lfs ultimate\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x534143500100000000000000070000002800000050060200136102000100000000000000000003067102000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000372A0100000000000100000001000000 "V:\barrow 2 & widen 100% sécurisé\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x534143500100000000000000070000002800000050060200136102000100000000000000000003067102000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000DEFC0000000000000100000001000000 "V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x534143500100000000000000070000002800000050060200136102000100000000000000000003067102000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000EA070100000000000100000001000000 "V:\events nouveau logo blini\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x534143500100000000000000070000002800000050060200136102000100000000000000000003067102000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000FA6A0100000000000100000001000000 "V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé\revo uninstaller pro portable\program files (x64)\RevoUninstallerPro_Portable\RevoUPPort.exe"=0x534143500100000000000000070000002800000050060200136102000100000000000000000003067102000033504C2B57DFD101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000008DFC0400000000000100000001000000 "V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé\Start.exe"=0x534143500100000000000000070000002800000000CD1500A021160001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000C03A2900000000000100000001000000 "C:\Program Files\Windows Defender\MSASCui.exe"=0x534143500100000000000000070000002800000000D613004AAE140001000000010000000000000A00210000D5B3B31A57DFD1010000000000000000 "V:\iso images pour zalman zm-ve350\Sidekick-ISO.exe"=0x5341435001000000000000000700000028000000D03EBE00000000000100000000000000000001067100000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000D0500000000000000200000002000000 "C:\Program Files (x86)\IMSIDesign\Turbo View & Convert\tvc.exe"=0x534143500100000000000000070000002800000000D3BC013F2ABD0101000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000C2965C00000000000400000004000000 "V:\barrow 2 & widen 100% sécurisé\PortableApps\FirefoxPortable\FirefoxPortable.exe"=0x5341435001000000000000000700000028000000683703008E1404000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000079640600000000000100000001000000 "C:\Users\Jean-Marie\Desktop\FHiwFm4qopB_RepWin\RepWin.exe"=0x5341435001000000000000000700000028000000009E4000D88441000100000000000000000003060001000033504C2B57DFD101000000800000000002000000280000000000000000000040000000000000000000000000000000000BB20000000000000100000001000000 "C:\Users\Jean-Marie\Desktop\EJsiNVDq8Kh_ListeLogsInstall.exe"=0x5341435001000000000000000700000028000000AC7A0D001F960A000100000000000000000001067102000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000EAC60000000000000100000001000000 "C:\Users\Jean-Marie\Desktop\EJtpvhjdbOh_FLPU.exe"=0x534143500100000000000000070000002800000000B41000C844110001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000099D5600000000000100000001000000 "V:\PortableApps\FastCopyPortable\FastCopyPortable.exe"=0x534143500100000000000000070000002800000000AA02003B7A03000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000009C3D0200000000000100000001000000 ---------- | IFEO ---------- | Mountpoints2 ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows Defender] "UIFirstRun"=0 [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=0 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=131156367610926818 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "DisableAntiSpyware"=0 "TrustedImageIdentifier"=P004N3-B2V "ProductType"=2 "ManagedDefenderProductType"=0 "ProductStatus"=0 "InstallTime"=0x19AE51206EF5D101 "DisableAntiVirus"=0 "InstallLocation"=C:\Program Files\Windows Defender\ "OOBEInstallTime"=0xFD5A28B105F6D101 "OneTimeSqmDataSent"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\prwntdrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) [HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012] : MSAFD Irda [IrDA] [HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012] : MSAFD Irda [IrDA] [HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012] : MSAFD Irda [IrDA] [HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012] : MSAFD Irda [IrDA] ---------- | Hosts 127.0.0.1 localhost ::1 localhost ---------- | @ [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "Start Page"=http://www.msn.com/ "Default_Page_URL"=http://g.uk.msn.com/CQDSK13/3 "Cache_Update_Frequency"=Once_Per_Session "Local Page"=C:\Windows\system32\blank.htm "NoUpdateCheck"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "IconCache"=7s76fp9 "ApplicationTileImmersiveActivation"=0 "AssociationActivationMode"=2 "OperationalData"=13 "EdgeSwitchingOSBuildNumber"=10240.th1.150819-1946 "ImageStoreRandomFolder"=qqutsh5 "CompatibilityFlags"=0 "IE10TourNoShow"=1 "FullScreen"=no "Window_Placement"=0x2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF240000002400000044030000A4020000 "Start Page_TIMESTAMP"=0x9847D27DDCFAD101 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"=0x010000001700000069EC0689E0C96C7111A9E3B0350FCBE38ED303D3A3F524020000000E0000007151394C514C694A713855253364 "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0x6447D586F4F5D101 "NotifyDownloadComplete"=yes "DownloadWindowPlacement"=0x0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "CertificateRevocation"=1 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EnableNegotiate"=1 "MigrateProxy"=1 "ProxyEnable"=0 "ZonesSecurityUpgrade"=0x6447D586F4F5D101 "EmailName"=User@ "AutoConfigProxy"=wininet.dll "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "WarnOnPost"=0x01000000 "UseSchannelDirectly"=0x01000000 "EnableHttp1_1"=1 "UrlEncoding"=0 "WarnonZoneCrossing"=0 "GlobalUserOffline"=0 [HKLM\Software\Microsoft\Internet Explorer\Main] "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Cache_Percent_of_Disk"=0x0A000000 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "DisableRandomFlighting"=0 "EnableLegacyEdgeSwitching"=1 "Default_Page_URL"=http://g.uk.msn.com/CQDSK13/3 "Start Page"=http://g.uk.msn.com/CQDSK13/3 "DoNotTrack"=1 [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 "ProxyEnable"=0 "GlobalUserOffline"=0 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\SysWOW64\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 "ProxyEnable"=0 "GlobalUserOffline"=0 ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | SSODL | SEH | URLSH | STS ---------- | Toolbar [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} "KnownProvidersUpgradeTime"=0x6447D586F4F5D101 "Version"=5 "UpgradeTime"=0x6447D586F4F5D101 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} ---------- | Extensions [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{25510184-5A38-4A99-B273-DCA8EEF6CD08}] : (@C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102) - [] ---------- | SearchScopes [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPDTDFJS : [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}] - (Yahoo) - http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF : [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}] - (eBay) - http://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPDTDFJS : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5BD8BA7A-83E9-4F8F-B045-4ACBBE3EDF7D}] - (Propositions de recherche Amazon.fr) - http://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}] - (Yahoo) - http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}] - (eBay) - http://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPDTDFJS : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}] - (Yahoo) - http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}] - (eBay) - http://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} : ---------- | ElevationPolicy [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD41E1A5-99E5-41BA-8703-6BE974416118}] - (C:\Program Files (x86)\Nero\Nero 2016\Nero Burning ROM\) - nero.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\4DDD5300-D063-473A-9D82-96B009619DA5] - (C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources) - HPSALauncher.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0002df01-0000-0000-c000-000000000046}] - (C:\Program Files\Internet Explorer) - iexplore.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{041a5213-ea64-4c45-99af-70d7d8e902ec}] - (C:\Program Files\Internet Explorer) - ielowutil.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] - (C:\Program Files\Common Files\Microsoft Shared\Ink) - tabtip.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] - (C:\Windows\System32) - wpcer.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695}] - (C:\Windows\System32) - winfxdocobj.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] - (C:\Windows\System32) - wuapp.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{130c40f0-1bcb-4852-8b63-291cf90a600b}] - (C:\Windows\System32) - msdt.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework64\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0935-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework64\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2391d819-9d17-44ec-9ac1-f6aa07549469}] - (%systemroot%\system32) - wermgr.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] - (C:\Program Files\Internet Explorer) - ieinstal.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2dec4925-1312-4d7f-a6f5-89272d848dcf}] - (%WINDIR%\system32\IME\IMEJP\) - IMJPUEX.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{357FBE87-6C8E-490D-A059-4746C864AE6F}] - (C:\Program Files\Common Files\Microsoft Shared\Ink) - InputPersonalization.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38f2c092-34df-4c12-9d9e-c9679bf0ab31}] - (C:\Windows\SysWOW64) - presentationhost.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49E561B1-1091-4E65-98A0-AFCA4996CD1D}] - (C:\Windows\System32) - RuntimeBroker.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4f8ac1ca-7191-460b-8658-8730217499ac}] - (C:\WINDOWS\system32\spool\DRIVERS\x64\3) - E_IPRELPE.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8381C-2705-4DC2-ADF3-347D4D619350}] - (%WINDIR%\system32\IME\shared) - imecfmui.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61bd7005-d55e-4693-a191-0caa33601426}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{681f008a-b1c3-412d-9d95-e7a68837a6ce}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] - (%ProgramFiles%\Windows Media Player) - wmplayer.exe : %SystemRoot%\system32\wmp.dll [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] - (%ProgramFiles(x86)%\Windows Media Player) - wmplayer.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6e6d1593-209c-49d4-a2c1-56141b8953b8}] - (C:\WINDOWS\system32\spool\DRIVERS\x64\3) - E_IARNLPE.EXE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] - (C:\Program Files\Internet Explorer) - iedw.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{734A9EB3-A34D-4fb7-9DB4-549C28F7EF97}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] - (C:\Windows\System32\) - CertEnrollCtrl.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] - (C:\Windows\System32) - verclsid.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f7bd411-f034-4ac0-9424-224bd7ab4e4e}] - (%WINDIR%\system32\IME\SHARED\) - IMEPADSV.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{812954F9-FAA2-4aee-A9E7-3C4FDE2166A6}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] - (C:\Windows\System32) - ctfmon.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{877467C0-F9E4-4561-84F0-65AA7539833C}] - (C:\Windows\System32) - CredentialUIBroker.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] - (C:\Windows) - helppane.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{989F13EE-B25B-4FAB-9AED-C4336C8CCF0C}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98E3C2D3-E92F-469F-87EB-76054F640517}] - (C:\Windows\System32\IME\SHARED\) - imesearch.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a1ad1bbb-3b33-4260-a74c-5fd8bc1479fc}] - (C:\Windows) - splwow64.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a4fbcbc6-4be5-4c3d-8ab5-8b873357a23e}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] - (C:\Windows\SysWOW64\xpsviewer) - xpsviewer.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{afe26134-8a16-4149-b798-242574f3f4a9}] - (%SystemRoot%\system32\IME\IMETC\) - IMTCPROP.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] - (C:\Windows\System32) - cmd.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] - (%systemroot%\system32) - TSWbPrxy.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D802E3EF-2513-4661-972E-BAD737EFBA88}] - (C:\Program Files (x86)\DivX\DivX OVS Helper) - OVSHelperBroker.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] - (C:\Windows\System32) - notepad.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea109b0c-6a97-45f0-9eb4-5907dd99b995}] - (%WINDIR%\system32\IME\SHARED\) - imedictupdateui.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] - (C:\Windows\System32) - presentationhost.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f5d04f46-b4b2-4202-a191-f780421b4200}] - (%WINDIR%\system32\IME\IMEJP\) - imjpdct.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa6f0991-f729-4899-b095-d3fbca253cf6}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] - (C:\Windows\System32\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] - (C:\Windows\System32\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\4DDD5300-D063-473A-9D82-96B009619DA5] - (C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources) - HPSALauncher.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0002df01-0000-0000-c000-000000000046}] - (C:\Program Files (x86)\Internet Explorer) - iexplore.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{041a5213-ea64-4c45-99af-70d7d8e902ec}] - (C:\Program Files (x86)\Internet Explorer) - ielowutil.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] - (C:\Program Files (x86)\Common Files\Microsoft Shared\Ink) - tabtip.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] - (C:\Windows\SysWOW64) - wpcer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}] - (C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat Elements) - Acrobat Elements.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695}] - (C:\Windows\SysWOW64) - winfxdocobj.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] - (C:\Windows\SysWOW64) - wuapp.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{130c40f0-1bcb-4852-8b63-291cf90a600b}] - (C:\Windows\SysWOW64) - msdt.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] - (C:\Program Files (x86)\Internet Explorer) - ieinstal.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2dec4925-1312-4d7f-a6f5-89272d848dcf}] - (%WINDIR%\system32\IME\IMEJP\) - IMJPUEX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{357FBE87-6C8E-490D-A059-4746C864AE6F}] - (C:\Program Files (x86)\Common Files\Microsoft Shared\Ink) - InputPersonalization.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{380689D0-AFAA-47E6-B80E-A33436FE314B}] - (C:\Program Files (x86)\Windows Live\Contacts\) - wlcomm.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49E561B1-1091-4E65-98A0-AFCA4996CD1D}] - (C:\Windows\SysWOW64) - RuntimeBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}] - (C:\Program Files (x86)\adobe\acrobat 7.0\reader) - acrord32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8381C-2705-4DC2-ADF3-347D4D619350}] - (%WINDIR%\system32\IME\shared) - imecfmui.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F17E524-3447-4c7d-8E5F-4EFF31CDE3B7}] - (C:\Program Files (x86)\Common Files\DivX Shared\DesktopService) - DDMService.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61bd7005-d55e-4693-a191-0caa33601426}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{64903E32-AE0B-408D-909C-09A08791F28D}] - (C:\Program Files (x86)\DivX\DivX Web Player) - dwpBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{681f008a-b1c3-412d-9d95-e7a68837a6ce}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] - (%ProgramFiles%\Windows Media Player) - wmplayer.exe : %SystemRoot%\system32\wmp.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] - (%ProgramFiles(x86)%\Windows Media Player) - wmplayer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] - (C:\Program Files (x86)\Internet Explorer) - iedw.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{734A9EB3-A34D-4fb7-9DB4-549C28F7EF97}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] - (C:\Windows\SysWOW64\) - CertEnrollCtrl.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] - (C:\Windows\SysWOW64) - verclsid.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f7bd411-f034-4ac0-9424-224bd7ab4e4e}] - (%WINDIR%\sysnative\IME\SHARED\) - IMEPADSV.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{812954F9-FAA2-4aee-A9E7-3C4FDE2166A6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] - (C:\Windows\SysWOW64) - ctfmon.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{877467C0-F9E4-4561-84F0-65AA7539833C}] - (C:\Windows\SysWOW64) - CredentialUIBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] - (C:\Windows) - helppane.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9019d14b-638d-4383-bb95-441b7f57eafb}] - (C:\Program Files (x86)\Windows Live\Installer\) - wlstartup.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}] - (C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat) - acrobat.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{989F13EE-B25B-4FAB-9AED-C4336C8CCF0C}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98E3C2D3-E92F-469F-87EB-76054F640517}] - (C:\Windows\SysWOW64\IME\SHARED\) - imesearch.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}] - (C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements) - Acrobat Elements.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a1ad1bbb-3b33-4260-a74c-5fd8bc1479fc}] - (C:\Windows) - splwow64.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a4fbcbc6-4be5-4c3d-8ab5-8b873357a23e}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] - (C:\Windows\SysWOW64\xpsviewer) - xpsviewer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{afe26134-8a16-4149-b798-242574f3f4a9}] - (%SystemRoot%\system32\IME\IMETC\) - IMTCPROP.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] - (C:\Windows\SysWOW64) - cmd.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] - (%systemroot%\system32) - TSWbPrxy.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AED-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D802E3EF-2513-4661-972E-BAD737EFBA88}] - (C:\Program Files (x86)\DivX\DivX OVS Helper) - OVSHelperBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] - (C:\Windows\SysWOW64) - notepad.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD41E1A5-99E5-41BA-8703-6BE974416118}] - (C:\Program Files (x86)\Nero\Nero 2016\Nero Burning ROM\) - nero.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e5f90a07-7db7-4dcb-bd6d-d3fecd376ca3}] - (C:\Program Files (x86)\adobe\acrobat 6.0\reader) - acrord32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea109b0c-6a97-45f0-9eb4-5907dd99b995}] - (%WINDIR%\sysnative\IME\SHARED\) - imedictupdateui.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] - (C:\Windows\SysWOW64) - presentationhost.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f5d04f46-b4b2-4202-a191-f780421b4200}] - (%WINDIR%\system32\IME\IMEJP\) - imjpdct.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa6f0991-f729-4899-b095-d3fbca253cf6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] - (C:\Windows\SysWOW64\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] - (C:\Windows\SysWOW64\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}] - (C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat) - acrobat.exe : ---------- | Ext\Settings ---------- | Ext\Stats [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25336920-03F9-11CF-8FD0-00AA00686F13}] : : C:\Windows\SysWOW64\mshtml.dll [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] : : [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}] : : ---------- | Browser Helper Objects ---------- | Chrome ---------- | Opera ---------- | Firefox [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 22.0.0.209 Plugin) : C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] - (DivX VOD Helper Plug-in) : C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 22.0.0.209 Plugin) : C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] - (DivX VOD Helper Plug-in) : C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0] - (DivX Web Player) : C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@Nero.com/KM] - () : C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL ---------- | Active Connections ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=192.168.1.1 192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{b389ab24-c362-4fab-b29c-601c91b5a911}] "DhcpNameServer"=192.168.1.1 192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{b389ab24-c362-4fab-b29c-601c91b5a911}] "DhcpNameServer"=192.168.1.1 192.168.1.1 ---------- | ActiveX [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] - () - [1,1,1,9] - -> [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - () - [10,0,14393,0] - -> [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - () - [12,0,10011,16384] - -> [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] - () - [10,0,14393,51] - -> [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - () - [11,0,14393,0] - -> [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - [] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player) - [12,0,14393,0] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\inf\unregmp2.exe /ShowWMP [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player 12.0) - [12,0,10011,16384] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] - (Themes Setup) - [1,1,1,9] - @%SystemRoot%\system32\themeui.dll,-2682 -> /UserInstall [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{31699572-6286-3C1C-A03C-511D59181038}] - (.NET Framework) - [4,0,30319,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] - (Offline Browsing Pack) - [11,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - (Microsoft Windows) - [10,0,14393,0] - -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] - (DirectDrawEx) - [4,71,1113,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] - (Internet Explorer Help) - [11,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] - (Microsoft Windows Script 5.6) - [5,6,0,8833] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] - (Internet Explorer Setup Tools) - [11,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] - (Browsing Enhancements) - [11,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - (Microsoft Windows Media Player) - [12,0,10011,16384] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /FirstLogon [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] - (MSN Site Access) - [4,9,9,2] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] - (Address Book 7) - [10,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] - (Windows Desktop Update) - [10,0,14393,51] - @%SystemRoot%\system32\shell32.dll,-32969 -> U [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - (Web Platform Customizations) - [11,0,14393,0] - @C:\Windows\System32\ie4uinit.exe,-2000 -> C:\Windows\System32\ie4uinit.exe -UserConfig [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - [] - -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] - (Dynamic HTML Data Binding) - [11,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] - (Internet Explorer Core Fonts) - [11,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] - (HTML Help) - [10,0,14393,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] - (Active Directory Service Interface) - [5,0,00,0] - -> [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}] - (.NET Framework) - [2,0,50727,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player) - [12,0,10011,16384] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /ShowWMP [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player 12.0) - [12,0,10011,16384] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] - (Offline Browsing Pack) - [11,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - (Microsoft Windows) - [10,0,14393,0] - -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] - (DirectDrawEx) - [4,71,1113,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] - (Internet Explorer Help) - [11,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] - (Microsoft Windows Script 5.6) - [5,6,0,8833] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] - (Internet Explorer Setup Tools) - [11,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] - (Browsing Enhancements) - [11,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - (Microsoft Windows Media Player) - [12,0,10011,16384] - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /FirstLogon [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] - (MSN Site Access) - [4,9,9,2] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{71A5A636-652F-3BE0-BC14-02545E9F5EC7}] - (.NET Framework) - [4,0,30319,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] - (Address Book 7) - [10,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}] - (.NET Framework) - [2,0,50727,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - () - [] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - [] - -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] - (Dynamic HTML Data Binding) - [11,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{9C142C0C-124C-4467-B117-EBCC62801D7B}] - (Vivaldi) - [43,0,0,0] - -> "C:\Program Files (x86)\Vivaldi\Application\1.3.551.30\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}] - (.NET Framework) - [2,0,50727,1] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] - (Internet Explorer Core Fonts) - [11,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] - (HTML Help) - [10,0,14393,0] - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] - (Active Directory Service Interface) - [5,0,00,0] - -> ---------- | Applications [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\vivaldi.exe] : "C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe" -- "%1" [HKLM\SOFTWARE\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vivaldi.exe] : "C:\Program Files (x86)\Vivaldi\Application\vivaldi.exe" -- "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | DCOMApplications Name: User Notification - AppID: {0010890e-8789-413c-adbc-48f5b511b3af} Name: PhotoAcquire - AppID: {00f22b16-589e-4982-a172-a51d9dcceb68} Name: PhotoAcqHWEventHandler - AppID: {00f2b433-44e4-4d88-b2b0-2698a0a91dba} Name: TabTip - AppID: {01419581-4d63-4d43-ac26-6e2fc976c1f3} Name: lfsvc - AppID: {020FB939-2C8B-4DB7-9E90-9527966E38E5} Name: PLA - AppID: {03837503-098b-11d8-9414-505054503030} Name: CTapiLuaLib Class - AppID: {03e15b2e-cca6-451c-8fb0-1e2ee37a27dd} Name: Microsoft SQL Server Replication Remote Merge Agent 11.0 - AppID: {042A4340-A4D7-44DD-A22E-93278FB52475} Name: DevicesFlowExperienceFlow - AppID: {046AEAD9-5A27-4D3C-8A67-F82552E0A91B} Name: COpenControlPanel - AppID: {06622D85-6856-4460-8DE1-A81921B41C4B} Name: SMLUA - AppID: {0671E064-7C24-4AC0-AF10-0F3055707C32} Name: PhotoAcqDropTargetEventHandler - AppID: {06A2568A-CED6-4187-BB20-400B8C02BE5A} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {06C792F8-6212-4F39-BF70-E8C0AC965C23} Name: OOBE Bio Enrollment - AppID: {0771f7af-8de6-4bce-9528-2d4a12cb8168} Name: sppui - AppID: {0868DC9B-D9A2-4f64-9362-133CEA201299} Name: Retail Demo User COM Agent - AppID: {0886dae5-13ba-49d6-a6ef-d0922e502d96} Name: RtkApoApi - AppID: {08B039CA-84AA-40EA-8E9C-1D9537DC415B} Name: WIA Extension Host for 64 bit extensions - AppID: {08F646B3-5E7F-4B7A-A5CB-F95445F9F67A} Name: Proximity Sharing - AppID: {08FC06E4-C6B5-40BE-97B0-B80F943C615B} Name: PersistentZoneIdentifier - AppID: {0968e258-16c7-4dba-aa86-462dd61e31a3} Name: Windows Media Player Rich Preview Handler - AppID: {09C5C2B5-1D32-4598-B87E-203F32BB08E3} Name: QuickTimeShellExt - AppID: {0A18A436-2A7A-49F3-A488-30538A2F6323} Name: SwapAPODll - AppID: {0A21D954-674A-4C09-806E-DB4FBE8F199C} Name: AxInstSv - AppID: {0B15AFD8-3A99-4A6E-9975-30D66F70BD94} Name: NotificationController App ID - AppID: {0B789C73-D8DA-416D-B665-C1603676CEB1} Name: RASDLGLUA - AppID: {0C3B05FB-3498-40C3-9C03-4B22D735550C} Name: %SystemRoot%\system32\appwiz.cpl - AppID: {0da7bfdf-c0a0-44eb-be82-b7a82c4721de} Name: NeroShellExt - AppID: {10EBE05D-77B3-4C15-9080-6002AFD08B48} Name: IIS W3 Control - AppID: {119817C9-666D-4053-AEDA-627D0E25CCEF} Name: Sync Center Client - AppID: {1202DB60-1DAC-42C5-AED5-1ABDD432248E} Name: Virtual Factory for DiagCpl - AppID: {12C21EA7-2EB8-4B55-9249-AC243DA8C666} Name: Shell Create Object Task Server - AppID: {133eac4f-5891-4d04-bada-d84870380a80} Name: Shell Create Object Handler - AppID: {135fd325-45b7-4c30-89f8-4386961669f0} Name: TPM Virtual Smart Card VCard Module Manager - AppID: {150F28F1-49A5-4C28-BE1A-CFA854A1D04B} Name: Remote TPM Virtual Smart Card Manager - AppID: {152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC} Name: TPM Virtual Smart Card Manager - AppID: {16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A} Name: Speech Runtime COM - AppID: {1725704B-A716-4E04-8EF6-87ED4F0A180A} Name: Immersive TPM Virtual Smart Card Manager - AppID: {19833350-BF9B-42A1-BDF0-BD1FCBE1FD31} Name: Sync Center Control - AppID: {1A1F4206-0688-4E7F-BE03-D82EC69DF9A5} Name: GIDS Smart Card Simulator Manager - AppID: {1AC32B1A-E379-4CAD-B655-F978A30856EC} Name: NAUpdate - AppID: {1AC9CDC0-9D87-4371-9DE7-65C3F39AE5E6} Name: %systemroot%\system32\lpksetup.exe - AppID: {1C749B87-568C-4865-8E73-6413F8372CE6} Name: TIManagersProxy Class Application - AppID: {1EF75F33-893B-4E8F-9655-C3D602BA4897} Name: rshx32.dll - AppID: {1f2e5c40-9550-11ce-99d2-00aa006e086c} Name: ThirdPartyEapDispatcherPeerConfig - AppID: {1F7D1BE9-7A50-40B6-A605-C4F3696F49C0} Name: Microsoft WMI Provider Subsystem Secured Host - AppID: {1F87137D-0E7C-44d5-8C73-4EFFB68962F2} Name: DetectionAndSharing - AppID: {1fda955b-61ff-11da-978c-0008744faab7} Name: Microsoft Software Protection Platform Admin Object (Inner) - AppID: {205609B7-5E08-443E-B0A7-A7AED3F3A717} Name: Microsoft Windows WSMan Provider Host With User Settings - AppID: {209444d2-2540-495e-962c-a61ad3243526} Name: Provisioning Core - AppID: {217700E0-0000-11DF-ADB9-F4CE462D9137} Name: MSDAINITIALIZE - AppID: {2206CDB0-19C1-11D1-89E0-00C04FD7A829} Name: CortanaExperienceFlow - AppID: {24AC8F2B-4D4A-4C17-9607-6A4B14068F97} Name: InstallAgent - AppID: {260eb9de-5cbe-4bff-a99a-3710af55bf1e} Name: Microsoft WBEM Active Scripting Event Consumer Provider - AppID: {266C72E7-62E8-11D1-AD89-00C04FD8FDFF} Name: Exchange Active Sync Policies Broker - AppID: {26795871-6B8F-4115-89DD-986213012798} Name: IMAPI2 - AppID: {273541FF-7F64-5B0F-8F00-5D77AFBE261E} Name: WInRTDesktopBroker - AppID: {27550CA0-E9DE-4186-A566-37A59BB6CA69} Name: Cloud Change Wnf Monitor - AppID: {276D4FD3-C41D-465F-8CA9-A82A7762DF32} Name: netman - AppID: {27AF75ED-20D9-11D1-B1CE-00805FC1270E} Name: WalletService - AppID: {27D6B72D-094D-445A-9ACE-8298CBA0611A} Name: AERTACap - AppID: {288E7ECC-EB53-45df-8EBD-72EAF9AFCB00} Name: InstallAgentUserBroker - AppID: {28d08f70-46eb-4f26-a6cb-54b75132e100} Name: ImageHost - AppID: {2903EDD7-545F-4156-977A-5E730E57F253} Name: RasMobilityManager - AppID: {292bed96-e9ce-40f8-b71b-c313defa3a78} Name: Windows Live Photo Gallery Autoplay Drop Target - AppID: {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} Name: faultrep.dll - AppID: {2C256447-3F0D-4CBB-9D12-575BB20CDA0A} Name: FileSystemImage - AppID: {2C941FD1-975B-59BE-A960-9A2A262853A5} Name: DTS Package Host (32-bit) - AppID: {2CB1C2AA-A8EA-41CD-B439-25F4F4C846A9} Name: WalletService - AppID: {2EA38040-0B9C-4379-87FD-4D38BB892F37} Name: DevicesFlow - AppID: {2F93C02D-77F9-46B4-95FB-8CBB81EEB62C} Name: Immersive Shell Broker - AppID: {2FD08A73-D1F1-43EB-B888-24C2496F95FD} Name: ShellServiceHostBrokerProvider - AppID: {30AD8C8E-AE85-42FA-B9E8-7E99E3DFBFC5} Name: Identity Store - AppID: {30d49246-d217-465f-b00b-ac9ddd652eb7} Name: AuthHost - AppID: {31337EC7-5767-11CF-BEAB-00AA006C3606} Name: Immersive Shell - AppID: {316CDED5-E4AE-4B15-9113-7055D84DCC97} Name: Delivery Optimization Mgmt - AppID: {338B40F9-9D68-4B53-A793-6B9AA0C5F63B} Name: Language Components Installer Com Handler - AppID: {33ADC7D5-BAF1-4661-9822-1FD23E63B39F} Name: wpnservice - AppID: {34E76A18-223B-4E23-BEAD-F59358CC0A90} Name: Windows Push Notification Platform - AppID: {362cc086-4d81-4824-bbb5-666d34b3197d} Name: Microsoft SQL Server Replication Logreader Agent 11.0 - AppID: {368C2E48-7E89-4970-94C9-6757E96C49AF} Name: TabTip - AppID: {36938566-B1AA-4E77-9B3F-730CF4E996AB} Name: Delivery Optimization - AppID: {379001DE-7108-4A45-8A74-6CD0A9FBEF2C} Name: Microsoft Portable Workspace Launcher - AppID: {37B73D7B-A976-43AE-97E4-BD4977B241F2} Name: CContactDb - AppID: {380689D0-AFAA-47E6-B80E-A33436FE314B} Name: LivePhotoAcqHWEventHandler - AppID: {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F} Name: CortanaMapiHelper - AppID: {3BFADDE5-09ED-42AE-8190-2E68B650CFE6} Name: WorkspacePolicyProcessor - AppID: {3C3F40BC-60EB-4567-B90C-480C87C21AC1} Name: EEL64A - AppID: {3D5781D9-B2FF-4396-8478-395412020995} Name: CMLUAUTIL - AppID: {3E000D72-A845-4CD9-BD83-80C07C3B881F} Name: Microsoft Windows Remote Shell Host - AppID: {3e5ca495-8d6a-4d1f-ad99-177b426c8b8e} Name: CMSTPLUA - AppID: {3E5FC7F9-9A51-4367-9063-A120244FBEC7} Name: WinInetCacheServer - AppID: {3eb3c877-1f16-487c-9050-104dbcd66683} Name: Out Of Proc Mapi Handler - AppID: {3F5E4B87-C907-4f76-82E4-6FDF0CE90E25} Name: Microsoft Windows WSMan Provider Host - AppID: {3feb2f63-0eec-4b96-84ab-da1307e0117c} Name: HTML Application - AppID: {40AEEAB6-8FDA-41e3-9A5F-8350D4CFCA91} Name: Connected User Store - AppID: {40AFA0B6-3B2F-4654-8C3F-161DE85CF80E} Name: AERTARen - AppID: {41C98373-FE7F-4a42-B694-34CC4F979E61} Name: EntAppSvc - AppID: {42C21DF5-FB58-4102-90E9-96A213DC7CE8} Name: AccessibilityCplAdmin - AppID: {434A6274-C539-4E99-88FC-44206D942775} Name: SPP External COM Object - AppID: {44831FEC-DC51-4716-A7E1-E898FDF83C85} Name: Thumbnail Extraction Host Class - AppID: {4545dea0-2dfc-4906-a728-6d986ba399a9} Name: Add to Windows Media Player list - AppID: {45597c98-80f6-4549-84ff-752cf55e2d29} Name: Application Activation Manager - AppID: {45BA127D-10A8-46EA-8AB7-56EA9078943C} Name: Set Network Location Elevated Virtual Factory - AppID: {46B988E8-BEC2-401F-A1C5-16C694F26D3E} Name: Radio Management Service - AppID: {478B41E6-3257-4519-BDA8-E971F9843849} Name: EEG64A - AppID: {47EC1E17-F30B-430b-B9C4-DF60ED501A4B} Name: ShellServiceHost - AppID: {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} Name: IASDataStoreComServer - AppID: {48da6741-1bf0-4a44-8325-293086c79077} Name: COM_SRS_HP360 - AppID: {49611624-F1A3-4AA7-8A06-0209D7D6BA92} Name: Microsoft WBEM Unsecured Apartment - AppID: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Name: Telephony App Launcher - AppID: {49EBD8BE-1A92-4A86-A651-70AC565E0FEB} Name: UIAutomationCrossBitnessHook64 Class - AppID: {49f171dd-b51a-40d3-9a6c-52d674cc729d} Name: IndexedDbCacheServer - AppID: {49f6e667-6658-4bd1-9de9-6af87f9faf85} Name: Virtual Factory for Languages Configuration - AppID: {4A3F2F56-454A-4CC5-9734-BB7D8141AC0A} Name: RASGCWLUA - AppID: {4A6B8BAD-9872-4525-A812-71A52367DC17} Name: wercplsupport.dll - AppID: {4BC67F23-D805-4384-BCA3-6F1EDFF50E2C} Name: AszBrowseHelper - AppID: {4D0EF64C-71D3-4A05-93B1-8EC58AE8D6D9} Name: Shell Security Editor - AppID: {4D111E08-CBF7-4f12-A926-2C7920AF52FC} Name: DTS Task Host (32-bit) - AppID: {4D3E4495-4A1C-4AB6-BFCB-E4056EB546D0} Name: Dispatch - AppID: {4D5F23BB-D55A-4961-9BC0-3FE728E15D9D} Name: Microsoft Volume Shadow Copy Service software provider - AppID: {4db9c793-c48d-449c-9754-46027ee45c94} Name: COM+ Event System - AppID: {4E14FBA2-2E22-11D1-9964-00C04FBBB345} Name: upnpcont.exe - AppID: {4F0AC159-5804-4aa7-AE91-117D6E67BB9B} Name: Shell Computer Accounts - AppID: {4f6bcd94-c2a5-42ce-8dbc-31e794be4630} Name: WkspRT.exe - AppID: {4FCDA643-B15B-41C6-84F8-5E447F6F6D25} Name: HomeGroup CPL Advanced Settings Writer - AppID: {50a9ab2a-20f8-4d71-9f32-9fd305b49601} Name: Microsoft Windows Font Folder - AppID: {50d69d24-961d-4828-9d1c-5f4717f226d1} Name: wuapihost - AppID: {50E1C3FD-EC35-490E-9CCF-C68F9AE91919} Name: acppage.dll - AppID: {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} Name: %systemroot%\system32\intl.cpl - AppID: {514B5E31-5596-422F-BE58-D804464683B5} Name: Offline Files Service - AppID: {52551A19-B337-498d-AE75-2283E29902DE} Name: FsrmPropertiesPropSheet - AppID: {52FC5917-F4E4-4C78-B469-20E722379F6C} Name: RemoteProxyFactory32 Class - AppID: {53362C32-A296-4F2D-A2F8-FD984D08340B} Name: RemoteProxyFactory32 Class - AppID: {53362C64-A296-4F2D-A2F8-FD984D08340B} Name: 32-bit Preview Handler Surrogate Host - AppID: {534A1E02-D58F-44f0-B58B-36CBED287C7C} Name: Virtual Disk Service Loader - AppID: {5364ED0E-493F-4B16-9DBF-AE486CF22660} Name: LockScreenContentServer Out of Proc Helper for LockScreenContent Clients - AppID: {536AACFB-5238-4314-B4D4-5B0A2E8B968E} Name: ShareFlow - AppID: {549e57e9-b362-49d1-b679-b64d510efe4b} Name: SRS_APO_Universal - AppID: {553C48B2-BA6B-412B-9F8D-2B62B1B912AA} Name: ShapeCollector - AppID: {56676660-4A4D-45B0-B24E-9CF6B35E9ABF} Name: Volume Shadow Copy Service - AppID: {56BE716B-2F76-4dfa-8702-67AE10044F0B} Name: Elevated System Settings COM Host - AppID: {57360832-5F9B-4190-8467-000D2D510212} Name: PrintNotify - AppID: {588E10FA-0618-48A1-BE2F-0AD93E899FCC} Name: Watson subscriber for SENS Network Events - AppID: {58FC39EB-9DBD-4EA7-B7B4-9404CC6ACFAB} Name: FaxCommon Class - AppID: {59347292-B72D-41F2-98C5-E9ACA1B247A2} Name: Authentication UI Terminal Services Bump Dialog - AppID: {59c7f6ec-7d18-412f-a68e-877982768e61} Name: Video Capture Wizard - AppID: {5AB7566D-F75B-4A53-9615-115B6CB1D59B} Name: WalletService - AppID: {5BC7A3A1-E905-414B-9790-E511346F5CA6} Name: Microsoft Maps Background Transfer Service - AppID: {5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309} Name: EED64A - AppID: {5C73574D-FC7B-4747-8352-143F011923A0} Name: PrintBrmEngine - AppID: {5C797117-3B23-4549-A6D8-475AB3B62228} Name: WLXMP4ParserThumbnailProvider - AppID: {5D6E8BC8-01F3-41CC-BF7D-D7EEF436896E} Name: WiaWow64 - AppID: {5E1395B2-B685-44e3-8AED-E2304D85ACD1} Name: Splash screen - AppID: {5EAD00DC-0E8B-497C-BDE8-B9153058CBEF} Name: User OOBE Create User Object Server - AppID: {5f7f3f7b-1177-4d4b-b1db-bc6f671b8f25} Name: UIAutomationCrossBitnessHook32 Class - AppID: {60a90a2f-858d-42af-8929-82be9d99e8a1} Name: wlidcli - AppID: {623D5F5E-2F09-427d-8BD7-64495CD9835D} Name: Sync Center (Private) - AppID: {6295DF2D-35EE-11D1-8707-00C04FD93327} Name: PenIMC2 - AppID: {63CE6D27-426A-41F9-8E51-549C1132DAE2} Name: Windows Update Agent - AppID: {653C5148-4DCE-4905-9CFD-1B23662D3D9E} Name: FwCplLUA - AppID: {6571503D-D0FB-4D98-BBC3-1FBB2B3F344E} Name: tiledatamodelsvc - AppID: {65E2E13A-7110-4912-9F03-9A42E253D8F6} Name: Background Intelligent Transfer Service - AppID: {69AD4AEE-51BE-439b-A92C-86AE490E8B30} Name: Sync Center Isolation Collection (Private) - AppID: {69F9CB25-25E2-4BE1-AB8F-07AA7CB535E8} Name: MsRdpSessionManager - AppID: {6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F} Name: Preview Handler Surrogate Host - AppID: {6d2b5079-2f0b-48dd-ab7f-97cec514d30b} Name: UPnPContainer - AppID: {6d8ff8e0-730d-11d4-bf42-00b0d0118b56} Name: UPnPContainer64 - AppID: {6d8ff8e8-730d-11d4-bf42-00b0d0118b56} Name: SPPComApi - AppID: {6D9A7A40-DDCA-414E-B48E-DFB032C03C1B} Name: TieringEngineService - AppID: {6DF5BCF4-22E9-446D-8763-A2C7677ECF7D} Name: HomeGroup UI Status - AppID: {6f33340d-8a01-473a-b75f-ded88c8360ce} Name: IEWindows - AppID: {6f5bad87-9d5e-459f-bd03-3957407051ca} Name: EditionUpgradeHelper - AppID: {6F65B602-F798-4094-8A41-A2A61961E5E8} Name: HomeGroup Provider Object - AppID: {6F7C8E8F-DC69-4e3f-BC05-439962A05FD5} Name: Windows Insider Service - AppID: {7006698d-2974-4091-a424-85dd0b909e23} Name: workfolderssvc - AppID: {712cedb9-16a4-4f79-801d-7de24d8c706e} Name: Sharing Elevated Virtual Factory - AppID: {72A7994A-3092-4054-B6BE-08FF81AEEFFC} Name: User Profile Service DCOM server - AppID: {72E3272B-4EEA-4104-B358-1A282E4FC1AD} Name: Microsoft WMI Provider Subsystem Host - AppID: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} Name: Trusted Installer Service - AppID: {752073A2-23F2-4396-85F0-8FDB879ED0ED} Name: PenIMC4 - AppID: {7568952A-571E-4C70-BEA9-7F9004393436} Name: PrintFilterPipelineSvc - AppID: {76db1bf3-e820-4765-a1b2-0b16a86b1950} Name: XWizard Virtual Factory - AppID: {777BA81A-2498-4875-933A-3067DE883070} Name: Dispatch - AppID: {7953C53B-4031-43ca-9AE7-033F565EFD5F} Name: Network and Sharing Center Cpl Elevated Virtual Factory - AppID: {7A076CE1-4B31-452a-A4F1-0304C8738100} Name: Shell FMIFS Wrapper - AppID: {7aa7790d-75d7-484b-98a1-3913d022091d} Name: CLMLSvc_P2G10 - AppID: {7AF75464-3A22-4BB6-A2A0-F9ED5B72DD77} Name: EapThirdPartyDllHost - AppID: {7B130458-E09C-4823-A8AF-2583DCD9AEC7} Name: Internet Explorer Add-on Installer - AppID: {7B29F495-0F55-49F7-8885-9E8A22CE3829} Name: Shell Create Object Local Server - AppID: {7B6EA1D5-03C2-4AE4-B21C-8D0515CC91B7} Name: WlanPrefLUA - AppID: {7C8AB6D9-8764-4033-8F62-2FE896E54B32} Name: Microsoft Windows Remote Shell Host With User Settings - AppID: {7d378de6-ed8d-426d-91df-0273d07cd7f6} Name: Dispatch - AppID: {7D7B609B-D089-4687-9606-264A9AA2FBB2} Name: HomeGroup Printing Device Class - AppID: {7DF8EF76-D449-485f-B4EB-58DC96B31EDB} Name: MMC Application Class - AppID: {7e0423cd-1119-0928-900c-e6d4a52a0715} Name: wisptis - AppID: {7F429620-16D1-471E-A81A-114992148034} Name: GPMC Reporting - AppID: {7f9bbc82-ba5f-4448-8622-ef76b8d007e6} Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {7FC12E96-4CB7-4ABD-ADAA-EF7845B10629} Name: hputils - AppID: {8195693E-0C55-4BE2-A2DB-32376ABC24C4} Name: CFmIfsEngine host - AppID: {82D94FB3-7FE6-4797-BB72-9A886C66073B} Name: Microsoft SQL Server Integration Services 11.0 - AppID: {83B33982-693D-4824-B42E-7196AE61BB05} Name: CustReg Class - AppID: {84D586C4-A423-11D2-B943-00C04F79D22F} Name: Virtual Factory for Usercpl - AppID: {86d5eb8a-859f-4c7b-a76b-2bd819b7a850} Name: CElevateWlanUi - AppID: {86F80216-5DD6-4F43-953B-35EF40A35AEE} Name: ThirdPartyEapDispatcherPeerRuntime - AppID: {87BB326B-E4A0-4DE1-94F0-B9F41D0C6059} Name: AppReadiness Service - AppID: {88283d7c-46f4-47d5-8fc2-db0b5cf0cb54} Name: Activation Manager Shim - AppID: {8A9AE632-CB07-4A11-8872-358A2A271A24} Name: Desktop Wallpaper Factory - AppID: {8B30085D-A3E3-44e3-AE7F-B03A1340EBED} Name: Windows Management and Instrumentation - AppID: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Name: TSTheme - AppID: {8be0366c-8522-40be-8b08-cb26557f2854} Name: IASExtensionHost - AppID: {8C334A55-DDB9-491C-817E-35A6B85D2ECB} Name: AP Client HxHelpPaneServer Class - AppID: {8cec58ae-07a1-11d9-b15e-000d56bfe6ee} Name: TiWorker - AppID: {8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D} Name: AppVClient - AppID: {8D315960-32C4-4235-8369-901DF222816F} Name: Sync Center Schedule Wizard - AppID: {8D8B8E30-C451-421B-8553-D2976AFA648C} Name: WalletService - AppID: {8E44A57C-5638-44D3-9B83-34DF70EB57F2} Name: RdpSa - AppID: {8e7fae4d-cff0-41d3-a326-5a80470264bb} Name: Shell Computer Groups - AppID: {8f3080a6-af99-4f2e-a806-f3d5702a0444} Name: SDRSVC service - AppID: {9037e3cf-1794-4af6-9c8d-92838d7a23db} Name: UACObject - AppID: {90B553F3-415D-44D8-8665-C2F78763F8F1} Name: SQLTaskConnections - AppID: {91A708A7-D12F-4B03-B8D0-DDE814119454} Name: Virtual Factory for Recovery - AppID: {9200689A-F979-4eea-8830-0E1D6B74821F} Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients - AppID: {924DC564-16A6-42EB-929A-9A61FA7DA06F} Name: RtkPgExt - AppID: {92842063-1ECC-4a1a-9343-9A8E1C972E60} Name: HtmlLocalFileResolver - AppID: {93AAD2A0-036A-4B11-A078-DA8776B38139} Name: PrintIsolationHost - AppID: {98a89e0c-1fde-4c2a-a373-b04831e6aa60} Name: Telephony Incoming Call Toast - AppID: {990F07C7-78DC-4BD2-B145-5F791410BDDE} Name: Microsoft SQL Server Replication Remote Dist Agent 11.0 - AppID: {99434DAB-0F08-4F30-8CCF-B3E80296C907} Name: Shell Hardware Mixed Content Handler - AppID: {995C996E-D918-4a8c-A302-45719A6F4EA7} Name: WLXAutoPlayMgr - AppID: {9B5CDBB0-6D57-4816-BD04-CA9E68DF5610} Name: ShellWindows - AppID: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Name: RuntimeBroker - AppID: {9CA88EE3-ACB7-47c8-AFC4-AB702511C276} Name: timedate.cpl - AppID: {9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8} Name: WSearch - AppID: {9E175B9C-F52A-11D8-B9A5-505054503030} Name: WMLSS - AppID: {9E88EF3C-E2BB-4E5E-AFBA-565B81069D7D} Name: ahadmin - AppID: {9fa5c497-f46d-447f-8011-05d03d7d7ddc} Name: CDP Reference Host - AppID: {A0316E2D-8793-4E74-AA48-8CE2ED05BA57} Name: RtkCfg - AppID: {A11009A7-DC01-48F8-B6AA-C4613FC5CB15} Name: WIA Device Manager - AppID: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Name: TrayNotify - AppID: {a2b77517-6d12-4c60-b0c6-725e971ec8fe} Name: rundll32.exe - AppID: {a2d9ca22-a492-400c-b875-78ac25c0a6f3} Name: Virtual Factory for Windows Firewall Cpl - AppID: {A4B07E49-6567-4FB8-8D39-01920E3B2357} Name: Shell ChkdskEx Dialog - AppID: {a4c31131-ff70-4984-afd6-0609ced53ad6} Name: DsmAdminApi - AppID: {A5065670-136D-4FD6-A45F-00C85B90359C} Name: WPDShextAutoplay - AppID: {A55803CC-4D53-404c-8557-FD63DBA95D24} Name: WLIDSvc - AppID: {A6721677-BA21-44E9-9E2A-76466D24D121} Name: Virtual Factory for MaintenanceUI - AppID: {A6BFEA43-501F-456F-A845-983D3AD7B8F0} Name: Microsoft Windows Defender - AppID: {A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F} Name: %SystemRoot%\System32\fveui.dll - AppID: {A7A63E5C-3877-4840-8727-C1EA9D7A4D50} Name: SysFxUi - AppID: {A7D2EC8B-B70F-434C-A0CE-0DF324805F7D} Name: SwapAPODll - AppID: {A85F41D6-156B-470D-B505-110388968D5A} Name: Delivery Optimization Mgmt - AppID: {AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800} Name: F12AppFrameClient Class - AppID: {AABAA6AA-5398-4C08-AE60-6321A7F05E9C} Name: DEFRAGSVC service - AppID: {ab7c873b-eb14-49a6-be60-a602f80e6d22} Name: Thumbnail Cache Out of Proc Server - AppID: {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} Name: BDEUILauncher Class - AppID: {AB93B6F1-BE76-4185-A488-A9001B105B94} Name: Out of proc server to enable Insider Hub scenarios to be reached from inside of its appcontainer - AppID: {ac0fd47a-37f4-4502-bfee-6b317e479d41} Name: RetailDemo Service - AppID: {ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325} Name: Windows Live Social Object Extractor Engine - AppID: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Name: WPN Srumon Server - AppID: {ada41b3c-c6fd-4a08-8cc1-d6efde67be7d} Name: TrayToastActivator - AppID: {AFC732E2-BA57-4B3E-A70A-71371F99B871} Name: WorkspaceBroker Class - AppID: {B06FF84E-0A77-4DD2-A919-0EABD8979DC1} Name: TabIps - AppID: {B1445657-5A98-11d9-A4E5-00301BB132BA} Name: Dispatch - AppID: {B1463312-25D9-4de4-96DC-FE9213084065} Name: DockInterface COM server - AppID: {b21858c6-9711-4257-99c8-5c0084bebce1} Name: Windows Update Agent - Remote Access - AppID: {B366DEBE-645B-43A5-B865-DDD82C345492} Name: AppActivationFailedHandler - AppID: {B3AADFEA-8404-4CBE-A62E-B0B715412C9E} Name: UACObject - AppID: {B49FBDA8-D846-43c4-ACAA-06D7794374C8} Name: RichVideo64 - AppID: {B58B304A-D419-4c50-BE1F-6F6CD234B7EF} Name: Found New Hardware Wizard - AppID: {B6A32FE6-E29D-AEAE-A608-D273E40CA34C} Name: WIA Device Manager 2 - AppID: {B6C292BC-7C88-41EE-8B54-8EC92617E599} Name: Com_SRS_TruSurroundHD - AppID: {B6D5C1B8-6F68-4A82-8E20-2D0F3A52BD6A} Name: Sync Center (Private) - AppID: {B8558612-DF5E-4F95-BB81-8E910B327FB2} Name: WLX Thumbnail Cache Out of Proc Server - AppID: {B8A2E14E-290D-4122-B092-1A7D86198CCE} Name: Windows Media Player - AppID: {B8C54A54-355E-11D3-83EB-00A0C92A2F2D} Name: ApplicationActivationImpl - AppID: {B9305506-D05B-4C36-81C5-0E50886C1755} Name: Application Frame Host - AppID: {B9B05098-3E30-483F-87F7-027CA78DA287} Name: Event Object Change 2 - AppID: {BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4} Name: SyncHost - AppID: {BBC4356A-F004-4628-A27A-E13D70412B70} Name: Virtual Factory for Power Options Control Panel - AppID: {BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B} Name: Setting Sync Task Factory - AppID: {bcbb3f8c-2889-474f-8fb7-904d4a416145} Name: DfsShlEx.dll - AppID: {BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B} Name: EditionUpgradeManagerObj - AppID: {BD54C901-076B-434E-B6C7-17C531F4AB41} Name: VM IC Heartbeat Service - AppID: {be0fc7f0-f248-4091-a123-34ca29a6901b} Name: Shell AutoPlay Direct - AppID: {BF8841C9-378A-4CAD-B4FC-5091366CBC0D} Name: OVSHelper - AppID: {BFEDD1F7-641C-4D64-9A6A-481A5E6BEC4F} Name: ShellBrowserWindow - AppID: {c08afd90-f2a1-11d1-8455-00a0c91f3880} Name: LockAppHost Out of Proc Helper for Lock Apps - AppID: {C08B030B-E91C-479D-BEFD-02DDA7FF1BCF} Name: provsvc.dll - AppID: {c2a71820-3463-498f-bab7-4798795a2ff6} Name: DataExchangeHost - AppID: {C2E9756F-8155-4EAC-9ED5-0B690169D412} Name: cttunesvr - AppID: {C3A34354-660F-41EE-B072-2AEA5E3A80AF} Name: Microsoft Block Level Backup Service - AppID: {C3B65D83-FB15-4e3f-BA04-097D1E2B5AC1} Name: Microsoft IMAPI - AppID: {C49F2185-50A7-11D3-9144-00104BA11C5E} Name: BdeUISrv - AppID: {C4AB7CB7-E735-48FF-AADD-39D09668F444} Name: HomeGroup Listener Service - AppID: {C4CDC408-581C-4480-9FFE-3B1C78D5C20D} Name: Acronis True Image Shell Extension Backend - AppID: {C4E69DB9-E094-483e-B922-E7ADE65FB497} Name: Xbox Live Game Saves - AppID: {C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3} Name: EntAppSvc - AppID: {C63261E4-6052-41FF-B919-496FECF4C4E5} Name: EmailClient Class - AppID: {C6E0A4C8-A933-411E-8068-406C2391665F} Name: FamilySafetyRefreshTask - AppID: {C844C79D-AED8-4DCE-AB25-4D359BED84F8} Name: TSWbPrxy.exe - AppID: {C92A9617-0EAE-4235-BD2B-84540EF1FFA9} Name: DictationHost Class - AppID: {C945AD06-534F-460C-8CB4-17C33099AF81} Name: Sync Infrastructure - AppID: {C947D50F-378E-4FF6-8835-FCB50305244D} Name: netprofm - AppID: {C96887DA-A652-4426-905E-4A37546F847C} Name: editionupgradebroker - AppID: {C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125} Name: RCM - AppID: {C9F65BA8-1F8F-4382-AE27-C91FFB29275F} Name: User OOBE Create Elevated Object Server - AppID: {ca8c87c1-929d-45ba-94db-ef8e6cb346ad} Name: OpenSearch Description Create Search Connector Verb Handler - AppID: {CB1DFE3A-EDFF-4d1f-867D-8ADB02926F4B} Name: PrintIsolationSessionHost - AppID: {CB363445-F453-4C1E-8EE4-BD123C5E394F} Name: UACObject - AppID: {CB43451C-E132-4866-B714-435253C98BBA} Name: EnhancedStorageShell - AppID: {CC70FEAD-94B9-4F76-88CC-004BB068ACDF} Name: Dispatch - AppID: {CCA04D30-62E9-4801-B935-EDC8EA177B13} Name: sppui - AppID: {CCFDD24D-CEAB-458B-A4F1-F884973395DF} Name: Dispatch - AppID: {CD9DD8FF-5FE5-44AB-AA3E-646052717FFF} Name: Windows Media Player Burn Audio CD Handler - AppID: {cdc32574-7521-4124-90c3-8d5605a34933} Name: Elevated-Unelevated Explorer Factory - AppID: {CDCBCFCA-3CDC-436f-A4E2-0E02075250C2} Name: PNPXAssoc.dll - AppID: {cee8ccc9-4f6b-4469-a235-5a22869eef03} Name: sdchange - AppID: {CF254B00-1986-4b24-A92D-463D01F7E395} Name: Event Object Change - AppID: {D0565000-9DF4-11D1-A281-00C04FCA0AA7} Name: HTMLScrubber - AppID: {D1761C4C-B847-4699-8304-12378B0FE0AD} Name: Winmgmt MOF Compiler OOP - AppID: {D215781D-019E-4FA0-903D-0CDCDE13A4F5} Name: Color Management - AppID: {D2E7041B-2927-42fb-8E9F-7CE93B6DC937} Name: Bitmap Image - AppID: {D3E34B21-9D75-101A-8C3D-00AA001A1652} Name: Microsoft SQL Server Replication Distribution Agent 11.0 - AppID: {D41192E9-AB13-4A23-AB3B-A5FED98306DB} Name: Sync Center User Profile Notification Handler - AppID: {D63AA156-D534-4BAC-9BF1-55359CF5EC30} Name: CloudStorageWizard - AppID: {D8775A07-C529-4EA7-B307-BA7C8CBBDA03} Name: Microsoft Software Protection Platform Admin Object (outer) - AppID: {D8D4249F-A8FB-44A7-8AA0-564E8C385BD6} Name: IndexedDbBrokerServer - AppID: {dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6} Name: BrowserBrokerServer - AppID: {DD9C53BC-8441-4B94-BD0E-36E6E02A6D61} Name: Srumon Server - AppID: {ddcfd26b-feed-44cd-b71d-79487d2e5e5a} Name: rundll32.exe - AppID: {de5d803e-5d2a-4b5f-9c63-af25a465cc44} Name: AccStore Class - AppID: {DE5DBCDC-104A-4cbc-A4D5-0C2104A142C5} Name: LockScreen Call Broker - AppID: {DE7D3D65-5454-4EF5-9518-776739DAB39F} Name: Profile Notification Host - AppID: {E10F6C3A-F1AE-4adc-AA9D-2FE65525666E} Name: Immersive Print Dialog Surrogate - AppID: {E15FBAC2-C276-4523-92CA-561456EBCF3E} Name: RtkAPODll - AppID: {E1D2965E-D32B-4e1c-B9F1-159ACB984258} Name: Windows Update Agent User Interface for Published Applications - AppID: {e30984f1-b02b-4c27-a40f-23d11b8c1212} Name: Scan - AppID: {E32549C4-C2B8-4BCC-90D7-0FC3511092BB} Name: Execute Unknown - AppID: {e44e9428-bdbc-4987-a099-40dc8fd255e7} Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients (Failed Mouse In Pointer) - AppID: {E45A56CE-399C-45F0-9E6F-BFAACD3C711F} Name: COM_SRS_WOWHD2 - AppID: {E46D2660-D86E-4B0A-BB61-F0FFE9BBDEB5} Name: upnphost - AppID: {E495081B-BBA5-4b89-BA3C-3B86A686B87A} Name: TrayDesktopBand - AppID: {E6442437-6C68-4f52-94DD-2CFED267EFB9} Name: Orchestrator Service - AppID: {E7299E79-75E5-47BB-A03D-6D319FB7F886} Name: TokenBroker Out Of Proc COM Server - AppID: {E73A797B-24CE-424A-AD4F-48E98B1E95B8} Name: UICOM - AppID: {E8054D20-497D-4E16-BF41-6E69FCD381A5} Name: iisctl - AppID: {E8FB8615-588F-11D2-9D61-00C04F79C5FE} Name: wscui.cpl - AppID: {E9495B87-D950-4ab5-87A5-FF6D70BF3E90} Name: Remove Device elevation surrogate - AppID: {E95186C7-7D80-4311-843D-0702CBC8B1E4} Name: File Prop Sheet Page Helper - AppID: {E96767E0-7EAA-45E1-8E7D-64414AFF281A} Name: HomeGroup Provider Service - AppID: {EA022610-0748-4c24-B229-6C507EBDFDBB} Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8} Name: LNSSCommunicator - AppID: {EA84CBF9-3B71-45BC-B2A0-305840C36F24} Name: Immersive Print Dialog Surrogate - AppID: {EB28E902-728E-42C4-97DC-DA89E144C744} Name: Remote Desktop Services Message Server - AppID: {EB521D7D-4095-4E61-88FB-BF25700F142A} Name: ComEvents.ComServiceEvents - AppID: {ECABB0C3-7F19-11D2-978E-0000F8757E2A} Name: ComEvents.ComSystemAppEventData - AppID: {ECABB0C6-7F19-11D2-978E-0000F8757E2A} Name: Play with Windows Media Player - AppID: {ed1d0fdf-4414-470a-a56d-cfb68623fc58} Name: ImagXpr7 - AppID: {ED512BE6-6629-4FB4-953D-D0C353847163} Name: Windows Media Player Launch - AppID: {ED6BB178-B06A-47ad-98B3-6066E0CF0147} Name: Share Manager - AppID: {edb5f444-cb8d-445a-a523-ec5ab6ea33c7} Name: RichVideo - AppID: {EEDE56D6-82E5-4B98-B99E-D4339825E216} Name: CloudExperienceHost Broker AppID - AppID: {efe2d6d8-a81b-41e7-ae77-e5244ab80522} Name: Microsoft Audio Device Graph Server - AppID: {F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC} Name: AvailableNetworksExperienceFlow - AppID: {F2506CD7-82C2-43D9-A1D3-F85F5EFE7D09} Name: Acronis VSS Requestor - AppID: {F282135C-65A6-4A99-80F1-F315BAC76BF4} Name: Virtual Disk Service - AppID: {F290BFB2-1864-45B1-8804-2654194A87E7} Name: FodHelper - AppID: {F2F94BB3-595C-4509-B7EE-243FA2BDEA5B} Name: SPPSurrogate - AppID: {f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801} Name: NDFAPI - AppID: {F3D3AA8D-EF96-4470-848E-BD70B803047A} Name: PerfCenter Enabler - AppID: {f4be747e-45c4-4701-90f1-d49d9ac30248} Name: sdclt - AppID: {f56b7b2a-5b5a-46d8-b6f9-d927ce34b717} Name: Pen Workspace Discover Broker - AppID: {F5A6ACF4-FFE0-4934-AE1D-5F960EA0AAD9} Name: WMPNSSCI - AppID: {F74BCE98-9EB4-4022-8317-11C723E5CCF8} Name: CloudExperienceHost Create System Object Server - AppID: {f7fa3149-91e7-43b7-8040-b707688ced1a} Name: Mantle - AppID: {F803D965-CC2F-43AA-BAD4-68CB51235062} Name: logagent - AppID: {F808DF63-6049-11D1-BA20-006097D2898E} Name: WLIDFDP - AppID: {F828BB1A-2FAE-4AC4-AE6F-CAC9B529F996} Name: RAServer - AppID: {F8FD03A6-DDD9-4C1B-84EE-58159476A0D7} Name: WinInetBrokerServer - AppID: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Name: NCLUA - AppID: {FA1456D3-4B97-4f9c-8511-2786161DC333} Name: VssEvent - AppID: {FAF53CC4-BD73-4E36-83F1-2B23F46E513E} Name: Shell Hardware Mixed Content Handler Cancelled - AppID: {fb479c02-9ec4-4fed-8599-debe037452cb} Name: RegisterControl - AppID: {FC38B7C8-9E50-497d-A387-7DEBDAD14160} Name: Hotspot Auth Module - AppID: {FC5EEAF6-0002-11DF-ADB9-F4CE462D9137} Name: appwiz.cpl - AppID: {FCC74B77-EC3E-4dd8-A80B-008A702075A9} Name: Wordpad - AppID: {fd6c8b29-e936-4a61-8da6-b0c12ad3ba00} Name: Microsoft SQL Server Replication Queuereader Agent 11.0 - AppID: {FD737704-43CB-4791-B4DB-EE8CDBC64450} Name: Proximity UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10C} Name: MP UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10D} Name: Microsoft SQL Server Replication Merge Agent 11.0 - AppID: {FDF7E044-456E-46C5-A396-807479AAFB4D} Name: Shell Execute Hardware Event Handler - AppID: {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} Name: EntAppSvc - AppID: {FFE1E5FE-F1F0-48C8-953E-72BA272F2744} Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-32-559" Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0771f7af-8de6-4bce-9528-2d4a12cb8168}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{0771f7af-8de6-4bce-9528-2d4a12cb8168}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{0868DC9B-D9A2-4f64-9362-133CEA201299}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0868DC9B-D9A2-4f64-9362-133CEA201299}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{0EA3EECE-6ABF-467A-9040-11AA728B7B0B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{0EA3EECE-6ABF-467A-9040-11AA728B7B0B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{0EA3EECE-6ABF-467A-9040-11AA728B7B0B}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{119817C9-666D-4053-AEDA-627D0E25CCEF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{119817C9-666D-4053-AEDA-627D0E25CCEF}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{136A0DC7-DF5C-4271-A2AC-15DF1A1323F2}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{136A0DC7-DF5C-4271-A2AC-15DF1A1323F2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-547" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-556" Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{205609B7-5E08-443E-B0A7-A7AED3F3A717}" - Win32_SID.SID="S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628" Win32_DCOMApplication.AppID="{205609B7-5E08-443E-B0A7-A7AED3F3A717}" - Win32_SID.SID="S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-556" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-15-3-1024-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937" Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-15-3-1024-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937" Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-32-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-15-3-1024-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-32-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937" Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-15-3-1024-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937" Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{2A947841-0594-48CF-9C53-A08C95C22B55}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{2A947841-0594-48CF-9C53-A08C95C22B55}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-15-3-1024-1314380931-3989923313-3249193833-1963115619-3940350845-1282913705-2904921893-3519892189" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1212" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{34E76A18-223B-4E23-BEAD-F59358CC0A90}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{34E76A18-223B-4E23-BEAD-F59358CC0A90}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{34E76A18-223B-4E23-BEAD-F59358CC0A90}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-80-611605672-2879557022-2206624263-4029342278-3129212340" Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4D5F23BB-D55A-4961-9BC0-3FE728E15D9D}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{4D5F23BB-D55A-4961-9BC0-3FE728E15D9D}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{4FCDA643-B15B-41C6-84F8-5E447F6F6D25}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-32-2707581722-3970398075-3301609242-3412871183-2565310287-2959982868-2531230773-2372594412" Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-15-3-1024-2707581722-3970398075-3301609242-3412871183-2565310287-2959982868-2531230773-2372594412" Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{52FC5917-F4E4-4C78-B469-20E722379F6C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{52FC5917-F4E4-4C78-B469-20E722379F6C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{59347292-B72D-41F2-98C5-E9ACA1B247A2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{59347292-B72D-41F2-98C5-E9ACA1B247A2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-15-3-1024-3625662137-2682091254-856171984-2868379045-3001028726-1009205972-4175949866-684286152" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1031" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376" Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{5E176815-9A63-4A69-810F-62E90D36612A}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{5E176815-9A63-4A69-810F-62E90D36612A}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{65E2E13A-7110-4912-9F03-9A42E253D8F6}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{65E2E13A-7110-4912-9F03-9A42E253D8F6}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{730BFCEC-E4BF-4D3A-9FBB-01DD132467A4}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-32-546" Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7953C53B-4031-43ca-9AE7-033F565EFD5F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7953C53B-4031-43ca-9AE7-033F565EFD5F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7D7B609B-D089-4687-9606-264A9AA2FBB2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7D7B609B-D089-4687-9606-264A9AA2FBB2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{7f9bbc82-ba5f-4448-8622-ef76b8d007e6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{7f9bbc82-ba5f-4448-8622-ef76b8d007e6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{83B33982-693D-4824-B42E-7196AE61BB05}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{83B33982-693D-4824-B42E-7196AE61BB05}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{84D586C4-A423-11D2-B943-00C04F79D22F}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-15-3-1024-1701033769-137094913-3738083205-577272984-1204217555-1180762924-3352773070-2589626690" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1210" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{90B553F3-415D-44D8-8665-C2F78763F8F1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{90B553F3-415D-44D8-8665-C2F78763F8F1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A0316E2D-8793-4E74-AA48-8CE2ED05BA57}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{A0ADD4EC-5BD3-4f70-A47B-07797A45C635}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A0ADD4EC-5BD3-4f70-A47B-07797A45C635}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A0ADD4EC-5BD3-4f70-A47B-07797A45C635}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-6" Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{B06FF84E-0A77-4DD2-A919-0EABD8979DC1}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{B06FF84E-0A77-4DD2-A919-0EABD8979DC1}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{B1463312-25D9-4de4-96DC-FE9213084065}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{B1463312-25D9-4de4-96DC-FE9213084065}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708" Win32_DCOMApplication.AppID="{B366DEBE-645B-43A5-B865-DDD82C345492}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{B49FBDA8-D846-43c4-ACAA-06D7794374C8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{B49FBDA8-D846-43c4-ACAA-06D7794374C8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{B8C54A54-355E-11D3-83EB-00A0C92A2F2D}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{B8C54A54-355E-11D3-83EB-00A0C92A2F2D}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-11" Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{C92A9617-0EAE-4235-BD2B-84540EF1FFA9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CB43451C-E132-4866-B714-435253C98BBA}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CB43451C-E132-4866-B714-435253C98BBA}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CCA04D30-62E9-4801-B935-EDC8EA177B13}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CCA04D30-62E9-4801-B935-EDC8EA177B13}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CCFDD24D-CEAB-458B-A4F1-F884973395DF}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{CCFDD24D-CEAB-458B-A4F1-F884973395DF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CD9DD8FF-5FE5-44AB-AA3E-646052717FFF}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CD9DD8FF-5FE5-44AB-AA3E-646052717FFF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{CF254B00-1986-4b24-A92D-463D01F7E395}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{CF254B00-1986-4b24-A92D-463D01F7E395}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{D215781D-019E-4FA0-903D-0CDCDE13A4F5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}" - Win32_SID.SID="S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628" Win32_DCOMApplication.AppID="{D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}" - Win32_SID.SID="S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464" Win32_DCOMApplication.AppID="{dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-15-3-1024-2819154332-3691255550-2499738133-2646149002-4290075130-3069449926-721213713-3168903538" Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-32-545" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E73A797B-24CE-424A-AD4F-48E98B1E95B8}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-32-551" Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-3433512109-503559027-1389316256-1766580070-2256751264" Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-1260278928-804197538-2066346633-4268302704-2216462912" Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-345135819-4012009209-3062012967-1747265747-3674605950" Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-951620777-1059631183-2804607755-3010024351-809615488" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-80-364023826-931424190-487969545-1024119571-74567675" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{F8FD03A6-DDD9-4C1B-84EE-58159476A0D7}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-15-2-1" Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-544" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-19" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-20" Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-556" Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-4" Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-1-0" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-10" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-18" Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-32-544" ---------- | Svchost - Netsvcs (Whitelisted) NetSetupSvc - %SystemRoot%\System32\NetSetupSvc.dll : %SystemRoot%\System32\svchost.exe -k netsvcs UserManager - %SystemRoot%\System32\usermgr.dll : %SystemRoot%\system32\svchost.exe -k netsvcs ---------- | Software [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Acronis] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\AppDataLow] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\ArcticLine] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\ASProtect] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\ATI] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\BitTorrent] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\BugSplat] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Chromium] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\CyberLink] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\DivX] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\DivXNetworks] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\EaseUS] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\EffectMgr] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Embarcadero] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\EPSON] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\g3n-h@ckm@n] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\GFI] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Google] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Hewlett-Packard] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\IMSIDesign] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\iolo] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Licenses] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\LogMeInRescueCallingCard] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\LSoft Technologies] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\MainConcept] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Mine] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Mozilla] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Nero] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\NewBlue] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Policies] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\PortableApps.com] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\QtProject] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\RegisteredApplications] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Soft-R Research] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\SyncEngines] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Sysinternals] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\The Silicon Realms Toolworks] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Trolltech] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\UsbFix] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\UsbFix Standard] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\uTorrentPlus] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Vivaldi] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Wondershare] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Wow6432Node] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\ZebHelpProcess Helper] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\AppDataLow\Software\adawarebp] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\Roaming] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\Acronis] [HKLM\Software\AMD] [HKLM\Software\ArcticLine] [HKLM\Software\Ashampoo] [HKLM\Software\ATI] [HKLM\Software\ATI Technologies] [HKLM\Software\AVC3] [HKLM\Software\Bitdefender] [HKLM\Software\cGNzcGVlZHVwcHJvLm5ldA==] [HKLM\Software\Clients] [HKLM\Software\CyberLink] [HKLM\Software\Dell] [HKLM\Software\DivX] [HKLM\Software\EPSON] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\GFI] [HKLM\Software\Hewlett-Packard] [HKLM\Software\Intel] [HKLM\Software\KasperskyLab] [HKLM\Software\Khronos] [HKLM\Software\Lavasoft] [HKLM\Software\Logitech] [HKLM\Software\Macromedia] [HKLM\Software\Microsoft] [HKLM\Software\MozillaPlugins] [HKLM\Software\NewBlue] [HKLM\Software\Norton] [HKLM\Software\Nuance] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\Partner] [HKLM\Software\Policies] [HKLM\Software\proDAD] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\RMSProvidor] [HKLM\Software\SRS Labs] [HKLM\Software\sysinternals] [HKLM\Software\WiseCleaner] [HKLM\Software\Wondershare] [HKLM\Software\WOW6432Node] [HKLM\Software\Microsoft\Windows\ClickNote] [HKLM\Software\Microsoft\Windows\Configuration] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\DWM] [HKLM\Software\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\apphost] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\iissvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\Software\WOW6432Node\Acronis] [HKLM\Software\WOW6432Node\Ashampoo] [HKLM\Software\WOW6432Node\ATI] [HKLM\Software\WOW6432Node\ATI Technologies] [HKLM\Software\WOW6432Node\Avanquest Software] [HKLM\Software\WOW6432Node\CyberLink] [HKLM\Software\WOW6432Node\DivX] [HKLM\Software\WOW6432Node\DivXNetworks] [HKLM\Software\WOW6432Node\DRWNewFree] [HKLM\Software\WOW6432Node\EaseUS] [HKLM\Software\WOW6432Node\EPSON] [HKLM\Software\WOW6432Node\g3n-h@ckm@n] [HKLM\Software\WOW6432Node\GFI] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\Hewlett-Packard] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\IObit] [HKLM\Software\WOW6432Node\iolo] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\Lake] [HKLM\Software\WOW6432Node\Lavasoft] [HKLM\Software\WOW6432Node\Licenses] [HKLM\Software\WOW6432Node\LogMeInRescueCallingCard] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\Nero] [HKLM\Software\WOW6432Node\NewBlue] [HKLM\Software\WOW6432Node\Norton] [HKLM\Software\WOW6432Node\Nuance] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\Realtek] [HKLM\Software\WOW6432Node\Realtek Semiconductor Corp.] [HKLM\Software\WOW6432Node\S3R521] [HKLM\Software\WOW6432Node\SOSVirus] [HKLM\Software\WOW6432Node\SymNRT] [HKLM\Software\WOW6432Node\sysinternals] [HKLM\Software\WOW6432Node\Turbo View & Convert] [HKLM\Software\WOW6432Node\Vivaldi] [HKLM\Software\WOW6432Node\WafCX] [HKLM\Software\WOW6432Node\WildTangent] [HKLM\Software\WOW6432Node\Wondershare] [HKLM\Software\WOW6432Node\WOW6432Node] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\iissvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] ---------- | FeatureControl [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION] [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL] "WindowsAnytimeUpgradeUI.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "infopath.exe"="0" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS] "HelpPane.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] "HelpPane.exe"="10000" "prevhost.exe"="8000" "Filmora.exe"="9999" "PDR.exe"="8000" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "SAPfewgsrv.exe"="0" "SAPGUI.exe"="0" "SAPGuiIT.exe"="0" "SAPLgPad.exe"="0" "SAPLOGON.exe"="0" "Scale_for_R3.exe"="0" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP] "ieuser.exe"="1" "iexplore.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK] "YahooMusicEngine.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE] "HelpPane.exe"="100000" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT] "devenv.exe"="1" "dexplore.exe"="1" "helppane.exe"="1" "PresentationHost.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS] "msfeedssync.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS] "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE] "HelpPane.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG] ""="" "msiexec.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART] "cs.exe"="1" "waol.exe"="1" "wm.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS] "iexplore.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS] "helppane.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS] "wlmail.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] "explorer.exe"="4" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] "explorer.exe"="2" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME] "mshta.exe"="1" "outlook.exe"="1" "sidebar.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN] "explorer.exe"="0" "iexplore.exe"="0" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING] "communicator.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD] "msimn.exe"="1" "prevhost.exe"="1" "winmail.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND] "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE] "HelpPane.exe"="0" "prevhost.exe"="0" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX] "PresentationHost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN] "msimn.exe"="1" "outlook.exe"="1" "winmail.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK] "HelpPane.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL] "excel.exe"="1" "infopath.exe"="1" "powerpnt.exe"="1" "winword.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE] "HelpPane.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD] "msn.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER] "iexplore.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION] "explorer.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "infopath.exe"="0" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS] "HelpPane.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] "HelpPane.exe"="10000" "prevhost.exe"="8000" "WiseJetSearch.exe"="11000" "MediaShow6.exe"="11000" "Power2Go10.exe"="8000" "PowerDVD.exe"="8000" "WiseCare365.exe"="11000" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL] "*"="1" "explorer.exe"="1" "iexplore.exe"="1" "SAPfewgsrv.exe"="0" "SAPGUI.exe"="0" "SAPGuiIT.exe"="0" "SAPLgPad.exe"="0" "SAPLOGON.exe"="0" "Scale_for_R3.exe"="0" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP] "ieuser.exe"="1" "iexplore.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL] "HelpPane.exe"="1" "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK] "YahooMusicEngine.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE] "HelpPane.exe"="100000" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT] "devenv.exe"="1" "dexplore.exe"="1" "helppane.exe"="1" "PresentationHost.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS] "msfeedssync.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS] "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE] "HelpPane.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG] ""="" "msiexec.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART] "cs.exe"="1" "waol.exe"="1" "wm.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS] "iexplore.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS] "helppane.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS] "wlmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] "explorer.exe"="4" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] "explorer.exe"="2" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME] "mshta.exe"="1" "outlook.exe"="1" "sidebar.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN] "explorer.exe"="0" "iexplore.exe"="0" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING] "communicator.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD] "msimn.exe"="1" "prevhost.exe"="1" "winmail.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ] "HelpPane.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT] "explorer.exe"="1" "HelpPane.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND] "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE] "HelpPane.exe"="0" "prevhost.exe"="0" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX] "PresentationHost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN] "msimn.exe"="1" "outlook.exe"="1" "winmail.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK] "HelpPane.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL] "excel.exe"="1" "infopath.exe"="1" "powerpnt.exe"="1" "winword.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL] "HelpPane.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE] "HelpPane.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD] "msn.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS] "explorer.exe"="1" "iexplore.exe"="1" "wmplayer.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER] "iexplore.exe"="1" "prevhost.exe"="1" [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION] "explorer.exe"="1" "iexplore.exe"="1" "PresentationHost.exe"="1" "prevhost.exe"="1" "wmplayer.exe"="1" ---------- | The Created last ones ¦ Modified [MD5.00000000000000000000000000000000] - [21/08/2016 09:49:27] - |AD| - [373281290] - C:\Program Files (x86)\Acronis [MD5.00000000000000000000000000000000] - [21/08/2016 12:32:13] - |D| - [31639787] - C:\Program Files (x86)\AoaoPhoto Digital Studio [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:16] - |D| - [110093050] - C:\Program Files (x86)\ATI Technologies [MD5.00000000000000000000000000000000] - [18/08/2016 11:42:30] - |D| - [0] - C:\Program Files (x86)\Avanquest [MD5.00000000000000000000000000000000] - [14/08/2016 10:44:28] - |D| - [470770] - C:\Program Files (x86)\CMAK [MD5.00000000000000000000000000000000] - [14/08/2016 21:39:35] - |D| - [207708213] - C:\Program Files (x86)\DivX [MD5.00000000000000000000000000000000] - [20/08/2016 05:42:00] - |D| - [85777269] - C:\Program Files (x86)\EaseUS [MD5.00000000000000000000000000000000] - [14/08/2016 19:37:22] - |D| - [1790134] - C:\Program Files (x86)\File Identifier [MD5.00000000000000000000000000000000] - [21/08/2016 20:39:46] - |AD| - [5426601] - C:\Program Files (x86)\FileMarker.NET [MD5.00000000000000000000000000000000] - [21/08/2016 11:13:09] - |D| - [428919376] - C:\Program Files (x86)\GFI [MD5.00000000000000000000000000000000] - [14/08/2016 18:37:36] - |D| - [12011650] - C:\Program Files (x86)\IIS Express [MD5.00000000000000000000000000000000] - [14/08/2016 19:36:28] - |D| - [148183952] - C:\Program Files (x86)\IMSIDesign [MD5.00000000000000000000000000000000] - [14/08/2016 07:51:26] - |D| - [28382294] - C:\Program Files (x86)\Microsoft [MD5.00000000000000000000000000000000] - [15/08/2016 10:18:37] - |D| - [1670519] - C:\Program Files (x86)\Microsoft ASP.NET [MD5.00000000000000000000000000000000] - [21/08/2016 10:40:43] - |AD| - [639630979] - C:\Program Files (x86)\Microsoft SQL Server [MD5.00000000000000000000000000000000] - [21/08/2016 11:06:35] - |D| - [4850] - C:\Program Files (x86)\Microsoft Visual Studio 10.0 [MD5.00000000000000000000000000000000] - [14/08/2016 10:33:11] - |D| - [25757] - C:\Program Files (x86)\MSBuild [MD5.00000000000000000000000000000000] - [19/08/2016 07:22:18] - |AD| - [2313046120] - C:\Program Files (x86)\Nero [MD5.00000000000000000000000000000000] - [14/08/2016 21:55:30] - |D| - [54782380] - C:\Program Files (x86)\NewBlue [MD5.00000000000000000000000000000000] - [14/08/2016 21:31:03] - |D| - [63354022] - C:\Program Files (x86)\NSIS Uninstall Information [MD5.00000000000000000000000000000000] - [14/08/2016 10:33:11] - |D| - [38450433] - C:\Program Files (x86)\Reference Assemblies [MD5.00000000000000000000000000000000] - [20/08/2016 20:57:45] - |D| - [331342005] - C:\Program Files (x86)\Vivaldi [MD5.00000000000000000000000000000000] - [14/08/2016 07:41:40] - |D| - [28780680] - C:\Program Files (x86)\Wondershare [MD5.00000000000000000000000000000000] - [21/08/2016 14:41:01] - |D| - [15142993] - C:\WINDOWS\ADAM [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/08/2016 09:58:13] - |A| - [0] - C:\WINDOWS\ativpsrm.bin [MD5.045397ADC16504152400CB7660985C56] - [14/08/2016 09:57:18] - |AS| - [67584] - C:\WINDOWS\bootstat.dat [MD5.00000000000000000000000000000000] - [13/08/2016 21:40:03] - |D| - [0] - C:\WINDOWS\CSC [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [14/08/2016 10:25:10] - |A| - [7623] - C:\WINDOWS\diagerr.xml [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [14/08/2016 10:25:10] - |A| - [7623] - C:\WINDOWS\diagwrn.xml [MD5.452CF3E6DB51D819944146C028D096B6] - [14/08/2016 19:58:37] - |A| - [480] - C:\WINDOWS\dm.dmap [MD5.B3799261A085A302F22A9FF7ED3C0B68] - [14/08/2016 19:58:37] - |A| - [66560] - C:\WINDOWS\dm_batch.bak [MD5.40DCC3C4C53DC0501F4B918156CE5340] - [21/08/2016 11:23:09] - |A| - [39939] - C:\WINDOWS\iis.log [MD5.00000000000000000000000000000000] - [23/08/2016 09:59:40] - |D| - [504517295] - C:\WINDOWS\Microsoft Antimalware [MD5.00000000000000000000000000000000] - [20/08/2016 08:27:07] - |D| - [0] - C:\WINDOWS\Minidump [MD5.00000000000000000000000000000000] - [14/08/2016 10:54:09] - |DC| - [119426366] - C:\WINDOWS\Panther [MD5.927062B36A9EE89C14A6B74AF9CD4187] - [20/08/2016 09:16:47] - |A| - [10420] - C:\WINDOWS\PFRO.log [MD5.00000000000000000000000000000000] - [14/08/2016 09:56:02] - |D| - [37183427] - C:\WINDOWS\Prefetch [MD5.09394999ADB19901C665454EE964B13C] - [14/08/2016 07:37:36] - |A| - [36] - C:\WINDOWS\progress.ini [MD5.00000000000000000000000000000000] - [14/08/2016 09:55:50] - |D| - [44230469] - C:\WINDOWS\ServiceProfiles [MD5.0BDDB1F59D32C5CBA1B99ADC0EDC2498] - [16/08/2016 09:29:39] - |A| - [5549] - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [16/08/2016 09:29:39] - |A| - [0] - C:\WINDOWS\setuperr.log [MD5.00000000000000000000000000000000] - [13/08/2016 16:29:57] - |D| - [42873310] - C:\WINDOWS\SoftwareDistribution [MD5.038356387332650843BCB352BB89A101] - [16/08/2016 10:25:17] - |A| - [275] - C:\WINDOWS\WindowsUpdate.log [MD5.E01507A0CADD7796502CB0422DFA8A0E] - [22/08/2016 10:32:41] - |A| - [65] - C:\WINDOWS\wininit.ini [MD5.81082E9E753FBEB85F23F9B2CC179C56] - [19/08/2016 07:04:45] - |A| - [35158016] - C:\WINDOWS\Installer\24d78cc.msi [MD5.A94AB35BA3BEF7F94E163FC964E44675] - [19/08/2016 07:12:09] - |A| - [2140672] - C:\WINDOWS\Installer\24d78d3.msi [MD5.E41BF30257495A6FF15BC30FDE08E08C] - [19/08/2016 07:11:57] - |A| - [5588992] - C:\WINDOWS\Installer\24d78db.msi [MD5.E4A68C523300D19EFAC25B0455A86201] - [19/08/2016 07:08:46] - |A| - [1199104] - C:\WINDOWS\Installer\24d78e3.msi [MD5.C398032386D565AA9DEEF9B4CBE68690] - [19/08/2016 07:08:33] - |A| - [1216000] - C:\WINDOWS\Installer\24d78eb.msi [MD5.979F1F98EA72C0B18F9C3A7ED4A928C2] - [19/08/2016 07:12:14] - |A| - [3156992] - C:\WINDOWS\Installer\24d78f3.msi [MD5.241116FACDD2275530D2AB31D942EB93] - [19/08/2016 07:10:48] - |A| - [1216000] - C:\WINDOWS\Installer\24d78fb.msi [MD5.A21C9CB38F4A56EB2E0DDDD92911E5B4] - [19/08/2016 07:08:26] - |A| - [1217536] - C:\WINDOWS\Installer\24d7903.msi [MD5.0CE3DB6358B90E9CC1A53D59A13E5E32] - [19/08/2016 07:08:22] - |A| - [3817472] - C:\WINDOWS\Installer\24d790b.msi [MD5.CCD1A3FF06A8338BFD9E5F760754B7B5] - [19/08/2016 07:07:21] - |A| - [867328] - C:\WINDOWS\Installer\24d7913.msi [MD5.E53A82728A820134CA9E5820FE329254] - [19/08/2016 07:11:22] - |A| - [1812480] - C:\WINDOWS\Installer\24d791b.msi [MD5.C04CB61ECD7207150E960D23017734B1] - [19/08/2016 07:10:44] - |A| - [3005440] - C:\WINDOWS\Installer\24d7923.msi [MD5.6C3D5D17E37BFCCC6ED2924EE222ACFF] - [19/08/2016 07:09:06] - |A| - [2101248] - C:\WINDOWS\Installer\24d792b.msi [MD5.88F348EAD95E84FC203EB578EDC58B29] - [19/08/2016 07:07:39] - |A| - [5206528] - C:\WINDOWS\Installer\24d7933.msi [MD5.87B42C89EDAC6D0B7E8057EEE5B134E5] - [19/08/2016 07:07:46] - |A| - [4472320] - C:\WINDOWS\Installer\24d793b.msi [MD5.73AAC6E63825CF6EAED974AF9F312398] - [19/08/2016 07:06:03] - |A| - [5762560] - C:\WINDOWS\Installer\24d7943.msi [MD5.4EE74D0ED3F3B8049F55A2501D7BEEA0] - [19/08/2016 07:07:30] - |A| - [1181696] - C:\WINDOWS\Installer\24d794b.msi [MD5.63115A5698215F6D1A388A7E3CF5B8FC] - [19/08/2016 07:08:53] - |A| - [4322304] - C:\WINDOWS\Installer\24d7959.msi [MD5.E0732E2D2725DAE49CC4D343D0DEBB16] - [19/08/2016 07:10:53] - |A| - [3717632] - C:\WINDOWS\Installer\24d7961.msi [MD5.CA70C605C7423D3BD80BAA96527BAC6B] - [19/08/2016 07:12:18] - |A| - [2830336] - C:\WINDOWS\Installer\24d7969.msi [MD5.83D2E5BDBB119F6BA08AE5EC9DA44769] - [19/08/2016 07:10:38] - |A| - [1168896] - C:\WINDOWS\Installer\24d7971.msi [MD5.51B34393B44FE1EF6976D8C841421F21] - [19/08/2016 07:11:17] - |A| - [866816] - C:\WINDOWS\Installer\24d7979.msi [MD5.7730C7CB6213D019A9ED600B6F336FEB] - [19/08/2016 07:07:16] - |A| - [2380288] - C:\WINDOWS\Installer\24d7981.msi [MD5.08132257EF664AA0ABB4CE98427FE73E] - [19/08/2016 07:46:36] - |A| - [5780992] - C:\WINDOWS\Installer\26b86f3.msi [MD5.72C6757046F50341BEC71B0E0F4C8670] - [19/08/2016 07:47:39] - |A| - [1183744] - C:\WINDOWS\Installer\26b86fa.msi [MD5.F9651F199BEF3A36F25CE49ECDD99950] - [19/08/2016 07:48:42] - |A| - [1357824] - C:\WINDOWS\Installer\26b8702.msi [MD5.5C429B2E031B1FB6C3139BE4C20B7DF4] - [19/08/2016 07:48:27] - |A| - [1306112] - C:\WINDOWS\Installer\26b870a.msi [MD5.8F496261809F0034D99FD6135F00F86D] - [19/08/2016 07:48:03] - |A| - [1369600] - C:\WINDOWS\Installer\26b8712.msi [MD5.EAB06DCA869C39A4F5950FA07468F8EF] - [19/08/2016 07:47:50] - |A| - [1255424] - C:\WINDOWS\Installer\26b871a.msi [MD5.AB22AF8618E3649A971C4D40C75D0239] - [19/08/2016 07:47:45] - |A| - [1231872] - C:\WINDOWS\Installer\26b8722.msi [MD5.3D6EFEF0BDD46F566F972DAAA9F698B0] - [19/08/2016 07:47:29] - |A| - [1195520] - C:\WINDOWS\Installer\26b872a.msi [MD5.1C180E3110B50E9B72C0D7BE63C8C6D3] - [19/08/2016 07:51:24] - |A| - [1228288] - C:\WINDOWS\Installer\26b8733.msi [MD5.F53C829E593395923E376B1881201EE3] - [19/08/2016 07:51:00] - |A| - [1216512] - C:\WINDOWS\Installer\26b873b.msi [MD5.CADC161C76F43C9B2311584DB697AAC2] - [19/08/2016 07:50:09] - |A| - [1485824] - C:\WINDOWS\Installer\26b8743.msi [MD5.76A1754E69C7B3D0ED7BC7E012009525] - [19/08/2016 07:49:53] - |A| - [1241088] - C:\WINDOWS\Installer\26b874b.msi [MD5.5EEF9703364D15DFF4464B3FD7A715F0] - [19/08/2016 07:49:35] - |A| - [1201152] - C:\WINDOWS\Installer\26b8753.msi [MD5.63407A91C80A0BEB3771B283EDDD362B] - [19/08/2016 07:49:14] - |A| - [1291264] - C:\WINDOWS\Installer\26b875b.msi [MD5.133B355891AA59038709C14F8D1534D5] - [19/08/2016 07:47:27] - |A| - [1308160] - C:\WINDOWS\Installer\26b8764.msi [MD5.F97C73296EF65E4E4C4DC504A851AEEB] - [20/08/2016 06:13:16] - |A| - [737280] - C:\WINDOWS\Installer\39beec0.msi [MD5.FBC6B7466EF6D2E5BF77E8D2FEE3E1F2] - [20/08/2016 06:13:53] - |A| - [5128192] - C:\WINDOWS\Installer\39beecc.msi [MD5.7FE4A7C732CDEB00670A1743A456AED6] - [20/08/2016 06:14:01] - |A| - [7847936] - C:\WINDOWS\Installer\39beed2.msi [MD5.648AC4D27F48DFFC37F6E0F622414E1B] - [20/08/2016 06:14:02] - |A| - [126976] - C:\WINDOWS\Installer\39beed8.msi [MD5.3BAF7804E9F1BC8BB0B7CD77D1411C92] - [21/08/2016 09:48:20] - |A| - [508448768] - C:\WINDOWS\Installer\436b7e0.msi [MD5.36A56605CE826993FA91623C7FB3D6DB] - [21/08/2016 10:35:35] - |A| - [56975360] - C:\WINDOWS\Installer\47c523c.msi [MD5.8B34A428829EEAAA444CE657217922CE] - [21/08/2016 10:36:02] - |A| - [165605376] - C:\WINDOWS\Installer\47c5240.msi [MD5.C42F369840341E6CCEB49D5A079F1546] - [21/08/2016 14:39:23] - |A| - [16421376] - C:\WINDOWS\Installer\541b829.msi [MD5.5C84F84D805DE62A4905AC7B3A735F91] - [21/08/2016 14:28:19] - |A| - [177628160] - C:\WINDOWS\Installer\541b82d.msi [MD5.00000000000000000000000000000000] - [21/08/2016 11:43:37] - |D| - [694896] - C:\WINDOWS\Installer\MSI140B.tmp- [MD5.00000000000000000000000000000000] - [23/08/2016 07:37:22] - |D| - [0] - C:\WINDOWS\Installer\MSI2194.tmp- [MD5.00000000000000000000000000000000] - [23/08/2016 07:40:05] - |D| - [0] - C:\WINDOWS\Installer\MSI9BB0.tmp- [MD5.00000000000000000000000000000000] - [23/08/2016 07:40:12] - |D| - [0] - C:\WINDOWS\Installer\MSIB9AB.tmp- [MD5.00000000000000000000000000000000] - [23/08/2016 07:37:08] - |D| - [0] - C:\WINDOWS\Installer\MSIE832.tmp- [MD5.32A6EB9C463717ACC9212EB8FB7A7D43] - [19/08/2016 07:54:23] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4} [MD5.018E6C1AD939E0F2EA3405FC2F9A1D53] - [19/08/2016 07:33:53] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{05C6B128-1B40-4495-9CB9-090B368BFA0A} [MD5.4020E797377E394D5869C3E866DC4F63] - [14/08/2016 09:59:55] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{063E67F0-C298-8A2A-0FA6-84C15322A4E0} [MD5.FB175B1C9578531EC634D8E0FC200AEC] - [14/08/2016 09:59:41] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{07326A3E-02B3-1078-25D7-B8666BA8FE15} [MD5.3F1C9C46BFFD2AAEF41ED0592C26BE25] - [14/08/2016 09:59:34] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF} [MD5.2170310307B94A9CE757CA1800A5D084] - [14/08/2016 22:18:40] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{0c8ebb00-4909-459c-8347-b2068b7f0319} [MD5.BAB08B4EB0B3335BDA6D7E7E31FFEFD4] - [21/08/2016 11:06:10] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{0E8670B8-3965-4930-ADA6-570348B67153} [MD5.EE07A69ECCFBD03C5C7ECD89C1C08311] - [14/08/2016 09:59:17] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{11087D24-567D-7D88-69C6-D7A08B5F4C47} [MD5.D9E7F78240DC3D11B3E0E829C4765686] - [21/08/2016 11:05:55] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{124D51A1-F3C2-45AE-B812-D3CA71247093} [MD5.5ACCE6D5F06CD14CC2B91380A3FE50E9] - [21/08/2016 14:40:13] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39} [MD5.CAA0038B2FC9838377DB04AD927AA263] - [14/08/2016 18:37:02] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} [MD5.6367D009CC5A95B7F3A5842D1E4B68CB] - [19/08/2016 08:00:08] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{150D88F1-40AF-4678-A39D-BCE2332F34E5} [MD5.D760D8DD9F5B52AB775B94A526890160] - [21/08/2016 11:13:02] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{160301DE-306A-4ADE-8A47-BC5790AF0486} [MD5.2458034B5853B7A9985F5D5B170E53BC] - [14/08/2016 09:59:19] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{1AD99E77-37CC-744E-39CA-67F6FD34565A} [MD5.FDAD86A08BB88AAE6F5A11E90BE9300D] - [19/08/2016 07:23:29] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{1B6F5E51-575E-4693-BCA2-7543570D076D} [MD5.960D3478360FF4DA10E34D8CBCF10754] - [14/08/2016 09:59:31] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6} [MD5.8671638F5364FEA9546D5100AAC5B329] - [19/08/2016 07:36:53] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{1C63279A-BF36-4852-9924-B1978D6585A6} [MD5.55F08857E0B918CED4F0CB0672155750] - [21/08/2016 11:31:29] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{1D62E6DA-CDCC-43FE-BC61-A55916E0605E} [MD5.41ACE69B00576A1DCF10693F0084AA4F] - [14/08/2016 09:59:35] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C} [MD5.923ADC3F93EC04517DDCA741AF50AD02] - [14/08/2016 18:37:24] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{22025051-1991-48EB-8BE8-7A3329DAE7ED} [MD5.53C7D47234133B50EA522275AE8A9533] - [19/08/2016 07:57:57] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB} [MD5.502193DF9146866B4ED12C0E57813A17] - [19/08/2016 07:25:25] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{2432E589-6256-4513-B0BF-EFA8E325D5F0} [MD5.481366908A3AF77E34B4FA846D474CCB] - [14/08/2016 09:59:47] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F} [MD5.E27001BB09978D753D92D426C3855F02] - [19/08/2016 07:58:13] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8} [MD5.BBC38CDB231BD8020FEA20DD25CD7BE8] - [19/08/2016 07:24:22] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{29F67D84-3A70-456E-806A-52301B02070B} [MD5.D3C85DA60F28B303D83292DFD708866A] - [14/08/2016 09:59:36] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{2D07E15C-A9A4-D8D6-D371-92EC8779E587} [MD5.A18901EC0B3AD28DC7B64A01ED4CCFF2] - [14/08/2016 21:56:05] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{2DFD8316-9EF1-3210-908C-4CB61961C1AC} [MD5.FECECE21781484B1C7703A2ADE1EEE9E] - [21/08/2016 11:04:52] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{30CA21F2-901A-44DB-A43F-FC31CD0F2493} [MD5.92274D4342B80BCDA4787E32EAC4967E] - [14/08/2016 09:59:33] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0} [MD5.98F845F4DDA85C7BE2E8FE8F9BADDD1D] - [14/08/2016 09:59:52] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{35A71DED-DA81-1313-352A-EC8A0B27DF3B} [MD5.734A3D76C4D12E262DB2094F5E190DC7] - [14/08/2016 21:28:25] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{37B8F9C7-03FB-3253-8781-2517C99D7C00} [MD5.1A9F90E0E0B25EA816899F8E90FB1B78] - [21/08/2016 11:16:55] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{38FCF27C-71A7-442D-A4AA-274C4394044C} [MD5.5299B1DD0069C70E0DC64A754F06294A] - [21/08/2016 11:04:38] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E} [MD5.DABC2ECCFF9A52CAB8747F82C6574B7D] - [14/08/2016 18:39:27] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{3F31FAA8-6CC1-4FFE-894C-D31E54067C8A} [MD5.F68F7BD4DBAB95ED528F97DDD6BF510A] - [18/08/2016 08:52:27] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{3FE312D5-B862-40CE-8E4E-A6D8ABF62736} [MD5.813AEF9756C3B30922D8BA8AB536E75A] - [21/08/2016 09:48:56] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{43B5FB0A-9900-43B0-BD46-9E7F89C88A98} [MD5.454FDA17479B302FEA34E032DB8DD8F0] - [21/08/2016 11:04:29] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{49D665A2-4C2A-476E-9AB8-FCC425F526FC} [MD5.928C9E79A5AA73CADCDAACA36090F883] - [21/08/2016 11:04:47] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{4B9E6EB0-0EED-4E74-9479-F982C3254F71} [MD5.8B5E43A4EAB0EB4BA08466DDD0976867] - [19/08/2016 07:57:13] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{4D25D881-7183-462F-95C8-990CA1944E0B} [MD5.F03C87D57A6858D4013BA80294864358] - [19/08/2016 08:00:22] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{504D84ED-AE75-4F85-A68B-BB3D4CB3E169} [MD5.30E4408E402A2F3CB12B0F9696544261] - [14/08/2016 21:55:45] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E} [MD5.8C4B598DECED633A4A2035F3EFD66A84] - [21/08/2016 11:06:15] - |A| - [45056] - C:\WINDOWS\Installer\SourceHash{54F84805-0116-467F-8713-899DFC472235} [MD5.EC0D895BF99D9F7E0712469261604420] - [19/08/2016 07:25:11] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{5F284483-EE8D-447E-BEBE-2BF13B08C4BF} [MD5.8EA71320A0B3E545EA17E2E06DF6F55B] - [18/08/2016 08:52:47] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4} [MD5.D7F9D9812D61F467A2F66F2010B07769] - [19/08/2016 07:26:38] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{60251665-84B4-41D6-84BF-6D50CE68DD08} [MD5.DCBAC2F6913C5EC0C94EA5BDE393ABCA] - [14/08/2016 09:59:16] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{64D5A142-BD50-726E-ED9E-D2508D2A17E2} [MD5.C166831480008387AB77252F984079CE] - [19/08/2016 07:34:09] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{65BB0407-4CC8-4DC7-952E-3EEFDF05602A} [MD5.5D2693D0F0C17F44E78011F7B8BB44A3] - [19/08/2016 07:30:47] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{6861C1AD-9829-4DE4-8647-4785ECEA421A} [MD5.94E7397D0DC1ADE67A8138832A94145F] - [14/08/2016 09:59:23] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494} [MD5.CAB4BA4BE607E6DFAA93CEB696ABE3B5] - [14/08/2016 21:26:23] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{7299052b-02a4-4627-81f2-1818da5d550d} [MD5.68362BE3FDD185A151272586DEF3E60F] - [14/08/2016 22:14:55] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB} [MD5.51FFA8D6700F7BBC7ABD98FE59016BA7] - [14/08/2016 09:59:54] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{79D22166-78C1-2AD4-04E7-BD22BD58FD46} [MD5.6812085E79C4185C55C78DD1C8B6321F] - [19/08/2016 07:56:00] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23} [MD5.63937660ACDE1F4FF07791761E967CE7] - [14/08/2016 07:51:23] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{7D095455-D971-4D4C-9EFD-9AF6A6584F3A} [MD5.C483D0C85FC8E01FE7F7EB8188C08369] - [21/08/2016 11:05:34] - |A| - [24576] - C:\WINDOWS\Installer\SourceHash{7D29ED63-84F9-4EC7-B49F-994A3A3195B2} [MD5.23D44AC22839DA0D3692F49155F55AD6] - [19/08/2016 07:27:01] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} [MD5.6C51D67AE39AB40E2A4F986F1EBF4D9E] - [19/08/2016 07:28:55] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{7F22DD97-256D-491D-9090-743FADC79BBE} [MD5.0608219CE34774CC76459D3B7020F1C6] - [14/08/2016 21:28:41] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8220EEFE-38CD-377E-8595-13398D740ACE} [MD5.D843B6283BA81451822D5684160B24E5] - [14/08/2016 09:59:38] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{82CA1714-13EA-F419-91FE-12834424745E} [MD5.A484040E6562EDB17D98B25F203AC7ED] - [19/08/2016 07:56:29] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588} [MD5.ACB115E83BD183918F369CB13BF25ED0] - [21/08/2016 11:07:55] - |A| - [28672] - C:\WINDOWS\Installer\SourceHash{87D50333-E534-493A-8E98-0A49BC28F64B} [MD5.7DA3C280E74D1C58D5CFB890F13887E5] - [19/08/2016 07:57:37] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1} [MD5.D56A649C52F79274522B8743414F84EC] - [14/08/2016 09:59:51] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68} [MD5.CBFCA6748A2EB5662DFAAB20C98165B5] - [21/08/2016 14:45:41] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464} [MD5.67A3D7072B9DF984F73DF88EF22F029D] - [14/08/2016 21:36:11] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E} [MD5.9BDC60A57028A0A58AE3FD93680B0F8A] - [14/08/2016 09:59:49] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81} [MD5.52968CC41B686732FBA2F91E5D88B7B0] - [19/08/2016 07:37:06] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{910B539D-F257-46C8-9CB8-6C95EFF9CF22} [MD5.3CB8CF57E4125F3528839C3A681859C8] - [19/08/2016 07:25:39] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{92EBE575-0C6E-4713-B095-34BB927E5AC6} [MD5.A024CDD6F594B492235D9BD89245A77A] - [14/08/2016 21:39:54] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{933B4015-4618-4716-A828-5289FC03165F} [MD5.1D17400863642F32F10A1BCF20D397AE] - [19/08/2016 07:55:10] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{955BF340-C379-4375-AA2F-F3BCB2A498AB} [MD5.CB1E5C6A6BB53D2A6A681B0D83C7F52B] - [18/08/2016 08:53:25] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{9BE518E6-ECC6-35A9-88E4-87755C07200F} [MD5.FBFF961AADA67FD27E4F9AE4611F1DBC] - [19/08/2016 07:21:37] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{9C637A56-4287-487F-95BF-1422FC1AA879} [MD5.FC4E0ABE12A9DB90C493E9947B21358A] - [19/08/2016 07:35:44] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{A163159C-B476-4501-B163-3F77809AC833} [MD5.CCE9B4F3FDB2783EC1FB0378226A91CA] - [14/08/2016 09:59:43] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{A5A6A4D0-2005-2A05-2E21-495808CF95ED} [MD5.BCCA2272DACDB5547B072B826DCB07E0] - [14/08/2016 09:59:50] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{A760847A-C4D9-E7EF-716F-07C6CBF6B147} [MD5.1D75C4BBB23EC505A390F10D6CEF1281] - [19/08/2016 07:22:09] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{ABC88553-8770-4B97-B43E-5A90647A5B63} [MD5.FBA389807C9897F5153EC5AF7FD03870] - [19/08/2016 07:24:44] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{ACE49D50-19CD-44A6-B192-46F985283B26} [MD5.6A0960ED69222E0880EEF646102B8B6C] - [14/08/2016 21:46:58] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{ADD5DB49-72CF-11D8-9D75-000129760D75} [MD5.2F3754749C8ABD1B8E599C9A25CE354D] - [14/08/2016 10:00:02] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2} [MD5.161D9AEA458D8E60E5298526AD5634A4] - [14/08/2016 21:24:59] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{B175520C-86A2-35A7-8619-86DC379688B9} [MD5.FC4A93B70FF9B5E04EC0BEE493E39FDD] - [19/08/2016 07:29:30] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} [MD5.B226D485EE6A1B52A73FF5C29E8BDE32] - [20/08/2016 06:13:23] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{B2CD1132-75C5-427F-8B06-9DA507A5A2B6} [MD5.FD531DC9C446AB62101A151F7C9D9C8D] - [20/08/2016 06:15:39] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{B48ADDCA-1A6C-4818-8FAC-A49B8AE55C65} [MD5.E4C0459274D799F77269E503A1DF34B0] - [14/08/2016 09:59:46] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{B839153C-D4D2-F89C-5033-0A160C62706B} [MD5.BB4F778FF2B99ADE1D949F2DAE467B1A] - [19/08/2016 07:34:59] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} [MD5.F78B9740F64AF37FE35A6BCBB52F69FC] - [14/08/2016 21:24:38] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} [MD5.FB6E7312E8567D67A81FDDD7CF2531D9] - [19/08/2016 07:22:41] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{BEBEE34D-84A2-4EDD-8BEA-96CC54371263} [MD5.5A5646A2C665C92E17E1771061B81BAB] - [14/08/2016 18:38:43] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{C19B3EB6-B54C-3204-A4DF-88432E0C79F7} [MD5.09D43A893CA3CF91F4B4CD2020CA0142] - [14/08/2016 09:59:39] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{C1EA3764-1138-AE27-AD63-549BAD99BA15} [MD5.F8FC648B503498CACDF8EBA4C758853E] - [21/08/2016 11:07:24] - |A| - [28672] - C:\WINDOWS\Installer\SourceHash{C22613C2-C7A4-4761-A906-116ECD4E7477} [MD5.4DDCDBC5BD4AB827F47E8F430F98B534] - [14/08/2016 09:59:21] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{C3D13AB8-468A-0174-1D06-DB9AAE8A131B} [MD5.EB505277AF442475EF73DBD77962A640] - [19/08/2016 07:54:50] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A} [MD5.566C8A4B3256899A3BA1A3135C656751] - [14/08/2016 09:59:42] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E} [MD5.2DCDE496CED0E6BC8F11480E72D3A1D2] - [19/08/2016 07:59:45] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{CE675FBD-75C3-45F1-B6AF-8D250861D536} [MD5.CCC8B356654847740D980064392C65F0] - [14/08/2016 21:28:12] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97} [MD5.6D3348E20BE533A76C8DC1322628DD1A] - [19/08/2016 07:23:55] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} [MD5.C883C56B3FF3ED5FFFB16371165C80B7] - [21/08/2016 11:07:41] - |A| - [28672] - C:\WINDOWS\Installer\SourceHash{D0F44C37-A22B-4733-BBA7-86C9F4988725} [MD5.DAC91B3BB392BB7E7FA461E225985171] - [14/08/2016 22:19:10] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{D36DD326-7280-11D8-97C8-000129760CBE} [MD5.AAB5D941AD69470181816F5056061F05] - [21/08/2016 11:05:00] - |A| - [36864] - C:\WINDOWS\Installer\SourceHash{D441BD04-E548-4F8E-97A4-1B66135BAAA8} [MD5.6AF862AFCA85183B47C9AFF6A4931B4C] - [20/08/2016 06:15:03] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{D77E87FD-F024-4FDB-88FB-83C579AA644B} [MD5.052203436498B73E37821A1102675DCF] - [14/08/2016 22:08:34] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3} [MD5.AD7B15F8D54AD656E66B0F1F019EA921] - [21/08/2016 11:06:04] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{DFB059F4-DBB2-497F-999E-AD86FA90E6DD} [MD5.AC9CF262227B7B3E7110DDBA49790564] - [19/08/2016 07:23:10] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{E17BCB76-9924-4BD5-B6D6-50D3407B4E74} [MD5.71264C908DC4462708B769F06F3CF1F8] - [14/08/2016 21:48:12] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{E3D04529-6EDB-11D8-A372-0050BAE317E1} [MD5.FDD0A74BE4BB4BE8BFDDA15E7B076430] - [14/08/2016 09:59:57] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{E7366CA8-7179-77AE-E712-BA18D70A0A07} [MD5.A1777700B5818996B136BD163274B441] - [14/08/2016 09:59:44] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{E817E580-6318-AFC8-2102-322C73117EC4} [MD5.7E03C79F43D3ADB37FC5E0A7FF426905] - [19/08/2016 07:58:30] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{EEBF1676-AF87-4266-93D8-0C14A34C4217} [MD5.3121A623BDD26E70A3470578F648DB28] - [19/08/2016 07:34:24] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{EF0BA418-AF37-471E-9594-EAE5913F4681} [MD5.CF015C4EFB5EFEC7C3744143B53954BC] - [19/08/2016 07:36:36] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{F030BFE8-8476-4C08-A553-233DE80A2BE1} [MD5.BAB0A0E9DB34F4A9F6E0E7FB8C1F0938] - [14/08/2016 09:59:24] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{F77474EE-EB6C-C87B-88AF-3310C848E068} [MD5.1E2F172EA727CC8012E227A4BD80A40B] - [14/08/2016 18:37:04] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} [MD5.C94084F1716FF01738A25474F77A4BD5] - [14/08/2016 09:59:22] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{F8DDBE95-DCBE-03B5-5359-DE3601146E21} [MD5.3EA32D50C471D76DE6B964CF4885C31D] - [19/08/2016 07:58:48] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{FE81E6B5-652B-40E7-B3B2-7171C6F297DA} [MD5.9BB22C0B5584D5CC2FE731DC59F51890] - [21/08/2016 10:57:20] - |A| - [131072] - C:\WINDOWS\Installer\SourceHash{FEC535DD-0EB2-4709-87BD-1708C6364EB6} [MD5.00000000000000000000000000000000] - [19/08/2016 07:54:34] - |D| - [454128] - C:\WINDOWS\Installer\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4} [MD5.00000000000000000000000000000000] - [19/08/2016 07:33:58] - |D| - [436208] - C:\WINDOWS\Installer\{05C6B128-1B40-4495-9CB9-090B368BFA0A} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:56] - |D| - [88102] - C:\WINDOWS\Installer\{063E67F0-C298-8A2A-0FA6-84C15322A4E0} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:41] - |D| - [88102] - C:\WINDOWS\Installer\{07326A3E-02B3-1078-25D7-B8666BA8FE15} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:34] - |D| - [88102] - C:\WINDOWS\Installer\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF} [MD5.00000000000000000000000000000000] - [14/08/2016 22:18:42] - |D| - [200974] - C:\WINDOWS\Installer\{0c8ebb00-4909-459c-8347-b2068b7f0319} [MD5.00000000000000000000000000000000] - [21/08/2016 11:06:11] - |D| - [5430] - C:\WINDOWS\Installer\{0E8670B8-3965-4930-ADA6-570348B67153} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:18] - |D| - [10134] - C:\WINDOWS\Installer\{11087D24-567D-7D88-69C6-D7A08B5F4C47} [MD5.00000000000000000000000000000000] - [21/08/2016 14:42:24] - |D| - [673768] - C:\WINDOWS\Installer\{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39} [MD5.00000000000000000000000000000000] - [19/08/2016 08:00:13] - |D| - [436208] - C:\WINDOWS\Installer\{150D88F1-40AF-4678-A39D-BCE2332F34E5} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:20] - |D| - [88102] - C:\WINDOWS\Installer\{1AD99E77-37CC-744E-39CA-67F6FD34565A} [MD5.00000000000000000000000000000000] - [19/08/2016 07:23:43] - |D| - [436208] - C:\WINDOWS\Installer\{1B6F5E51-575E-4693-BCA2-7543570D076D} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:32] - |D| - [88102] - C:\WINDOWS\Installer\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6} [MD5.00000000000000000000000000000000] - [19/08/2016 07:36:57] - |D| - [122880] - C:\WINDOWS\Installer\{1C63279A-BF36-4852-9924-B1978D6585A6} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:36] - |D| - [88102] - C:\WINDOWS\Installer\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C} [MD5.00000000000000000000000000000000] - [14/08/2016 18:38:03] - |D| - [706236] - C:\WINDOWS\Installer\{22025051-1991-48EB-8BE8-7A3329DAE7ED} [MD5.00000000000000000000000000000000] - [19/08/2016 07:58:03] - |D| - [436208] - C:\WINDOWS\Installer\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB} [MD5.00000000000000000000000000000000] - [19/08/2016 07:25:31] - |D| - [122880] - C:\WINDOWS\Installer\{2432E589-6256-4513-B0BF-EFA8E325D5F0} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:48] - |D| - [88102] - C:\WINDOWS\Installer\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F} [MD5.00000000000000000000000000000000] - [19/08/2016 07:58:21] - |D| - [436208] - C:\WINDOWS\Installer\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8} [MD5.00000000000000000000000000000000] - [19/08/2016 07:24:32] - |D| - [436208] - C:\WINDOWS\Installer\{29F67D84-3A70-456E-806A-52301B02070B} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:37] - |D| - [88102] - C:\WINDOWS\Installer\{2D07E15C-A9A4-D8D6-D371-92EC8779E587} [MD5.00000000000000000000000000000000] - [21/08/2016 11:04:54] - |D| - [5430] - C:\WINDOWS\Installer\{30CA21F2-901A-44DB-A43F-FC31CD0F2493} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:33] - |D| - [88102] - C:\WINDOWS\Installer\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:53] - |D| - [88102] - C:\WINDOWS\Installer\{35A71DED-DA81-1313-352A-EC8A0B27DF3B} [MD5.00000000000000000000000000000000] - [21/08/2016 11:17:32] - |D| - [1009386] - C:\WINDOWS\Installer\{38FCF27C-71A7-442D-A4AA-274C4394044C} [MD5.00000000000000000000000000000000] - [21/08/2016 11:04:44] - |D| - [5430] - C:\WINDOWS\Installer\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E} [MD5.00000000000000000000000000000000] - [14/08/2016 18:40:21] - |D| - [52357] - C:\WINDOWS\Installer\{3F31FAA8-6CC1-4FFE-894C-D31E54067C8A} [MD5.00000000000000000000000000000000] - [21/08/2016 09:52:06] - |D| - [1878978] - C:\WINDOWS\Installer\{43B5FB0A-9900-43B0-BD46-9E7F89C88A98} [MD5.00000000000000000000000000000000] - [21/08/2016 11:04:35] - |D| - [5430] - C:\WINDOWS\Installer\{49D665A2-4C2A-476E-9AB8-FCC425F526FC} [MD5.00000000000000000000000000000000] - [21/08/2016 11:04:50] - |D| - [5430] - C:\WINDOWS\Installer\{4B9E6EB0-0EED-4E74-9479-F982C3254F71} [MD5.00000000000000000000000000000000] - [19/08/2016 07:57:25] - |D| - [436200] - C:\WINDOWS\Installer\{4D25D881-7183-462F-95C8-990CA1944E0B} [MD5.00000000000000000000000000000000] - [19/08/2016 08:00:43] - |D| - [436208] - C:\WINDOWS\Installer\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169} [MD5.00000000000000000000000000000000] - [20/08/2016 06:15:30] - |D| - [147479] - C:\WINDOWS\Installer\{5A4A7D29-7589-427B-86BC-8C313278BF89} [MD5.00000000000000000000000000000000] - [19/08/2016 07:25:15] - |D| - [424272] - C:\WINDOWS\Installer\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF} [MD5.00000000000000000000000000000000] - [19/08/2016 07:26:42] - |D| - [710640] - C:\WINDOWS\Installer\{60251665-84B4-41D6-84BF-6D50CE68DD08} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:16] - |D| - [88102] - C:\WINDOWS\Installer\{64D5A142-BD50-726E-ED9E-D2508D2A17E2} [MD5.00000000000000000000000000000000] - [19/08/2016 08:00:56] - |D| - [69632] - C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A} [MD5.00000000000000000000000000000000] - [19/08/2016 07:33:29] - |D| - [2138048] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:23] - |D| - [88102] - C:\WINDOWS\Installer\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494} [MD5.00000000000000000000000000000000] - [14/08/2016 22:14:58] - |D| - [200974] - C:\WINDOWS\Installer\{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:54] - |D| - [88102] - C:\WINDOWS\Installer\{79D22166-78C1-2AD4-04E7-BD22BD58FD46} [MD5.00000000000000000000000000000000] - [19/08/2016 07:56:18] - |D| - [436208] - C:\WINDOWS\Installer\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23} [MD5.00000000000000000000000000000000] - [14/08/2016 08:11:49] - |D| - [123570] - C:\WINDOWS\Installer\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A} [MD5.00000000000000000000000000000000] - [19/08/2016 07:28:27] - |D| - [888768] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} [MD5.00000000000000000000000000000000] - [19/08/2016 07:29:05] - |D| - [1886152] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:38] - |D| - [88102] - C:\WINDOWS\Installer\{82CA1714-13EA-F419-91FE-12834424745E} [MD5.00000000000000000000000000000000] - [19/08/2016 07:57:01] - |D| - [436208] - C:\WINDOWS\Installer\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588} [MD5.00000000000000000000000000000000] - [19/08/2016 07:57:46] - |D| - [436208] - C:\WINDOWS\Installer\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:52] - |D| - [88102] - C:\WINDOWS\Installer\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68} [MD5.00000000000000000000000000000000] - [21/08/2016 14:51:26] - |D| - [233440] - C:\WINDOWS\Installer\{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464} [MD5.00000000000000000000000000000000] - [14/08/2016 21:36:14] - |D| - [348789] - C:\WINDOWS\Installer\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:49] - |D| - [88102] - C:\WINDOWS\Installer\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81} [MD5.00000000000000000000000000000000] - [19/08/2016 07:37:12] - |D| - [122880] - C:\WINDOWS\Installer\{910B539D-F257-46C8-9CB8-6C95EFF9CF22} [MD5.00000000000000000000000000000000] - [19/08/2016 07:26:23] - |D| - [710640] - C:\WINDOWS\Installer\{92EBE575-0C6E-4713-B095-34BB927E5AC6} [MD5.00000000000000000000000000000000] - [19/08/2016 07:55:47] - |D| - [436208] - C:\WINDOWS\Installer\{955BF340-C379-4375-AA2F-F3BCB2A498AB} [MD5.00000000000000000000000000000000] - [19/08/2016 07:21:50] - |D| - [456688] - C:\WINDOWS\Installer\{9C637A56-4287-487F-95BF-1422FC1AA879} [MD5.00000000000000000000000000000000] - [19/08/2016 07:36:24] - |D| - [122880] - C:\WINDOWS\Installer\{A163159C-B476-4501-B163-3F77809AC833} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:44] - |D| - [88102] - C:\WINDOWS\Installer\{A5A6A4D0-2005-2A05-2E21-495808CF95ED} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:50] - |D| - [88102] - C:\WINDOWS\Installer\{A760847A-C4D9-E7EF-716F-07C6CBF6B147} [MD5.00000000000000000000000000000000] - [19/08/2016 07:22:19] - |D| - [1374144] - C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63} [MD5.00000000000000000000000000000000] - [19/08/2016 07:24:53] - |D| - [436208] - C:\WINDOWS\Installer\{ACE49D50-19CD-44A6-B192-46F985283B26} [MD5.00000000000000000000000000000000] - [14/08/2016 21:47:39] - |D| - [132567] - C:\WINDOWS\Installer\{ADD5DB49-72CF-11D8-9D75-000129760D75} [MD5.00000000000000000000000000000000] - [14/08/2016 10:00:11] - |D| - [88102] - C:\WINDOWS\Installer\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2} [MD5.00000000000000000000000000000000] - [19/08/2016 07:30:24] - |D| - [1026000] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:46] - |D| - [88102] - C:\WINDOWS\Installer\{B839153C-D4D2-F89C-5033-0A160C62706B} [MD5.00000000000000000000000000000000] - [19/08/2016 07:35:27] - |D| - [329712] - C:\WINDOWS\Installer\{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} [MD5.00000000000000000000000000000000] - [19/08/2016 07:22:59] - |D| - [122880] - C:\WINDOWS\Installer\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:40] - |D| - [88102] - C:\WINDOWS\Installer\{C1EA3764-1138-AE27-AD63-549BAD99BA15} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:21] - |D| - [88102] - C:\WINDOWS\Installer\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B} [MD5.00000000000000000000000000000000] - [19/08/2016 07:54:56] - |D| - [436208] - C:\WINDOWS\Installer\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:43] - |D| - [88102] - C:\WINDOWS\Installer\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E} [MD5.00000000000000000000000000000000] - [19/08/2016 07:59:59] - |D| - [436208] - C:\WINDOWS\Installer\{CE675FBD-75C3-45F1-B6AF-8D250861D536} [MD5.00000000000000000000000000000000] - [19/08/2016 07:24:02] - |D| - [710640] - C:\WINDOWS\Installer\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} [MD5.00000000000000000000000000000000] - [14/08/2016 22:19:23] - |D| - [128012] - C:\WINDOWS\Installer\{D36DD326-7280-11D8-97C8-000129760CBE} [MD5.00000000000000000000000000000000] - [21/08/2016 11:05:18] - |D| - [5430] - C:\WINDOWS\Installer\{D441BD04-E548-4F8E-97A4-1B66135BAAA8} [MD5.00000000000000000000000000000000] - [14/08/2016 22:08:37] - |D| - [195904] - C:\WINDOWS\Installer\{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3} [MD5.00000000000000000000000000000000] - [21/08/2016 11:06:07] - |D| - [5430] - C:\WINDOWS\Installer\{DFB059F4-DBB2-497F-999E-AD86FA90E6DD} [MD5.00000000000000000000000000000000] - [19/08/2016 07:23:19] - |D| - [436208] - C:\WINDOWS\Installer\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74} [MD5.00000000000000000000000000000000] - [14/08/2016 21:48:42] - |D| - [139957] - C:\WINDOWS\Installer\{E3D04529-6EDB-11D8-A372-0050BAE317E1} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:58] - |D| - [4846] - C:\WINDOWS\Installer\{E7366CA8-7179-77AE-E712-BA18D70A0A07} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:45] - |D| - [88102] - C:\WINDOWS\Installer\{E817E580-6318-AFC8-2102-322C73117EC4} [MD5.00000000000000000000000000000000] - [19/08/2016 07:58:39] - |D| - [436208] - C:\WINDOWS\Installer\{EEBF1676-AF87-4266-93D8-0C14A34C4217} [MD5.00000000000000000000000000000000] - [19/08/2016 07:34:37] - |D| - [1013712] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681} [MD5.00000000000000000000000000000000] - [19/08/2016 07:36:39] - |D| - [419824] - C:\WINDOWS\Installer\{F030BFE8-8476-4C08-A553-233DE80A2BE1} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:24] - |D| - [88102] - C:\WINDOWS\Installer\{F77474EE-EB6C-C87B-88AF-3310C848E068} [MD5.00000000000000000000000000000000] - [14/08/2016 09:59:22] - |D| - [88102] - C:\WINDOWS\Installer\{F8DDBE95-DCBE-03B5-5359-DE3601146E21} [MD5.00000000000000000000000000000000] - [19/08/2016 07:59:37] - |D| - [436208] - C:\WINDOWS\Installer\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA} [MD5.00000000000000000000000000000000] - [21/08/2016 10:58:32] - |D| - [5430] - C:\WINDOWS\Installer\{FEC535DD-0EB2-4709-87BD-1708C6364EB6} [MD5.00000000000000000000000000000000] - [21/08/2016 11:04:31] - |D| - [336225] - C:\WINDOWS\system32\1033 [MD5.81760E0851C132C77F6DDAA55A0D2D02] - [14/08/2016 10:43:19] - |A| - [5511168] - C:\WINDOWS\system32\aclui.dll [MD5.D6D3EC8F8ECFC501603CCEE77CB04467] - [14/08/2016 10:43:20] - |A| - [151232] - C:\WINDOWS\system32\acmigration.dll [MD5.B477A3A5127C07DF309F5BC277FF9C51] - [14/08/2016 07:58:35] - |A| - [208072] - C:\WINDOWS\system32\AERTAC64.dll [MD5.B3E9EA31E37EDCC1D54CE20504549ABE] - [14/08/2016 07:58:35] - |A| - [108640] - C:\WINDOWS\system32\AERTAR64.dll [MD5.4B10D8998C824DD84AD597F9E058F6F0] - [13/08/2016 22:54:39] - |A| - [175648] - C:\WINDOWS\system32\amde31a.dat [MD5.C7628FE6341B7919D2F62DB9057DB4FC] - [13/08/2016 22:54:39] - |A| - [213488] - C:\WINDOWS\system32\amdgfxinfo64.dll [MD5.AF1928F5E15921A29877C2E18626F80E] - [13/08/2016 22:54:39] - |A| - [143344] - C:\WINDOWS\system32\amdhdl64.dll [MD5.DDEB20626133878B0CE79CCE29B031B9] - [13/08/2016 22:54:39] - |A| - [833800] - C:\WINDOWS\system32\amdicdxx.dat [MD5.82CAB4EAF1E1CBA85AE5DEBB4C068EE2] - [13/08/2016 22:54:39] - |A| - [631280] - C:\WINDOWS\system32\amdlvr64.dll [MD5.C366C5A2EE8F1F586691E4511AB56040] - [13/08/2016 22:54:39] - |A| - [6686192] - C:\WINDOWS\system32\amdmantle64.dll [MD5.3960C946E67311C9831550AEDC649C3A] - [13/08/2016 22:54:39] - |A| - [471312] - C:\WINDOWS\system32\amdmiracast.dll [MD5.4CA9A0DF33972919623BBFF8FBD1A501] - [13/08/2016 22:54:39] - |A| - [59368] - C:\WINDOWS\system32\amdmmcl6.dll [MD5.7BA9A6BBF176D945D7B201865897E158] - [13/08/2016 22:54:41] - |A| - [27544560] - C:\WINDOWS\system32\amdocl12cl64.dll [MD5.AFF92249DA8E62FF8C6D2B89977D3245] - [13/08/2016 22:54:42] - |A| - [47794160] - C:\WINDOWS\system32\amdocl64.dll [MD5.8305AA2FEBE5CAD45AB8D208C17DA930] - [13/08/2016 22:54:43] - |A| - [1196032] - C:\WINDOWS\system32\amdocl_as64.exe [MD5.187EB6A72565FAAF01AAE0CDD63DE56F] - [13/08/2016 22:54:44] - |A| - [1070592] - C:\WINDOWS\system32\amdocl_ld64.exe [MD5.2B79CD2445F85D54959702583ECBCC04] - [13/08/2016 22:54:44] - |A| - [88000] - C:\WINDOWS\system32\amdpcom64.dll [MD5.28DF09388444100467873AC906FD6CB2] - [13/08/2016 22:54:45] - |A| - [1256424] - C:\WINDOWS\system32\atiadlxx.dll [MD5.53650482B8E621276DC55E50C9FB2FEE] - [13/08/2016 22:54:45] - |A| - [662392] - C:\WINDOWS\system32\atiapfxx.blb [MD5.CC2470CA903EA355A24F05520D79BDB8] - [13/08/2016 22:54:45] - |A| - [375792] - C:\WINDOWS\system32\atiapfxx.exe [MD5.279066332FA267076E3BEE81C4297F87] - [13/08/2016 22:54:45] - |A| - [64496] - C:\WINDOWS\system32\aticalcl64.dll [MD5.3A0F17C7C8E37DCEAE1DA76B7D761702] - [13/08/2016 22:54:45] - |A| - [15725552] - C:\WINDOWS\system32\aticaldd64.dll [MD5.D22A08EE217DE15B6A41AE518B4F4FBE] - [13/08/2016 22:54:45] - |A| - [71152] - C:\WINDOWS\system32\aticalrt64.dll [MD5.BE92AD0155D4A23D0073AF51BE808B29] - [13/08/2016 22:54:45] - |A| - [1479808] - C:\WINDOWS\system32\aticfx64.dll [MD5.B565601728AF96EEFCF7E9CDE3CDD2BE] - [13/08/2016 22:54:45] - |A| - [451048] - C:\WINDOWS\system32\atidemgy.dll [MD5.8700278344BED8D4A3A5AC2875359584] - [13/08/2016 22:54:46] - |A| - [12088000] - C:\WINDOWS\system32\atidxx64.dll [MD5.69F82C40A189962A65F6D5A02DF8599F] - [13/08/2016 22:54:46] - |A| - [168944] - C:\WINDOWS\system32\atieah64.exe [MD5.B96BD9F5B2B0CD6549EE59FD242A6D56] - [13/08/2016 22:54:46] - |A| - [683504] - C:\WINDOWS\system32\atieclxx.exe [MD5.521248FA26458669BAAE6AB7DB21F3AC] - [13/08/2016 22:54:46] - |A| - [255472] - C:\WINDOWS\system32\atiesrxx.exe [MD5.E4F96DFF0501430BF7C6E90841A7282D] - [13/08/2016 22:54:46] - |A| - [83952] - C:\WINDOWS\system32\atig6pxx.dll [MD5.86F2AE002AF9222F34937823B98753C2] - [13/08/2016 22:54:46] - |A| - [165360] - C:\WINDOWS\system32\atig6txx.dll [MD5.0C3156664885AF41100B63853EBCE037] - [13/08/2016 22:54:46] - |A| - [78320] - C:\WINDOWS\system32\atiglpxx.dll [MD5.079EFFD5BECB418FE6596229B28D7324] - [13/08/2016 22:54:46] - |A| - [737410] - C:\WINDOWS\system32\atiicdxx.dat [MD5.FE4E7138E51DA7EF01E51F28128A7F53] - [13/08/2016 22:54:46] - |A| - [88000] - C:\WINDOWS\system32\atimpc64.dll [MD5.C84C24F13663EF5A59C1E598A350C8C3] - [13/08/2016 22:54:46] - |A| - [38384] - C:\WINDOWS\system32\atimuixx.dll [MD5.7D9CCB5DD8837D6AC954956A5812112C] - [13/08/2016 22:54:46] - |A| - [30776304] - C:\WINDOWS\system32\atio6axx.dll [MD5.0E89795F721B2BC02D0A12C470750DF6] - [13/08/2016 22:54:47] - |A| - [59888] - C:\WINDOWS\system32\ATIODCLI.exe [MD5.C7A506822BE45CD42415710979CDAE7F] - [13/08/2016 22:54:47] - |A| - [341488] - C:\WINDOWS\system32\ATIODE.exe [MD5.3FE40633FC3BC5AE41EACDA0E1BA72FE] - [13/08/2016 22:54:47] - |A| - [199664] - C:\WINDOWS\system32\atitmm64.dll [MD5.067CED045532C58B46E6527BCE3CB47F] - [13/08/2016 22:54:47] - |A| - [130072] - C:\WINDOWS\system32\atiu9p64.dll [MD5.AC6970C74B7457B291BB2C0035AA7DAE] - [13/08/2016 22:54:47] - |A| - [8864920] - C:\WINDOWS\system32\atiumd64.dll [MD5.486D6985E7B7826DBBEAE12755851027] - [13/08/2016 22:54:47] - |A| - [3437632] - C:\WINDOWS\system32\atiumd6a.cap [MD5.0A9CA09952D768F768D2903F984102DC] - [13/08/2016 22:54:47] - |A| - [8982432] - C:\WINDOWS\system32\atiumd6a.dll [MD5.AE81C76C930DD6875E5D9C6BEA2F0966] - [13/08/2016 22:54:48] - |A| - [162232] - C:\WINDOWS\system32\atiuxp64.dll [MD5.EFA5E3D55F1CC185BC690B7D79D015A9] - [13/08/2016 22:54:48] - |A| - [100816] - C:\WINDOWS\system32\ativce02.dat [MD5.B974290EEE645249EE212FF62DD0824A] - [13/08/2016 22:54:48] - |A| - [177344] - C:\WINDOWS\system32\ativce03.dat [MD5.5EBC73A78E5903E7CE6F6B25E4A6BE8F] - [13/08/2016 22:54:48] - |A| - [234420] - C:\WINDOWS\system32\ativvaxy_cik.dat [MD5.C55D2CBC17AAE1FBAC9135E7C31A4D31] - [13/08/2016 22:54:48] - |A| - [232752] - C:\WINDOWS\system32\ativvaxy_cik_nd.dat [MD5.0770A5AB5218E6D3134A7A7239B9A216] - [13/08/2016 22:54:48] - |A| - [255808] - C:\WINDOWS\system32\ativvaxy_cz_nd.dat [MD5.A81F68A0D3387A06182EFA3880D3F0BD] - [13/08/2016 22:54:48] - |A| - [250884] - C:\WINDOWS\system32\ativvaxy_FJ.dat [MD5.7EE8F6853798F7A900DB15F3054A0277] - [13/08/2016 22:54:48] - |A| - [249088] - C:\WINDOWS\system32\ativvaxy_FJ_nd.dat [MD5.11355CAC5334C8999211C09CAAE194EF] - [13/08/2016 22:54:48] - |A| - [322868] - C:\WINDOWS\system32\ativvaxy_vi.dat [MD5.3544D6AF6E0C9783C2CF6FA9CE42D520] - [13/08/2016 22:54:48] - |A| - [321200] - C:\WINDOWS\system32\ativvaxy_vi_nd.dat [MD5.7C163EDE63854539828F5B2C1BC529FD] - [13/08/2016 22:54:48] - |A| - [157144] - C:\WINDOWS\system32\ativvsva.dat [MD5.219D7091DD1D93728392337FE9C7ADD6] - [13/08/2016 22:54:48] - |A| - [204952] - C:\WINDOWS\system32\ativvsvl.dat [MD5.00000000000000000000000000000000] - [21/08/2016 11:22:57] - |D| - [76188] - C:\WINDOWS\system32\BestPractices [MD5.78C35DD7CF780428650B1EE9B0F8D41E] - [14/08/2016 10:43:19] - |A| - [770048] - C:\WINDOWS\system32\bisrv.dll [MD5.E08C00B7044F58E7D53CB4F6451D3ABB] - [14/08/2016 10:43:19] - |A| - [227840] - C:\WINDOWS\system32\cdd.dll [MD5.402010E58B3F92A42643F384A7BDE573] - [14/08/2016 10:43:28] - |A| - [8124416] - C:\WINDOWS\system32\Chakra.dll [MD5.5725D2F9E67D2D2F944777384BFC5EC3] - [14/08/2016 10:43:28] - |A| - [1081856] - C:\WINDOWS\system32\Chakradiag.dll [MD5.A972DDEFFEF76A9643A65F07C6762154] - [14/08/2016 10:43:29] - |A| - [140288] - C:\WINDOWS\system32\Chakrathunk.dll [MD5.F2D598B11C294EE360FDA0D3E81DA7EC] - [13/08/2016 22:54:54] - |A| - [243688] - C:\WINDOWS\system32\clinfo.exe [MD5.10C6A750AF9B13DC59BBF4FAC628DBE7] - [14/08/2016 10:43:19] - |A| - [241496] - C:\WINDOWS\system32\CloudExperienceHost.dll [MD5.A0E91D21C945781D03EA0BA1C95F821E] - [13/08/2016 22:54:54] - |A| - [874480] - C:\WINDOWS\system32\coinst_15.20.dll [MD5.A797EED94B22B29D3974CB20B66BE6C6] - [14/08/2016 07:58:36] - |A| - [110592] - C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll [MD5.73BBDD6A450AF2708B089B0DFEE74252] - [14/08/2016 10:43:19] - |A| - [495104] - C:\WINDOWS\system32\DataSenseHandlers.dll [MD5.274A83622B43240F74E9CAA257142DDA] - [13/08/2016 22:54:54] - |A| - [12784] - C:\WINDOWS\system32\detoured.dll [MD5.17CA16C7B5AFE34B919D5C86C0E41C5D] - [14/08/2016 10:43:19] - |A| - [289792] - C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll [MD5.CCEDCF29AC3AD4C00B646D3F8F282264] - [14/08/2016 10:43:28] - |A| - [22572032] - C:\WINDOWS\system32\edgehtml.dll [MD5.097C96CC5CFAA6A0CD0D0A50E327EAC4] - [13/08/2016 21:44:13] - |A| - [23208] - C:\WINDOWS\system32\emptyregdb.dat [MD5.BAC5074667751F72A9CE48CDC31BAC48] - [14/08/2016 19:02:22] - |A| - [10752] - C:\WINDOWS\system32\E_GCINST.DLL [MD5.8159960E8BA20F1C4A4EBCF0DAEC60E5] - [14/08/2016 19:01:39] - |A| - [83968] - C:\WINDOWS\system32\E_ID4BLPE.DLL [MD5.2E21840342850A8A7F28D28D6DD3A1CD] - [14/08/2016 19:01:40] - |A| - [179712] - C:\WINDOWS\system32\E_ILMBLPE.DLL [MD5.46D901798362F966BA1EA3FACB7F8450] - [14/08/2016 07:58:39] - |A| - [2743328] - C:\WINDOWS\system32\FMAPO64.dll [MD5.4F575C282EE093323D00A4FD86762000] - [14/08/2016 09:55:40] - |A| - [206536] - C:\WINDOWS\system32\FNTCACHE.DAT [MD5.AF3851142081D5ACC3FC46971F9FFEAD] - [14/08/2016 18:41:03] - |A| - [4] - C:\WINDOWS\system32\fsdbcrpt.kar.{4d726ee4-96ff-4771-b054-fa7322787611} [MD5.726C487C409C7DEB114451B6EFFD990B] - [14/08/2016 10:43:20] - |A| - [1656320] - C:\WINDOWS\system32\GdiPlus.dll [MD5.77071BF934BEF16D5F02E31624258A91] - [13/08/2016 22:54:54] - |A| - [111600] - C:\WINDOWS\system32\hsa-thunk64.dll [MD5.B498C439EAD02478BA3F337394295FB9] - [14/08/2016 10:43:19] - |A| - [2745224] - C:\WINDOWS\system32\iertutil.dll [MD5.D13EA5B1CC8BA39847B56DE96880B8DB] - [12/08/2016 08:00:18] - |A| - [698288] - C:\WINDOWS\system32\im-fre.exe [MD5.6B9F8614D6A0EAB2EF3A6570F7E9CC4A] - [14/08/2016 10:43:28] - |A| - [261120] - C:\WINDOWS\system32\indexeddbserver.dll [MD5.D506921989872994B9C5615D4761882C] - [19/08/2016 08:02:48] - |A| - [128288] - C:\WINDOWS\system32\IObitSmartDefragExtension.dll [MD5.8527953FFC8707AB5EA5E1C6461FCF6D] - [14/08/2016 10:43:19] - |A| - [43008] - C:\WINDOWS\system32\LaunchWinApp.exe [MD5.84B686AFB958D7ECDC2A1FA5D87353E1] - [14/08/2016 10:54:08] - |A| - [52328] - C:\WINDOWS\system32\license.rtf [MD5.804FEF2567E7CC81312903074371B179] - [14/08/2016 10:43:19] - |A| - [1260384] - C:\WINDOWS\system32\LicenseManager.dll [MD5.7385ECF9E68A5C3F165FF316A71C84C5] - [14/08/2016 10:43:19] - |A| - [1491456] - C:\WINDOWS\system32\lsasrv.dll [MD5.D7EDFAF69B63B5247670BE8CBD669113] - [14/08/2016 09:59:07] - |A| - [7818] - C:\WINDOWS\system32\lvcoinst.log [MD5.D3F4E00C322EDA78873848BE75ACC8A4] - [13/08/2016 22:54:54] - |A| - [136176] - C:\WINDOWS\system32\mantle64.dll [MD5.EA33454E28EE1F3CA432DA87203DA24F] - [13/08/2016 22:54:54] - |A| - [103408] - C:\WINDOWS\system32\mantleaxl64.dll [MD5.00000000000000000000000000000000] - [14/08/2016 10:40:15] - |D| - [5220] - C:\WINDOWS\system32\Microsoft [MD5.8D1765328902CE63392055F5451C3480] - [14/08/2016 01:33:14] - |N| - [504488] - C:\WINDOWS\system32\MpSigStub.exe [MD5.00000000000000000000000000000000] - [14/08/2016 01:29:51] - |D| - [0] - C:\WINDOWS\system32\MRT [MD5.649BBC16880D6D85CB91873C81A1094C] - [14/08/2016 01:29:38] - |AC| - [147640136] - C:\WINDOWS\system32\MRT.exe [MD5.43F717FBB79C9B408D96FAAF6732C4A2] - [14/08/2016 10:43:20] - |A| - [1418304] - C:\WINDOWS\system32\msctf.dll [MD5.754DDF1A87E7CF5FAFBF9F2C440E8558] - [14/08/2016 18:41:03] - |A| - [4] - C:\WINDOWS\system32\msdbcrpt.kar.{4d726ee4-96ff-4771-b054-fa7322787611} [MD5.797636D76C2F1D0A101A66E1BEF8AEDB] - [14/08/2016 10:43:28] - |A| - [23682048] - C:\WINDOWS\system32\mshtml.dll [MD5.CDEB6DC6F451BFBC41A474A5085563C0] - [14/08/2016 10:43:28] - |A| - [2755584] - C:\WINDOWS\system32\mshtml.tlb [MD5.21D2999AE3EDB633E2843B7C9AF55B6E] - [14/08/2016 10:43:19] - |A| - [6664192] - C:\WINDOWS\system32\mspaint.exe [MD5.BDD6CA90C01467DFC19A69C45161450F] - [14/08/2016 09:55:53] - |A| - [17060] - C:\WINDOWS\system32\NetSetupMig.log [MD5.8CA03831CA43C6258F6C0266A76A2656] - [14/08/2016 10:43:19] - |A| - [115200] - C:\WINDOWS\system32\offlinelsa.dll [MD5.F192E1998A5F6826BE6955F6EAE7CDA1] - [13/08/2016 22:54:45] - |A| - [73712] - C:\WINDOWS\system32\OpenCL.dll [MD5.9D02A2A9F1D2C7C7DBE55E7E1A95FA29] - [14/08/2016 10:03:20] - |A| - [2641970] - C:\WINDOWS\system32\PerfStringBackup.INI [MD5.587DDEDEA34DBDF2B7C4F5EEC1685A19] - [14/08/2016 10:31:42] - |A| - [124624] - C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll [MD5.CAF55CA39F076939E6CF4C8660235610] - [14/08/2016 10:31:43] - |A| - [1166520] - C:\WINDOWS\system32\PresentationNative_v0300.dll [MD5.0225FC6F0D91F84B44CE252487D8D725] - [14/08/2016 21:56:20] - |A| - [607256] - C:\WINDOWS\system32\prodad-codec.dll [MD5.E5FCE41A5114E40EE573AB8631925BF3] - [14/08/2016 21:56:16] - |A| - [376344] - C:\WINDOWS\system32\proDAD-PA-Support.dll [MD5.C36C982BDDA232A84A664C25036C4BD0] - [20/08/2016 05:46:25] - |A| - [18528] - C:\WINDOWS\system32\prwntdrv.sys [MD5.11F9D326FCD5B08549280B1C8D185932] - [14/08/2016 07:58:51] - |A| - [147672] - C:\WINDOWS\system32\RCoInstII64.dll [MD5.7044C9C27DAD038EFADAF102AAF8C116] - [14/08/2016 07:58:51] - |A| - [30311936] - C:\WINDOWS\system32\RCoRes64.dat [MD5.E9D4A333DF15D06C68AC4BFB9B6581CB] - [14/08/2016 07:58:52] - |A| - [310104] - C:\WINDOWS\system32\RP3DAA64.dll [MD5.B6FE01558CC03F3866C9AD0ED19261D8] - [14/08/2016 07:58:52] - |A| - [310104] - C:\WINDOWS\system32\RP3DHT64.dll [MD5.C2E9CFE429FA37A1CD25DDE21B6F380A] - [14/08/2016 07:58:52] - |A| - [1284680] - C:\WINDOWS\system32\RTCOM64.dll [MD5.AD57F227B6116ACB68442F9FCB075EC9] - [14/08/2016 07:58:53] - |A| - [617176] - C:\WINDOWS\system32\RtDataProc64.dll [MD5.A6286A6C7A1BBFCBA17AA54384A21D1C] - [14/08/2016 07:58:53] - |A| - [204120] - C:\WINDOWS\system32\RTEED64A.dll [MD5.6F4CD493196100EEF349D7132CECAFD9] - [14/08/2016 07:58:53] - |A| - [78680] - C:\WINDOWS\system32\RTEEG64A.dll [MD5.ECAEC5FBBBEF8612AF0A866AFA5F7EF2] - [14/08/2016 07:58:53] - |A| - [101208] - C:\WINDOWS\system32\RTEEL64A.dll [MD5.D0D0D82B7366E691275E433CD34F89B2] - [14/08/2016 07:58:53] - |A| - [375128] - C:\WINDOWS\system32\RTEEP64A.dll [MD5.55B0ADC2D452FB82FE957C7DB9051457] - [14/08/2016 07:58:53] - |A| - [1004248] - C:\WINDOWS\system32\RtkApi64.dll [MD5.9BEE3AA4449847E423CA7FAA703F9681] - [14/08/2016 07:58:54] - |A| - [2585304] - C:\WINDOWS\system32\RtkAPO64.dll [MD5.0805289E121F3E3C458C970B08314EB2] - [14/08/2016 07:58:54] - |A| - [149608] - C:\WINDOWS\system32\RtkCfg64.dll [MD5.8814A281406553A2640D6A04702C63BD] - [14/08/2016 07:58:54] - |A| - [14952] - C:\WINDOWS\system32\RtkCoLDR64.dll [MD5.CA1D7D09854D305A64B100DC1400BA21] - [14/08/2016 07:58:57] - |A| - [331880] - C:\WINDOWS\system32\RtlCPAPI64.dll [MD5.903524B7B39CD23F3D292B216DC2438E] - [14/08/2016 07:58:57] - |A| - [2795224] - C:\WINDOWS\system32\RtPgEx64.dll [MD5.3F8A63EDF6E0E6827D5494CD8720F7CC] - [14/08/2016 07:58:57] - |A| - [1662024] - C:\WINDOWS\system32\RTSnMg64.cpl [MD5.3F34CDE2C58C1A996C3D37416A114D56] - [14/08/2016 10:43:19] - |A| - [509952] - C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll [MD5.664366A014A9CD0EC72C7E343E91A305] - [14/08/2016 10:43:19] - |A| - [4749312] - C:\WINDOWS\system32\SettingsHandlers_nt.dll [MD5.D225070308AB489DC307C91AC4C938CA] - [20/08/2016 05:46:25] - |A| - [98400] - C:\WINDOWS\system32\setupprwdrvx64.exe [MD5.D9B1423D700666459BD54670B0273CEA] - [14/08/2016 10:43:19] - |A| - [22219328] - C:\WINDOWS\system32\shell32.dll [MD5.1F32156F2C7C3842C91DC2C13F5D94C0] - [14/08/2016 10:43:19] - |A| - [231424] - C:\WINDOWS\system32\shutdownux.dll [MD5.00000000000000000000000000000000] - [14/08/2016 09:55:50] - |D| - [5414448] - C:\WINDOWS\system32\SleepStudy [MD5.D57880A3F9F22D67974EF0EB8B67021C] - [19/08/2016 08:02:46] - |A| - [36824] - C:\WINDOWS\system32\SmartDefragBootTime.exe [MD5.A88BE9A6C4E646A2B2A1BD3A7F4B58E7] - [14/08/2016 07:59:01] - |A| - [198896] - C:\WINDOWS\system32\SRSHP64.dll [MD5.00000000000000000000000000000000] - [14/08/2016 09:58:34] - |D| - [2177408] - C:\WINDOWS\system32\SRSLabs [MD5.A028717B791416182959B325D5B40679] - [14/08/2016 07:59:01] - |A| - [211184] - C:\WINDOWS\system32\SRSTSH64.dll [MD5.018D3D2478754AA411DE6DA6DE5F8F21] - [14/08/2016 07:59:01] - |A| - [518896] - C:\WINDOWS\system32\SRSTSX64.dll [MD5.2FCADCC14F8E540F6ADE4BF92BD8AEDD] - [14/08/2016 07:59:01] - |A| - [155888] - C:\WINDOWS\system32\SRSWOW64.dll [MD5.ADE940101D037E0C8048C07A8B751435] - [14/08/2016 10:43:19] - |A| - [496128] - C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll [MD5.DB5CEDD2D9B6BEC1F008AB32F6430407] - [14/08/2016 10:31:43] - |A| - [35480] - C:\WINDOWS\system32\TsWpfWrp.exe [MD5.9B27A791D3B58C8EC5CDC5ADD4E512A5] - [14/08/2016 10:43:19] - |A| - [9125888] - C:\WINDOWS\system32\twinui.dll [MD5.AD920A85D98B2048373A69B02B9E08B7] - [14/08/2016 10:43:19] - |A| - [1785856] - C:\WINDOWS\system32\urlmon.dll [MD5.958AD14CDF4EBB6BADDB13F8B39A97CF] - [14/08/2016 10:43:19] - |A| - [1461200] - C:\WINDOWS\system32\user32.dll [MD5.D10864C1730172780C2D4BE633B9220A] - [14/08/2016 22:44:56] - |A| - [1795952] - C:\WINDOWS\system32\WdfCoInstaller01011.dll [MD5.37BD0ED26D65A28E7CAA32F446BDA67A] - [14/08/2016 10:43:19] - |A| - [389000] - C:\WINDOWS\system32\wevtapi.dll [MD5.4B53781598D1DB2D33DE9F7248F5A26F] - [14/08/2016 10:43:19] - |A| - [1708544] - C:\WINDOWS\system32\wevtsvc.dll [MD5.3CF052C22F34174BE783DAF2F3A81D8A] - [14/08/2016 10:43:19] - |A| - [210944] - C:\WINDOWS\system32\win32k.sys [MD5.D74E08C83CB93EB5E099702FDEF157B9] - [14/08/2016 10:43:19] - |A| - [1508864] - C:\WINDOWS\system32\win32kbase.sys [MD5.1E25FC0F0CBDC16A7597FF2B47DF66DE] - [14/08/2016 10:43:19] - |A| - [3617280] - C:\WINDOWS\system32\win32kfull.sys [MD5.0482CFC6D06935953519340A0D360329] - [14/08/2016 10:43:19] - |A| - [114192] - C:\WINDOWS\system32\win32u.dll [MD5.6FB48F624829BFD03D67E3666822D170] - [14/08/2016 10:43:19] - |A| - [58880] - C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll [MD5.F10387C12A9FD47AC67764E75312739C] - [14/08/2016 10:43:19] - |A| - [909312] - C:\WINDOWS\system32\Windows.UI.Search.dll [MD5.850BBEFE1D202E832F5148E8A821500D] - [14/08/2016 10:43:19] - |A| - [49152] - C:\WINDOWS\system32\Windows.UI.Shell.dll [MD5.D41D8CD98F00B204E9800998ECF8427E] - [13/08/2016 16:31:19] - |RASH| - [0] - C:\WINDOWS\system32\Drivers\103C_HP_cPC_CQ2904EF_Y53316J_0U_Q4CH3100VPJ_E12WE3RR8607_4A_I2AE3_SHP_V1.02_B8.17_T130125_W8101-0_L40C_M3660_J1000_7AMD_8BFF_91.40_#130304_N19692062_Z_G10029809_Ohp DVD A DH16ACSHR_DACRAD46.MRK [MD5.440AB537812B635B710D78D7895AC201] - [13/08/2016 22:54:45] - |A| - [52208] - C:\WINDOWS\system32\Drivers\ati2erec.dll [MD5.D1F059A530620DCF71303B525D52CA97] - [13/08/2016 22:54:46] - |A| - [21648880] - C:\WINDOWS\system32\Drivers\atikmdag.sys [MD5.AD96CC96B6A0CEE8910A13679426C970] - [13/08/2016 22:54:46] - |A| - [674288] - C:\WINDOWS\system32\Drivers\atikmpag.sys [MD5.19863788DFFBE37CB63BF19D1FD5C247] - [14/08/2016 21:32:28] - |A| - [25864] - C:\WINDOWS\system32\Drivers\CLBStor.sys [MD5.C3EE731B310E6C563A47F80C0ADD39CD] - [14/08/2016 21:32:32] - |A| - [379144] - C:\WINDOWS\system32\Drivers\CLBUDF.sys [MD5.0C7626AFB2419207B2ABCB6F8AEA334F] - [14/08/2016 21:43:13] - |A| - [103176] - C:\WINDOWS\system32\Drivers\CLVirtualBus01.sys [MD5.E09C3E2CD29727AAC0977E1A7CE0425E] - [14/08/2016 10:43:19] - |A| - [619368] - C:\WINDOWS\system32\Drivers\cng.sys [MD5.68B1E0DA1BB1680494227E88CE821E2F] - [14/08/2016 10:43:19] - |A| - [62816] - C:\WINDOWS\system32\Drivers\dam.sys [MD5.A90C76FB62526DEB5A5557A8839841AB] - [14/08/2016 10:43:19] - |A| - [2190688] - C:\WINDOWS\system32\Drivers\dxgkrnl.sys [MD5.14AE4AAED71AE09151AED376420B630D] - [14/08/2016 10:43:19] - |A| - [402272] - C:\WINDOWS\system32\Drivers\dxgmms1.sys [MD5.661B84B24D690DF50BD47DFA7B036122] - [14/08/2016 10:43:19] - |A| - [658784] - C:\WINDOWS\system32\Drivers\dxgmms2.sys [MD5.27B3C0F193F00D65F2D6B2C8C7FD22FF] - [21/08/2016 09:54:13] - |A| - [339800] - C:\WINDOWS\system32\Drivers\file_tracker.sys [MD5.4AD91299304A5E75084434F246DE0F9A] - [21/08/2016 09:52:21] - |A| - [163160] - C:\WINDOWS\system32\Drivers\fltsrv.sys [MD5.3B342AD20A76FAEC4851A38774B99AB4] - [14/08/2016 10:43:19] - |A| - [168800] - C:\WINDOWS\system32\Drivers\ksecpkg.sys [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/08/2016 11:57:11] - |AH| - [0] - C:\WINDOWS\system32\Drivers\Msft_Kernel_avchv_01009.Wdf [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/08/2016 09:57:04] - |AH| - [0] - C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf [MD5.D41D8CD98F00B204E9800998ECF8427E] - [23/08/2016 15:46:50] - |AH| - [0] - C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf [MD5.DFA16A1C41989C28074E00C40D67C23C] - [14/08/2016 07:58:52] - |A| - [620273] - C:\WINDOWS\system32\Drivers\RTAIODAT.DAT [MD5.E9740A3BC0AE6EA035FF7ECE3A1B27B6] - [14/08/2016 07:58:56] - |A| - [3564376] - C:\WINDOWS\system32\Drivers\RTKVHD64.sys [MD5.67E7E7DB39769F2D8C4DC7BD4EBA02E6] - [21/08/2016 09:52:25] - |A| - [340312] - C:\WINDOWS\system32\Drivers\snapman.sys [MD5.D66C989F0C86A11472A57963841643D4] - [21/08/2016 09:52:32] - |A| - [1267552] - C:\WINDOWS\system32\Drivers\tib.sys [MD5.0F9FD35675C7B29AA01DF7CA038FC18C] - [21/08/2016 09:52:35] - |A| - [193376] - C:\WINDOWS\system32\Drivers\tib_mounter.sys [MD5.21AFBEAC264AB4C6A399E41EF7B2A500] - [21/08/2016 09:52:39] - |A| - [601432] - C:\WINDOWS\system32\Drivers\tnd.sys [MD5.0D5A09B08568760AE85A801FCBC0F83D] - [19/08/2016 06:17:54] - |A| - [28272] - C:\WINDOWS\system32\Drivers\TrueSight.sys [MD5.593D66A1424176B07E1E04B581C636C2] - [21/08/2016 09:52:42] - |A| - [279392] - C:\WINDOWS\system32\Drivers\virtual_file.sys [MD5.A556768CC1FA4F36022BEE2F0EDE2566] - [13/08/2016 22:56:54] - |A| - [26880] - C:\WINDOWS\system32\Drivers\wdcsam64.sys [MD5.00000000000000000000000000000000] - [21/08/2016 11:04:30] - |D| - [336225] - C:\WINDOWS\syswow64\1033 [MD5.EEDCAB9ABD75871943644940A4BC4FC4] - [14/08/2016 10:43:20] - |A| - [5398016] - C:\WINDOWS\syswow64\aclui.dll [MD5.7D4761FD5A02353C9BD70C1F5B15AA4F] - [13/08/2016 22:54:39] - |A| - [198632] - C:\WINDOWS\syswow64\amdgfxinfo32.dll [MD5.F12467373381C72FAE9CA7C08ED6C919] - [13/08/2016 22:54:39] - |A| - [132080] - C:\WINDOWS\syswow64\amdhdl32.dll [MD5.87882BCCDF63B74B675ECCE6B6609DC2] - [13/08/2016 22:54:39] - |A| - [524272] - C:\WINDOWS\syswow64\amdlvr32.dll [MD5.8F2144D05F41DD27308548B5D9D19101] - [13/08/2016 22:54:39] - |A| - [5216240] - C:\WINDOWS\syswow64\amdmantle32.dll [MD5.F9F99EA40AF48C716C2E823F2B6FD2D8] - [13/08/2016 22:54:39] - |A| - [48112] - C:\WINDOWS\syswow64\amdmmcl.dll [MD5.E30B1D883DC886016C38FDEE6755CCC6] - [13/08/2016 22:54:39] - |A| - [39721456] - C:\WINDOWS\syswow64\amdocl.dll [MD5.5F0F6073A243FC8C4C190E3F06D1247E] - [13/08/2016 22:54:40] - |A| - [22327280] - C:\WINDOWS\syswow64\amdocl12cl.dll [MD5.40A2E4C2933EB5DE99C06F00A9E2C589] - [13/08/2016 22:54:43] - |A| - [1004024] - C:\WINDOWS\syswow64\amdocl_as32.exe [MD5.985589A3C4BB14ED23A15D9477475F7B] - [13/08/2016 22:54:44] - |A| - [807424] - C:\WINDOWS\syswow64\amdocl_ld32.exe [MD5.170EA2F4A32130BBF7EABD2D94B235AE] - [13/08/2016 22:54:44] - |A| - [81160] - C:\WINDOWS\syswow64\amdpcom32.dll [MD5.546E937838E7D9FD945D6505529F2209] - [13/08/2016 22:54:45] - |A| - [935408] - C:\WINDOWS\syswow64\atiadlxx.dll [MD5.546E937838E7D9FD945D6505529F2209] - [13/08/2016 22:54:45] - |A| - [935408] - C:\WINDOWS\syswow64\atiadlxy.dll [MD5.53650482B8E621276DC55E50C9FB2FEE] - [13/08/2016 22:54:45] - |A| - [662392] - C:\WINDOWS\syswow64\atiapfxx.blb [MD5.4A8BC73F07C13E602B573BE723BFB360] - [13/08/2016 22:54:45] - |A| - [57840] - C:\WINDOWS\syswow64\aticalcl.dll [MD5.64E261847856C53DE5A3007682707290] - [13/08/2016 22:54:45] - |A| - [14310896] - C:\WINDOWS\syswow64\aticaldd.dll [MD5.F1E925DE8ECC7BE99BCC380BBA3F477E] - [13/08/2016 22:54:45] - |A| - [60912] - C:\WINDOWS\syswow64\aticalrt.dll [MD5.DCE2F09D2DF45938DB476B287D6F560B] - [13/08/2016 22:54:45] - |A| - [1223552] - C:\WINDOWS\syswow64\aticfx32.dll [MD5.194B36603ED7BB93290F4A3C73B94764] - [13/08/2016 22:54:45] - |A| - [10211016] - C:\WINDOWS\syswow64\atidxx32.dll [MD5.B84EF06D0D8192F33EE5BC12B2BA3702] - [13/08/2016 22:54:46] - |A| - [152560] - C:\WINDOWS\syswow64\atieah32.exe [MD5.B728F7B42DA61395F43C86BDDE5196E5] - [13/08/2016 22:54:46] - |A| - [150512] - C:\WINDOWS\syswow64\atigktxx.dll [MD5.0C3156664885AF41100B63853EBCE037] - [13/08/2016 22:54:46] - |A| - [78320] - C:\WINDOWS\syswow64\atiglpxx.dll [MD5.B344A7D717211B7DF53E369FC58290DF] - [13/08/2016 22:54:46] - |A| - [81160] - C:\WINDOWS\syswow64\atimpc32.dll [MD5.6557A2BB671495C8F7E127FCD23FAF3E] - [13/08/2016 22:54:47] - |A| - [25320432] - C:\WINDOWS\syswow64\atioglxx.dll [MD5.E183E40B75E742A6E597A922168C2405] - [13/08/2016 22:54:47] - |A| - [112360] - C:\WINDOWS\syswow64\atiu9pag.dll [MD5.E638384DCD47CEA8F0DF2B6BAFB11F57] - [13/08/2016 22:54:48] - |A| - [7482560] - C:\WINDOWS\syswow64\atiumdag.dll [MD5.A98DA23A524803615B083CFCED1CE362] - [13/08/2016 22:54:48] - |A| - [3471376] - C:\WINDOWS\syswow64\atiumdva.cap [MD5.34438A391DADBD03940AF0760E2932CB] - [13/08/2016 22:54:48] - |A| - [8009360] - C:\WINDOWS\syswow64\atiumdva.dll [MD5.C62336798199A3705424A6708445DD11] - [13/08/2016 22:54:48] - |A| - [143056] - C:\WINDOWS\syswow64\atiuxpag.dll [MD5.7C163EDE63854539828F5B2C1BC529FD] - [13/08/2016 22:54:48] - |A| - [157144] - C:\WINDOWS\syswow64\ativvsva.dat [MD5.219D7091DD1D93728392337FE9C7ADD6] - [13/08/2016 22:54:48] - |A| - [204952] - C:\WINDOWS\syswow64\ativvsvl.dat [MD5.00000000000000000000000000000000] - [21/08/2016 11:22:58] - |D| - [0] - C:\WINDOWS\syswow64\BestPractices [MD5.02B891B9B443C2C9406F70C3B7F153AC] - [14/08/2016 10:43:29] - |A| - [6044672] - C:\WINDOWS\syswow64\Chakra.dll [MD5.1375FA26B9483F8C2D607E1741F3A440] - [14/08/2016 10:43:29] - |A| - [822784] - C:\WINDOWS\syswow64\Chakradiag.dll [MD5.5750D828D956B7B0247C291540746497] - [14/08/2016 10:43:29] - |A| - [121344] - C:\WINDOWS\syswow64\Chakrathunk.dll [MD5.83EBA442F07AAB8D6375D2EEC945C46C] - [19/08/2016 07:15:20] - |A| - [1868128] - C:\WINDOWS\syswow64\d3dcsx_43.dll [MD5.20C835843FCEC4DEDFCD7BFFA3B91641] - [19/08/2016 07:19:31] - |A| - [470880] - C:\WINDOWS\syswow64\d3dx10_43.dll [MD5.86E39E9161C3D930D93822F1563C280D] - [19/08/2016 07:17:51] - |A| - [1998168] - C:\WINDOWS\syswow64\D3DX9_43.dll [MD5.2955C49DDEB6A013B0F3C16C7817755F] - [13/08/2016 22:54:54] - |A| - [12784] - C:\WINDOWS\syswow64\detoured.dll [MD5.D92AC9E58E478015596333ADF5DAED01] - [01/08/2016 06:18:56] - |A| - [365536] - C:\WINDOWS\syswow64\DivXControlPanelApplet.cpl [MD5.8D1849FAB3C99819CDBACDA369D73A04] - [14/08/2016 10:43:28] - |A| - [19423232] - C:\WINDOWS\syswow64\edgehtml.dll [MD5.3FE6F1234DBE0C5F3A17CA329C1A9641] - [21/08/2016 11:08:25] - |A| - [69208] - C:\WINDOWS\syswow64\fssres.dll [MD5.C59193A613F8CFFC9BFF5B6DA08D43F0] - [14/08/2016 10:43:19] - |A| - [1456640] - C:\WINDOWS\syswow64\GdiPlus.dll [MD5.1130EF1F3D0F6080ECCAA9DBD4CAB626] - [21/08/2016 11:08:23] - |A| - [147032] - C:\WINDOWS\syswow64\hadrres.dll [MD5.506C5BE8B184615F7F35A85C00A16E76] - [13/08/2016 22:54:54] - |A| - [111088] - C:\WINDOWS\syswow64\hsa-thunk.dll [MD5.AA6831AB1012776693B9D416664D7433] - [14/08/2016 10:43:29] - |A| - [2251440] - C:\WINDOWS\syswow64\iertutil.dll [MD5.7C5D5F5932C8DAA001A901E6F9B276BA] - [14/08/2016 10:43:28] - |A| - [198656] - C:\WINDOWS\syswow64\indexeddbserver.dll [MD5.11ADC4B688C3A7C50CAAB2E9F6D57848] - [14/08/2016 10:43:20] - |A| - [34304] - C:\WINDOWS\syswow64\LaunchWinApp.exe [MD5.84B686AFB958D7ECDC2A1FA5D87353E1] - [14/08/2016 10:54:08] - |A| - [52328] - C:\WINDOWS\syswow64\license.rtf [MD5.DE1FBFD74FCCA57FB99145A23A3D4C5B] - [14/08/2016 10:43:19] - |A| - [843104] - C:\WINDOWS\syswow64\LicenseManager.dll [MD5.39CE334A6E1CBED62462A0CCCC080A5C] - [13/08/2016 22:54:54] - |A| - [122344] - C:\WINDOWS\syswow64\mantle32.dll [MD5.890CD0E80FA4CA7728FF49E372D789F2] - [13/08/2016 22:54:54] - |A| - [96752] - C:\WINDOWS\syswow64\mantleaxl32.dll [MD5.94867CBFA10DEBED8433E29063499BA9] - [20/08/2016 20:51:38] - |A| - [74703] - C:\WINDOWS\syswow64\mfc45.dat [MD5.E52859FCB7A827CACFCE7963184C7D24] - [19/08/2016 06:33:00] - |A| - [1070152] - C:\WINDOWS\syswow64\MSCOMCTL.OCX [MD5.4E7F889EC171866CDAE9C1AD06F8FCF3] - [14/08/2016 10:43:19] - |A| - [1265424] - C:\WINDOWS\syswow64\msctf.dll [MD5.8B942FFF76086CEDE06DDEDC19F53FE2] - [14/08/2016 10:43:28] - |A| - [19417600] - C:\WINDOWS\syswow64\mshtml.dll [MD5.68154F8F0BFE0986CBC8279EA652C24B] - [14/08/2016 10:43:28] - |A| - [2755584] - C:\WINDOWS\syswow64\mshtml.tlb [MD5.EFAB481C53AB0065A7E12BC75E845E4D] - [14/08/2016 10:43:20] - |A| - [6474752] - C:\WINDOWS\syswow64\mspaint.exe [MD5.3E62CF18441A03A440B280182E4B6935] - [19/08/2016 06:33:00] - |A| - [129872] - C:\WINDOWS\syswow64\MSSTDFMT.DLL [MD5.E947212A96C9A4140E12AC5C292EBF5C] - [14/08/2016 10:43:19] - |A| - [102912] - C:\WINDOWS\syswow64\offlinelsa.dll [MD5.DF941127C8DAA428F15FE0657CB0B152] - [13/08/2016 22:54:45] - |A| - [68080] - C:\WINDOWS\syswow64\OpenCL.dll [MD5.0AA6629F94E3FE8E81100D40D6F7D0E8] - [21/08/2016 11:08:42] - |A| - [82520] - C:\WINDOWS\syswow64\perf-MSSQL$SQLEXPRESS-sqlctr11.0.2100.60.dll [MD5.BF41DD04598870EA08D306A002EEB9DD] - [21/08/2016 11:09:52] - |A| - [45656] - C:\WINDOWS\syswow64\perf-MSSQL11.SQLEXPRESS-sqlagtctr.dll [MD5.05894B48C5548DA868D90200A429EAEE] - [14/08/2016 10:03:11] - |A| - [2307378] - C:\WINDOWS\syswow64\PerfStringBackup.INI [MD5.989CF65E711803AEF6163FFC66D6C530] - [14/08/2016 10:31:47] - |A| - [103120] - C:\WINDOWS\syswow64\PresentationCFFRasterizerNative_v0300.dll [MD5.01B89BD21BE07010F812F9610B94D63C] - [14/08/2016 10:31:47] - |A| - [778936] - C:\WINDOWS\syswow64\PresentationNative_v0300.dll [MD5.D0818657648366B03C7CB4AA2DCED253] - [14/08/2016 09:58:52] - |A| - [2716672] - C:\WINDOWS\syswow64\PrintConfig.dll [MD5.94472C7137C848C574A3F5EFAEEC75B3] - [20/08/2016 05:46:22] - |A| - [15456] - C:\WINDOWS\syswow64\prwntdrv.sys [MD5.00000000000000000000000000000000] - [14/08/2016 09:58:20] - |D| - [2125808] - C:\WINDOWS\syswow64\RTCOM [MD5.BD02234756274708E0CA9083C2418EF4] - [20/08/2016 05:46:22] - |A| - [100448] - C:\WINDOWS\syswow64\setupprwdrv03.exe [MD5.5CFD7174DFD5F9E9E19E40D110B17F20] - [14/08/2016 10:43:20] - |A| - [20965240] - C:\WINDOWS\syswow64\shell32.dll [MD5.00000000000000000000000000000000] - [21/08/2016 11:13:09] - |D| - [1280512] - C:\WINDOWS\syswow64\System32 [MD5.EBB019782606C198813D621DF161B5F0] - [14/08/2016 10:31:47] - |A| - [35480] - C:\WINDOWS\syswow64\TsWpfWrp.exe [MD5.4B00AB5A03EB19F582E900ED8447A6CB] - [14/08/2016 10:43:20] - |A| - [7623168] - C:\WINDOWS\syswow64\twinui.dll [MD5.1786D5DD0985C776E818204ACA7DE20D] - [14/08/2016 10:43:29] - |A| - [1600512] - C:\WINDOWS\syswow64\urlmon.dll [MD5.039C8465C730E7E9713819AB859505E9] - [14/08/2016 10:43:19] - |A| - [1435896] - C:\WINDOWS\syswow64\user32.dll [MD5.A5A97A461D514333AFD1F3FE8D926307] - [21/08/2016 14:44:05] - |A| - [552] - C:\WINDOWS\syswow64\WCFClientSettings.xml [MD5.0D76DAA261682157606F740C96FA6E33] - [14/08/2016 10:43:19] - |A| - [297552] - C:\WINDOWS\syswow64\wevtapi.dll [MD5.55336C6F59AD2162F9DBF877395B85B6] - [14/08/2016 10:43:19] - |A| - [150528] - C:\WINDOWS\syswow64\win32k.sys [MD5.4526A4CD4396DB72CCA1CB25D4EC66E9] - [14/08/2016 10:43:19] - |A| - [2999296] - C:\WINDOWS\syswow64\win32kfull.sys [MD5.9D8F7BD41657B515DD46C7BF90A26CDB] - [14/08/2016 10:43:19] - |A| - [79536] - C:\WINDOWS\syswow64\win32u.dll [MD5.B30EF73AC4993A1B2D540B0B9E5D3978] - [14/08/2016 10:43:20] - |A| - [47104] - C:\WINDOWS\syswow64\Windows.Shell.Search.UriHandler.dll [MD5.F2BCE0CF75943E18852148B2875F632B] - [14/08/2016 01:18:17] - |A| - [41472] - C:\WINDOWS\syswow64\Windows.Speech.Pal.dll [MD5.98CB7EC07B8B9EE4CF0D3A2643600CED] - [14/08/2016 10:43:20] - |A| - [712192] - C:\WINDOWS\syswow64\Windows.UI.Search.dll [MD5.00000000000000000000000000000000] - [14/08/2016 10:33:14] - |D| - [10400] - C:\WINDOWS\syswow64\XPSViewer [MD5.D41D8CD98F00B204E9800998ECF8427E] - [13/08/2016 16:31:19] - |RASH| - [0] - C:\WINDOWS\syswow64\Drivers\103C_HP_cPC_CQ2904EF_Y53316J_0U_Q4CH3100VPJ_E12WE3RR8607_4A_I2AE3_SHP_V1.02_B8.17_T130125_W8101-0_L40C_M3660_J1000_7AMD_8BFF_91.40_#130304_N19692062_Z_G10029809_Ohp DVD A DH16ACSHR_DACRAD46.MRK ---------- | Drives Y: [20/07/2016 10:42:01] - |A| - (.-.) - [5504] - (0.0.0.0) - Y:\a2settings.ini X: V: [09/08/2016 13:11:32] - |A| - (.-.) - [1503] - (0.0.0.0) - V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1503] - (0.0.0.0) - V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen - Raccourci (3).lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1503] - (0.0.0.0) - V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen - Raccourci (4).lnk [09/08/2016 12:14:04] - |A| - (.-.) - [1503] - (0.0.0.0) - V:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [2486] - (0.0.0.0) - V:\2ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisés.PNG - Raccourci (2).lnk [03/08/2016 12:51:31] - |A| - (.-.) - [2486] - (0.0.0.0) - V:\2ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisés.PNG - Raccourci.lnk [08/08/2016 20:06:37] - |A| - (.-.) - [2539] - (0.0.0.0) - V:\3ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisés.PNG - Raccourci (2).lnk [09/08/2016 12:14:06] - |A| - (.-.) - [2539] - (0.0.0.0) - V:\3ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisés.PNG - Raccourci (3).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [2539] - (0.0.0.0) - V:\3ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisés.PNG - Raccourci (4).lnk [08/08/2016 14:24:46] - |A| - (.-.) - [2539] - (0.0.0.0) - V:\3ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisés.PNG - Raccourci.lnk [10/08/2016 12:43:18] - |A| - (.-.) - [3090] - (0.0.0.0) - V:\4ème image bing quand 100% sécurisé finalis (& lfs ultra) finalisée - nous fêtons la c de la lotte de jessica j de piment ô self.PNG - Raccourci.lnk [08/08/2016 14:24:47] - |A| - (.-.) - [1468] - (0.0.0.0) - V:\adaware-pro-3-ans.txt.pdf - Raccourci (2).lnk [08/08/2016 08:09:18] - |A| - (.-.) - [1468] - (0.0.0.0) - V:\adaware-pro-3-ans.txt.pdf - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1463] - (0.0.0.0) - V:\Addition.txt - Raccourci (2).lnk [08/08/2016 20:06:37] - |A| - (.-.) - [1463] - (0.0.0.0) - V:\Addition.txt - Raccourci (3).lnk [08/08/2016 08:09:04] - |A| - (.-.) - [1463] - (0.0.0.0) - V:\Addition.txt - Raccourci.lnk [03/08/2016 12:51:45] - |A| - (.-.) - [1904] - (0.0.0.0) - V:\AdsFix_03_08_2016_11_42_41.txt - Raccourci (2).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1904] - (0.0.0.0) - V:\AdsFix_03_08_2016_11_42_41.txt - Raccourci.lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1283] - (0.0.0.0) - V:\Ashampoo_Snap_2016.08.08_10h49m36s_001_.wmv - Raccourci (2).lnk [09/08/2016 12:14:06] - |A| - (.-.) - [1283] - (0.0.0.0) - V:\Ashampoo_Snap_2016.08.08_10h49m36s_001_.wmv - Raccourci (3).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1283] - (0.0.0.0) - V:\Ashampoo_Snap_2016.08.08_10h49m36s_001_.wmv - Raccourci (4).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1283] - (0.0.0.0) - V:\Ashampoo_Snap_2016.08.08_10h49m36s_001_.wmv - Raccourci (5).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1283] - (0.0.0.0) - V:\Ashampoo_Snap_2016.08.08_10h49m36s_001_.wmv - Raccourci.lnk [23/06/2016 07:51:44] - |A| - (.-.) - [1474] - (0.0.0.0) - V:\barrow 2 & widen 100% sécurisé - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [989] - (0.0.0.0) - V:\Bureau - Raccourci (2).lnk [08/08/2016 08:08:48] - |A| - (.-.) - [1085] - (0.0.0.0) - V:\Bureau - Raccourci (3).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1093] - (0.0.0.0) - V:\Bureau - Raccourci (4).lnk [08/08/2016 20:06:35] - |A| - (.-.) - [1093] - (0.0.0.0) - V:\Bureau - Raccourci (5).lnk [09/08/2016 12:14:04] - |A| - (.-.) - [1097] - (0.0.0.0) - V:\Bureau - Raccourci (6).lnk [09/08/2016 13:11:32] - |A| - (.-.) - [1097] - (0.0.0.0) - V:\Bureau - Raccourci (7).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1097] - (0.0.0.0) - V:\Bureau - Raccourci (8).lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1097] - (0.0.0.0) - V:\Bureau - Raccourci (9).lnk [03/08/2016 12:51:29] - |A| - (.-.) - [989] - (0.0.0.0) - V:\Bureau - Raccourci.lnk [09/08/2016 13:11:33] - |A| - (.-.) - [2304] - (0.0.0.0) - V:\chan final le 100% séc séc fach mc flu de luchon peacock a le brulog noemie.zip - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [2304] - (0.0.0.0) - V:\chan final le 100% séc séc fach mc flu de luchon peacock a le brulog noemie.zip - Raccourci (3).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [2304] - (0.0.0.0) - V:\chan final le 100% séc séc fach mc flu de luchon peacock a le brulog noemie.zip - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [2304] - (0.0.0.0) - V:\chan final le 100% séc séc fach mc flu de luchon peacock a le brulog noemie.zip - Raccourci.lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1319] - (0.0.0.0) - V:\clé de liccence windows 10 proffessionnal.txt - Raccourci.lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1784] - (0.0.0.0) - V:\clé de licence et facture rev unin prof portable.txt - Raccourci (2).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1784] - (0.0.0.0) - V:\clé de licence et facture rev unin prof portable.txt - Raccourci (3).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1784] - (0.0.0.0) - V:\clé de licence et facture rev unin prof portable.txt - Raccourci (4).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1784] - (0.0.0.0) - V:\clé de licence et facture rev unin prof portable.txt - Raccourci (5).lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1784] - (0.0.0.0) - V:\clé de licence et facture rev unin prof portable.txt - Raccourci.lnk [09/08/2016 13:11:32] - |A| - (.-.) - [3100] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci (2).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1746] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci (3).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [3100] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci (4).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1746] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci (5).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [3100] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci (6).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1746] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci (7).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1746] - (0.0.0.0) - V:\clé de license zemana.txt - Raccourci.lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1043] - (0.0.0.0) - V:\Documents - Raccourci (10).lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1043] - (0.0.0.0) - V:\Documents - Raccourci (11).lnk [03/08/2016 12:51:47] - |A| - (.-.) - [999] - (0.0.0.0) - V:\Documents - Raccourci (2).lnk [08/08/2016 08:08:50] - |A| - (.-.) - [1039] - (0.0.0.0) - V:\Documents - Raccourci (3).lnk [08/08/2016 08:08:51] - |A| - (.-.) - [898] - (0.0.0.0) - V:\Documents - Raccourci (4).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1043] - (0.0.0.0) - V:\Documents - Raccourci (5).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [898] - (0.0.0.0) - V:\Documents - Raccourci (6).lnk [08/08/2016 20:06:35] - |A| - (.-.) - [898] - (0.0.0.0) - V:\Documents - Raccourci (7).lnk [09/08/2016 12:14:04] - |A| - (.-.) - [1043] - (0.0.0.0) - V:\Documents - Raccourci (8).lnk [09/08/2016 13:11:32] - |A| - (.-.) - [1043] - (0.0.0.0) - V:\Documents - Raccourci (9).lnk [03/08/2016 12:51:29] - |A| - (.-.) - [999] - (0.0.0.0) - V:\Documents - Raccourci.lnk [08/08/2016 08:09:21] - |A| - (.-.) - [3386] - (0.0.0.0) - V:\erreur installation.PNG - Raccourci.lnk [09/08/2016 13:11:32] - |A| - (.-.) - [1991] - (0.0.0.0) - V:\finalisation 100% sécurisé (& lfs ultra).zip - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1991] - (0.0.0.0) - V:\finalisation 100% sécurisé (& lfs ultra).zip - Raccourci (3).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1991] - (0.0.0.0) - V:\finalisation 100% sécurisé (& lfs ultra).zip - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1991] - (0.0.0.0) - V:\finalisation 100% sécurisé (& lfs ultra).zip - Raccourci.lnk [03/08/2016 12:51:45] - |A| - (.-.) - [1302] - (0.0.0.0) - V:\Fix it 12 proffessionnal utilities Clé De License.txt - Raccourci (2).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1302] - (0.0.0.0) - V:\Fix it 12 proffessionnal utilities Clé De License.txt - Raccourci.lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\freesoft9 giveaways.txt - Raccourci (2).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\freesoft9 giveaways.txt - Raccourci (3).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\freesoft9 giveaways.txt - Raccourci (4).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\freesoft9 giveaways.txt - Raccourci (5).lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\freesoft9 giveaways.txt - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1431] - (0.0.0.0) - V:\FRST.txt - Raccourci (2).lnk [08/08/2016 08:09:05] - |A| - (.-.) - [1431] - (0.0.0.0) - V:\FRST.txt - Raccourci.lnk [09/08/2016 13:11:33] - |A| - (.-.) - [3203] - (0.0.0.0) - V:\gfi mail essentials installation.pdf - Raccourci (2).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [3203] - (0.0.0.0) - V:\gfi mail essentials installation.pdf - Raccourci (3).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [3203] - (0.0.0.0) - V:\gfi mail essentials installation.pdf - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [3203] - (0.0.0.0) - V:\gfi mail essentials installation.pdf - Raccourci.lnk [03/08/2016 12:51:47] - |A| - (.-.) - [994] - (0.0.0.0) - V:\Images - Raccourci (2).lnk [09/08/2016 12:14:04] - |A| - (.-.) - [1038] - (0.0.0.0) - V:\Images - Raccourci (3).lnk [09/08/2016 13:11:32] - |A| - (.-.) - [1038] - (0.0.0.0) - V:\Images - Raccourci (4).lnk [09/08/2016 16:38:52] - |A| - (.-.) - [1038] - (0.0.0.0) - V:\Images - Raccourci (5).lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1038] - (0.0.0.0) - V:\Images - Raccourci (6).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [994] - (0.0.0.0) - V:\Images - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [3275] - (0.0.0.0) - V:\jeremih - break up to make up.mp3 - Raccourci (2).lnk [03/08/2016 12:51:31] - |A| - (.-.) - [3275] - (0.0.0.0) - V:\jeremih - break up to make up.mp3 - Raccourci.lnk [09/08/2016 12:14:05] - |A| - (.-.) - [2303] - (0.0.0.0) - V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé.zip - Raccourci (2).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [2303] - (0.0.0.0) - V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé.zip - Raccourci (3).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [2303] - (0.0.0.0) - V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé.zip - Raccourci (4).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [2303] - (0.0.0.0) - V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé.zip - Raccourci (5).lnk [08/08/2016 20:06:36] - |A| - (.-.) - [2150] - (0.0.0.0) - V:\logarythms - souvenirs 2005 & 2011 - lfs ultra & 100% sécurisé.zip - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1622] - (0.0.0.0) - V:\malwarebytes rapport 07_08_2016.txt - Raccourci (2).lnk [08/08/2016 20:06:37] - |A| - (.-.) - [1622] - (0.0.0.0) - V:\malwarebytes rapport 07_08_2016.txt - Raccourci (3).lnk [08/08/2016 08:09:03] - |A| - (.-.) - [1622] - (0.0.0.0) - V:\malwarebytes rapport 07_08_2016.txt - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [1673] - (0.0.0.0) - V:\marque-syrtos.jpg - Raccourci (2).lnk [03/08/2016 12:51:32] - |A| - (.-.) - [1673] - (0.0.0.0) - V:\marque-syrtos.jpg - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1496] - (0.0.0.0) - V:\mban rapports.txt - Raccourci (2).lnk [08/08/2016 08:09:17] - |A| - (.-.) - [1496] - (0.0.0.0) - V:\mban rapports.txt - Raccourci.lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\me10installation_fr.pdf - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\me10installation_fr.pdf - Raccourci (3).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\me10installation_fr.pdf - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\me10installation_fr.pdf - Raccourci.lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1287] - (0.0.0.0) - V:\newtyear - lime (citron vert) de 2005 & 2011 - Raccourci (2).lnk [08/08/2016 08:08:51] - |A| - (.-.) - [1287] - (0.0.0.0) - V:\newtyear - lime (citron vert) de 2005 & 2011 - Raccourci.lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1090] - (0.0.0.0) - V:\office 2016 keys.pdf - Raccourci (2).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1090] - (0.0.0.0) - V:\office 2016 keys.pdf - Raccourci (3).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1090] - (0.0.0.0) - V:\office 2016 keys.pdf - Raccourci (4).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1090] - (0.0.0.0) - V:\office 2016 keys.pdf - Raccourci (5).lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1090] - (0.0.0.0) - V:\office 2016 keys.pdf - Raccourci.lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\organization m-disc.txt - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\organization m-disc.txt - Raccourci (3).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\organization m-disc.txt - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1121] - (0.0.0.0) - V:\organization m-disc.txt - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [1195] - (0.0.0.0) - V:\PHOTO-ERREL.jpg - Raccourci (2).lnk [03/08/2016 12:51:31] - |A| - (.-.) - [1195] - (0.0.0.0) - V:\PHOTO-ERREL.jpg - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [2124] - (0.0.0.0) - V:\power2go 11 info.pdf - Raccourci (2).lnk [08/08/2016 20:06:37] - |A| - (.-.) - [2124] - (0.0.0.0) - V:\power2go 11 info.pdf - Raccourci (3).lnk [09/08/2016 12:14:06] - |A| - (.-.) - [2124] - (0.0.0.0) - V:\power2go 11 info.pdf - Raccourci (4).lnk [08/08/2016 08:09:01] - |A| - (.-.) - [2124] - (0.0.0.0) - V:\power2go 11 info.pdf - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [2034] - (0.0.0.0) - V:\power2go 11 présentation.txt - Raccourci (2).lnk [08/08/2016 20:06:37] - |A| - (.-.) - [2034] - (0.0.0.0) - V:\power2go 11 présentation.txt - Raccourci (3).lnk [08/08/2016 08:09:01] - |A| - (.-.) - [2034] - (0.0.0.0) - V:\power2go 11 présentation.txt - Raccourci.lnk [03/08/2016 12:51:45] - |A| - (.-.) - [1695] - (0.0.0.0) - V:\Pre_Scan_03_08_2016_00_26_48.txt - Raccourci (2).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1695] - (0.0.0.0) - V:\Pre_Scan_03_08_2016_00_26_48.txt - Raccourci.lnk [08/08/2016 08:09:21] - |A| - (.-.) - [1502] - (0.0.0.0) - V:\Problème Boot Kickstart Pour Forums.txt - Raccourci.lnk [08/08/2016 08:09:20] - |A| - (.-.) - [1319] - (0.0.0.0) - V:\problème gfi & hitman pro kickstart.pdf - Raccourci.lnk [08/08/2016 08:09:20] - |A| - (.-.) - [1265] - (0.0.0.0) - V:\problème gfi & hitman pro kickstart.txt - Raccourci.lnk [08/08/2016 08:09:21] - |A| - (.-.) - [1445] - (0.0.0.0) - V:\problème hitmanpro kickstart, firefox salix & gfi.txt - Raccourci.lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1618] - (0.0.0.0) - V:\problèmes gfi mail essentials et web monitor, hitman kickstart & premier o.txt - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1618] - (0.0.0.0) - V:\problèmes gfi mail essentials et web monitor, hitman kickstart & premier o.txt - Raccourci.lnk [03/08/2016 12:51:45] - |A| - (.-.) - [1696] - (0.0.0.0) - V:\QuickDiag_02_08_2016_20_31_53.txt - Raccourci (2).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1696] - (0.0.0.0) - V:\QuickDiag_02_08_2016_20_31_53.txt - Raccourci.lnk [08/08/2016 14:24:47] - |A| - (.-.) - [851] - (0.0.0.0) - V:\QuickScript.txt - Raccourci (2).lnk [08/08/2016 08:09:19] - |A| - (.-.) - [851] - (0.0.0.0) - V:\QuickScript.txt - Raccourci.lnk [08/08/2016 08:09:20] - |A| - (.-.) - [1204] - (0.0.0.0) - V:\quickscripts gfi & kickstart.txt - Raccourci.lnk [08/08/2016 14:24:47] - |A| - (.-.) - [1622] - (0.0.0.0) - V:\QuickScript_07_08_2016_16_22_14.txt - Raccourci (2).lnk [08/08/2016 08:09:18] - |A| - (.-.) - [1622] - (0.0.0.0) - V:\QuickScript_07_08_2016_16_22_14.txt - Raccourci.lnk [09/08/2016 13:11:32] - |A| - (.-.) - [1150] - (0.0.0.0) - V:\revo uninstaller pro portable - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1150] - (0.0.0.0) - V:\revo uninstaller pro portable - Raccourci (3).lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1150] - (0.0.0.0) - V:\revo uninstaller pro portable - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1150] - (0.0.0.0) - V:\revo uninstaller pro portable - Raccourci.lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\revouninproport316.zip - Raccourci (2).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\revouninproport316.zip - Raccourci (3).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\revouninproport316.zip - Raccourci (4).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\revouninproport316.zip - Raccourci (5).lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\revouninproport316.zip - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [1701] - (0.0.0.0) - V:\rsz_marque-syrtos.png - Raccourci (2).lnk [03/08/2016 12:51:31] - |A| - (.-.) - [1701] - (0.0.0.0) - V:\rsz_marque-syrtos.png - Raccourci.lnk [03/08/2016 12:51:47] - |A| - (.-.) - [1237] - (0.0.0.0) - V:\sauvetage clé usb hitman.pro kickstart - Raccourci (2).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1237] - (0.0.0.0) - V:\sauvetage clé usb hitman.pro kickstart - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1463] - (0.0.0.0) - V:\Shortcut.txt - Raccourci (2).lnk [08/08/2016 20:06:37] - |A| - (.-.) - [1463] - (0.0.0.0) - V:\Shortcut.txt - Raccourci (3).lnk [08/08/2016 08:09:04] - |A| - (.-.) - [1463] - (0.0.0.0) - V:\Shortcut.txt - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [3333] - (0.0.0.0) - V:\soutien pour ou for de la catherine ca'nar (ape).pdf - Raccourci (2).lnk [03/08/2016 12:51:31] - |A| - (.-.) - [3333] - (0.0.0.0) - V:\soutien pour ou for de la catherine ca'nar (ape).pdf - Raccourci.lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1487] - (0.0.0.0) - V:\test.zip - Raccourci (2).lnk [09/08/2016 12:14:06] - |A| - (.-.) - [1487] - (0.0.0.0) - V:\test.zip - Raccourci (3).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1487] - (0.0.0.0) - V:\test.zip - Raccourci (4).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1487] - (0.0.0.0) - V:\test.zip - Raccourci (5).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1487] - (0.0.0.0) - V:\test.zip - Raccourci (6).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1487] - (0.0.0.0) - V:\test.zip - Raccourci.lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1370] - (0.0.0.0) - V:\UsbFix [Clean 4] 100P100_S_FIN.txt - Raccourci (2).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1370] - (0.0.0.0) - V:\UsbFix [Clean 4] 100P100_S_FIN.txt - Raccourci (3).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1370] - (0.0.0.0) - V:\UsbFix [Clean 4] 100P100_S_FIN.txt - Raccourci (4).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1370] - (0.0.0.0) - V:\UsbFix [Clean 4] 100P100_S_FIN.txt - Raccourci (5).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1370] - (0.0.0.0) - V:\UsbFix [Clean 4] 100P100_S_FIN.txt - Raccourci (6).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1370] - (0.0.0.0) - V:\UsbFix [Clean 4] 100P100_S_FIN.txt - Raccourci.lnk [03/08/2016 12:51:46] - |A| - (.-.) - [1431] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (2).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (3).lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (5).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (6).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (7).lnk [10/08/2016 12:43:19] - |A| - (.-.) - [1584] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci (8).lnk [03/08/2016 12:51:31] - |A| - (.-.) - [1431] - (0.0.0.0) - V:\UsbFix_Report.txt - Raccourci.lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1464] - (0.0.0.0) - V:\UsbFix_Standard.zip - Raccourci (2).lnk [09/08/2016 12:14:06] - |A| - (.-.) - [1464] - (0.0.0.0) - V:\UsbFix_Standard.zip - Raccourci (3).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1464] - (0.0.0.0) - V:\UsbFix_Standard.zip - Raccourci (4).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1464] - (0.0.0.0) - V:\UsbFix_Standard.zip - Raccourci (5).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1464] - (0.0.0.0) - V:\UsbFix_Standard.zip - Raccourci.lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1099] - (0.0.0.0) - V:\Windows 10 Pro FR X64.iso - Raccourci.lnk [08/08/2016 20:06:36] - |A| - (.-.) - [1408] - (0.0.0.0) - V:\Wise JetSearch.zip - Raccourci (2).lnk [09/08/2016 12:14:06] - |A| - (.-.) - [1408] - (0.0.0.0) - V:\Wise JetSearch.zip - Raccourci (3).lnk [09/08/2016 13:11:33] - |A| - (.-.) - [1408] - (0.0.0.0) - V:\Wise JetSearch.zip - Raccourci (4).lnk [09/08/2016 16:38:54] - |A| - (.-.) - [1408] - (0.0.0.0) - V:\Wise JetSearch.zip - Raccourci (5).lnk [08/08/2016 14:24:45] - |A| - (.-.) - [1408] - (0.0.0.0) - V:\Wise JetSearch.zip - Raccourci.lnk [09/08/2016 13:11:32] - |A| - (.-.) - [1323] - (0.0.0.0) - V:\zemana antilogger pro beta free lifetime license - Raccourci (2).lnk [09/08/2016 16:38:53] - |A| - (.-.) - [1323] - (0.0.0.0) - V:\zemana antilogger pro beta free lifetime license - Raccourci (3).lnk [10/08/2016 12:43:18] - |A| - (.-.) - [1323] - (0.0.0.0) - V:\zemana antilogger pro beta free lifetime license - Raccourci (4).lnk [09/08/2016 12:14:05] - |A| - (.-.) - [1323] - (0.0.0.0) - V:\zemana antilogger pro beta free lifetime license - Raccourci.lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1477] - (0.0.0.0) - V:\ZHPCleaner.txt - Raccourci (2).lnk [08/08/2016 20:06:37] - |A| - (.-.) - [1477] - (0.0.0.0) - V:\ZHPCleaner.txt - Raccourci (3).lnk [08/08/2016 08:09:02] - |A| - (.-.) - [1477] - (0.0.0.0) - V:\ZHPCleaner.txt - Raccourci.lnk [03/08/2016 12:51:45] - |A| - (.-.) - [1450] - (0.0.0.0) - V:\ZHPDiag.txt - Raccourci (2).lnk [08/08/2016 08:09:14] - |A| - (.-.) - [1450] - (0.0.0.0) - V:\ZHPDiag.txt - Raccourci (3).lnk [08/08/2016 14:24:46] - |A| - (.-.) - [1450] - (0.0.0.0) - V:\ZHPDiag.txt - Raccourci (4).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1450] - (0.0.0.0) - V:\ZHPDiag.txt - Raccourci.lnk [03/08/2016 12:51:45] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\ZHPFixReport.txt - Raccourci (2).lnk [03/08/2016 12:51:30] - |A| - (.-.) - [1491] - (0.0.0.0) - V:\ZHPFixReport.txt - Raccourci.lnk [21/02/2016 19:04:14] - |A| - (.Copyright © 1999-2012 - BASS.) - [105528] - (2.4.9.0) - V:\bass.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2005-2012 by radio42: Bernd Niedergesaess, Germany. http://www.bass.radio42.com/ - bn@radio42.com - BASS.NET API for .Net.) - [638976] - (2.4.9.1) - V:\Bass.Net.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2003-2009 - BASSCD.) - [17472] - (2.4.2.0) - V:\basscd.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2004-2009 - BASSFLAC.) - [24640] - (2.4.0.3) - V:\bassflac.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2005-2009 - BASSmix.) - [16448] - (2.4.2.0) - V:\bassmix.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2012 - BASSOPUS.) - [53816] - (2.4.0.0) - V:\bassopus.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2002-2010 - BASSWMA.) - [17472] - (2.4.4.0) - V:\basswma.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2007-2009 - BASSWV.) - [28224] - (2.4.1.3) - V:\basswv.dll [21/02/2016 19:04:14] - |A| - (.2003-2006, MaresWEB - Apple Lossless Audio Codec add-on for the BASS library.) - [9416] - (2.4.3.0) - V:\bass_alac.dll [21/02/2016 19:04:14] - |A| - (.2003-2006, MaresWEB - Monkey's Audio add-on for the BASS library.) - [33624] - (2.4.0.4) - V:\bass_ape.dll [21/02/2016 19:04:14] - |A| - (.2003-2006, MaresWEB - Musepack add-on for the BASS library.) - [21320] - (2.4.1.0) - V:\bass_mpc.dll [15/03/2016 19:18:10] - |A| - (.Copyright © 2002-2008 Canneverbe Limited - CDBXPExt.) - [69120] - (4.5.6.6059) - V:\CDBXP.dll [21/02/2016 19:04:14] - |A| - (.-.) - [337408] - (13.0.0.0) - V:\LogicNP.FolderView.dll [21/02/2016 19:04:14] - |A| - (.Copyright (c) Rocket Division Software, StarBurn Software 2001-2015. - StarBurn CD/DVD/Blu-Ray/HD-DVD Burning, Grabbing and Mastering Toolkit for Windows 95/98/Me/NT/2000/XP/2003/Vista/Longhorn/7/8/2010.) - [3235200] - (15.5.1.4144) - V:\StarBurn.dll [11/07/2016 08:44:19] - |A| - (.Copyright (C) 2011 Flexera Software, Inc. and/or InstallShield Co. Inc. - InstallScript Setup Launcher.) - [371303208] - (18.0.0.329) - V:\10295_Video-facile-1.exe [11/07/2016 08:43:51] - |A| - (.Copyright (C) 2011 Flexera Software, Inc. and/or InstallShield Co. Inc. - InstallScript Setup Launcher.) - [371303208] - (18.0.0.329) - V:\10295_Video-facile.exe [04/09/2015 17:47:32] - |A| - (.-.) - [220130080] - (0.0.0.0) - V:\1_CyberLink_Power2Go10_Platinum_Upgrade_P2G150522-04.exe [18/10/2015 18:58:26] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - 7-Zip Portable.) - [2362400] - (9.20.0.3) - V:\7-ZipPortable_9.20_Rev_3.paf.exe [11/07/2016 08:44:52] - |A| - (.-.) - [318714912] - (0.0.0.0) - V:\ABBYY_BCR20Win_ESD.exe [14/06/2016 07:35:24] - |A| - (.-.) - [368371848] - (0.0.0.0) - V:\ABBYY_FR12_PRO_TRIAL.exe [09/07/2016 23:53:01] - |A| - (.-.) - [252432728] - (0.0.0.0) - V:\ABBYY_ScreenshotReader_11_ESD.exe [14/06/2016 07:27:21] - |A| - (.-.) - [71143096] - (0.0.0.0) - V:\ABBYY_Screenshot_Reader_ESD.exe [16/07/2016 06:47:43] - |A| - (.© 2016 Acelogix Software - System maintenance and Optimizer utility.) - [9138432] - (6.2.0.289) - V:\aceutils.exe [21/08/2016 09:40:38] - |A| - (.-.) - [5466520] - (19.0.0.6571) - V:\AcronisTrueImage2016_web.exe [11/07/2016 08:45:17] - |A| - (.c Lavasoft Limited. - Web Companion Installer.) - [340568] - (2.3.1411.2698) - V:\Ad-Aware Web Companion Pro 2.3.1411.2698.exe [14/08/2016 16:43:40] - |A| - (. - Adblock Plus IE Setup .) - [6162288] - (0.0.0.0) - V:\adblockplusie-1.4.exe [14/07/2016 11:17:41] - |A| - (.-.) - [42799000] - (0.0.0.0) - V:\any-audio-converter(1).exe [06/07/2016 18:35:50] - |A| - (.-.) - [42799000] - (0.0.0.0) - V:\any-audio-converter.exe [15/07/2016 13:48:43] - |A| - (.Copyright (c) Apowersoft Ltd. 2016 All rights reserved - Apowersoft Online Launcher Setup .) - [1223336] - (1.4.4.0) - V:\apowersoft-online-launcher (1).exe [15/07/2016 13:47:19] - |A| - (.Copyright (c) Apowersoft Ltd. 2016 All rights reserved - Apowersoft Online Launcher Setup .) - [1223336] - (1.4.4.0) - V:\apowersoft-online-launcher.exe [11/07/2016 08:45:18] - |A| - (.-.) - [1006637056] - (0.0.0.0) - V:\appstore lfs ultra, power2go 11, & efm du musée de l'homme.exe [10/07/2016 19:04:24] - |A| - (. - Ashampoo Backup 2016 Setup .) - [2608520] - (1.0.0.0) - V:\ashampoo_backup_2016_dl.exe [10/07/2016 19:04:25] - |A| - (. - Ashampoo Backup Pro 10 Setup .) - [2610664] - (1.0.0.0) - V:\ashampoo_backup_pro_10_dl.exe [11/07/2016 08:48:01] - |A| - (. - Ashampoo Burning Studio 16 Setup .) - [92298344] - (16.0.6.0) - V:\ashampoo_burning_studio_16_e16.0.6_sm.exe [11/07/2016 08:48:11] - |A| - (. - Ashampoo Core Tuner 2 Setup .) - [2493632] - (1.0.0.0) - V:\ashampoo_core_tuner_2_dl.exe [11/07/2016 08:48:12] - |A| - (. - Ashampoo Cover Studio 2 Setup .) - [40270904] - (2.2.0.0) - V:\ashampoo_cover_studio_2_2.2.0_sm.exe [21/08/2016 13:39:11] - |A| - (. - Ashampoo HDD Control 2017 Setup .) - [13677680] - (3.10.1.0) - V:\ashampoo_hdd_control_2017_24209.exe [14/07/2016 04:03:31] - |A| - (. - Ashampoo Media Sync Setup .) - [12641832] - (1.0.2.0) - V:\ashampoo_media_sync_e1.0.2_sm.exe [09/07/2016 23:58:12] - |A| - (. - Ashampoo Music Studio 4 Setup .) - [43875848] - (4.1.2.0) - V:\ashampoo_music_studio_4_4.1.2_16904.exe [11/07/2016 08:48:16] - |A| - (. - Ashampoo Music Studio 5 Setup .) - [50101560] - (5.0.7.0) - V:\ashampoo_music_studio_5_e5.0.7_sm.exe [11/07/2016 08:48:22] - |A| - (. - Ashampoo Music Studio 6 Setup .) - [45366192] - (6.0.2.0) - V:\ashampoo_music_studio_6_e6.0.2_sm.exe [10/07/2016 19:04:58] - |A| - (. - Ashampoo Photo Commander Free Setup .) - [163570320] - (11.2.0.0) - V:\ashampoo_photo_commander_free_21556.exe [09/07/2016 23:58:35] - |A| - (. - Ashampoo Photo Recovery Setup .) - [8033992] - (1.0.3.0) - V:\ashampoo_photo_recovery_e1.0.3_sm.exe [04/08/2016 10:45:39] - |A| - (. - Ashampoo Slideshow Studio HD 4 Setup .) - [2614656] - (1.0.0.0) - V:\ashampoo_slideshow_studio_hd_4_dl.exe [12/07/2016 11:11:22] - |A| - (. - Ashampoo Slideshow Studio HD 4 Setup .) - [53664272] - (4.0.0.0) - V:\ashampoo_slideshow_studio_hd_4_e4.0.0_sm.exe [10/07/2016 19:05:42] - |A| - (. - Ashampoo Snap 2017 Setup .) - [52382680] - (1.0.1.0) - V:\ashampoo_snap_2017_23494.exe [14/07/2016 14:52:15] - |A| - (. - Ashampoo Snap 9 Setup .) - [56773968] - (9.0.1.0) - V:\ashampoo_snap_9_e9.0.1_sm.exe [04/08/2016 16:33:23] - |A| - (. - Ashampoo Snap Business Setup .) - [52186504] - (9.0.1.0) - V:\ashampoo_snap_business_9.0.1_demo_sm.exe [11/07/2016 08:48:27] - |A| - (. - Ashampoo Undeleter Setup .) - [2493176] - (1.0.0.0) - V:\ashampoo_undeleter_dl.exe [10/07/2016 07:45:11] - |A| - (. - Ashampoo UnInstaller 5 Setup .) - [21088224] - (5.4.0.0) - V:\ashampoo_uninstaller_5_e5.0.4_sm.exe [10/07/2016 19:05:58] - |A| - (. - Ashampoo UnInstaller 5 Setup .) - [22345192] - (5.6.0.0) - V:\ashampoo_uninstaller_5_e5.0.6_sm.exe [17/07/2016 17:17:52] - |A| - (. - Ashampoo UnInstaller 6 Setup .) - [18412280] - (6.0.14.0) - V:\ashampoo_uninstaller_6_e6.00.14_sm.exe [10/07/2016 07:45:14] - |A| - (. - Ashampoo Video Styler Setup .) - [27869488] - (1.0.1.0) - V:\ashampoo_video_styler_e1.0.1_sm.exe [11/07/2016 08:48:30] - |A| - (. - Ashampoo WinOptimizer 14 Setup .) - [28220040] - (14.0.0.0) - V:\ashampoo_winoptimizer_14_e14.00.00_sm.exe [11/07/2016 08:48:33] - |A| - (.Copyright (C) 2004-2012 - Astroburn Audio Setup.) - [6086824] - (1.6.0.47) - V:\AstroburnAudio160-0047.exe [18/10/2015 18:31:30] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - Audacity Portable.) - [6521072] - (2.1.1.0) - V:\AudacityPortable_2.1.1.paf.exe [08/07/2016 07:22:41] - |A| - (.-.) - [4999096] - (0.0.0.0) - V:\ausetup.exe [09/07/2016 05:48:53] - |A| - (.2007-2015@Auslogics Software Pty Ltd - Auslogics BitReplica Installation File .) - [6628472] - (2.1.1.0) - V:\auslogics-bitreplica-setup.exe [12/08/2016 10:50:04] - |A| - (.Copyright (C) 1990-2002 InstallShield Software Corporation - PackageForTheWeb Stub .) - [15075952] - (4.1.100.1332) - V:\AutoSaveEssentialsFR (1).exe [05/08/2016 13:04:47] - |A| - (.Copyright (C) 1990-2002 InstallShield Software Corporation - PackageForTheWeb Stub .) - [15075952] - (4.1.100.1332) - V:\AutoSaveEssentialsFR.exe [05/07/2016 10:02:25] - |A| - (.Copyright (c) 2012 AVAST Software - Avast! Browser Cleanup Sfx.) - [4284888] - (12.1.2272.125) - V:\avast-browser-cleanup-sfx.exe [10/07/2016 19:07:11] - |A| - (.Copyright 2003 Avery - Création d'étiquettes et de pochettes .) - [7744030] - (4.1.100.1332) - V:\AveryDesignPro_FR.exe [10/07/2016 19:07:13] - |A| - (.Copyright © 2015 Avira Operations GmbH & Co. KG and its Licensors - Avira Launcher.) - [4630840] - (1.1.63.21885) - V:\avira_fr_av_57559d7b12d97__wsd.exe [10/06/2016 11:13:32] - |A| - (.-.) - [13915352] - (0.0.0.0) - V:\BDAntiCryptoWall_Release.exe [11/07/2016 08:49:00] - |A| - (.Copyright © 1997-2015 Bitdefender - BDAntiRansomware Setup .) - [4677896] - (0.0.0.0) - V:\BDAntiRansomwareSetup.exe [05/07/2016 06:10:33] - |A| - (.© Microsoft Corporation. - Win32 Cabinet Self-Extractor .) - [10513112] - (6.0.2800.1168) - V:\BingDesktopSetup.exe [11/07/2016 08:49:03] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - V:\BitTorrent (1).exe [10/07/2016 00:00:15] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - V:\BitTorrent (2).exe [10/07/2016 00:00:16] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - V:\BitTorrent (3).exe [11/07/2016 08:49:04] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - V:\BitTorrent(btkey,https^3A^2F^2Futp.st^2FAq2NsdKU).exe [11/07/2016 08:49:04] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - V:\BitTorrent(btkey,https^3A^2F^2Futp.st^2FjSAg97W0).exe [10/07/2016 19:07:22] - |A| - (.Copyright (c) BlueStack Systems Inc. - BlueStacks Thin Installer.) - [319729248] - (0.0.0.0) - V:\BlueStacks2_native_mobile-retention.exe [14/06/2016 07:47:58] - |A| - (.PortableApps.com Installer Copyright 2007-2010 PortableApps.com. - CamStudio Portable.) - [1433632] - (2.0.0.1) - V:\CamStudioPortable_2.0_English.paf.exe [18/10/2015 18:59:38] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - CamStudio Portable.) - [13800280] - (2.7.2.0) - V:\CamStudioPortable_2.7.2_English.paf.exe [11/07/2016 08:50:13] - |A| - (.-.) - [252605800] - (8.1.2.1327) - V:\camtasia_864c253ee677b4609b331d451009a871.exe [10/07/2016 19:08:48] - |A| - (.Copyright (C) Piriform 2013-2015 - CCleaner Cloud Installer.) - [6259936] - (1.4.0.1817) - V:\CCleanerCloudSetup_1_4_1817.exe [10/07/2016 19:08:46] - |A| - (.Copyright © 2005-2016 Piriform Ltd - CCleaner Installer.) - [6868672] - (2.0.0.0) - V:\ccleaner_5-16_fr_14492.exe [13/06/2016 14:08:59] - |A| - (.Copyright © 2005-2016 Piriform Ltd - CCleaner Installer.) - [6868672] - (2.0.0.0) - V:\ccsetup_516.exe [11/07/2016 08:50:47] - |A| - (.Copyright © 2005-2016 Piriform Ltd - CCleaner Installer.) - [7033368] - (2.0.0.0) - V:\ccsetup_517.exe [15/03/2016 19:20:06] - |A| - (.Copyright © 2002-2008 Canneverbe Limited - CDBurnerXP command line version.) - [25712] - (4.5.6.6059) - V:\cdbxpcmd.exe [15/03/2016 19:20:06] - |A| - (.Copyright © 2002-2008 Canneverbe Limited - CDBurnerXP.) - [1746032] - (4.5.6.6059) - V:\cdbxpp.exe [10/07/2016 12:08:39] - |A| - (.2001-2014 Canneverbe Limited - CDBurnerXP .) - [6230152] - (4.5.7.6140) - V:\cdbxp_setup_4.5.7.6139.exe [14/08/2016 16:43:44] - |A| - (.Copyright 2007-2010 Google Inc. - Google Update Setup.) - [880208] - (1.3.26.9) - V:\ChromeSetup.exe [11/07/2016 08:50:54] - |A| - (.Copyright (C) 2009-2015, Ivo Beltchev - Adds classic shell features to Windows 7 and Windows 8.) - [6968048] - (4.2.5.0) - V:\ClassicShellSetup_4_2_5.exe [10/06/2016 12:33:10] - |A| - (.-.) - [497903] - (0.0.0.0) - V:\CLCleaner2-PhotoDirector_5.exe [10/07/2016 00:03:34] - |A| - (.Copyright (c) 2009-2015, Comodo Security Solutions, Inc. - Comodo Dragon.) - [55056152] - (45.8.12.389) - V:\Comodo Dragon 45.8.12.389 + Portable.exe [10/07/2016 00:04:08] - |A| - (.2005-2014 COMODO. - COMODO Internet Security.) - [230403208] - (7.0.55655.4142) - V:\Comodo Firewall 7.0.317799.4142.exe [11/07/2016 08:52:47] - |A| - (.2005-2015 COMODO. - COMODO Internet Security.) - [217812544] - (8.2.0.4792) - V:\Comodo Internet Security Premium 8.2.0.4792 Final.exe [10/07/2016 19:10:42] - |A| - (.8pecxstudios 2012-2016 - Cyberfox Web Browser Fibre optics of the web .) - [50060432] - (45.0.2.0) - V:\Cyberfox-45.0.2.en-US.win64-x86_64.intel.exe [10/07/2016 00:07:23] - |A| - (.-.) - [1887724608] - (0.0.0.0) - V:\CyberLinkDirectorSuite2.0_DRS131210-01_TR131226-021.part1.exe [10/07/2016 19:10:55] - |A| - (.-.) - [1048863800] - (0.0.0.0) - V:\CyberLinkMediaSuite12.0_Ultimate_MES140428-01_TR140718-022.part1.exe [10/07/2016 19:10:55] - |A| - (.-.) - [1048863800] - (0.0.0.0) - V:\cyberlinkmediasuite12.0_ultimate_mes140428-01_tr140718-022.part1.exe [11/07/2016 12:50:06] - |A| - (.-.) - [1993434200] - (0.0.0.0) - V:\CyberLinkMediaSuite14.0_Trial_MES160530-01_TR160628-024.exe [16/07/2016 12:28:02] - |A| - (.-.) - [1048870784] - (0.0.0.0) - V:\CyberLinkMediaSuite14.0_Ultimate_MES160511-03_TR160627-004.part1.exe [16/07/2016 13:46:34] - |A| - (.-.) - [111981936] - (0.0.0.0) - V:\CyberLink_CreativeDesignPack_TravelPack4_CDP160425-01.exe [10/07/2016 19:10:54] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_Director_Suite_Downloader.exe [15/08/2016 08:15:55] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1089304] - (2.9.1.7801) - V:\CyberLink_MakeupDirector_Downloader.exe [13/05/2016 06:34:57] - |A| - (.-.) - [97557896] - (0.0.0.0) - V:\CyberLink_MediaEspresso7.5_MEX160302-01.exe [10/07/2016 19:10:54] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_MediaEspresso_Downloader.exe [11/07/2016 12:49:02] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1089304] - (2.9.1.7801) - V:\CyberLink_Media_Suite_Downloader.exe [11/07/2016 08:55:24] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_PhotoDirector_Downloader.exe [11/07/2016 08:55:25] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_PhotoDirector_Downloader_1.exe [13/04/2016 06:57:46] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1064376] - (2.9.1.7325) - V:\CyberLink_Power2Go_Downloader.exe [14/06/2016 07:48:31] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_PowerDirector_Downloader.exe [11/07/2016 08:55:25] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_PowerDirector_Ultimate_Suite_Downloader.exe [11/07/2016 08:55:25] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_PowerDirector_Ultimate_Suite_Downloader_1.exe [14/06/2016 07:33:45] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1031608] - (2.9.1.6109) - V:\CyberLink_PowerDVD_Downloader.exe [14/06/2016 07:48:33] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [967200] - (2.9.1.3520) - V:\CyberLink_PowerProducer_Downloader.exe [15/08/2016 08:06:39] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1040152] - (2.9.1.6109) - V:\CyberLink_PresenterLinkPlus_Downloader.exe [16/07/2016 12:29:00] - |A| - (.-.) - [78368488] - (0.0.0.0) - V:\CyberLink_TravelPack3_YouCam_CDP150508-01.exe [15/08/2016 07:58:37] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1040152] - (2.9.1.6109) - V:\CyberLink_VideoMeetingPlus_Downloader.exe [16/07/2016 12:29:13] - |A| - (.-.) - [411978176] - (0.0.0.0) - V:\CyberLink_YouCam7_Deluxe_YUC150721-01.exe [11/07/2016 08:55:26] - |A| - (.Copyright (C) 2000-2015 - DAEMON Tools Lite Setup.) - [19062208] - (10.1.0.74) - V:\DAEMON Tools Lite 10.1.0.74.exe [10/07/2016 19:32:06] - |A| - (.Copyright © BVRP Software 2004 - .) - [60183082] - (4.1.100.1332) - V:\DigitalVideoDuplicator3_FR(1).exe [14/06/2016 07:26:45] - |A| - (. - .) - [61197060] - (4.1.100.1332) - V:\DigitalVideoDuplicator3_FR.exe [18/08/2016 09:56:35] - |A| - (.2016 DivX, LLC. - DivX Setup.) - [2424264] - (3.0.0.83) - V:\DivXInstaller.exe [15/07/2016 11:47:10] - |A| - (.Copyright (c) 2006-2012 CHENGDU YIWO Tech Development Co., Ltd (YIWO Tech Ltd, for short). - EaseUS Disk Copy Home Edition 2.3.) - [45470992] - (1.1.0.1) - V:\EaseUS_DiskCopy_Home.exe [30/07/2016 13:23:08] - |A| - (.-.) - [440998489] - (1.1.3.70) - V:\emsisoft on barrow ushuaia.exe [11/07/2016 09:03:40] - |A| - (.Copyright 2003-2015 Emsisoft Ltd. - Emsisoft Anti-Malware Setup .) - [237135456] - (11.7.0.6394) - V:\EmsisoftAntiMalwareSetup.exe [11/07/2016 09:04:18] - |A| - (.-.) - [232114840] - (0.0.0.0) - V:\EmsisoftEmergencyKit (1).exe [19/07/2016 09:36:47] - |A| - (.-.) - [243326440] - (0.0.0.0) - V:\EmsisoftEmergencyKit(1).exe [19/07/2016 13:32:45] - |A| - (.-.) - [243326440] - (0.0.0.0) - V:\EmsisoftEmergencyKit(2).exe [14/07/2016 07:34:44] - |A| - (.-.) - [245670120] - (0.0.0.0) - V:\EmsisoftEmergencyKit.exe [11/07/2016 09:04:37] - |A| - (.Copyright 2003-2015 Emsisoft Ltd. - Emsisoft Internet Security Setup .) - [226980568] - (11.5.1.6247) - V:\EmsisoftInternetSecuritySetup.exe [14/06/2016 07:59:26] - |A| - (.Serif WebPlus Starter Edition 4.0.2 © 2014 Serif (Europe) Ltd. Tous droits réservés. - Serif WebPlus Starter Edition Install.) - [175768400] - (1.0.0.0) - V:\ESDPK-WLX7-WebPlusStarterEdition-fr-FR.exe [11/07/2016 09:06:33] - |A| - (.Serif WebPlus Starter Edition 4.0.2 © 2014 Serif (Europe) Ltd. Tous droits réservés. - Serif WebPlus Starter Edition Install.) - [175768400] - (1.0.0.0) - V:\ESDPK-WLX7-WebPlusStarterEdition-fr-FR_1.exe [10/07/2016 19:38:19] - |A| - (.Copyright (c) ESET 1992-2011. - ESET Smart Installer.) - [2870984] - (1.0.0.6421) - V:\esetsmartinstaller_enu.exe [11/07/2016 09:06:53] - |A| - (.© 2006 Microsoft Corporation. -.) - [53610536] - (12.0.6320.5000) - V:\ExcelViewer.exe [11/07/2016 09:07:05] - |A| - (.© 2013-2016 F-Secure Corporation. - F-Secure Download Tool.) - [524248] - (1.0.265.0) - V:\F-SecureOnlineScanner.exe [10/06/2016 12:23:44] - |A| - (.-.) - [167034] - (0.0.0.0) - V:\fileassassin-setup-1.06.exe [18/10/2015 18:29:02] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - Mozilla Firefox Developer Edition, Portable.) - [963240] - (42.999.0.0) - V:\FirefoxPortableDeveloper_43.0_Alpha_2_English_online.paf.exe [14/06/2016 08:08:08] - |A| - (.PortableApps.com Installer Copyright 2007-2011 PortableApps.com. - Mozilla Firefox, Portable Edition (Legacy 3.6).) - [9178672] - (3.6.25.0) - V:\FirefoxPortableLegacy36_3.6.25_English.paf.exe [18/10/2015 18:27:38] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - Mozilla Firefox, Portable Edition.) - [45416176] - (41.0.2.0) - V:\FirefoxPortable_41.0.2_English.paf.exe [04/08/2016 14:21:04] - |A| - (.Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. - InstallScript Setup Launcher.) - [73332576] - (15.0.32.28) - V:\Fix-It_Professional_ENU_15.0.32.28.exe [04/08/2016 14:21:20] - |A| - (.Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. - InstallScript Setup Launcher.) - [60823296] - (15.6.32.12) - V:\Fix-It_Professional_ENU_signed.exe [25/07/2016 09:25:28] - |A| - (.MindGems, Inc. - Folder Size .) - [2301330] - (3.4.0.0) - V:\FolderSize.exe [19/07/2016 13:57:07] - |A| - (.MindGems, Inc. - Folder Size .) - [2301330] - (3.4.0.0) - V:\foldersize_2-6_en_18550.exe [18/10/2015 18:40:30] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - Foxit Reader Portable.) - [27571097] - (7.2.2.929) - V:\FoxitReaderPortable_7.2.2.929.paf.exe [22/08/2013 15:57:30] - |A| - (.-.) - [472466] - (0.8.0.2) - V:\Framakey.exe [26/07/2016 14:06:39] - |A| - (.2005-2015 © par l'équipe Framakey - Framakey Installer.) - [486775300] - (2.2.0.2) - V:\FramakeyInstaller_2.2.0.2-LaTeX-fr.exe [10/07/2016 02:11:31] - |A| - (.2005-2007© by Framakey Team - Framakey Installer pour Windows XP et suivants.) - [515917547] - (1.13.0.8) - V:\FramakeyInstaller_Full-1.13.0.8.exe [11/07/2016 09:07:01] - |A| - (.Copyright © 2016 iSkysoft. - iSkysoft Free Video Downloader Setup .) - [33832392] - (4.9.1.0) - V:\free-video-downloader_full1683.exe [05/07/2016 08:16:43] - |A| - (. - Free Studio Setup .) - [2267896] - (1.0.1.0) - V:\FreeStudio_6.6.24.627_d.exe [05/07/2016 14:13:23] - |A| - (. - Free Video to MP3 Converter Setup .) - [2267840] - (1.0.1.0) - V:\FreeVideoToMP3Converter_5.0.96.627_o.exe [08/08/2016 10:06:02] - |A| - (.©1999-2015 Jonathan Bennett & AutoIt Team - Farbar Recovery Scan Tool.) - [2393600] - (3.8.2016.0) - V:\FRST64.exe [26/01/2016 18:30:26] - |A| - (.© Microsoft Corporation. - GWX WEB WINDOWS.) - [7635472] - (6.3.9600.18124) - V:\GetWindows10-Web_Default_Attr(1).exe [26/01/2016 18:30:27] - |A| - (.© Microsoft Corporation. - GWX WEB WINDOWS.) - [7635472] - (6.3.9600.18124) - V:\GetWindows10-Web_Default_Attr.exe [10/06/2016 11:27:21] - |A| - (.-.) - [14892728] - (0.0.0.0) - V:\Glary_Utilities_Pro_v5.17.0.30.exe [18/10/2015 18:25:30] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - Google Chrome Portable.) - [1411824] - (46.0.2490.71) - V:\GoogleChromePortable_46.0.2490.71_online.paf.exe [11/07/2016 09:07:09] - |A| - (.Copyright Reason Company Software Inc. - herdProtect Anti-Malware Scanner.) - [2873112] - (1.0.3.9) - V:\herdProtectScan_Setup.exe [02/08/2016 13:10:48] - |A| - (.© 2006-2016 SurfRight, a Sophos company - HitmanPro 3.7.) - [10451640] - (3.7.14.265) - V:\HitmanPro.exe [11/07/2016 09:07:11] - |A| - (.© 2006-2016 SurfRight, a Sophos company - HitmanPro 3.7.) - [11441168] - (3.7.14.263) - V:\HitmanPro_x64(1).exe [02/08/2016 13:10:49] - |A| - (.© 2006-2016 SurfRight, a Sophos company - HitmanPro 3.7.) - [11438608] - (3.7.14.265) - V:\HitmanPro_x64.exe [10/07/2016 17:02:53] - |A| - (.Copyright(c) 2005-2012 - IObit Uninstaller.) - [1688408] - (2.2.0.127) - V:\iobit-uninstaller.exe [19/08/2016 06:36:21] - |A| - (.Copyright© 2005-2016 - IObit Uninstaller.) - [13138208] - (6.0.2.143) - V:\iobituninstaller.exe [18/10/2015 19:01:36] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - IObit Uninstaller Portable.) - [6576115] - (5.0.3.171) - V:\IObitUninstallerPortable_5.0.3.171.paf.exe [18/10/2015 19:03:06] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - IObit Unlocker Portable.) - [1466422] - (1.1.0.0) - V:\IObitUnlockerPortable_1.1.paf.exe [18/10/2015 18:50:08] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.19.0 - Kaspersky TDSSKiller Portable.) - [331920] - (3.1.0.5) - V:\KasperskyTDSSKillerPortable_3.1.0.5_English_online.paf.exe [10/07/2016 19:39:30] - |A| - (.Copyright © 1998-2015 KC Softwares - KC Softwares KCleaner Setup .) - [1414720] - (0.0.0.0) - V:\kcleaner.exe [10/07/2016 02:20:28] - |A| - (.Copyright Lavasoft. - Lavasoft Digital Lock .) - [6089248] - (7.7.0.2) - V:\LavasoftDigitalLock_30days.exe [10/07/2016 02:20:30] - |A| - (.Lavasoft © 2001-2007 - Lavasoft Encrypted File (SFX).) - [126312] - (7.7.0.8) - V:\LavasoftEncryptionReader.exe [10/07/2016 02:20:30] - |A| - (.Copyright Lavasoft. - Lavasoft File Shredder .) - [5263480] - (7.7.0.2) - V:\LavasoftFileShredder_30days.exe [10/07/2016 02:20:31] - |A| - (.Copyright Lavasoft. - Lavasoft Privacy Toolbox .) - [6443280] - (7.7.0.2) - V:\LavasoftPrivacyToolbox_30days.exe [11/07/2016 09:23:55] - |A| - (.2007-2016 PortableApps.com, PortableApps.com Installer 3.2.0.0 - LibreOffice Portable.) - [174042352] - (5.1.3.0) - V:\LibreOfficePortable_5.1.3_MultilingualAll.paf.exe [10/07/2016 19:39:50] - |A| - (.Copyright (C) 2007 Macrovision Corporation - Setup Launcher .) - [11309264] - (14.0.0.166) - V:\LightScribeTemplateLabeler_1.18.15.1.exe [07/08/2016 09:33:06] - |A| - (.GPL, Lime Wire LLC - The Fastest File Sharing Program on Earth.) - [21930163] - (5.6.2.0) - V:\limewire-pirate-edition_1_64494.exe [04/08/2016 07:19:30] - |A| - (.-.) - [141627462] - (1.1.3.70) - V:\luminaires, logo tom & scénario 100% sécurisé finalis à bricocash.exe [15/07/2016 14:11:16] - |A| - (.(c) Malwarebytes. - Malwarebytes Anti-Malware .) - [22851472] - (2.2.1.1043) - V:\mbam-setup-cnet.35891-2.2.1.1043.exe [10/07/2016 17:04:21] - |A| - (.Copyright © Malwarebytes Corporation - Malwarebytes Anti-Rootkit.) - [16563352] - (1.9.3.1001) - V:\mbar-1.09.3.1001.exe [10/07/2016 19:40:12] - |A| - (.© MOVAVI. - Movavi Video Suite 11.) - [100766168] - (11.2.0.0) - V:\MovaviVideoSuiteSetup.exe [10/07/2016 19:40:59] - |A| - (.© Movavi. - Video Suite.) - [140213832] - (15.3.0.0) - V:\MovaviVideoSuiteSetupF(1).exe [10/07/2016 19:41:26] - |A| - (.© Movavi. - Video Suite.) - [140213832] - (15.3.0.0) - V:\MovaviVideoSuiteSetupF(2).exe [10/07/2016 19:40:31] - |A| - (.© Movavi. - Video Suite.) - [153857904] - (15.2.0.0) - V:\movavivideosuitesetupf.exe [10/07/2016 02:27:17] - |A| - (.Copyright 2011 Nero AG and its licensors - Nero Self Extractor.) - [262941032] - (12.0.3.0) - V:\Nero2015-16.0.05500_trial.exe [10/07/2016 19:41:54] - |A| - (.(c) 2015 Nero AG and its affiliates - NeroInstaller.) - [2559496] - (1.6.0.0) - V:\Nero2016-17.09.2015_stub_trial.exe [11/07/2016 09:24:27] - |A| - (.(c) 2015 Nero AG and its affiliates - NeroInstaller.) - [2563536] - (1.7.0.8) - V:\Nero_CoverDesigner_3p.exe [31/07/2016 11:40:16] - |A| - (.(c) 2015 Nero AG and its affiliates - NeroInstaller.) - [2563536] - (1.7.0.8) - V:\Nero_SoundTrax.exe [10/07/2016 19:41:55] - |A| - (.Copyright (C) 2009 Secure By Design Inc - Ninite.) - [307200] - (0.1.1.986) - V:\Ninite AdAware Classic Start Dropbox Essentials Installer.exe [20/07/2016 09:03:17] - |A| - (.Copyright (C) 2009 Secure By Design Inc - Ninite.) - [307200] - (0.1.1.986) - V:\Ninite Classic Start Installer.exe [04/07/2016 18:45:35] - |A| - (.(c) 2009 Nitro PDF Software - Installation and setup files for Nitro PDF Reader (fr-FR).) - [56666816] - (2.1.1009.0) - V:\nitro_reader5_64.exe [27/07/2016 13:38:00] - |A| - (.Copyright (C) 2016 Neuxpower Solutions Ltd - NXPowerLite™ - Optimize Microsoft Office, PDF, JPEG and ZIP files.) - [24532464] - (7.0.6.0) - V:\NXPowerLiteSetup70_6.exe [25/07/2016 09:25:29] - |A| - (.© Microsoft Corporation. - Microsoft OneDrive Setup.) - [9040072] - (17.3.6390.509) - V:\OneDriveSetup.exe [14/06/2016 07:43:08] - |A| - (. - Online Video Recorder Setup .) - [16879392] - (3.4.4.1) - V:\OnlineVideoRecorder_3_4_4_AQFR.exe [11/07/2016 09:24:30] - |A| - (.Copyright 2013 O&O Software GmbH - O&O SafeErase Professional.) - [772296] - (6.0.0.0) - V:\OOSafeEraseProfessional10ENU.exe [08/08/2016 12:23:16] - |A| - (.(c) Software Assistant - OpenOffice.) - [1142760] - (3.0.0.157) - V:\OpenOffice_Setup.exe [10/07/2016 19:42:18] - |A| - (.© Panda 2016 - Panda Security SFX.) - [2252720] - (15.14.2.0) - V:\PANDAFREEAV.exe [11/07/2016 09:24:33] - |A| - (.© pdfforge GmbH - PDFCreator is the easy way of creating PDFs..) - [27980440] - (2.2.2.0) - V:\PDFCreator_Plus-2_2_2-setup.exe [14/06/2016 07:32:38] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - PhotoFiltre Portable.) - [5878212] - (7.1.2.0) - V:\PhotoFiltrePortable_7.1.2.paf.exe [11/07/2016 09:24:37] - |A| - (.Copyright 2011, 2012, 2013, 2014, 2015, 2016 Sony Corporation - PlayMemories Home Installer.) - [16496720] - (8.0.7600.16385) - V:\PMHOME_5100DL.exe [14/06/2016 09:05:05] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - PortableApps.com AppCompactor.) - [895480] - (3.1.0.0) - V:\PortableApps.comAppCompactor_3.1.0_English.paf.exe [14/06/2016 07:38:15] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - PortableApps.com Launcher.) - [767904] - (2.2.0.0) - V:\PortableApps.comLauncher_2.2.paf (1).exe [14/06/2016 07:44:26] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - PortableApps.com Launcher.) - [767904] - (2.2.0.0) - V:\PortableApps.comLauncher_2.2.paf.exe [14/06/2016 08:06:15] - |A| - (.PortableApps.com - PortableApps.com Platform.) - [3793168] - (12.2.0.0) - V:\PortableApps.com_Platform_Setup_12.2.paf.exe [11/07/2016 09:24:39] - |A| - (.PortableApps.com - PortableApps.com Platform.) - [4409424] - (13.0.0.0) - V:\PortableApps.com_Platform_Setup_13.0.paf.exe [11/07/2016 09:24:39] - |A| - (.PortableApps.com - PortableApps.com Platform.) - [4353008] - (14.0.0.0) - V:\PortableApps.com_Platform_Setup_14.0.paf.exe [19/07/2016 09:39:56] - |A| - (.PortableApps.com - PortableApps.com Platform.) - [4140968] - (14.1.0.0) - V:\PortableApps.com_Platform_Setup_14.1.paf(1).exe [14/07/2016 07:35:44] - |A| - (.PortableApps.com - PortableApps.com Platform.) - [4140968] - (14.1.0.0) - V:\PortableApps.com_Platform_Setup_14.1.paf.exe [14/06/2016 08:21:22] - |A| - (.PortableApps.com - PortableApps.com Suite.) - [140562568] - (1.6.1.0) - V:\PortableApps.com_Suite_Setup_1.6.1_English (1).exe [14/06/2016 08:07:07] - |A| - (.PortableApps.com - PortableApps.com Suite.) - [140562568] - (1.6.1.0) - V:\PortableApps.com_Suite_Setup_1.6.1_English.exe [08/08/2016 10:06:11] - |A| - (.© 2000-2015 Safer-Networking Ltd.. - Post-Windows 10 Upgrade re-installer for Spybot - Search & D.) - [821920] - (2.5.43.0) - V:\Post Win10 Spybot-install.exe [11/07/2016 09:24:42] - |A| - (.© 2010 Microsoft Corporation. -.) - [63347104] - (14.0.4730.1010) - V:\PowerPointViewer.exe [14/06/2016 07:57:59] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - Private Browsing by PortableApps.com.) - [1487280] - (3.0.0.0) - V:\PrivateBrowsingByPortableApps_3.0.paf.exe [10/07/2016 19:42:55] - |A| - (.2007-2016 PortableApps.com, PortableApps.com Installer 3.1.1.0 - qBittorrent Portable.) - [9120168] - (3.3.3.0) - V:\qBittorrentPortable_3.3.3.paf.exe [11/07/2016 09:24:54] - |A| - (.Copyright © 2016 Reason Software Company Inc. - Reason Core Security Setup.) - [3919376] - (1.1.2.0) - V:\reason-core-security-setup (1).exe [11/07/2016 09:24:53] - |A| - (.Copyright © 2016 Reason Software Company Inc. - Reason Core Security Setup.) - [3919376] - (1.1.2.0) - V:\reason-core-security-setup.exe [11/07/2016 09:24:54] - |A| - (.Copyright © 2015 Reason Software Company Inc. - Reason Core Security Setup.) - [3855576] - (1.1.1.0) - V:\reason-core-security-setup_1.1.1.0.exe [20/08/2016 21:14:23] - |A| - (.© Microsoft Corporation. - Self-Extracting Cabinet.) - [376528] - (6.3.13.0) - V:\RefreshWindowsTool.exe [10/06/2016 15:20:24] - |A| - (.(c) Malwarebytes - Malwarebytes' RegASSASSIN.) - [65232] - (1.0.0.3) - V:\regassassin-setup-1.03.exe [09/07/2016 14:19:14] - |A| - (.Copyright © 2008-2014 Auslogics Labs Pty Ltd - Auslogics Registry Cleaner Installation File .) - [7253752] - (4.1.0.0) - V:\registry-cleaner-setup.exe [11/07/2016 09:24:59] - |A| - (.-.) - [409449] - (1.3.0.0) - V:\rstassociations-version-exe_1.3.exe [11/07/2016 09:29:03] - |A| - (.-.) - [487400] - (3.3.9.4) - V:\Search_The_Crack.exe [10/07/2016 19:44:49] - |A| - (.kastorsoft.com - Free Video Converter Setup .) - [6509896] - (2.3.0.0) - V:\SetupFreeVideoConverter.exe [11/07/2016 09:29:08] - |A| - (. - ShadowExplorer Setup .) - [969845] - (0.9.462.0) - V:\ShadowExplorer-0.9-setup.exe [11/07/2016 09:29:08] - |A| - (.© 2015 simplitec GmbH - simplitec setup .) - [21595680] - (2.2.22.27) - V:\simplitec_simpliclean_int.exe [11/07/2016 09:29:59] - |A| - (.Copyright 1989-2016 Sophos Limited. - Sophos Extractor.) - [196787200] - (1.3.3.7) - V:\SophosInstall.exe [08/08/2016 09:25:53] - |A| - (.© 2000-2014 Safer-Networking Ltd.. - Licence installer for Spybot - Search & Destroy .) - [558344] - (2.3.39.0) - V:\spybot2-license.exe [29/07/2016 16:59:27] - |A| - (.-.) - [109259] - (0.0.0.0) - V:\steam.exe [09/07/2016 05:50:18] - |A| - (.Stellar Information Technology Pvt Ltd. - Stellar Information Technology Pvt Ltd. .) - [5979488] - (6.0.0.1) - V:\StellarPhoenixWindowsDataRecovery-Professional.exe [10/07/2016 19:46:38] - |A| - (.1995-2013 Stellar Information Systems Ltd. - Stellar Information Systems Ltd .) - [6471304] - (6.0.0.0) - V:\StellarPhoenixWindowsDataRecovery-ProfessionalV6_AQFR.exe [14/06/2016 07:25:56] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - Sumatra PDF Portable.) - [2541384] - (2.3.2.0) - V:\SumatraPDFPortable_2.3.2.paf.exe [05/07/2016 09:39:21] - |A| - (.-.) - [7157328] - (0.0.0.0) - V:\susetupPro.exe [11/07/2016 09:30:26] - |A| - (.PortableApps.com Installer Copyright 2007-2012 PortableApps.com. - TeamViewer Portable.) - [10876344] - (11.0.59518.0) - V:\TeamViewerPortable_11.0.59518.paf.exe [10/07/2016 19:46:51] - |A| - (.TeamViewer GmbH -.) - [9666224] - (11.0.59518.0) - V:\TeamViewer_Setup_fr.exe [11/07/2016 09:30:28] - |A| - (.-.) - [23398464] - (0.0.0.0) - V:\tenorshare-android-data-recovery-trial.exe [14/06/2016 07:43:53] - |A| - (.-.) - [24727614] - (0.0.0.0) - V:\tenorshare-free-video-converter.exe [11/07/2016 09:30:33] - |A| - (.-.) - [8074734] - (0.0.0.0) - V:\tenorshare-pdf-password-recovery-trial.exe [11/07/2016 09:30:34] - |A| - (.-.) - [5015718] - (0.0.0.0) - V:\tenorshare-pdf-password-remover-trial.exe [05/07/2016 13:46:37] - |A| - (.-.) - [25106954] - (0.0.0.0) - V:\tenorshare-samsung-data-recovery-trial.exe [14/06/2016 07:45:03] - |A| - (.-.) - [24343000] - (0.0.0.0) - V:\tenorshare-video-converter-trial.exe [14/06/2016 08:03:50] - |A| - (.-.) - [266046792] - (0.0.0.0) - V:\tenorshare-windows-boot-genius-trial.exe [14/06/2016 08:06:43] - |A| - (.-.) - [32563203] - (0.0.0.0) - V:\tenorshare-windows-video-downloader-trial.exe [11/07/2016 04:50:20] - |A| - (.-.) - [271572636] - (1.1.3.70) - V:\tentatives lfs ultra finalis efm et didinser.exe [19/07/2016 19:23:09] - |A| - (.Mozilla - Thunderbird.) - [35165800] - (4.42.0.0) - V:\Thunderbird Setup 45.2.0.exe [21/08/2016 11:32:06] - |A| - (.Copyright © 2016 Wondershare. - Wondershare TidyMyMusic Setup .) - [19390976] - (1.5.0.1) - V:\tidymymusic_full1690.exe [19/07/2016 13:55:05] - |A| - (.© 1996-2016 by Joachim Marder e.K. - TreeSize Free Setup .) - [5963008] - (3.4.5.343) - V:\TreeSizeFreeSetup.exe [11/07/2016 09:31:52] - |A| - (.Copyright ©2011 - 2016 - Setup Application.) - [21382440] - (3.9.0.0) - V:\tweaking.com_windows_repair_aio_setup.exe [26/07/2016 18:02:08] - |A| - (.-.) - [6848474] - (0.0.0.0) - V:\ultracopier-ultimate-windows-x86_64-1.2.3.2-setup.exe [04/08/2016 14:26:05] - |A| - (.-.) - [6938568] - (0.0.0.0) - V:\ultracopier-windows-x86-1.2.1.0-setup.exe [11/07/2016 09:31:55] - |A| - (.Copyright - Geza Kovacs - License - GNU GPL v2+ - UNetbootin - Universal Netboot Installer - http://unetbootin.sourceforge.net.) - [4831744] - (1.1.1.1) - V:\unetbootin-windows-613.exe [04/08/2016 14:26:14] - |A| - (.Copyright © 2005-2015 - IObit Unlocker .) - [2451912] - (1.1.0.0) - V:\unlocker-setup.exe [08/08/2016 09:25:54] - |A| - (.-.) - [402911] - (0.0.0.0) - V:\Unlocker1.9.2.exe [10/06/2016 11:10:42] - |A| - (.© 2008/2014 - El Desaparecido - www.SosVirus.net - UsbFix - Remove Malware From Your Drive!.) - [3989160] - (7.8.0.6) - V:\UsbFix-7.806.exe [10/07/2016 17:04:37] - |A| - (.© 2008/2016 - El Desaparecido - www.SOSVirus.net - UsbFix - Remove Malware From Your Drive!.) - [3124797] - (8.2.2.8) - V:\UsbFix_2016_8.233.exe [08/08/2016 20:07:05] - |A| - (.© 2008/2016 - El Desaparecido - www.SOSVirus.net - UsbFix - Remove Malware From Your Drive!.) - [3124524] - (8.2.4.7) - V:\UsbFix_2016_8.248(1).exe [01/08/2016 12:47:45] - |A| - (.© 2008/2016 - El Desaparecido - www.SOSVirus.net - UsbFix - Remove Malware From Your Drive!.) - [3124524] - (8.2.4.7) - V:\UsbFix_2016_8.248.exe [08/08/2016 09:22:50] - |A| - (.© 2008/2016 - El Desaparecido - www.SOSVirus.net - UsbFix - Remove Malware From Your Drive!.) - [3114746] - (8.2.4.9) - V:\UsbFix_8.152.exe [11/07/2016 09:31:58] - |A| - (.Copyright (c) 2016 Steganos Software GmbH - Steganos PortableSafe USB Starter.) - [4127744] - (17.1.3.11700) - V:\usbstarter.exe [10/07/2016 19:48:12] - |A| - (. - Panda USB Vaccine Setup .) - [848856] - (1.0.1.4) - V:\USBVaccineSetup.exe [11/07/2016 09:31:59] - |A| - (.2007-2016 PortableApps.com, PortableApps.com Installer 3.1.1.0 - uTorrent Portable.) - [2370592] - (3.4.6.42178) - V:\uTorrentPortable_3.4.6.42178_online.paf.exe [10/07/2016 16:14:51] - |A| - (.Copyright 2015 Wondershare Corporation - videoconverterfree_setup_full1129.exe.) - [800840] - (1.2.1.1) - V:\video-converter-free_setup_full1129.exe [10/07/2016 19:48:31] - |A| - (. - .) - [46736640] - (9.0.18.0) - V:\video-converter-ultimate(1).exe [10/07/2016 19:48:19] - |A| - (. - .) - [46736640] - (9.0.18.0) - V:\video-converter-ultimate.exe [04/08/2016 14:26:17] - |A| - (.Copyright 2015 Wondershare Corporation - videoeditor_setup_full1084.exe.) - [939080] - (1.2.1.1) - V:\video-editor_setup_full1084.exe [23/07/2016 05:19:21] - |A| - (.- Video to Picture Setup.) - [12937488] - (1.0.0.0) - V:\video-to-picture.exe [11/07/2016 09:32:15] - |A| - (.- Professional video watermarking program.) - [16786240] - (5.1.0.0) - V:\video-watermark-pro.exe [11/07/2016 09:32:13] - |A| - (.- Video watermarking program.) - [16733504] - (5.1.0.0) - V:\video-watermark.exe [10/07/2016 19:48:17] - |A| - (.Copyright © 2014 UpdateStar - Video Converter Setup .) - [8704008] - (7.0.3.91) - V:\VideoConverter.exe [24/06/2016 11:31:58] - |A| - (.-.) - [89589712] - (0.0.0.0) - V:\VideoMeetingPlus_1.0.1711.0_Beta_VMX160226-03.exe [10/07/2016 12:33:54] - |A| - (.Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. - InstallScript Setup Launcher.) - [453686816] - (17.0.0.717) - V:\Video_Explosion_Deluxe_Setup.exe [10/07/2016 07:41:44] - |A| - (.- Télécharge et installe VirtualBox portable.) - [301259] - (3.3.6.1) - V:\VirtualBoxPortable.exe [14/06/2016 07:15:38] - |A| - (.2007-2015 PortableApps.com, PortableApps.com Installer 3.0.17.0 - VLC Media Player Portable.) - [26948496] - (2.2.1.0) - V:\VLCPortable_2.2.1.paf.exe [14/06/2016 07:23:56] - |A| - (.tenorshare.com - Windows Care Genius .) - [16035976] - (3.9.4.355) - V:\windows-care-genius-trial.exe [11/07/2016 09:32:28] - |A| - (.© 2006 Microsoft Corporation. -.) - [25746416] - (12.0.6038.3000) - V:\wordview_fr-fr.exe [11/07/2016 09:32:31] - |A| - (.-.) - [33087576] - (0.0.0.0) - V:\x-audio-maker6-fr.exe [11/07/2016 09:32:34] - |A| - (.-.) - [16868162] - (0.0.0.0) - V:\x-dailymotion-video-downloader-fr.exe [11/07/2016 09:32:36] - |A| - (.-.) - [28206392] - (0.0.0.0) - V:\x-download-youtube-video5-fr.exe [11/07/2016 09:32:39] - |A| - (.-.) - [37509928] - (0.0.0.0) - V:\x-video-converter-ultimate7-fr.exe [11/07/2016 09:32:43] - |A| - (.-.) - [26640091] - (0.0.0.0) - V:\x-video-editor2-fr.exe [29/07/2016 16:59:27] - |A| - (.-.) - [38457] - (0.0.0.0) - V:\xpsoft.exe [29/07/2016 16:59:27] - |A| - (.-.) - [38683] - (0.0.0.0) - V:\xpsolive.exe [09/08/2016 08:54:31] - |A| - (.© Copyright 2015 - Advanced Malware Protection .) - [5669936] - (2.21.278.0) - V:\Zemana.AntiLogger.Setup.exe [07/08/2016 16:41:12] - |A| - (.Nicolas Coolman - ZHPCleane.) - [2334720] - (2016.8.6.99) - V:\ZHPCleaner.exe [01/08/2016 12:47:47] - |A| - (.Nicolas Coolman - ZHPDiag.) - [2281984] - (2016.8.5.126) - V:\ZHPDiag3.exe [03/08/2016 12:52:05] - |A| - (.Nicolas Coolman - ZHPFix .) - [3521617] - (2015.10.19.9) - V:\ZHPFix.exe [11/07/2016 09:32:49] - |A| - (.Copyright © 1998-2016, Check Point, LTD - ZoneAlarm.) - [3412200] - (14.1.48.0) - V:\zonealarm-free-antivirus-firewall_14-1-048-000_fr_10494.exe [11/07/2016 09:32:48] - |A| - (.Copyright © 1999-2011 Pro Softnet Corp. - ZoneAlarm Backup Powered by IDrive Setup .) - [9468744] - (0.0.0.0) - V:\ZoneAlarmBackupSetup.exe [08/07/2016 19:32:32] - |A| - (.-.) - [262] - (0.0.0.0) - V:\.label.info [10/07/2016 19:01:41] - |A| - (.-.) - [4248] - (0.0.0.0) - V:\0x0404.ini [10/07/2016 19:01:41] - |A| - (.-.) - [7094] - (0.0.0.0) - V:\0x0407.ini [10/07/2016 19:01:41] - |A| - (.-.) - [6129] - (0.0.0.0) - V:\0x0409.ini [10/07/2016 19:01:41] - |A| - (.-.) - [7022] - (0.0.0.0) - V:\0x040a.ini [10/07/2016 19:01:41] - |A| - (.-.) - [7242] - (0.0.0.0) - V:\0x040c.ini [10/07/2016 19:01:41] - |A| - (.-.) - [6897] - (0.0.0.0) - V:\0x0410.ini [10/07/2016 19:01:41] - |A| - (.-.) - [6623] - (0.0.0.0) - V:\0x0411.ini [10/07/2016 19:01:42] - |A| - (.-.) - [5724] - (0.0.0.0) - V:\0x0412.ini [10/07/2016 19:01:42] - |A| - (.-.) - [4315] - (0.0.0.0) - V:\0x0804.ini [11/07/2016 08:44:52] - |A| - (.-.) - [5504] - (0.0.0.0) - V:\a2settings.ini [11/07/2016 08:44:52] - |A| - (.-.) - [64] - (0.0.0.0) - V:\a2whitelist.ini [11/04/2010 13:02:38] - |A| - (.-.) - [24] - (0.0.0.0) - V:\Config.ini [10/07/2016 19:10:42] - |A| - (.-.) - [142] - (0.0.0.0) - V:\Custom.ini [10/07/2016 19:31:48] - |A| - (.-.) - [40] - (0.0.0.0) - V:\Define.ini [18/07/2016 18:18:04] - |A| - (.-.) - [282] - (0.0.0.0) - V:\desktop(1).ini [10/07/2016 19:31:48] - |A| - (.-.) - [282] - (0.0.0.0) - V:\desktop_FromLFS_ULTRA.ini [27/11/2013 15:14:04] - |A| - (.-.) - [2054] - (0.0.0.0) - V:\Framakey.ini [10/07/2016 19:39:27] - |A| - (.-.) - [101] - (0.0.0.0) - V:\info.ini [09/08/2016 16:00:26] - |A| - (.-.) - [44] - (0.0.0.0) - V:\language.ini [11/07/2016 09:24:15] - |A| - (.-.) - [0] - (0.0.0.0) - V:\LogAnalyZer.ini [10/07/2016 19:44:47] - |A| - (.-.) - [1953] - (0.0.0.0) - V:\Setup.ini [10/07/2016 19:48:12] - |A| - (.-.) - [208] - (0.0.0.0) - V:\ureg.ini [12/05/2016 12:06:17] - |A| - (.-.) - [1598] - (0.0.0.0) - V:\UserSettings.ini [11/07/2016 09:32:19] - |A| - (.-.) - [27] - (0.0.0.0) - V:\VTU.ini U: [21/02/2016 19:04:14] - |A| - (.Copyright © 1999-2012 - BASS.) - [105528] - (2.4.9.0) - U:\bass.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2005-2012 by radio42: Bernd Niedergesaess, Germany. http://www.bass.radio42.com/ - bn@radio42.com - BASS.NET API for .Net.) - [638976] - (2.4.9.1) - U:\Bass.Net.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2003-2009 - BASSCD.) - [17472] - (2.4.2.0) - U:\basscd.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2004-2009 - BASSFLAC.) - [24640] - (2.4.0.3) - U:\bassflac.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2005-2009 - BASSmix.) - [16448] - (2.4.2.0) - U:\bassmix.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2012 - BASSOPUS.) - [53816] - (2.4.0.0) - U:\bassopus.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2002-2010 - BASSWMA.) - [17472] - (2.4.4.0) - U:\basswma.dll [21/02/2016 19:04:14] - |A| - (.Copyright © 2007-2009 - BASSWV.) - [28224] - (2.4.1.3) - U:\basswv.dll [21/02/2016 19:04:14] - |A| - (.2003-2006, MaresWEB - Apple Lossless Audio Codec add-on for the BASS library.) - [9416] - (2.4.3.0) - U:\bass_alac.dll [21/02/2016 19:04:14] - |A| - (.2003-2006, MaresWEB - Monkey's Audio add-on for the BASS library.) - [33624] - (2.4.0.4) - U:\bass_ape.dll [21/02/2016 19:04:14] - |A| - (.2003-2006, MaresWEB - Musepack add-on for the BASS library.) - [21320] - (2.4.1.0) - U:\bass_mpc.dll [15/03/2016 19:18:10] - |A| - (.Copyright © 2002-2008 Canneverbe Limited - CDBXPExt.) - [69120] - (4.5.6.6059) - U:\CDBXP.dll [21/02/2016 19:04:14] - |A| - (.-.) - [337408] - (13.0.0.0) - U:\LogicNP.FolderView.dll [21/02/2016 19:04:14] - |A| - (.Copyright (c) Rocket Division Software, StarBurn Software 2001-2015. - StarBurn CD/DVD/Blu-Ray/HD-DVD Burning, Grabbing and Mastering Toolkit for Windows 95/98/Me/NT/2000/XP/2003/Vista/Longhorn/7/8/2010.) - [3235200] - (15.5.1.4144) - U:\StarBurn.dll [14/07/2016 04:03:31] - |A| - (. - Ashampoo Media Sync Setup .) - [12641832] - (1.0.2.0) - U:\ashampoo_media_sync_e1.0.2_sm.exe [13/05/2016 06:34:57] - |A| - (.-.) - [97557896] - (0.0.0.0) - U:\CyberLink_MediaEspresso7.5_MEX160302-01.exe [15/03/2016 19:20:06] - |A| - (.Copyright © 2002-2008 Canneverbe Limited - CDBurnerXP command line version.) - [25712] - (4.5.6.6059) - U:\cdbxpcmd.exe [15/03/2016 19:20:06] - |A| - (.Copyright © 2002-2008 Canneverbe Limited - CDBurnerXP.) - [1746032] - (4.5.6.6059) - U:\cdbxpp.exe [12/05/2016 12:06:17] - |A| - (.-.) - [1598] - (0.0.0.0) - U:\UserSettings.ini [11/04/2010 13:02:38] - |A| - (.-.) - [24] - (0.0.0.0) - U:\Config.ini Q: [31/01/2016 11:57:05] - |A| - (.-.) - [983040] - (0.8.0.5) - Q:\Framakey.exe [31/01/2016 11:43:52] - |A| - (.-.) - [2141] - (0.0.0.0) - Q:\Framakey.ini P: [16/08/2016 12:18:13] - |A| - (.Copyright (C) 2011 Flexera Software, Inc. and/or InstallShield Co. Inc. - InstallScript Setup Launcher.) - [371303208] - (18.0.0.329) - P:\10295_Video-facile.exe [22/08/2016 08:34:46] - |A| - (.Copyright (C) CyberLink Corporation. All rights reserved - CyberLink Downloader.) - [1040152] - (2.9.1.6109) - P:\CyberLink_VideoMeetingPlus_Downloader.exe O: [30/04/2016 19:13:58] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - O:\BitTorrent (1).exe [30/04/2016 19:17:08] - |RA| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - O:\BitTorrent(btkey,https^3A^2F^2Futp.st^2FjSAg97W0).exe [24/05/2016 08:34:30] - |A| - (.-.) - [64] - (0.0.0.0) - O:\a2whitelist.ini [24/05/2016 06:32:13] - |A| - (.-.) - [5774] - (0.0.0.0) - O:\a2settings.ini N: [05/05/2016 17:15:18] - |A| - (.© 2008/2016 - El Desaparecido - www.SOSVirus.net - UsbFix - Remove Malware From Your Drive!.) - [3124797] - (8.2.2.8) - N:\UsbFix_2016_8.233.exe [08/05/2016 13:18:31] - |A| - (.©2016 BitTorrent, Inc. - BitTorrent.) - [1963528] - (7.9.6.42179) - N:\BitTorrent(btkey,https^3A^2F^2Futp.st^2FAq2NsdKU).exe [08/05/2016 13:18:36] - |A| - (.Copyright © 2005-2016 Piriform Ltd - CCleaner Installer.) - [7033368] - (2.0.0.0) - N:\ccsetup_517.exe [08/05/2016 13:18:42] - |A| - (.Copyright 2003-2015 Emsisoft Ltd. - Emsisoft Anti-Malware Setup .) - [237135456] - (11.7.0.6394) - N:\EmsisoftAntiMalwareSetup.exe [08/05/2016 13:19:02] - |A| - (.-.) - [232114840] - (0.0.0.0) - N:\EmsisoftEmergencyKit (1).exe [08/05/2016 13:19:19] - |A| - (.-.) - [232114840] - (0.0.0.0) - N:\EmsisoftEmergencyKit.exe [08/05/2016 13:19:43] - |A| - (.© 2006-2016 SurfRight, a Sophos company - HitmanPro 3.7.) - [11441168] - (3.7.14.263) - N:\hitmanpro_x64.exe [08/05/2016 13:20:35] - |A| - (.Copyright © Malwarebytes Corporation - Malwarebytes Anti-Rootkit.) - [16563352] - (1.9.3.1001) - N:\mbar-1.09.3.1001.exe [08/05/2016 13:20:43] - |A| - (.Copyright ©2011 - 2016 - Setup Application.) - [21258848] - (3.8.0.7) - N:\tweaking.com_windows_repair_aio_setup.exe [08/05/2016 13:20:46] - |A| - (.© Copyright 2015 - AntiMalware .) - [5479312] - (2.20.613.0) - N:\Zemana.AntiMalware.Setup.exe [07/06/2016 10:44:01] - |A| - (.PortableApps.com - PortableApps.com Platform.) - [4140968] - (14.1.0.0) - N:\PortableApps.com_Platform_Setup_14.1.paf.exe [11/05/2016 19:55:40] - |A| - (.-.) - [505346176] - (0.0.0.0) - N:\CyberLink_ActionDirector_ACD160414-01.exe M: [09/10/2015 12:49:33] - |R| - (.-.) - [53604184] - (12.0.0.49974) - M:\Paragon-283-PEF_WinInstallSNx64_10.1.25.813_000.exe [09/10/2015 12:49:30] - |R| - (.-.) - [51289432] - (12.0.0.49974) - M:\Paragon-283-PEF_WinInstallSN_10.1.25.813_000.exe K: [03/08/2016 07:40:06] - |A| - (.© 2006-2016 SurfRight, a Sophos company - HitmanPro 3.7.) - [10451640] - (3.7.14.265) - K:\HitmanPro.exe [03/08/2016 07:40:10] - |A| - (.© 2006-2016 SurfRight, a Sophos company - HitmanPro 3.7.) - [11438608] - (3.7.14.265) - K:\HitmanPro_x64.exe I: H: [09/05/2011 20:08:50] - |N| - (.- Télécharge et installe VirtualBox portable.) - [301259] - (3.3.6.1) - H:\VirtualBoxPortable.exe [04/05/2011 17:11:58] - |N| - (.-.) - [472466] - (0.8.0.2) - H:\Framakey.exe [03/05/2011 11:24:12] - |N| - (.-.) - [2054] - (0.0.0.0) - H:\Framakey.ini G: D: [13/08/2016 16:31:06] - |A| - (.-.) - [44] - (0.0.0.0) - D:\language.ini ---------- | C: [14/08/2016 06:34:57] - |D| - [3472444518] - C:\$GetCurrent [05/03/2013 01:30:20] - |SHD| - [5333443] - C:\$RECYCLE.BIN [14/08/2016 07:51:51] - |D| - [1120118588] - C:\$WINDOWS.~BT [20/08/2016 09:29:20] - |D| - [0] - C:\AdsFix [22/08/2016 09:04:47] - |D| - [12561577] - C:\AdwCleaner [13/08/2016 22:56:10] - |D| - [126944772] - C:\AMD [02/08/2012 04:02:18] - |SHD| - [18179356] - C:\Boot [MD5.21BF183C15AFE62A8D1137BB9007B2A3] - [26/07/2012 10:18:43] - |RASH| - (.-.) - [398156] - (0.0.0.0) - C:\bootmgr [MD5.93B885ADFE0DA089CDF634904FD59F71] - [26/07/2012 10:18:43] - |N| - (.-.) - [1] - (0.0.0.0) - C:\BOOTNXT [23/08/2016 07:11:19] - |SHD| - [0] - C:\Config.Msi [30/07/2015 23:51:49] - |SD| - [0] - C:\Documents and Settings [15/08/2016 15:32:34] - |D| - [898250913] - C:\DrWeb Archive [15/08/2016 15:54:45] - |SHD| - [0] - C:\DrWeb Quarantine [22/08/2016 21:02:16] - |D| - [109784571] - C:\FRST [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/08/2016 10:16:49] - |ASH| - (.-.) - [1535000576] - (0.0.0.0) - C:\hiberfil.sys [07/01/2013 13:49:41] - |D| - [4053085] - C:\hp [14/08/2016 10:33:10] - |D| - [1435016] - C:\inetpub [10/09/2015 07:56:11] - |D| - [13975552] - C:\Logs [MD5.6647127648904754DEF707A6C636DA69] - [23/08/2016 20:50:46] - |A| - (.-.) - [35358] - (0.0.0.0) - C:\Look_my_hardware.tmp [22/08/2016 08:32:33] - |D| - [0] - C:\My Works [MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/03/2013 09:30:46] - |N| - (.-.) - [0] - (0.0.0.0) - C:\OS [23/08/2016 14:20:46] - |D| - [471676832] - C:\OTLPE_7 [MD5.D41D8CD98F00B204E9800998ECF8427E] - [13/08/2016 16:21:44] - |ASH| - (.-.) - [419430400] - (0.0.0.0) - C:\pagefile.sys [18/08/2016 18:43:57] - |D| - [10983120] - C:\PcPinPoint [16/07/2016 13:47:47] - |D| - [0] - C:\PerfLogs [20/08/2016 09:24:42] - |D| - [339142212] - C:\Pre_Scan [MD5.D758E891C93D5B4368D7B010F6FC8C1C] - [20/08/2016 14:09:05] - |RA| - (.-.) - [18451] - (0.0.0.0) - C:\Pre_Scan_20_08_2016_14_09_03.txt [16/07/2016 08:04:24] - |RD| - [5292418068] - C:\Program Files [16/07/2016 08:04:24] - |RD| - [11763294465] - C:\Program Files (x86) [16/07/2016 13:47:48] - |HD| - [4998156067] - C:\ProgramData [21/08/2016 12:09:12] - |D| - [34980039] - C:\QuickDiag [MD5.67FA9725EC36251A1DFEED245E92B78E] - [23/08/2016 20:45:55] - |A| - (.-.) - [442416] - (0.0.0.0) - C:\QuickDiag.txt [14/08/2016 10:54:16] - |SHD| - [971] - C:\Recovery [13/08/2016 20:56:25] - |D| - [0] - C:\sources [MD5.D41D8CD98F00B204E9800998ECF8427E] - [13/08/2016 16:21:45] - |ASH| - (.-.) - [268435456] - (0.0.0.0) - C:\swapfile.sys [02/08/2012 05:15:28] - |AD| - [1021170408] - C:\SWSETUP [13/08/2016 16:21:43] - |SHD| - [0] - C:\System Volume Information [01/08/2012 11:57:15] - |D| - [5674404] - C:\SYSTEM.SAV [14/08/2016 10:59:37] - |D| - [33896035] - C:\UsbFix [16/07/2016 08:04:24] - |RD| - [15942803621] - C:\Users [16/07/2016 08:04:24] - |D| - [23146309793] - C:\Windows [14/08/2016 10:47:14] - |D| - [0] - C:\Windows.old [14/08/2016 06:33:38] - |D| - [15973889] - C:\Windows10Upgrade [20/08/2016 05:33:23] - |D| - [0] - C:\_Backup ---------- | C:\WINDOWS [21/08/2016 14:41:01] - |D| - [15142993] - C:\WINDOWS\ADAM [16/07/2016 13:47:48] - |D| - [802] - C:\WINDOWS\addins [16/07/2016 13:47:48] - |D| - [20555990] - C:\WINDOWS\appcompat [16/07/2016 13:47:48] - |D| - [12435960] - C:\WINDOWS\AppPatch [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\AppReadiness [16/07/2016 13:47:47] - |RSD| - [1357143129] - C:\WINDOWS\assembly [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/08/2016 09:58:13] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\ativpsrm.bin [26/07/2012 10:12:59] - |D| - [0] - C:\WINDOWS\AUInstallAgent [16/07/2016 13:47:48] - |D| - [261076] - C:\WINDOWS\bcastdvr [MD5.7B465E25ADF5D6DBCE9DCAE3C6545405] - [16/07/2016 13:42:16] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [61440] - (10.0.14393.0) - C:\WINDOWS\bfsvc.exe [17/07/2016 00:46:17] - |SD| - [591899] - C:\WINDOWS\BitLockerDiscoveryVolumeContents [16/07/2016 13:47:48] - |D| - [38077683] - C:\WINDOWS\Boot [MD5.045397ADC16504152400CB7660985C56] - [14/08/2016 09:57:18] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [16/07/2016 13:47:48] - |D| - [3715608] - C:\WINDOWS\Branding [16/07/2016 13:36:22] - |D| - [0] - C:\WINDOWS\CbsTemp [13/08/2016 21:40:03] - |D| - [0] - C:\WINDOWS\CSC [MD5.B749466D1A93B0BFE3590BD487A793BF] - [05/03/2013 01:14:16] - |A| - (.-.) - [10] - (0.0.0.0) - C:\WINDOWS\csup.txt [16/07/2016 13:47:48] - |D| - [8970858] - C:\WINDOWS\Cursors [16/07/2016 13:47:48] - |D| - [3707137] - C:\WINDOWS\debug [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [14/08/2016 10:25:10] - |A| - (.-.) - [7623] - (0.0.0.0) - C:\WINDOWS\diagerr.xml [16/07/2016 13:47:48] - |D| - [4543876] - C:\WINDOWS\diagnostics [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [14/08/2016 10:25:10] - |A| - (.-.) - [7623] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml [17/07/2016 00:40:08] - |D| - [0] - C:\WINDOWS\DigitalLocker [MD5.452CF3E6DB51D819944146C028D096B6] - [14/08/2016 19:58:37] - |A| - (.-.) - [480] - (0.0.0.0) - C:\WINDOWS\dm.dmap [MD5.B3799261A085A302F22A9FF7ED3C0B68] - [14/08/2016 19:58:37] - |A| - (.-.) - [66560] - (0.0.0.0) - C:\WINDOWS\dm_batch.bak [16/07/2016 13:47:48] - |SD| - [65] - C:\WINDOWS\Downloaded Program Files [16/07/2016 13:47:48] - |D| - [44056] - C:\WINDOWS\ELAMBKUP [26/07/2012 11:43:43] - |D| - [116160] - C:\WINDOWS\en-GB [17/07/2016 00:40:08] - |D| - [0] - C:\WINDOWS\en-US [MD5.05181A5AC4197D6C5C02ACE6070AF234] - [16/07/2016 13:42:40] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4673304] - (10.0.14393.0) - C:\WINDOWS\explorer.exe [16/07/2016 13:47:48] - |RSD| - [361964516] - C:\WINDOWS\Fonts [05/03/2013 01:46:39] - |D| - [116648] - C:\WINDOWS\fr [17/07/2016 00:40:08] - |D| - [122368] - C:\WINDOWS\fr-FR [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\GameBarPresenceWriter [16/07/2016 13:47:48] - |D| - [20733376] - C:\WINDOWS\Globalization [16/07/2016 13:47:48] - |D| - [2100702] - C:\WINDOWS\Help [MD5.553DF2ABF34649763324BC5470D04317] - [16/07/2016 13:42:20] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [975360] - (10.0.14393.0) - C:\WINDOWS\HelpPane.exe [MD5.52AFE6DE5E463B7A08C184B1EB49DD6A] - [16/07/2016 13:42:21] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.14393.0) - C:\WINDOWS\hh.exe [MD5.40DCC3C4C53DC0501F4B918156CE5340] - [21/08/2016 11:23:09] - |A| - (.-.) - [39939] - (0.0.0.0) - C:\WINDOWS\iis.log [16/07/2016 13:47:48] - |D| - [173189928] - C:\WINDOWS\IME [16/07/2016 13:47:48] - |RD| - [6842480] - C:\WINDOWS\ImmersiveControlPanel [16/07/2016 13:45:54] - |D| - [127165809] - C:\WINDOWS\INF [16/07/2016 13:47:48] - |D| - [966051391] - C:\WINDOWS\InfusedApps [16/07/2016 13:47:48] - |D| - [36285422] - C:\WINDOWS\InputMethod [16/07/2016 13:47:48] - |SHD| - [1707577667] - C:\WINDOWS\Installer [16/07/2016 13:47:48] - |D| - [89407] - C:\WINDOWS\L2Schemas [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\LiveKernelReports [16/07/2016 08:04:29] - |D| - [35357774] - C:\WINDOWS\Logs [16/07/2016 13:47:48] - |RSD| - [20316123] - C:\WINDOWS\Media [MD5.23AF90D2355D8C83AA4567EF1763B467] - [16/07/2016 13:42:12] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [23/08/2016 09:59:40] - |D| - [504517295] - C:\WINDOWS\Microsoft Antimalware [16/07/2016 13:47:47] - |RD| - [847001871] - C:\WINDOWS\Microsoft.NET [16/07/2016 13:47:48] - |D| - [2563] - C:\WINDOWS\Migration [20/08/2016 08:27:07] - |D| - [0] - C:\WINDOWS\Minidump [16/07/2016 13:47:48] - |RD| - [484593] - C:\WINDOWS\MiracastView [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\ModemLogs [MD5.3B508CAE5DEBCBA928B5BC355517E2E6] - [16/07/2016 13:43:51] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [243200] - (10.0.14393.0) - C:\WINDOWS\notepad.exe [17/07/2016 00:41:15] - |D| - [199472] - C:\WINDOWS\OCR [16/07/2016 13:47:48] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [14/08/2016 10:54:09] - |DC| - [119426366] - C:\WINDOWS\Panther [16/07/2016 13:47:48] - |D| - [28866614] - C:\WINDOWS\Performance [MD5.927062B36A9EE89C14A6B74AF9CD4187] - [20/08/2016 09:16:47] - |A| - (.-.) - [10420] - (0.0.0.0) - C:\WINDOWS\PFRO.log [16/07/2016 13:47:48] - |D| - [1382870] - C:\WINDOWS\PLA [16/07/2016 13:47:48] - |D| - [6815449] - C:\WINDOWS\PolicyDefinitions [14/08/2016 09:56:02] - |D| - [37183427] - C:\WINDOWS\Prefetch [16/07/2016 13:47:48] - |RD| - [2036530] - C:\WINDOWS\PrintDialog [MD5.4ACE1A172D35E492443D29527441BB30] - [17/07/2016 00:47:31] - |A| - (.-.) - [33882] - (0.0.0.0) - C:\WINDOWS\Professional.xml [MD5.09394999ADB19901C665454EE964B13C] - [14/08/2016 07:37:36] - |A| - (.-.) - [36] - (0.0.0.0) - C:\WINDOWS\progress.ini [16/07/2016 13:47:48] - |D| - [1409651] - C:\WINDOWS\Provisioning [MD5.EFE3D78833FEDAF7F24C264BF9976301] - [16/07/2016 13:42:17] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [320512] - (10.0.14393.0) - C:\WINDOWS\regedit.exe [16/07/2016 13:47:48] - |D| - [1117876] - C:\WINDOWS\registration [17/07/2016 00:46:17] - |D| - [0] - C:\WINDOWS\RemotePackages [16/07/2016 13:47:48] - |D| - [5359372] - C:\WINDOWS\rescache [16/07/2016 13:47:48] - |D| - [3934930] - C:\WINDOWS\Resources [MD5.2A7B78F4CFA0F1A5655891DDAACEFAD9] - [05/03/2013 01:18:17] - |A| - (.Copyright (C) 2012 Realtek Semiconductor Corp. - RtlExUpd DLL for setup utility function.) - [1706640] - (1.0.3.8) - C:\WINDOWS\RtlExUpd.dll [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\SchCache [16/07/2016 13:47:48] - |D| - [121229] - C:\WINDOWS\schemas [16/07/2016 13:47:48] - |D| - [3566750] - C:\WINDOWS\security [14/08/2016 09:55:50] - |D| - [44232193] - C:\WINDOWS\ServiceProfiles [16/07/2016 08:04:24] - |D| - [71322554] - C:\WINDOWS\servicing [16/07/2016 13:49:46] - |D| - [882] - C:\WINDOWS\Setup [MD5.0BDDB1F59D32C5CBA1B99ADC0EDC2498] - [16/08/2016 09:29:39] - |A| - (.-.) - [5549] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [16/08/2016 09:29:39] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log [16/07/2016 13:47:48] - |D| - [31188480] - C:\WINDOWS\ShellExperiences [10/09/2015 07:28:34] - |D| - [0] - C:\WINDOWS\ShellNew [17/07/2016 00:40:46] - |D| - [3070736] - C:\WINDOWS\SKB [13/08/2016 16:29:57] - |D| - [42873310] - C:\WINDOWS\SoftwareDistribution [16/07/2016 13:47:48] - |D| - [86039341] - C:\WINDOWS\Speech [16/07/2016 13:47:48] - |D| - [53541356] - C:\WINDOWS\Speech_OneCore [MD5.92900A3B878F9475021DD236CFDB6BA7] - [16/07/2016 13:42:39] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [130560] - (10.0.14393.0) - C:\WINDOWS\splwow64.exe [MD5.2664EEEE55F34BC4FAAA8EE41393D2CD] - [31/07/2015 00:25:21] - |A| - (.-.) - [31856] - (0.0.0.0) - C:\WINDOWS\Starter.xml [MD5.98540955F498DF125A5199E1C1DFBCFD] - [07/07/2016 09:08:40] - |A| - (.-.) - [86448] - (0.0.0.0) - C:\WINDOWS\suite.vssMgr.exe [16/07/2016 13:47:48] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [26/07/2012 07:26:52] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [16/07/2016 08:04:24] - |D| - [8515759427] - C:\WINDOWS\System32 [16/07/2016 13:47:48] - |D| - [145477840] - C:\WINDOWS\SystemApps [16/07/2016 13:47:48] - |D| - [17494901] - C:\WINDOWS\SystemResources [16/07/2016 08:04:27] - |D| - [1478842399] - C:\WINDOWS\SysWOW64 [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\TAPI [26/07/2012 10:12:59] - |D| - [2914] - C:\WINDOWS\Tasks [16/07/2016 13:47:48] - |D| - [334886] - C:\WINDOWS\Temp [26/07/2012 10:12:59] - |RD| - [0] - C:\WINDOWS\ToastData [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\tracing [16/07/2016 13:47:48] - |D| - [7680] - C:\WINDOWS\twain_32 [MD5.21F91141B4796108A50733B14850CDF2] - [16/07/2016 13:43:52] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [66560] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [16/07/2016 13:47:48] - |D| - [12420] - C:\WINDOWS\Vss [MD5.98540955F498DF125A5199E1C1DFBCFD] - [07/07/2016 09:08:40] - |A| - (.-.) - [86448] - (0.0.0.0) - C:\WINDOWS\vssMgr.exe [16/07/2016 13:47:48] - |D| - [25457486] - C:\WINDOWS\Web [MD5.23CF8138F49416231807E6DE371FB9E6] - [26/07/2012 07:26:52] - |A| - (.-.) - [92] - (0.0.0.0) - C:\WINDOWS\win.ini [MD5.C844CA459F3B209329984772269B6E56] - [16/07/2016 13:42:32] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.038356387332650843BCB352BB89A101] - [16/08/2016 10:25:17] - |A| - (.-.) - [275] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.9328E170E5407D9DDE7EB1E208A2CBB4] - [16/07/2016 13:42:48] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [10240] - (10.0.14393.0) - C:\WINDOWS\winhlp32.exe [MD5.E01507A0CADD7796502CB0422DFA8A0E] - [22/08/2016 10:32:41] - |A| - (.-.) - [65] - (0.0.0.0) - C:\WINDOWS\wininit.ini [16/07/2016 08:04:24] - |D| - [6134627589] - C:\WINDOWS\WinSxS [MD5.D935AD9372C6858C04E3FB423149134C] - [28/07/2012 04:54:00] - |A| - (.© 2012 Microsoft Corporation. Tous droits réservés. - Écran de veille de la Galerie de photos.) - [321472] - (16.4.3503.728) - C:\WINDOWS\WLXPGSS.SCR [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [16/07/2016 13:43:08] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.E87C6A38E61A712C48025A6AD54C1113] - [16/07/2016 13:42:39] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.14393.0) - C:\WINDOWS\write.exe ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [28/08/2015 20:06:24] - C:\WINDOWS\Installer\10044a.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [11/11/2014 10:49:56] - C:\WINDOWS\Installer\100451.msi : (Branding - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:16] - C:\WINDOWS\Installer\100457.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:22] - C:\WINDOWS\Installer\10045e.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:30] - C:\WINDOWS\Installer\100465.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:36] - C:\WINDOWS\Installer\10046c.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:44] - C:\WINDOWS\Installer\100473.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:52] - C:\WINDOWS\Installer\10047a.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:00] - C:\WINDOWS\Installer\100481.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:06] - C:\WINDOWS\Installer\100488.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:16] - C:\WINDOWS\Installer\10048f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:22] - C:\WINDOWS\Installer\100496.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:30] - C:\WINDOWS\Installer\10049d.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:38] - C:\WINDOWS\Installer\1004a4.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:46] - C:\WINDOWS\Installer\1004ab.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:54] - C:\WINDOWS\Installer\1004b2.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:02] - C:\WINDOWS\Installer\1004b9.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:10] - C:\WINDOWS\Installer\1004c0.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:18] - C:\WINDOWS\Installer\1004c7.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:26] - C:\WINDOWS\Installer\1004ce.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:34] - C:\WINDOWS\Installer\1004d5.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:42] - C:\WINDOWS\Installer\1004dc.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:50] - C:\WINDOWS\Installer\1004e3.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:58] - C:\WINDOWS\Installer\1004ea.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:06] - C:\WINDOWS\Installer\1004f1.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:40] - C:\WINDOWS\Installer\1004f7.msi : (Catalyst Control Center Utility 64 - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:07:30] - C:\WINDOWS\Installer\1004fd.msi : (AMD Fuel - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:12] - C:\WINDOWS\Installer\100503.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/08/2012 07:20:32] - C:\WINDOWS\Installer\15b2f8.msi : (HP Postscript Converter - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [17/07/2012 04:07:50] - C:\WINDOWS\Installer\15b307.msi : ( - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [21/07/2012 01:12:59] - C:\WINDOWS\Installer\15b310.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:04:45] - C:\WINDOWS\Installer\24d78cc.msi : (Nero 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:12:09] - C:\WINDOWS\Installer\24d78d3.msi : (NeroControlCenter - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:11:57] - C:\WINDOWS\Installer\24d78db.msi : (Nero Core Components - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:08:46] - C:\WINDOWS\Installer\24d78e3.msi : (Nero 12 Disc Menus Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:08:33] - C:\WINDOWS\Installer\24d78eb.msi : (Nero 12 Kwik Themes Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:12:14] - C:\WINDOWS\Installer\24d78f3.msi : (Nero Burning ROM 15 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:10:48] - C:\WINDOWS\Installer\24d78fb.msi : (Nero 12 Effects Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:08:26] - C:\WINDOWS\Installer\24d7903.msi : (Nero 12 PiP Effects Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:08:22] - C:\WINDOWS\Installer\24d790b.msi : (Nero Prerequisites - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:07:21] - C:\WINDOWS\Installer\24d7913.msi : (Nero SharedVideoCodecs - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:11:22] - C:\WINDOWS\Installer\24d791b.msi : (Nero CoverDesigner - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:10:44] - C:\WINDOWS\Installer\24d7923.msi : (Nero Express 15 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:09:06] - C:\WINDOWS\Installer\24d792b.msi : (Nero MediaHome - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:07:39] - C:\WINDOWS\Installer\24d7933.msi : (Nero RescueAgent 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:07:46] - C:\WINDOWS\Installer\24d793b.msi : (Nero Recode 10 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:06:03] - C:\WINDOWS\Installer\24d7943.msi : (Nero Video 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:07:30] - C:\WINDOWS\Installer\24d794b.msi : (Nero 12 Video Samples - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:08:53] - C:\WINDOWS\Installer\24d7959.msi : (Nero Launcher - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:10:53] - C:\WINDOWS\Installer\24d7961.msi : (Nero Disc to Device - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:12:18] - C:\WINDOWS\Installer\24d7969.msi : (Nero BurningCore 15 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:10:38] - C:\WINDOWS\Installer\24d7971.msi : (Nero Info - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:11:17] - C:\WINDOWS\Installer\24d7979.msi : (Nero Device Updates - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:07:16] - C:\WINDOWS\Installer\24d7981.msi : (Nero Video 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:46:36] - C:\WINDOWS\Installer\26b86f3.msi : (Nero 2016 Content Pack - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:47:39] - C:\WINDOWS\Installer\26b86fa.msi : (Nero 12 Image Samples - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:48:42] - C:\WINDOWS\Installer\26b8702.msi : (Nero Family and Events Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:48:27] - C:\WINDOWS\Installer\26b870a.msi : (Nero Football (Soccer) Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:48:03] - C:\WINDOWS\Installer\26b8712.msi : (Nero Retro Film Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:47:50] - C:\WINDOWS\Installer\26b871a.msi : (Nero 12 PiP Effects 1 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:47:45] - C:\WINDOWS\Installer\26b8722.msi : (Nero Platinum Effects 12 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:47:29] - C:\WINDOWS\Installer\26b872a.msi : (Nero 12 Video Transitions 1 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:51:24] - C:\WINDOWS\Installer\26b8733.msi : (Nero 12 Cliparts - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:51:00] - C:\WINDOWS\Installer\26b873b.msi : (Nero 12 Disc Menus 1 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:50:09] - C:\WINDOWS\Installer\26b8743.msi : (Nero 12 Disc Menus 2 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:49:53] - C:\WINDOWS\Installer\26b874b.msi : (Nero 12 Disc Menus 3 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:49:35] - C:\WINDOWS\Installer\26b8753.msi : (Nero Abstract Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:49:14] - C:\WINDOWS\Installer\26b875b.msi : (Nero Holiday and Sports Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:47:27] - C:\WINDOWS\Installer\26b8764.msi : (Nero Update - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/07/2012 00:22:32] - C:\WINDOWS\Installer\2dfc7.msi : (Blank Project Template - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:54] - C:\WINDOWS\Installer\2dfcc.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:05:09] - C:\WINDOWS\Installer\2dfd2.msi : (AMD Catalyst Install Manager Installer (64 bit) - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 09:59:01] - C:\WINDOWS\Installer\2dfd7.msi : (Branding - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:01:33] - C:\WINDOWS\Installer\2dfdc.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:01:42] - C:\WINDOWS\Installer\2dfe1.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:01:46] - C:\WINDOWS\Installer\2dfe6.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:01:52] - C:\WINDOWS\Installer\2dfeb.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:01:58] - C:\WINDOWS\Installer\2dff0.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:04] - C:\WINDOWS\Installer\2dff5.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:11] - C:\WINDOWS\Installer\2dffa.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:16] - C:\WINDOWS\Installer\2dfff.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:20] - C:\WINDOWS\Installer\2e004.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:27] - C:\WINDOWS\Installer\2e009.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:33] - C:\WINDOWS\Installer\2e00e.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:37] - C:\WINDOWS\Installer\2e013.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:43] - C:\WINDOWS\Installer\2e018.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:47] - C:\WINDOWS\Installer\2e01d.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:52] - C:\WINDOWS\Installer\2e022.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:02:59] - C:\WINDOWS\Installer\2e027.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:03] - C:\WINDOWS\Installer\2e02c.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:10] - C:\WINDOWS\Installer\2e031.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:14] - C:\WINDOWS\Installer\2e036.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:20] - C:\WINDOWS\Installer\2e03b.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:26] - C:\WINDOWS\Installer\2e040.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:32] - C:\WINDOWS\Installer\2e045.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:36] - C:\WINDOWS\Installer\2e04a.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:03:44] - C:\WINDOWS\Installer\2e04f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:04:11] - C:\WINDOWS\Installer\2e054.msi : (Catalyst Control Center Utility 64 - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:01:24] - C:\WINDOWS\Installer\2e05a.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/08/2012 10:05:35] - C:\WINDOWS\Installer\2e05f.msi : (AMD Accelerated Parallel Processing SDK - Advanced Micro Devices Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/03/2013 01:20:47] - C:\WINDOWS\Installer\2e065.msi : (HP Support Assistant - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [01/06/2012 09:46:42] - C:\WINDOWS\Installer\2e06a.msi : (Blank Project Template - Hewlett-Packard Company) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/03/2013 01:24:47] - C:\WINDOWS\Installer\2e06f.msi : (Blank Project Template - Hewlett-Packard) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [31/07/2012 03:38:58] - C:\WINDOWS\Installer\2e073.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [16/07/2012 23:59:51] - C:\WINDOWS\Installer\2e086.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/08/2016 06:13:16] - C:\WINDOWS\Installer\39beec0.msi : (AccountService installation package - Essentware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/08/2016 06:13:53] - C:\WINDOWS\Installer\39beecc.msi : (PCKLang.fr - Essentware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/08/2016 06:14:01] - C:\WINDOWS\Installer\39beed2.msi : (PCKeeper antivirus installation package - Essentware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [20/08/2016 06:14:02] - C:\WINDOWS\Installer\39beed8.msi : (PCKAVLang.fr - Essentware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:24] - C:\WINDOWS\Installer\41372.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [11/11/2014 10:49:56] - C:\WINDOWS\Installer\41378.msi : (Branding - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:16] - C:\WINDOWS\Installer\4137e.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:22] - C:\WINDOWS\Installer\41384.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:30] - C:\WINDOWS\Installer\4138a.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:36] - C:\WINDOWS\Installer\41390.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:44] - C:\WINDOWS\Installer\41395.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:52] - C:\WINDOWS\Installer\4139b.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:00] - C:\WINDOWS\Installer\413a1.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:06] - C:\WINDOWS\Installer\413a7.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:16] - C:\WINDOWS\Installer\413ad.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:22] - C:\WINDOWS\Installer\413b3.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:30] - C:\WINDOWS\Installer\413b9.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:38] - C:\WINDOWS\Installer\413bf.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:46] - C:\WINDOWS\Installer\413c5.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:04:54] - C:\WINDOWS\Installer\413cb.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:02] - C:\WINDOWS\Installer\413d1.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:10] - C:\WINDOWS\Installer\413d7.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:18] - C:\WINDOWS\Installer\413dd.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:26] - C:\WINDOWS\Installer\413e3.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:34] - C:\WINDOWS\Installer\413e9.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:42] - C:\WINDOWS\Installer\413ef.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:50] - C:\WINDOWS\Installer\413f5.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:05:58] - C:\WINDOWS\Installer\413fb.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:06] - C:\WINDOWS\Installer\41401.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:06:40] - C:\WINDOWS\Installer\41407.msi : (Catalyst Control Center Utility 64 - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:07:30] - C:\WINDOWS\Installer\4140d.msi : (AMD Fuel - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/08/2015 20:03:12] - C:\WINDOWS\Installer\41413.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [21/08/2016 10:35:35] - C:\WINDOWS\Installer\47c523c.msi : (GFI LanGuard 12 Agent - GFI Software Development Ltd.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/06/2016 20:10:27] - C:\WINDOWS\Installer\4d2003.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [26/07/2011 20:36:38] - C:\WINDOWS\Installer\4d2009.msi : ( - DivX, Inc) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/06/2016 20:30:13] - C:\WINDOWS\Installer\4d200d.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/06/2016 20:33:02] - C:\WINDOWS\Installer\4d2011.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [27/06/2016 14:41:34] - C:\WINDOWS\Installer\4d2021.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [16/06/2016 23:22:41] - C:\WINDOWS\Installer\4d2025.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/06/2016 19:30:38] - C:\WINDOWS\Installer\4d202b.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/06/2016 21:25:01] - C:\WINDOWS\Installer\4d202f.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [21/08/2016 14:39:23] - C:\WINDOWS\Installer\541b829.msi : (GFI Directory - GFI Software Development Ltd) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/10/2015 17:40:16] - C:\WINDOWS\Installer\84518f.msi : (GFI WebMonitor 10 - GFI Software Ltd) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/08/2016 07:54:34] - [301040] - C:\WINDOWS\Installer\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:33:58] - [313328] - C:\WINDOWS\Installer\{05C6B128-1B40-4495-9CB9-090B368BFA0A}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:56] - [88102] - C:\WINDOWS\Installer\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:41] - [88102] - C:\WINDOWS\Installer\{07326A3E-02B3-1078-25D7-B8666BA8FE15}\ARPPRODUCTICON.exe () - () [05/03/2013 01:24:49] - [10134] - C:\WINDOWS\Installer\{07FA4960-B038-49EB-891B-9F95930AA544}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:34] - [88102] - C:\WINDOWS\Installer\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:08] - [88102] - C:\WINDOWS\Installer\{09BE17DC-59D2-FD28-371D-DCE0AE76CE75}\ARPPRODUCTICON.exe () - () [14/08/2016 22:18:42] - [143630] - C:\WINDOWS\Installer\{0c8ebb00-4909-459c-8347-b2068b7f0319}\ARPPRODUCTICON.exe () - () [05/03/2013 01:37:42] - [300318] - C:\WINDOWS\Installer\{0FA995CC-C849-4755-B14B-5404CC75DC24}\_853F67D554F05449430E7E.exe () - () [05/03/2013 01:20:03] - [88102] - C:\WINDOWS\Installer\{104D7F23-A414-EE6D-315E-A07CB75ADEEE}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:18] - [10134] - C:\WINDOWS\Installer\{11087D24-567D-7D88-69C6-D7A08B5F4C47}\ARPPRODUCTICON.exe () - () [21/08/2016 14:42:24] - [296952] - C:\WINDOWS\Installer\{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [21/08/2016 14:42:24] - [296952] - C:\WINDOWS\Installer\{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39}\GFIDIRShortcut_42A6C409841044B481894640EF7848A5.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [21/08/2016 14:42:24] - [47096] - C:\WINDOWS\Installer\{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39}\NewShortcut2_EB9043FBD83847689812616DD5B55278.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 08:00:13] - [313328] - C:\WINDOWS\Installer\{150D88F1-40AF-4678-A39D-BCE2332F34E5}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:02] - [88102] - C:\WINDOWS\Installer\{1A7CF3BE-0D4A-33DF-DFD9-824487726365}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:20] - [88102] - C:\WINDOWS\Installer\{1AD99E77-37CC-744E-39CA-67F6FD34565A}\ARPPRODUCTICON.exe () - () [19/08/2016 07:23:43] - [313328] - C:\WINDOWS\Installer\{1B6F5E51-575E-4693-BCA2-7543570D076D}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:32] - [88102] - C:\WINDOWS\Installer\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:04] - [88102] - C:\WINDOWS\Installer\{1BC4C58D-D726-172B-DA2C-BBE6AE5DEB76}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:11] - [88102] - C:\WINDOWS\Installer\{1E6AF4B4-0910-4821-CB20-F8FD7AA09CCB}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:36] - [88102] - C:\WINDOWS\Installer\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}\ARPPRODUCTICON.exe () - () [19/08/2016 07:58:03] - [313328] - C:\WINDOWS\Installer\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:48] - [88102] - C:\WINDOWS\Installer\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}\ARPPRODUCTICON.exe () - () [19/08/2016 07:58:21] - [313328] - C:\WINDOWS\Installer\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:24:32] - [313328] - C:\WINDOWS\Installer\{29F67D84-3A70-456E-806A-52301B02070B}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:37] - [88102] - C:\WINDOWS\Installer\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:16] - [88102] - C:\WINDOWS\Installer\{2E2526C8-51A8-F6EB-8289-6787E880CE27}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:16] - [88102] - C:\WINDOWS\Installer\{2E58F5E0-B5EF-844C-5B18-4C21F800CAD6}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:33] - [88102] - C:\WINDOWS\Installer\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:53] - [88102] - C:\WINDOWS\Installer\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}\ARPPRODUCTICON.exe () - () [21/08/2016 11:17:32] - [539760] - C:\WINDOWS\Installer\{38FCF27C-71A7-442D-A4AA-274C4394044C}\LanGuard.exe (Copyright © GFI Software) - (GFI LanGuard) [05/03/2013 01:25:52] - [74032] - C:\WINDOWS\Installer\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\ARPPRODUCTICON.exe () - () [19/08/2016 07:57:25] - [313320] - C:\WINDOWS\Installer\{4D25D881-7183-462F-95C8-990CA1944E0B}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:23] - [10134] - C:\WINDOWS\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe () - () [19/08/2016 08:00:43] - [313328] - C:\WINDOWS\Installer\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [20/08/2016 06:15:30] - [147479] - C:\WINDOWS\Installer\{5A4A7D29-7589-427B-86BC-8C313278BF89}\IconPCKAV.exe () - () [05/03/2013 01:20:06] - [88102] - C:\WINDOWS\Installer\{5AD25D5C-C813-146B-4FB0-76561F7875B7}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:09] - [88102] - C:\WINDOWS\Installer\{5B4886EE-5A95-C257-A68F-2DCADE47A273}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:12] - [88102] - C:\WINDOWS\Installer\{5DB58618-7021-C650-EE8A-58CD1FAA95F9}\ARPPRODUCTICON.exe () - () [19/08/2016 07:25:15] - [301392] - C:\WINDOWS\Installer\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:01] - [88102] - C:\WINDOWS\Installer\{5F5ACD0C-A454-32A7-E206-EE89B1510128}\ARPPRODUCTICON.exe () - () [05/03/2013 01:19:38] - [88102] - C:\WINDOWS\Installer\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}\ARPPRODUCTICON.exe () - () [05/03/2013 01:19:38] - [88102] - C:\WINDOWS\Installer\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}\NewShortcut2_3B1A0823966A48909E77539C330FBF6E.exe () - () [05/03/2013 01:19:38] - [88102] - C:\WINDOWS\Installer\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}\NewShortcut3_3B1A0823966A48909E77539C330FBF6E.exe () - () [05/03/2013 01:19:38] - [88102] - C:\WINDOWS\Installer\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}\NewShortcut4_3B1A0823966A48909E77539C330FBF6E.exe () - () [05/03/2013 01:19:38] - [88102] - C:\WINDOWS\Installer\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}\NewShortcut5_3B1A0823966A48909E77539C330FBF6E.exe () - () [19/08/2016 07:26:42] - [587760] - C:\WINDOWS\Installer\{60251665-84B4-41D6-84BF-6D50CE68DD08}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:16] - [88102] - C:\WINDOWS\Installer\{64D5A142-BD50-726E-ED9E-D2508D2A17E2}\ARPPRODUCTICON.exe () - () [19/08/2016 08:00:56] - [69632] - C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC.) - (InstallShield) [05/03/2013 01:20:11] - [88102] - C:\WINDOWS\Installer\{67087BB4-19B4-C169-3E52-2BED796D8AB3}\ARPPRODUCTICON.exe () - () [19/08/2016 07:33:29] - [587760] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:33:34] - [587760] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ScVisionDestop_7F7E5B0B4C2946E6A57D5A77942B7F3A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:33:32] - [587760] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ScVisionStartMenu_88036A9DCD1D412A84701A23A35FB37B.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:08] - [88102] - C:\WINDOWS\Installer\{6AE04BB9-A455-16ED-5806-DCFBB14505D6}\ARPPRODUCTICON.exe () - () [05/03/2013 01:24:44] - [53248] - C:\WINDOWS\Installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F}\ARPPRODUCTICON.exe (Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:23] - [88102] - C:\WINDOWS\Installer\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}\ARPPRODUCTICON.exe () - () [14/08/2016 22:14:58] - [143630] - C:\WINDOWS\Installer\{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB}\ARPPRODUCTICON.exe () - () [05/03/2013 01:19:59] - [10134] - C:\WINDOWS\Installer\{7474548C-E456-4818-8ED0-4A1F00EF77A1}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:04] - [88102] - C:\WINDOWS\Installer\{76DFBEB9-9E55-8CC6-B99A-9CEFAC573A1F}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:54] - [88102] - C:\WINDOWS\Installer\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}\ARPPRODUCTICON.exe () - () [19/08/2016 07:56:18] - [313328] - C:\WINDOWS\Installer\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:28:27] - [190448] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\NeroKwikMedia._63C8A7B0BBE5459F9AC436392B2FF50D.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:28:33] - [190448] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\ScKwikMediaDesk_DAE4ED9540AC4C38962344CC52ED8A73.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:28:29] - [190448] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\ScKwikMediaStar_594597E2768645E1995B7F203ACC4488.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:28:31] - [194544] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\ScMediaBrowser_9BF9A3F46C13407797C1395E985F61EA.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:29:05] - [587760] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:29:07] - [587760] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\NeroRescueAgent.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:29:10] - [587752] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\ScRescueAgentStart_322CFA6F80AB4438A8748366873E3688.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:38] - [88102] - C:\WINDOWS\Installer\{82CA1714-13EA-F419-91FE-12834424745E}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:00] - [88102] - C:\WINDOWS\Installer\{839D1577-5415-6C89-6642-515DFFE6432F}\ARPPRODUCTICON.exe () - () [19/08/2016 07:57:01] - [313328] - C:\WINDOWS\Installer\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:07] - [88102] - C:\WINDOWS\Installer\{84B13BF6-F7AF-198E-0E77-DCA4027B9D19}\ARPPRODUCTICON.exe () - () [19/08/2016 07:57:46] - [313328] - C:\WINDOWS\Installer\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:52] - [88102] - C:\WINDOWS\Installer\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}\ARPPRODUCTICON.exe () - () [21/08/2016 14:51:26] - [59376] - C:\WINDOWS\Installer\{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [21/08/2016 14:51:27] - [141296] - C:\WINDOWS\Installer\{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464}\NewShortcut11_1C7C7563584B48F88ED32DA671EC0FBB.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 21:36:14] - [291445] - C:\WINDOWS\Installer\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:49] - [88102] - C:\WINDOWS\Installer\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}\ARPPRODUCTICON.exe () - () [19/08/2016 07:26:23] - [587760] - C:\WINDOWS\Installer\{92EBE575-0C6E-4713-B095-34BB927E5AC6}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:55:47] - [313328] - C:\WINDOWS\Installer\{955BF340-C379-4375-AA2F-F3BCB2A498AB}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:21:50] - [301040] - C:\WINDOWS\Installer\{9C637A56-4287-487F-95BF-1422FC1AA879}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 09:59:44] - [88102] - C:\WINDOWS\Installer\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:13] - [88102] - C:\WINDOWS\Installer\{A666A6E7-3A51-E289-559B-BF3486036ABF}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:50] - [88102] - C:\WINDOWS\Installer\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}\ARPPRODUCTICON.exe () - () [05/03/2013 01:19:36] - [88102] - C:\WINDOWS\Installer\{ABA39912-380C-0EF3-C820-868115EB1DAC}\ARPPRODUCTICON.exe () - () [19/08/2016 07:22:19] - [587760] - C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:22:22] - [587752] - C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ScControlCenterSta_FC2653898C5047A6A872CAF6433C43A8.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:03] - [88102] - C:\WINDOWS\Installer\{AC7A441A-353F-75F6-6ABA-3BF98161B530}\ARPPRODUCTICON.exe () - () [19/08/2016 07:24:53] - [313328] - C:\WINDOWS\Installer\{ACE49D50-19CD-44A6-B192-46F985283B26}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 21:47:39] - [75223] - C:\WINDOWS\Installer\{ADD5DB49-72CF-11D8-9D75-000129760D75}\ARPPRODUCTICON.exe () - () [14/08/2016 10:00:11] - [88102] - C:\WINDOWS\Installer\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}\ARPPRODUCTICON.exe () - () [19/08/2016 07:30:24] - [301040] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:30:26] - [301040] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ScRecodeStartMenu1_729B957FFE3C40528A62D7F32390F7C3.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:30:25] - [301040] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ScRecodeStartMenu_563A75F05683422E8C558ED3B6DA617D.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:05] - [88102] - C:\WINDOWS\Installer\{B6480ED1-448E-813B-4FE0-BED811D1C01F}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:46] - [88102] - C:\WINDOWS\Installer\{B839153C-D4D2-F89C-5033-0A160C62706B}\ARPPRODUCTICON.exe () - () [19/08/2016 07:35:27] - [206832] - C:\WINDOWS\Installer\{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}\ScDisc2DeviceStart_31C5D7D15DA846FBB6553A0819A0C381.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:00] - [88102] - C:\WINDOWS\Installer\{BDBF9803-B57C-AB2A-8830-CBED34703840}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:09] - [88102] - C:\WINDOWS\Installer\{BFB6DE5F-9BEA-1FBB-3584-2C78639CE59A}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:40] - [88102] - C:\WINDOWS\Installer\{C1EA3764-1138-AE27-AD63-549BAD99BA15}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:21] - [88102] - C:\WINDOWS\Installer\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}\ARPPRODUCTICON.exe () - () [19/08/2016 07:54:56] - [313328] - C:\WINDOWS\Installer\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:29:54] - [79345] - C:\WINDOWS\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:43] - [88102] - C:\WINDOWS\Installer\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}\ARPPRODUCTICON.exe () - () [19/08/2016 07:59:59] - [313328] - C:\WINDOWS\Installer\{CE675FBD-75C3-45F1-B6AF-8D250861D536}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:24:02] - [587760] - C:\WINDOWS\Installer\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 22:19:23] - [70668] - C:\WINDOWS\Installer\{D36DD326-7280-11D8-97C8-000129760CBE}\ARPPRODUCTICON.exe () - () [14/08/2016 22:08:37] - [138560] - C:\WINDOWS\Installer\{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:06] - [88102] - C:\WINDOWS\Installer\{DD35ECFB-5C95-398B-CAFA-B5E8881363C3}\ARPPRODUCTICON.exe () - () [05/03/2013 01:43:25] - [297086] - C:\WINDOWS\Installer\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\ARPPRODUCTICON.exe () - () [19/08/2016 07:23:19] - [313328] - C:\WINDOWS\Installer\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [14/08/2016 21:48:42] - [82613] - C:\WINDOWS\Installer\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:58] - [4846] - C:\WINDOWS\Installer\{E7366CA8-7179-77AE-E712-BA18D70A0A07}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:45] - [88102] - C:\WINDOWS\Installer\{E817E580-6318-AFC8-2102-322C73117EC4}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:20] - [88102] - C:\WINDOWS\Installer\{E8406BA9-5D47-4A62-08C3-759EA677229A}\ARPPRODUCTICON.exe () - () [19/08/2016 07:58:39] - [313328] - C:\WINDOWS\Installer\{EEBF1676-AF87-4266-93D8-0C14A34C4217}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:34:37] - [296944] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:34:38] - [296944] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\NeroLauncher.ex_06255901E67449719980557FAA5EC1C6.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:34:39] - [296944] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\NeroLauncher.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [19/08/2016 07:36:39] - [296944] - C:\WINDOWS\Installer\{F030BFE8-8476-4C08-A553-233DE80A2BE1}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:20:14] - [88102] - C:\WINDOWS\Installer\{F193812F-83C0-3CED-1EDE-BE2525267303}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:13] - [88102] - C:\WINDOWS\Installer\{F754BC24-2C04-F76E-C403-0175F0954560}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:24] - [88102] - C:\WINDOWS\Installer\{F77474EE-EB6C-C87B-88AF-3310C848E068}\ARPPRODUCTICON.exe () - () [14/08/2016 09:59:22] - [88102] - C:\WINDOWS\Installer\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}\ARPPRODUCTICON.exe () - () [05/03/2013 01:20:10] - [88102] - C:\WINDOWS\Installer\{FC62C740-2339-618C-467B-36CE6D409E5F}\ARPPRODUCTICON.exe () - () [19/08/2016 07:59:37] - [313328] - C:\WINDOWS\Installer\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:23:32] - [98304] - C:\WINDOWS\Installer\{FF27F674-821E-4BA2-985B-DDF539C2CD03}\ARPPRODUCTICON.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:23:32] - [98304] - C:\WINDOWS\Installer\{FF27F674-821E-4BA2-985B-DDF539C2CD03}\HPSF.exe2_2EBA634C3DB04BEC8765F065A06AB6AA.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) [05/03/2013 01:23:32] - [98304] - C:\WINDOWS\Installer\{FF27F674-821E-4BA2-985B-DDF539C2CD03}\NewShortcut2_06EDE08E9D6342F1AC2C30BC31ED1770.exe (Copyright (C) 2009 Acresso Software Inc. and/or InstallShield Co. Inc.) - (InstallShield) ---------- | %System%\*.in* [16/07/2016 13:43:16] - [4988] - C:\WINDOWS\System32\delegwiz.inf [16/07/2016 13:43:08] - [3458] - C:\WINDOWS\System32\ieuinit.inf [26/10/2012 16:42:24] - [29494] - C:\WINDOWS\System32\lvcoin64.ini [14/08/2016 10:03:20] - [2641970] - C:\WINDOWS\System32\PerfStringBackup.INI [16/07/2016 13:42:39] - [60124] - C:\WINDOWS\System32\tcpmon.ini [16/07/2016 13:42:11] - [2307] - C:\WINDOWS\System32\WimBootCompress.ini [16/07/2016 13:43:59] - [3458] - C:\WINDOWS\Syswow64\ieuinit.inf [14/08/2016 10:03:11] - [2307378] - C:\WINDOWS\Syswow64\PerfStringBackup.INI [16/07/2016 13:42:43] - [2307] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | [.NET v2.0] [21/08/2016 11:27:47] - |HD| - [1265058] - C:\Users\.NET v2.0\AppData [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Application Data [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Cookies [21/08/2016 11:27:46] - |RD| - [0] - C:\Users\.NET v2.0\Desktop [21/08/2016 11:27:39] - |RD| - [204484211] - C:\Users\.NET v2.0\Documents [21/08/2016 11:27:39] - |RD| - [0] - C:\Users\.NET v2.0\Downloads [21/08/2016 11:27:39] - |RD| - [1277] - C:\Users\.NET v2.0\Favorites [21/08/2016 11:27:39] - |RD| - [0] - C:\Users\.NET v2.0\Links [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Local Settings [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Menu Démarrer [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Mes documents [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Modèles [21/08/2016 11:27:39] - |RD| - [0] - C:\Users\.NET v2.0\Music [21/08/2016 11:27:39] - |AH| - [262144] - C:\Users\.NET v2.0\NTUSER.DAT [21/08/2016 11:28:20] - |ASH| - [8192] - C:\Users\.NET v2.0\ntuser.dat.LOG1 [21/08/2016 11:28:20] - |ASH| - [0] - C:\Users\.NET v2.0\ntuser.dat.LOG2 [21/08/2016 11:28:20] - |ASH| - [65536] - C:\Users\.NET v2.0\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [21/08/2016 11:28:20] - |ASH| - [524288] - C:\Users\.NET v2.0\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [21/08/2016 11:28:20] - |ASH| - [524288] - C:\Users\.NET v2.0\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [21/08/2016 11:28:21] - |ASH| - [20] - C:\Users\.NET v2.0\ntuser.ini [21/08/2016 11:27:39] - |RD| - [0] - C:\Users\.NET v2.0\Pictures [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Recent [21/08/2016 11:27:39] - |D| - [0] - C:\Users\.NET v2.0\Saved Games [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\SendTo [21/08/2016 11:27:39] - |RD| - [0] - C:\Users\.NET v2.0\Videos [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Voisinage d'impression [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\Voisinage réseau [21/08/2016 11:27:47] - |SD| - [23212] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\AppData\Local\Application Data [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\AppData\Local\Historique [21/08/2016 11:27:47] - |D| - [1241846] - C:\Users\.NET v2.0\AppData\Local\Microsoft [21/08/2016 11:27:47] - |D| - [0] - C:\Users\.NET v2.0\AppData\Local\Temp [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\AppData\Local\Temporary Internet Files [21/08/2016 11:28:21] - |SHD| - [0] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [21/08/2016 11:27:47] - |D| - [19158] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [21/08/2016 11:27:47] - |RD| - [3888] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [21/08/2016 11:27:47] - |RD| - [1486] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 11:27:47] - |D| - [170] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 11:27:47] - |RD| - [6376] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 11:27:47] - |RD| - [7238] - C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [.NET v2.0 Classic] [21/08/2016 11:25:13] - |HD| - [1265058] - C:\Users\.NET v2.0 Classic\AppData [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Application Data [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Cookies [21/08/2016 11:25:13] - |RD| - [0] - C:\Users\.NET v2.0 Classic\Desktop [21/08/2016 11:25:08] - |RD| - [204484211] - C:\Users\.NET v2.0 Classic\Documents [21/08/2016 11:25:08] - |RD| - [0] - C:\Users\.NET v2.0 Classic\Downloads [21/08/2016 11:25:08] - |RD| - [1277] - C:\Users\.NET v2.0 Classic\Favorites [21/08/2016 11:25:08] - |RD| - [0] - C:\Users\.NET v2.0 Classic\Links [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Local Settings [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Menu Démarrer [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Mes documents [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Modèles [21/08/2016 11:25:08] - |RD| - [0] - C:\Users\.NET v2.0 Classic\Music [21/08/2016 11:25:08] - |AH| - [262144] - C:\Users\.NET v2.0 Classic\NTUSER.DAT [21/08/2016 11:27:29] - |ASH| - [8192] - C:\Users\.NET v2.0 Classic\ntuser.dat.LOG1 [21/08/2016 11:27:29] - |ASH| - [0] - C:\Users\.NET v2.0 Classic\ntuser.dat.LOG2 [21/08/2016 11:27:29] - |ASH| - [65536] - C:\Users\.NET v2.0 Classic\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [21/08/2016 11:27:29] - |ASH| - [524288] - C:\Users\.NET v2.0 Classic\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [21/08/2016 11:27:29] - |ASH| - [524288] - C:\Users\.NET v2.0 Classic\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [21/08/2016 11:27:29] - |ASH| - [20] - C:\Users\.NET v2.0 Classic\ntuser.ini [21/08/2016 11:25:08] - |RD| - [0] - C:\Users\.NET v2.0 Classic\Pictures [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Recent [21/08/2016 11:25:08] - |D| - [0] - C:\Users\.NET v2.0 Classic\Saved Games [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\SendTo [21/08/2016 11:25:08] - |RD| - [0] - C:\Users\.NET v2.0 Classic\Videos [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Voisinage d'impression [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\Voisinage réseau [21/08/2016 11:25:13] - |SD| - [23212] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\AppData\Local\Application Data [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\AppData\Local\Historique [21/08/2016 11:25:13] - |D| - [1241846] - C:\Users\.NET v2.0 Classic\AppData\Local\Microsoft [21/08/2016 11:25:13] - |D| - [0] - C:\Users\.NET v2.0 Classic\AppData\Local\Temp [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\AppData\Local\Temporary Internet Files [21/08/2016 11:27:29] - |SHD| - [0] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [21/08/2016 11:25:13] - |D| - [19158] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [21/08/2016 11:25:13] - |RD| - [3888] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [21/08/2016 11:25:13] - |RD| - [1486] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 11:25:13] - |D| - [170] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 11:25:13] - |RD| - [6376] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 11:25:13] - |RD| - [7238] - C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [.NET v4.5] [21/08/2016 11:42:06] - |HD| - [1265058] - C:\Users\.NET v4.5\AppData [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Application Data [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Cookies [21/08/2016 11:42:06] - |RD| - [0] - C:\Users\.NET v4.5\Desktop [21/08/2016 11:41:59] - |RD| - [204484211] - C:\Users\.NET v4.5\Documents [21/08/2016 11:41:59] - |RD| - [0] - C:\Users\.NET v4.5\Downloads [21/08/2016 11:41:59] - |RD| - [1277] - C:\Users\.NET v4.5\Favorites [21/08/2016 11:41:59] - |RD| - [0] - C:\Users\.NET v4.5\Links [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Local Settings [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Menu Démarrer [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Mes documents [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Modèles [21/08/2016 11:41:59] - |RD| - [0] - C:\Users\.NET v4.5\Music [21/08/2016 11:41:59] - |AH| - [262144] - C:\Users\.NET v4.5\NTUSER.DAT [21/08/2016 11:42:28] - |ASH| - [8192] - C:\Users\.NET v4.5\ntuser.dat.LOG1 [21/08/2016 11:42:28] - |ASH| - [0] - C:\Users\.NET v4.5\ntuser.dat.LOG2 [21/08/2016 11:42:28] - |ASH| - [65536] - C:\Users\.NET v4.5\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [21/08/2016 11:42:28] - |ASH| - [524288] - C:\Users\.NET v4.5\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [21/08/2016 11:42:28] - |ASH| - [524288] - C:\Users\.NET v4.5\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [21/08/2016 11:42:29] - |ASH| - [20] - C:\Users\.NET v4.5\ntuser.ini [21/08/2016 11:41:59] - |RD| - [0] - C:\Users\.NET v4.5\Pictures [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Recent [21/08/2016 11:41:59] - |D| - [0] - C:\Users\.NET v4.5\Saved Games [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\SendTo [21/08/2016 11:41:59] - |RD| - [0] - C:\Users\.NET v4.5\Videos [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Voisinage d'impression [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\Voisinage réseau [21/08/2016 11:42:06] - |SD| - [23212] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\AppData\Local\Application Data [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\AppData\Local\Historique [21/08/2016 11:42:06] - |D| - [1241846] - C:\Users\.NET v4.5\AppData\Local\Microsoft [21/08/2016 11:42:06] - |D| - [0] - C:\Users\.NET v4.5\AppData\Local\Temp [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\AppData\Local\Temporary Internet Files [21/08/2016 11:42:29] - |SHD| - [0] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [21/08/2016 11:42:06] - |D| - [19158] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [21/08/2016 11:42:06] - |RD| - [3888] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [21/08/2016 11:42:06] - |RD| - [1486] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 11:42:06] - |D| - [170] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 11:42:06] - |RD| - [6376] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 11:42:06] - |RD| - [7238] - C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [.NET v4.5 Classic] [21/08/2016 11:40:36] - |HD| - [1265058] - C:\Users\.NET v4.5 Classic\AppData [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Application Data [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Cookies [21/08/2016 11:40:36] - |RD| - [0] - C:\Users\.NET v4.5 Classic\Desktop [21/08/2016 11:40:28] - |RD| - [204484211] - C:\Users\.NET v4.5 Classic\Documents [21/08/2016 11:40:28] - |RD| - [0] - C:\Users\.NET v4.5 Classic\Downloads [21/08/2016 11:40:28] - |RD| - [1277] - C:\Users\.NET v4.5 Classic\Favorites [21/08/2016 11:40:28] - |RD| - [0] - C:\Users\.NET v4.5 Classic\Links [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Local Settings [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Menu Démarrer [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Mes documents [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Modèles [21/08/2016 11:40:28] - |RD| - [0] - C:\Users\.NET v4.5 Classic\Music [21/08/2016 11:40:28] - |AH| - [262144] - C:\Users\.NET v4.5 Classic\NTUSER.DAT [21/08/2016 11:41:42] - |ASH| - [8192] - C:\Users\.NET v4.5 Classic\ntuser.dat.LOG1 [21/08/2016 11:41:42] - |ASH| - [0] - C:\Users\.NET v4.5 Classic\ntuser.dat.LOG2 [21/08/2016 11:41:42] - |ASH| - [65536] - C:\Users\.NET v4.5 Classic\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [21/08/2016 11:41:42] - |ASH| - [524288] - C:\Users\.NET v4.5 Classic\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [21/08/2016 11:41:42] - |ASH| - [524288] - C:\Users\.NET v4.5 Classic\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [21/08/2016 11:41:42] - |ASH| - [20] - C:\Users\.NET v4.5 Classic\ntuser.ini [21/08/2016 11:40:28] - |RD| - [0] - C:\Users\.NET v4.5 Classic\Pictures [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Recent [21/08/2016 11:40:28] - |D| - [0] - C:\Users\.NET v4.5 Classic\Saved Games [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\SendTo [21/08/2016 11:40:28] - |RD| - [0] - C:\Users\.NET v4.5 Classic\Videos [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Voisinage d'impression [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\Voisinage réseau [21/08/2016 11:40:36] - |SD| - [23212] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\AppData\Local\Application Data [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\AppData\Local\Historique [21/08/2016 11:40:37] - |D| - [1241846] - C:\Users\.NET v4.5 Classic\AppData\Local\Microsoft [21/08/2016 11:40:37] - |D| - [0] - C:\Users\.NET v4.5 Classic\AppData\Local\Temp [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\AppData\Local\Temporary Internet Files [21/08/2016 11:41:42] - |SHD| - [0] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [21/08/2016 11:40:36] - |D| - [19158] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [21/08/2016 11:40:36] - |RD| - [3888] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [21/08/2016 11:40:36] - |RD| - [1486] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 11:40:36] - |D| - [170] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 11:40:36] - |RD| - [6376] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 11:40:36] - |RD| - [7238] - C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [Classic .NET AppPool] [21/08/2016 11:24:02] - |HD| - [1265058] - C:\Users\Classic .NET AppPool\AppData [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Application Data [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Cookies [21/08/2016 11:24:02] - |RD| - [0] - C:\Users\Classic .NET AppPool\Desktop [21/08/2016 11:23:58] - |RD| - [204484211] - C:\Users\Classic .NET AppPool\Documents [21/08/2016 11:23:58] - |RD| - [0] - C:\Users\Classic .NET AppPool\Downloads [21/08/2016 11:23:58] - |RD| - [1277] - C:\Users\Classic .NET AppPool\Favorites [21/08/2016 11:23:58] - |RD| - [0] - C:\Users\Classic .NET AppPool\Links [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Local Settings [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Menu Démarrer [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Mes documents [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Modèles [21/08/2016 11:23:58] - |RD| - [0] - C:\Users\Classic .NET AppPool\Music [21/08/2016 11:23:58] - |AH| - [262144] - C:\Users\Classic .NET AppPool\NTUSER.DAT [21/08/2016 11:25:05] - |ASH| - [8192] - C:\Users\Classic .NET AppPool\ntuser.dat.LOG1 [21/08/2016 11:25:05] - |ASH| - [0] - C:\Users\Classic .NET AppPool\ntuser.dat.LOG2 [21/08/2016 11:25:05] - |ASH| - [65536] - C:\Users\Classic .NET AppPool\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [21/08/2016 11:25:05] - |ASH| - [524288] - C:\Users\Classic .NET AppPool\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [21/08/2016 11:25:05] - |ASH| - [524288] - C:\Users\Classic .NET AppPool\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [21/08/2016 11:25:06] - |ASH| - [20] - C:\Users\Classic .NET AppPool\ntuser.ini [21/08/2016 11:23:58] - |RD| - [0] - C:\Users\Classic .NET AppPool\Pictures [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Recent [21/08/2016 11:23:58] - |D| - [0] - C:\Users\Classic .NET AppPool\Saved Games [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\SendTo [21/08/2016 11:23:58] - |RD| - [0] - C:\Users\Classic .NET AppPool\Videos [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Voisinage d'impression [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\Voisinage réseau [21/08/2016 11:24:02] - |SD| - [23212] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\AppData\Local\Application Data [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\AppData\Local\Historique [21/08/2016 11:24:02] - |D| - [1241846] - C:\Users\Classic .NET AppPool\AppData\Local\Microsoft [21/08/2016 11:24:02] - |D| - [0] - C:\Users\Classic .NET AppPool\AppData\Local\Temp [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\AppData\Local\Temporary Internet Files [21/08/2016 11:25:06] - |SHD| - [0] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [21/08/2016 11:24:02] - |D| - [19158] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [21/08/2016 11:24:02] - |RD| - [3888] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [21/08/2016 11:24:02] - |RD| - [1486] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 11:24:02] - |D| - [170] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 11:24:02] - |RD| - [6376] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 11:24:02] - |RD| - [7238] - C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [GFIDIRECTORY_ADMIN] [21/08/2016 14:42:42] - |HD| - [1380441] - C:\Users\GFIDIRECTORY_ADMIN\AppData [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Application Data [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Cookies [21/08/2016 14:42:42] - |RD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Desktop [21/08/2016 14:42:39] - |RD| - [204484211] - C:\Users\GFIDIRECTORY_ADMIN\Documents [21/08/2016 14:42:39] - |RD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Downloads [21/08/2016 14:42:39] - |RD| - [1277] - C:\Users\GFIDIRECTORY_ADMIN\Favorites [21/08/2016 14:42:39] - |RD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Links [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Local Settings [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Menu Démarrer [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Mes documents [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Modèles [21/08/2016 14:42:39] - |RD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Music [21/08/2016 14:42:39] - |AH| - [262144] - C:\Users\GFIDIRECTORY_ADMIN\NTUSER.DAT [21/08/2016 14:43:26] - |ASH| - [104448] - C:\Users\GFIDIRECTORY_ADMIN\ntuser.dat.LOG1 [21/08/2016 14:43:26] - |ASH| - [73728] - C:\Users\GFIDIRECTORY_ADMIN\ntuser.dat.LOG2 [21/08/2016 14:43:26] - |ASH| - [65536] - C:\Users\GFIDIRECTORY_ADMIN\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [21/08/2016 14:43:26] - |ASH| - [524288] - C:\Users\GFIDIRECTORY_ADMIN\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [21/08/2016 14:43:26] - |ASH| - [524288] - C:\Users\GFIDIRECTORY_ADMIN\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [21/08/2016 14:43:27] - |SH| - [20] - C:\Users\GFIDIRECTORY_ADMIN\ntuser.ini [21/08/2016 14:42:39] - |RD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Pictures [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Recent [21/08/2016 14:42:39] - |D| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Saved Games [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\SendTo [21/08/2016 14:42:39] - |RD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Videos [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Voisinage d'impression [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\Voisinage réseau [21/08/2016 14:42:42] - |SD| - [23212] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Local\Application Data [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Local\Historique [21/08/2016 14:42:42] - |D| - [1357229] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Local\Microsoft [21/08/2016 14:42:42] - |D| - [0] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Local\Temp [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Local\Temporary Internet Files [21/08/2016 14:43:27] - |SHD| - [0] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [21/08/2016 14:42:42] - |D| - [19158] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [21/08/2016 14:42:42] - |RD| - [3888] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [21/08/2016 14:42:42] - |RD| - [1486] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 14:42:42] - |D| - [170] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 14:42:42] - |RD| - [6376] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 14:42:42] - |RD| - [7238] - C:\Users\GFIDIRECTORY_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [Jean-Marie] [18/08/2016 17:04:09] - |D| - [0] - C:\Users\Jean-Marie\.MCTranscodingSDK [14/08/2016 10:04:21] - |HD| - [3796531770] - C:\Users\Jean-Marie\AppData [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Application Data [13/08/2016 16:32:00] - |RD| - [412] - C:\Users\Jean-Marie\Contacts [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Cookies [13/08/2016 16:29:36] - |RD| - [30505517] - C:\Users\Jean-Marie\Desktop [13/08/2016 16:29:35] - |RD| - [601724576] - C:\Users\Jean-Marie\Documents [13/08/2016 16:29:35] - |RD| - [76500144] - C:\Users\Jean-Marie\Downloads [13/08/2016 16:29:35] - |RD| - [2194] - C:\Users\Jean-Marie\Favorites [13/08/2016 16:29:35] - |RD| - [2528] - C:\Users\Jean-Marie\Links [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Local Settings [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Menu Démarrer [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Mes documents [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Modèles [13/08/2016 16:29:35] - |RD| - [504] - C:\Users\Jean-Marie\Music [14/08/2016 10:04:20] - |AH| - [3145728] - C:\Users\Jean-Marie\ntuser.dat [14/08/2016 10:04:21] - |ASH| - [524288] - C:\Users\Jean-Marie\ntuser.dat.log1 [14/08/2016 10:04:21] - |ASH| - [638976] - C:\Users\Jean-Marie\ntuser.dat.log2 [14/08/2016 10:04:21] - |ASH| - [65536] - C:\Users\Jean-Marie\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TM.blf [14/08/2016 10:04:21] - |ASH| - [524288] - C:\Users\Jean-Marie\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000001.regtrans-ms [14/08/2016 10:04:21] - |ASH| - [524288] - C:\Users\Jean-Marie\NTUSER.DAT{bb66ff8e-61fc-11e6-a6ed-8c297c7ed1fc}.TMContainer00000000000000000002.regtrans-ms [18/08/2016 08:14:19] - |ASH| - [65536] - C:\Users\Jean-Marie\ntuser.dat{d7270acb-650a-11e6-be77-4c72b9f956a2}.TM.blf [18/08/2016 08:14:19] - |ASH| - [524288] - C:\Users\Jean-Marie\ntuser.dat{d7270acb-650a-11e6-be77-4c72b9f956a2}.TMContainer00000000000000000001.regtrans-ms [18/08/2016 08:14:19] - |ASH| - [524288] - C:\Users\Jean-Marie\ntuser.dat{d7270acb-650a-11e6-be77-4c72b9f956a2}.TMContainer00000000000000000002.regtrans-ms [14/08/2016 10:27:18] - |SH| - [20] - C:\Users\Jean-Marie\ntuser.ini [13/08/2016 22:49:56] - |RD| - [4803020652] - C:\Users\Jean-Marie\OneDrive [13/08/2016 16:29:35] - |RD| - [13618520] - C:\Users\Jean-Marie\Pictures [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Recent [13/08/2016 16:29:35] - |RD| - [282] - C:\Users\Jean-Marie\Saved Games [13/08/2016 16:32:00] - |RD| - [1875] - C:\Users\Jean-Marie\Searches [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\SendTo [13/08/2016 16:29:35] - |RD| - [694] - C:\Users\Jean-Marie\Videos [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Voisinage d'impression [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\Voisinage réseau [21/08/2016 10:02:06] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Acronis [13/08/2016 16:31:55] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Adobe [21/08/2016 20:40:10] - |D| - [1036] - C:\Users\Jean-Marie\AppData\Roaming\ArcticLine [13/08/2016 16:34:12] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\ATI [17/08/2016 13:46:54] - |D| - [17433587] - C:\Users\Jean-Marie\AppData\Roaming\AVAST Software [14/08/2016 21:36:21] - |D| - [190308291] - C:\Users\Jean-Marie\AppData\Roaming\CyberLink [17/08/2016 14:22:28] - |D| - [645772] - C:\Users\Jean-Marie\AppData\Roaming\DivX [19/08/2016 06:37:19] - |D| - [196] - C:\Users\Jean-Marie\AppData\Roaming\IObit [20/08/2016 20:51:38] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\iolo [14/08/2016 11:01:04] - |D| - [492] - C:\Users\Jean-Marie\AppData\Roaming\Macromedia [14/08/2016 10:04:21] - |SD| - [1582878] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft [14/08/2016 18:48:42] - |D| - [20] - C:\Users\Jean-Marie\AppData\Roaming\Mozilla [21/08/2016 09:52:41] - |D| - [318114] - C:\Users\Jean-Marie\AppData\Roaming\Nero [14/08/2016 21:56:21] - |D| - [48932] - C:\Users\Jean-Marie\AppData\Roaming\proDAD [22/08/2016 09:05:07] - |D| - [17516] - C:\Users\Jean-Marie\AppData\Roaming\ProductData [18/08/2016 08:19:27] - |D| - [77] - C:\Users\Jean-Marie\AppData\Roaming\Skype [19/08/2016 13:28:34] - |D| - [945507] - C:\Users\Jean-Marie\AppData\Roaming\TeraCopy [21/08/2016 08:57:04] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Wise Euask [21/08/2016 20:42:14] - |D| - [5684737] - C:\Users\Jean-Marie\AppData\Roaming\ZHP [14/08/2016 06:32:55] - |D| - [19533] - C:\Users\Jean-Marie\AppData\Local\AMD [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\AppData\Local\Application Data [13/08/2016 16:34:12] - |D| - [68104] - C:\Users\Jean-Marie\AppData\Local\ATI [18/08/2016 11:56:51] - |D| - [2348146] - C:\Users\Jean-Marie\AppData\Local\Avanquest [17/08/2016 14:52:46] - |D| - [24576] - C:\Users\Jean-Marie\AppData\Local\AVAST Software [17/08/2016 13:57:51] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\CEF [20/08/2016 20:58:15] - |D| - [40] - C:\Users\Jean-Marie\AppData\Local\Chromium [13/08/2016 22:42:12] - |D| - [20996200] - C:\Users\Jean-Marie\AppData\Local\Comms [14/08/2016 10:27:21] - |D| - [256790] - C:\Users\Jean-Marie\AppData\Local\ConnectedDevicesPlatform [14/08/2016 19:15:33] - |D| - [7634999] - C:\Users\Jean-Marie\AppData\Local\CrashDumps [14/08/2016 21:36:20] - |D| - [12726877] - C:\Users\Jean-Marie\AppData\Local\CyberLink [17/08/2016 16:02:21] - |D| - [469192] - C:\Users\Jean-Marie\AppData\Local\Diagnostics [21/08/2016 10:25:26] - |D| - [470781] - C:\Users\Jean-Marie\AppData\Local\ElevatedDiagnostics [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\AppData\Local\Historique [20/08/2016 14:09:33] - |AH| - [52578] - C:\Users\Jean-Marie\AppData\Local\IconCache.db [14/08/2016 10:04:21] - |D| - [556996899] - C:\Users\Jean-Marie\AppData\Local\Microsoft [14/08/2016 07:36:04] - |D| - [86845] - C:\Users\Jean-Marie\AppData\Local\MicrosoftEdge [23/08/2016 08:53:29] - |D| - [6930] - C:\Users\Jean-Marie\AppData\Local\Mozilla [21/08/2016 09:56:05] - |D| - [380701] - C:\Users\Jean-Marie\AppData\Local\Nero [13/08/2016 16:30:03] - |D| - [86990504] - C:\Users\Jean-Marie\AppData\Local\Packages [15/08/2016 12:59:33] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\PeerDistRepub [14/08/2016 22:22:31] - |D| - [40960] - C:\Users\Jean-Marie\AppData\Local\Power2Go10 [13/08/2016 16:33:02] - |D| - [40960] - C:\Users\Jean-Marie\AppData\Local\Power2Go8 [14/08/2016 07:33:17] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Programs [13/08/2016 22:45:33] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Publishers [22/08/2016 08:16:41] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Systweak [14/08/2016 10:04:21] - |D| - [2627747080] - C:\Users\Jean-Marie\AppData\Local\Temp [14/08/2016 10:04:21] - |SHD| - [0] - C:\Users\Jean-Marie\AppData\Local\Temporary Internet Files [13/08/2016 22:41:24] - |D| - [11952128] - C:\Users\Jean-Marie\AppData\Local\TileDataLayer [14/08/2016 19:37:27] - |D| - [2560] - C:\Users\Jean-Marie\AppData\Local\Turbo View & Convert [22/08/2016 11:52:59] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\uTorrent [14/08/2016 18:53:14] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\uTorrent.BackupByuTorrentPortable [13/08/2016 16:30:06] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\VirtualStore [20/08/2016 20:58:16] - |D| - [249297697] - C:\Users\Jean-Marie\AppData\Local\Vivaldi [14/08/2016 07:37:58] - |D| - [82] - C:\Users\Jean-Marie\AppData\Local\Wondershare [13/08/2016 16:32:00] - |ASH| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [14/08/2016 10:04:21] - |SD| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [14/08/2016 10:04:21] - |RD| - [33617] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [14/08/2016 10:04:21] - |RD| - [3888] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [14/08/2016 10:04:21] - |RD| - [2927] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [13/08/2016 16:32:00] - |RD| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [21/08/2016 12:32:14] - |D| - [3999] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AoaoPhoto Digital Studio [14/08/2016 10:27:37] - |ASH| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [14/08/2016 19:53:21] - |D| - [3128] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IM-Magic Partition Resizer Free [14/08/2016 10:04:21] - |D| - [170] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [13/08/2016 22:49:57] - |A| - [2465] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [13/08/2016 16:32:00] - |RD| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [14/08/2016 10:04:21] - |RD| - [5318] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [21/08/2016 11:49:52] - |D| - [3962] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Watermark Pro [14/08/2016 10:04:21] - |RD| - [7238] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [13/08/2016 16:32:00] - |ASH| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Public] [10/09/2015 07:56:21] - |RHD| - [196] - C:\Users\Public\AccountPictures [14/08/2016 22:22:42] - |D| - [552] - C:\Users\Public\CyberLink [26/07/2012 10:12:59] - |RHD| - [23436] - C:\Users\Public\Desktop [16/07/2016 13:47:50] - |ASH| - [174] - C:\Users\Public\desktop.ini [26/07/2012 10:12:59] - |RD| - [164579429] - C:\Users\Public\Documents [26/07/2012 10:12:59] - |RD| - [174] - C:\Users\Public\Downloads [16/07/2016 13:47:48] - |RHD| - [1135] - C:\Users\Public\Libraries [26/07/2012 10:12:59] - |RD| - [380] - C:\Users\Public\Music [26/07/2012 10:12:59] - |RD| - [1396943] - C:\Users\Public\Pictures [05/03/2013 01:49:07] - |D| - [0] - C:\Users\Public\Symantec [26/07/2012 10:12:59] - |RD| - [380] - C:\Users\Public\Videos ---------- | C:\ProgramData [21/08/2016 09:48:24] - |AD| - [11371876] - C:\ProgramData\Acronis [14/08/2016 10:00:01] - |D| - [608] - C:\ProgramData\AMD [05/03/2013 01:35:50] - |D| - [0] - C:\ProgramData\Apple [14/08/2016 10:26:24] - |SHD| - [58347117506] - C:\ProgramData\Application Data [14/08/2016 07:35:14] - |D| - [157574] - C:\ProgramData\Ashampoo [14/08/2016 06:31:44] - |D| - [186] - C:\ProgramData\ATI [17/08/2016 13:23:33] - |D| - [5658854] - C:\ProgramData\AVAST Software [13/08/2016 16:25:26] - |SHD| - [23436] - C:\ProgramData\Bureau [18/08/2016 08:22:03] - |D| - [0] - C:\ProgramData\BVRP Software [14/08/2016 21:29:00] - |D| - [3122] - C:\ProgramData\CLSK [16/07/2016 13:47:48] - |D| - [0] - C:\ProgramData\Comms [05/03/2013 01:28:53] - |D| - [59877874] - C:\ProgramData\CyberLink [14/08/2016 21:39:31] - |D| - [16902998] - C:\ProgramData\DivX [15/08/2016 10:34:49] - |D| - [211341580] - C:\ProgramData\Doctor Web [14/08/2016 10:26:24] - |SHD| - [164579429] - C:\ProgramData\Documents [14/08/2016 19:03:48] - |D| - [10666629] - C:\ProgramData\EPSON [14/08/2016 18:40:54] - |D| - [1048864] - C:\ProgramData\firebird [21/08/2016 11:13:09] - |D| - [2928352890] - C:\ProgramData\GFI [05/03/2013 01:28:11] - |D| - [451600] - C:\ProgramData\install_clap [19/08/2016 06:38:25] - |D| - [11392952] - C:\ProgramData\IObit [20/08/2016 20:51:38] - |D| - [1399694] - C:\ProgramData\iolo [19/08/2016 06:33:13] - |D| - [485] - C:\ProgramData\Licenses [19/08/2016 06:34:23] - |D| - [818] - C:\ProgramData\Logs [13/08/2016 16:25:27] - |SHD| - [255363] - C:\ProgramData\Menu Démarrer [16/07/2016 13:47:48] - |SD| - [979798059] - C:\ProgramData\Microsoft [14/08/2016 10:32:46] - |D| - [0] - C:\ProgramData\Microsoft OneDrive [05/03/2013 01:45:17] - |D| - [0] - C:\ProgramData\Microsoft SkyDrive [13/08/2016 16:25:27] - |SHD| - [0] - C:\ProgramData\Modèles [19/08/2016 07:21:49] - |AD| - [6246523] - C:\ProgramData\Nero [05/03/2013 01:48:08] - |D| - [3395] - C:\ProgramData\Norton [14/08/2016 20:06:49] - |RASH| - [8] - C:\ProgramData\ntuser.pol [14/08/2016 09:59:01] - |D| - [20783272] - C:\ProgramData\Package Cache [14/08/2016 22:01:01] - |D| - [36] - C:\ProgramData\PDVD [01/08/2012 19:06:12] - |D| - [24792] - C:\ProgramData\PRICache [14/08/2016 21:56:17] - |D| - [66867486] - C:\ProgramData\proDAD [22/08/2016 09:04:09] - |D| - [541] - C:\ProgramData\ProductData [14/08/2016 02:18:27] - |D| - [26874717] - C:\ProgramData\Recovery [16/07/2016 13:47:48] - |D| - [1001] - C:\ProgramData\regid.1991-06.com.microsoft [14/08/2016 18:51:50] - |D| - [716985] - C:\ProgramData\RogueKiller [16/07/2016 13:47:48] - |D| - [0] - C:\ProgramData\SoftwareDistribution [14/08/2016 21:29:02] - |D| - [13124305] - C:\ProgramData\SUPPORTDIR [05/03/2013 01:25:25] - |AD| - [3997081] - C:\ProgramData\Temp [17/08/2016 13:01:30] - |A| - [177] - C:\ProgramData\Temp.log [16/07/2016 13:47:48] - |D| - [3103] - C:\ProgramData\USOPrivate [14/08/2016 10:26:39] - |D| - [1425408] - C:\ProgramData\USOShared [05/03/2013 01:30:04] - |D| - [657372] - C:\ProgramData\WildTangent [14/08/2016 07:38:27] - |D| - [3359473] - C:\ProgramData\Wondershare [14/08/2016 07:34:26] - |D| - [569237623] - C:\ProgramData\Wondershare Video Editor [05/03/2013 01:20:47] - |D| - [46414838] - C:\ProgramData\{AFF99647-6D64-46F2-934A-F12F468037F6} ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [16/07/2016 13:47:50] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [21/08/2016 14:42:25] - |D| - [4209] - C:\ProgramData\Microsoft\Windows\Start Menu\GFI Directory [13/08/2016 16:25:27] - |SHD| - [250980] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [16/07/2016 13:47:48] - |RD| - [250980] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [16/07/2016 13:47:48] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [16/07/2016 13:47:48] - |RD| - [14299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [21/08/2016 09:52:07] - |D| - [20781] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis [21/08/2016 09:52:07] - |A| - [1288] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis True Image.lnk [16/07/2016 13:47:48] - |RD| - [28160] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [14/08/2016 10:00:13] - |D| - [4373] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center [14/08/2016 07:35:54] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo [14/08/2016 06:33:39] - |A| - [733] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à niveau de Windows 10.lnk [14/08/2016 07:51:46] - |D| - [1568] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing Bureau [14/08/2016 21:32:40] - |RD| - [30092] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite [14/08/2016 22:07:05] - |RD| - [2265] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PhotoDirector 7 [14/08/2016 22:45:18] - |RD| - [9631] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go 10 [16/07/2016 13:47:50] - |ASH| - [796] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [18/08/2016 10:52:09] - |D| - [6198] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX [20/08/2016 05:46:27] - |D| - [4109] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Recovery 8.5 [20/08/2016 05:45:13] - |D| - [2871] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo PCTrans [21/08/2016 20:39:47] - |D| - [3546] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileMarker.NET [05/03/2013 01:30:09] - |RD| - [198] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [21/08/2016 14:51:27] - |D| - [9382] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GFI Archiver [21/08/2016 11:17:32] - |D| - [10690] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GFI LanGuard [14/08/2016 18:40:21] - |D| - [5494] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GFI WebMonitor [05/03/2013 01:23:32] - |RD| - [11179] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support [21/08/2016 11:22:57] - |RD| - [1230] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS [16/07/2016 13:43:50] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [16/07/2016 13:47:48] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [21/08/2016 11:05:18] - |D| - [1475] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 [21/08/2016 10:58:32] - |D| - [4934] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2012 [16/07/2016 13:42:22] - |RAS| - [2219] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk [05/03/2013 01:46:34] - |A| - [1308] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk [05/03/2013 01:28:52] - |RD| - [2266] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos [19/08/2016 07:22:24] - |D| - [13089] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero [19/08/2016 07:24:04] - |D| - [17469] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2016 [14/08/2016 21:55:52] - |D| - [1361] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue [05/03/2013 01:46:30] - |A| - [1377] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk [16/07/2016 13:43:50] - |RAS| - [2199] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk [05/03/2013 01:29:57] - |RD| - [1523] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools [05/03/2013 01:25:55] - |RD| - [4633] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection [13/08/2016 16:31:30] - |RD| - [81] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services [16/07/2016 13:47:48] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [16/07/2016 13:47:48] - |RD| - [2670] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [10/09/2015 07:28:34] - |RHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC [14/08/2016 19:37:11] - |D| - [1298] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Turbo View & Convert [20/08/2016 20:58:11] - |A| - [2219] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vivaldi.lnk [14/08/2016 10:14:25] - |A| - [1519] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [14/08/2016 07:37:44] - |D| - [16150] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [16/07/2016 13:47:50] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | C:\Program Files (x86) [21/08/2016 09:49:27] - |AD| - [373281290] - C:\Program Files (x86)\Acronis [05/03/2013 01:20:22] - |D| - [2249244] - C:\Program Files (x86)\AMD APP [21/08/2016 12:32:13] - |D| - [31639787] - C:\Program Files (x86)\AoaoPhoto Digital Studio [14/08/2016 09:59:16] - |D| - [110093050] - C:\Program Files (x86)\ATI Technologies [18/08/2016 11:42:30] - |D| - [0] - C:\Program Files (x86)\Avanquest [14/08/2016 10:44:28] - |D| - [470770] - C:\Program Files (x86)\CMAK [16/07/2016 08:04:24] - |D| - [707508423] - C:\Program Files (x86)\Common Files [05/03/2013 01:28:38] - |D| - [5597328046] - C:\Program Files (x86)\CyberLink [16/07/2016 13:47:50] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [14/08/2016 21:39:35] - |D| - [207708213] - C:\Program Files (x86)\DivX [20/08/2016 05:42:00] - |D| - [85777269] - C:\Program Files (x86)\EaseUS [14/08/2016 19:37:22] - |D| - [1790134] - C:\Program Files (x86)\File Identifier [21/08/2016 20:39:46] - |AD| - [5426601] - C:\Program Files (x86)\FileMarker.NET [21/08/2016 11:13:09] - |D| - [428919376] - C:\Program Files (x86)\GFI [05/03/2013 01:14:24] - |D| - [77496418] - C:\Program Files (x86)\Hewlett-Packard [14/08/2016 18:37:36] - |D| - [12011650] - C:\Program Files (x86)\IIS Express [14/08/2016 19:36:28] - |D| - [148183952] - C:\Program Files (x86)\IMSIDesign [05/03/2013 01:18:18] - |HD| - [292014735] - C:\Program Files (x86)\InstallShield Installation Information [16/07/2016 13:47:48] - |D| - [1990246] - C:\Program Files (x86)\Internet Explorer [14/08/2016 07:51:26] - |D| - [28382294] - C:\Program Files (x86)\Microsoft [15/08/2016 10:18:37] - |D| - [1670519] - C:\Program Files (x86)\Microsoft ASP.NET [05/03/2013 01:45:48] - |D| - [5563840] - C:\Program Files (x86)\Microsoft SkyDrive [21/08/2016 10:40:43] - |AD| - [639630979] - C:\Program Files (x86)\Microsoft SQL Server [05/03/2013 01:46:24] - |D| - [1829877] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition [21/08/2016 11:06:35] - |D| - [4850] - C:\Program Files (x86)\Microsoft Visual Studio 10.0 [16/07/2016 13:47:48] - |D| - [608727] - C:\Program Files (x86)\Microsoft.NET [14/08/2016 10:33:11] - |D| - [25757] - C:\Program Files (x86)\MSBuild [19/08/2016 07:22:18] - |AD| - [2313046120] - C:\Program Files (x86)\Nero [14/08/2016 21:55:30] - |D| - [54782380] - C:\Program Files (x86)\NewBlue [14/08/2016 21:31:03] - |D| - [63354022] - C:\Program Files (x86)\NSIS Uninstall Information [05/03/2013 01:30:04] - |RD| - [1549625] - C:\Program Files (x86)\Online Services [05/03/2013 01:18:18] - |D| - [48454551] - C:\Program Files (x86)\Realtek [14/08/2016 10:33:11] - |D| - [38450433] - C:\Program Files (x86)\Reference Assemblies [05/03/2013 01:49:07] - |D| - [2562624] - C:\Program Files (x86)\SymSilent [05/03/2013 01:18:18] - |D| - [0] - C:\Program Files (x86)\Temp [20/08/2016 20:57:45] - |D| - [331342005] - C:\Program Files (x86)\Vivaldi [16/07/2016 13:47:48] - |D| - [1941504] - C:\Program Files (x86)\Windows Defender [05/03/2013 01:46:07] - |D| - [90972365] - C:\Program Files (x86)\Windows Live [16/07/2016 13:47:48] - |D| - [5958656] - C:\Program Files (x86)\Windows Mail [16/07/2016 13:47:48] - |D| - [3275416] - C:\Program Files (x86)\Windows Media Player [16/07/2016 13:47:48] - |D| - [34128] - C:\Program Files (x86)\Windows Multimedia Platform [16/07/2016 13:47:48] - |D| - [7584962] - C:\Program Files (x86)\Windows NT [16/07/2016 13:47:48] - |D| - [5424832] - C:\Program Files (x86)\Windows Photo Viewer [16/07/2016 13:47:48] - |D| - [34128] - C:\Program Files (x86)\Windows Portable Devices [16/07/2016 13:47:48] - |SD| - [0] - C:\Program Files (x86)\Windows Sidebar [16/07/2016 13:47:48] - |D| - [4139813] - C:\Program Files (x86)\WindowsPowerShell [14/08/2016 07:41:40] - |D| - [28780680] - C:\Program Files (x86)\Wondershare ---------- | C:\Program Files [14/08/2016 09:57:58] - |D| - [96636696] - C:\Program Files\AMD [05/03/2013 01:19:37] - |D| - [27488048] - C:\Program Files\ATI [14/08/2016 09:59:58] - |D| - [5595872] - C:\Program Files\ATI Technologies [17/08/2016 13:28:16] - |D| - [122993093] - C:\Program Files\AVAST Software [14/08/2016 10:44:28] - |D| - [212992] - C:\Program Files\CMAK [16/07/2016 08:04:24] - |D| - [72712896] - C:\Program Files\Common Files [14/08/2016 21:49:13] - |D| - [2409722494] - C:\Program Files\CyberLink [16/07/2016 13:47:50] - |ASH| - [174] - C:\Program Files\desktop.ini [14/08/2016 21:39:58] - |D| - [2126696] - C:\Program Files\DivX [15/08/2016 10:37:22] - |D| - [32321560] - C:\Program Files\DrWeb [13/08/2016 16:25:27] - |SHD| - [72712896] - C:\Program Files\Fichiers communs [14/08/2016 18:39:38] - |D| - [746086661] - C:\Program Files\GFI [05/03/2013 01:14:23] - |D| - [3855844] - C:\Program Files\Hewlett-Packard [14/08/2016 19:53:18] - |D| - [10888846] - C:\Program Files\IM-Magic [16/07/2016 13:47:47] - |D| - [2582085] - C:\Program Files\Internet Explorer [14/08/2016 11:53:18] - |D| - [0] - C:\Program Files\Lavasoft [21/08/2016 11:04:30] - |AD| - [2992169] - C:\Program Files\Microsoft SQL Server [14/08/2016 10:33:10] - |D| - [25757] - C:\Program Files\MSBuild [14/08/2016 21:55:52] - |D| - [70721537] - C:\Program Files\NewBlue [05/03/2013 01:43:57] - |RD| - [597724] - C:\Program Files\Online Services [14/08/2016 21:56:16] - |D| - [4540643] - C:\Program Files\proDAD [14/08/2016 09:58:21] - |D| - [35377120] - C:\Program Files\Realtek [14/08/2016 10:33:10] - |D| - [36850857] - C:\Program Files\Reference Assemblies [30/07/2015 23:52:28] - |HD| - [0] - C:\Program Files\Uninstall Information [16/07/2016 13:47:47] - |RD| - [14913860] - C:\Program Files\Windows Defender [17/07/2016 00:46:17] - |D| - [6280776] - C:\Program Files\Windows Defender Advanced Threat Protection [16/07/2016 13:47:47] - |D| - [6181888] - C:\Program Files\Windows Mail [16/07/2016 13:47:47] - |D| - [4989116] - C:\Program Files\Windows Media Player [16/07/2016 13:47:47] - |D| - [37784] - C:\Program Files\Windows Multimedia Platform [16/07/2016 13:47:47] - |D| - [7849154] - C:\Program Files\Windows NT [16/07/2016 13:47:47] - |D| - [6223552] - C:\Program Files\Windows Photo Viewer [16/07/2016 13:47:47] - |D| - [37784] - C:\Program Files\Windows Portable Devices [16/07/2016 13:47:47] - |SHD| - [0] - C:\Program Files\Windows Sidebar [16/07/2016 13:47:47] - |HD| - [1245244661] - C:\Program Files\WindowsApps [16/07/2016 13:47:47] - |D| - [4563154] - C:\Program Files\WindowsPowerShell [14/08/2016 07:34:25] - |D| - [311766990] - C:\Program Files\Wondershare ---------- | C:\Program Files (x86)\Common Files [21/08/2016 09:49:25] - |AD| - [344791273] - C:\Program Files (x86)\Common Files\Acronis [05/03/2013 01:37:28] - |D| - [34645608] - C:\Program Files (x86)\Common Files\CyberLink [14/08/2016 21:39:50] - |D| - [92135639] - C:\Program Files (x86)\Common Files\DivX Shared [05/03/2013 01:18:12] - |D| - [3257529] - C:\Program Files (x86)\Common Files\InstallShield [19/08/2016 06:38:19] - |D| - [1218] - C:\Program Files (x86)\Common Files\IObit [14/08/2016 09:59:17] - |D| - [337630] - C:\Program Files (x86)\Common Files\logishrd [16/07/2016 13:47:48] - |D| - [15985513] - C:\Program Files (x86)\Common Files\Microsoft Shared [19/08/2016 07:22:50] - |D| - [72779000] - C:\Program Files (x86)\Common Files\Nero [14/08/2016 21:55:51] - |D| - [286720] - C:\Program Files (x86)\Common Files\NewBlue [14/08/2016 22:07:10] - |D| - [1488873] - C:\Program Files (x86)\Common Files\Nikon [16/07/2016 13:47:48] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [16/07/2016 13:47:48] - |D| - [9639307] - C:\Program Files (x86)\Common Files\System [05/03/2013 01:45:06] - |D| - [125424671] - C:\Program Files (x86)\Common Files\Windows Live [14/08/2016 07:37:53] - |D| - [6732740] - C:\Program Files (x86)\Common Files\Wondershare ---------- | C:\Program Files\Common files [05/03/2013 01:09:47] - |D| - [0] - C:\Program Files\Common files\ATI Technologies [15/08/2016 10:38:24] - |D| - [18805008] - C:\Program Files\Common files\Doctor Web [14/08/2016 19:06:20] - |D| - [152640] - C:\Program Files\Common files\EPSON [21/08/2016 14:46:03] - |D| - [845405] - C:\Program Files\Common files\GFI [14/08/2016 09:59:07] - |D| - [1022022] - C:\Program Files\Common files\logishrd [16/07/2016 13:47:47] - |D| - [41286324] - C:\Program Files\Common files\microsoft shared [14/08/2016 21:56:10] - |D| - [352768] - C:\Program Files\Common files\NewBlue [16/07/2016 13:47:47] - |D| - [2702] - C:\Program Files\Common files\Services [16/07/2016 13:47:47] - |D| - [10246027] - C:\Program Files\Common files\System ---------- | Tasks [MD5.D513F6DEA96D6233088093CE172904B3] - [23/08/2016 17:41:48] - |A| - [1002] - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [MD5.3D9269D94D2C36DC3BBF426E52218DAC] - [20/08/2016 08:33:50] - |A| - [214] - C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job [MD5.C9430BC814EA9C1662F72366E90F06A0] - [14/08/2016 19:06:23] - |A| - [753] - C:\WINDOWS\Tasks\EPSON XP-710 Series Invitation {5B6F0BB0-E386-4C6E-8808-1C74CE83E5E9}.job [MD5.AA2E0B03870D7B25990D7EF434F7785C] - [14/08/2016 19:06:22] - |A| - [939] - C:\WINDOWS\Tasks\EPSON XP-710 Series Update {5B6F0BB0-E386-4C6E-8808-1C74CE83E5E9}.job [MD5.708EA029F398E51E2AEBBD0AD5E5CA73] - [14/08/2016 10:21:08] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.AC19C88C4520D93570940FB908629824] - [23/08/2016 17:41:48] - |A| - [3978] - C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater : C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.C00B5A0E93D0594B2B6DA0B160FCA0FF] - [14/08/2016 11:05:52] - |A| - [3654] - C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask : C:\WINDOWS\explorer.exe [MD5.35881027BC837CB9381DB38A8A3CD92F] - [14/08/2016 21:38:51] - |A| - [3296] - C:\WINDOWS\System32\Tasks\DeviceDetector7.5 : C:\Program Files (x86)\CyberLink\MediaEspresso7.5\DeviceDetector\DeviceDetector7.5.exe [MD5.4187A4B57DBD2295F1C1775F3AF2E15C] - [18/08/2016 10:54:14] - |A| - [3696] - C:\WINDOWS\System32\Tasks\DivXUpdate : C:\Program Files (x86)\Common Files\DivX Shared\Qt4.8\DivXUpdate.exe [MD5.00000000000000000000000000000000] - [15/08/2016 10:42:02] - |D| - [0] - C:\WINDOWS\System32\Tasks\Doctor Web [MD5.8F013198B0680CFDAD6DA903596ED654] - [14/08/2016 19:06:28] - |A| - [3958] - C:\WINDOWS\System32\Tasks\EPSON XP-710 Series Invitation {5B6F0BB0-E386-4C6E-8808-1C74CE83E5E9} : C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLPE.EXE [MD5.84EC799A1BAB7EFC94337DDD8FDA9374] - [14/08/2016 19:06:23] - |A| - [4136] - C:\WINDOWS\System32\Tasks\EPSON XP-710 Series Update {5B6F0BB0-E386-4C6E-8808-1C74CE83E5E9} : C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLPE.EXE [MD5.00000000000000000000000000000000] - [14/08/2016 10:21:05] - |D| - [10650] - C:\WINDOWS\System32\Tasks\Hewlett-Packard [MD5.4E64798F26858F24EEEC15B5D0E419D6] - [20/08/2016 20:51:49] - |A| - [3646] - C:\WINDOWS\System32\Tasks\iolo SCU task one : C:\ProgramData\iolo\SCU\sculnch.lnk [MD5.00000000000000000000000000000000] - [16/07/2016 13:47:48] - |D| - [551226] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.00000000000000000000000000000000] - [19/08/2016 07:36:44] - |D| - [3340] - C:\WINDOWS\System32\Tasks\Nero [MD5.00000000000000000000000000000000] - [14/08/2016 10:21:08] - |D| - [5354] - C:\WINDOWS\System32\Tasks\Norton Internet Security [MD5.69BCD7233D4FBC5EA1E7EEF68850F3C1] - [14/08/2016 10:21:08] - |A| - [2672] - C:\WINDOWS\System32\Tasks\Norton WSC Integration : "C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\WSCStub.exe" [MD5.DBAB001B1E526216984DBFB9F6CED6E0] - [18/08/2016 08:23:19] - |A| - [3350] - C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task : C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [MD5.5EBF437EE4AD073B84F26D4B93F91E7F] - [14/08/2016 10:21:08] - |A| - [2938] - C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3042704910-407304991-3750219112-1001 : C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [MD5.FE6EFFAF7756829988D849FDB6DAFFAA] - [20/08/2016 14:15:17] - |A| - [4174] - C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1AD0F82C-BCDB-4AB0-8EEC-D63AF373C8AA} : C:\WINDOWS\system32\msfeedssync.exe [MD5.00000000000000000000000000000000] - [14/08/2016 18:43:04] - |D| - [0] - C:\WINDOWS\System32\Tasks\WiseCleaner [MD5.00000000000000000000000000000000] - [14/08/2016 10:21:25] - |D| - [0] - C:\WINDOWS\System32\Tasks\WPD [MD5.00000000000000000000000000000000] - [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "IIS-WebServerRole-HTTPS-In-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=443|App=System|Name=@%windir%\system32\inetsrv\iisres.dll,-30502|Desc=@%windir%\system32\inetsrv\iisres.dll,-30512|EmbedCtxt=@%windir%\system32\inetsrv\iisres.dll,-30503| "IIS-WebServerRole-HTTP-In-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=80|App=System|Name=@%windir%\system32\inetsrv\iisres.dll,-30500|Desc=@%windir%\system32\inetsrv\iisres.dll,-30510|EmbedCtxt=@%windir%\system32\inetsrv\iisres.dll,-30501| "MDNS-Out-UDP"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|LPort=5353|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37305|Desc=@%SystemRoot%\system32\firewallapi.dll,-37306|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302| "MDNS-In-UDP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort2_24=mDNS|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37303|Desc=@%SystemRoot%\system32\firewallapi.dll,-37304|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302| "WirelessDisplay-Infra-In-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100| "WirelessDisplay-Out-UDP"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-In-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "Netlogon-TCP-RPC-In"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010| "Netlogon-NamedPipe-In"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "DeliveryOptimization-UDP-In"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "DeliveryOptimization-TCP-In"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "Wininit-Shutdown-In-Rule-TCP-RPC-EPMapper"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC-EPMap|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36755|Desc=@firewallapi.dll,-36756|EmbedCtxt=@firewallapi.dll,-36751| "Wininit-Shutdown-In-Rule-TCP-RPC"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36753|Desc=@firewallapi.dll,-36754|EmbedCtxt=@firewallapi.dll,-36751| "{FBCCFD89-C24F-479C-9924-63412F13EA6D}"=v2.26|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\GFI\LanGuard 12 Agent\Httpd\bin\httpd.exe|Name=GFI LanGuard 12 Communication Service| [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\standardprofile\authorizedapplications\list] "C:\Users\Jean-Marie\Desktop\pre-scan_6_20.07.2016.1.exe"=C:\Users\Jean-Marie\Desktop\pre-scan_6_20.07.2016.1.exe:*:Enabled:pre-scan_6_20.07.2016.1 ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (Security Accelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @%SystemRoot%\System32\DispCI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs) [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8496e87e-c0a1-4102-9d8d-bd9a9b8b07a9}] : (WDC_SAM) [] -> @oem9.inf,%WDC_SAM_ClassName%;WD Drive Management devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9d6d66a6-0b0c-4563-9077-a0e9a7955ae4}] : (Ramdisk) [] -> @ramdisk.inf,%ClassName%;RAM Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{E004269C-D387-4461-B955-25A64CFE23CE}] : (amdkmdag) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [16/07/2016 13:41:53] - (10.6.0.23) - (NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver) - C:\WINDOWS\System32\drivers\nvraid.sys [16/07/2016 13:41:52] - (7.12.31.105) - (QLogic Corporation - QLogic Gigabit Ethernet VBD) - C:\WINDOWS\System32\drivers\bxvbda.sys [16/07/2016 13:41:52] - (7.13.65.105) - (QLogic Corporation - QLogic 10 GigE VBD) - C:\WINDOWS\System32\drivers\evbda.sys [16/07/2016 13:41:53] - (8.0.9200.8110) - (VIA Corporation - VIA StorX RAID Controller Driver) - C:\WINDOWS\System32\drivers\vstxraid.sys [16/07/2016 13:41:53] - (5.1.0.51) - (LSI - LSI 3ware SCSI Storport Driver) - C:\WINDOWS\System32\drivers\3ware.sys [16/07/2016 13:41:53] - (3.7.1540.43) - (AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform) - C:\WINDOWS\System32\drivers\amdsbs.sys [16/07/2016 13:41:53] - (7.5.0.32048) - (PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver) - C:\WINDOWS\System32\drivers\arcsas.sys [16/07/2016 13:41:53] - (1.34.3.83) - (LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sas.sys [16/07/2016 13:41:53] - (2.0.79.80) - (LSI Corporation - LSI SAS Gen2 Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sas2i.sys [16/07/2016 13:41:53] - (2.51.12.80) - (Avago Technologies - Avago SAS Gen3 Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sas3i.sys [16/07/2016 13:41:53] - (2.10.61.81) - (LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sss.sys [16/07/2016 13:41:53] - (6.706.6.0) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\megasas.sys [16/07/2016 13:41:53] - (15.2.2013.129) - (LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver) - C:\WINDOWS\System32\drivers\megasr.sys [16/07/2016 13:41:53] - (1.0.5.1016) - (Marvell Semiconductor, Inc. - Marvell Flash Controller Driver) - C:\WINDOWS\System32\drivers\mvumis.sys [16/07/2016 13:41:53] - (10.6.0.23) - (NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver) - C:\WINDOWS\System32\drivers\nvstor.sys [16/07/2016 13:41:53] - (6.805.3.0) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\percsas2i.sys [16/07/2016 13:41:53] - (6.603.6.0) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\percsas3i.sys [16/07/2016 13:41:53] - (5.1.1039.2600) - (Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver) - C:\WINDOWS\System32\drivers\SiSRaid2.sys [16/07/2016 13:41:53] - (5.1.1039.3600) - (Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver) - C:\WINDOWS\System32\drivers\sisraid4.sys [16/07/2016 13:41:53] - (5.1.0.10) - (Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64) - C:\WINDOWS\System32\drivers\stexstor.sys [16/07/2016 13:41:53] - (7.0.9600.6352) - (VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64) - C:\WINDOWS\System32\drivers\vsmraid.sys [16/07/2016 13:41:53] - (1.3.0.10769) - (PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller) - C:\WINDOWS\System32\drivers\ADP80XX.SYS [16/07/2016 13:41:53] - (8.0.4.0) - (Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver) - C:\WINDOWS\System32\drivers\HpSAMD.sys [21/08/2016 09:54:13] - (1.1.0.2350) - (Acronis International GmbH - File tracker minifilter driver) - C:\WINDOWS\system32\DRIVERS\file_tracker.sys [21/08/2016 09:52:21] - (1.3.0.2243) - (Acronis International GmbH - Acronis Storage Filter Management Driver) - C:\WINDOWS\system32\DRIVERS\fltsrv.sys [21/08/2016 09:52:32] - (1.0.0.1163) - (Acronis International GmbH - Acronis Backup Archive Explorer) - C:\WINDOWS\system32\DRIVERS\tib.sys [14/08/2016 21:32:28] - (5.0.0.10524) - (Cyberlink Co.,Ltd. - Cyberlink Storage Helper Driver (WindowsNT5.x)) - C:\WINDOWS\system32\DRIVERS\CLBStor.sys [16/07/2016 13:41:53] - (2.1.0.16) - (Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabit Ethernet Controller) - C:\WINDOWS\System32\drivers\L1C63x64.sys [14/08/2016 21:43:13] - (2.0.0.3505) - (CyberLink - CyberLink Virtual CDROM Bus Enumerator) - C:\WINDOWS\System32\drivers\CLVirtualBus01.sys [16/02/2016 16:52:38] - (7.0.0.12) - (BitDefender LLC - BitDefender Firewall NDIS6 Filter Driver) - C:\WINDOWS\system32\DRIVERS\bdfndisf6.sys ---------- | LoadOrderGroup Name: System Reserved - DriverEnabled: True - GroupOrder: 1 - Status: OK Name: EMS - DriverEnabled: True - GroupOrder: 2 - Status: OK Name: WdfLoadGroup - DriverEnabled: True - GroupOrder: 3 - Status: OK Name: Boot Bus Extender - DriverEnabled: True - GroupOrder: 4 - Status: OK Name: System Bus Extender - DriverEnabled: True - GroupOrder: 5 - Status: OK Name: SCSI miniport - DriverEnabled: True - GroupOrder: 6 - Status: OK Name: Port - DriverEnabled: True - GroupOrder: 7 - Status: OK Name: Primary Disk - DriverEnabled: True - GroupOrder: 8 - Status: OK Name: SCSI Class - DriverEnabled: True - GroupOrder: 9 - Status: OK Name: SCSI CDROM Class - DriverEnabled: True - GroupOrder: 10 - Status: OK Name: FSFilter Infrastructure - DriverEnabled: True - GroupOrder: 11 - Status: OK Name: FSFilter System - DriverEnabled: True - GroupOrder: 12 - Status: OK Name: FSFilter Bottom - DriverEnabled: True - GroupOrder: 13 - Status: OK Name: FSFilter Copy Protection - DriverEnabled: True - GroupOrder: 14 - Status: OK Name: FSFilter Security Enhancer - DriverEnabled: True - GroupOrder: 15 - Status: OK Name: FSFilter Open File - DriverEnabled: True - GroupOrder: 16 - Status: OK Name: FSFilter Physical Quota Management - DriverEnabled: True - GroupOrder: 17 - Status: OK Name: FSFilter Virtualization - DriverEnabled: True - GroupOrder: 18 - Status: OK Name: FSFilter Encryption - DriverEnabled: True - GroupOrder: 19 - Status: OK Name: FSFilter Compression - DriverEnabled: True - GroupOrder: 20 - Status: OK Name: FSFilter Imaging - DriverEnabled: True - GroupOrder: 21 - Status: OK Name: FSFilter HSM - DriverEnabled: True - GroupOrder: 22 - Status: OK Name: FSFilter Cluster File System - DriverEnabled: True - GroupOrder: 23 - Status: OK Name: FSFilter System Recovery - DriverEnabled: True - GroupOrder: 24 - Status: OK Name: FSFilter Quota Management - DriverEnabled: True - GroupOrder: 25 - Status: OK Name: FSFilter Content Screener - DriverEnabled: True - GroupOrder: 26 - Status: OK Name: FSFilter Continuous Backup - DriverEnabled: True - GroupOrder: 27 - Status: OK Name: FSFilter Replication - DriverEnabled: True - GroupOrder: 28 - Status: OK Name: FSFilter Anti-Virus - DriverEnabled: True - GroupOrder: 29 - Status: OK Name: FSFilter Undelete - DriverEnabled: True - GroupOrder: 30 - Status: OK Name: FSFilter Activity Monitor - DriverEnabled: True - GroupOrder: 31 - Status: OK Name: FSFilter Top - DriverEnabled: True - GroupOrder: 32 - Status: OK Name: Filter - DriverEnabled: True - GroupOrder: 33 - Status: OK Name: Boot File System - DriverEnabled: True - GroupOrder: 34 - Status: OK Name: Base - DriverEnabled: True - GroupOrder: 35 - Status: OK Name: Pointer Port - DriverEnabled: True - GroupOrder: 36 - Status: OK Name: Keyboard Port - DriverEnabled: True - GroupOrder: 37 - Status: OK Name: Pointer Class - DriverEnabled: True - GroupOrder: 38 - Status: OK Name: Keyboard Class - DriverEnabled: True - GroupOrder: 39 - Status: OK Name: Video Init - DriverEnabled: True - GroupOrder: 40 - Status: OK Name: Video - DriverEnabled: True - GroupOrder: 41 - Status: OK Name: Video Save - DriverEnabled: True - GroupOrder: 42 - Status: OK Name: File System - DriverEnabled: True - GroupOrder: 43 - Status: OK Name: Streams Drivers - DriverEnabled: True - GroupOrder: 44 - Status: OK Name: NDIS Wrapper - DriverEnabled: True - GroupOrder: 45 - Status: OK Name: COM Infrastructure - DriverEnabled: True - GroupOrder: 46 - Status: OK Name: Event Log - DriverEnabled: True - GroupOrder: 47 - Status: OK Name: ProfSvc_Group - DriverEnabled: True - GroupOrder: 48 - Status: OK Name: AudioGroup - DriverEnabled: True - GroupOrder: 49 - Status: OK Name: UIGroup - DriverEnabled: True - GroupOrder: 50 - Status: OK Name: MS_WindowsLocalValidation - DriverEnabled: True - GroupOrder: 51 - Status: OK Name: PlugPlay - DriverEnabled: True - GroupOrder: 52 - Status: OK Name: Cryptography - DriverEnabled: True - GroupOrder: 53 - Status: OK Name: PNP_TDI - DriverEnabled: True - GroupOrder: 54 - Status: OK Name: NDIS - DriverEnabled: True - GroupOrder: 55 - Status: OK Name: TDI - DriverEnabled: True - GroupOrder: 56 - Status: OK Name: iSCSI - DriverEnabled: True - GroupOrder: 57 - Status: OK Name: NetBIOSGroup - DriverEnabled: True - GroupOrder: 58 - Status: OK Name: ShellSvcGroup - DriverEnabled: True - GroupOrder: 59 - Status: OK Name: SchedulerGroup - DriverEnabled: True - GroupOrder: 60 - Status: OK Name: SpoolerGroup - DriverEnabled: True - GroupOrder: 61 - Status: OK Name: SmartCardGroup - DriverEnabled: True - GroupOrder: 62 - Status: OK Name: NetworkProvider - DriverEnabled: True - GroupOrder: 63 - Status: OK Name: MS_WindowsRemoteValidation - DriverEnabled: True - GroupOrder: 64 - Status: OK Name: NetDDEGroup - DriverEnabled: True - GroupOrder: 65 - Status: OK Name: Parallel arbitrator - DriverEnabled: True - GroupOrder: 66 - Status: OK Name: Extended Base - DriverEnabled: True - GroupOrder: 67 - Status: OK Name: PCI Configuration - DriverEnabled: True - GroupOrder: 68 - Status: OK Name: MS Transactions - DriverEnabled: True - GroupOrder: 69 - Status: OK Name: Core - DriverEnabled: False - GroupOrder: 70 - Status: OK Name: Network - DriverEnabled: False - GroupOrder: 71 - Status: OK Name: PnP Filter - DriverEnabled: False - GroupOrder: 72 - Status: OK Name: Core Security Extensions - DriverEnabled: False - GroupOrder: 73 - Status: OK Name: NetworkService - DriverEnabled: False - GroupOrder: 74 - Status: OK Name: Early-Launch - DriverEnabled: False - GroupOrder: 75 - Status: OK Name: LocalService - DriverEnabled: False - GroupOrder: 76 - Status: OK ---------- | LoadOrderGroupServiceDependencies LoadOrderGroup.Name="NetBIOSGroup" - Service.Name="RemoteAccess" LoadOrderGroup.Name="SCSI CDROM Class" - SystemDriver.Name="cdfs" ---------- | LoadOrderGroupServiceMembers LoadOrderGroup.Name="Event log" - Service.Name="AMD External Events Utility" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="AppIDSvc" LoadOrderGroup.Name="AudioGroup" - Service.Name="AudioEndpointBuilder" LoadOrderGroup.Name="AudioGroup" - Service.Name="Audiosrv" LoadOrderGroup.Name="NetworkProvider" - Service.Name="BFE" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="BrokerInfrastructure" LoadOrderGroup.Name="NetworkProvider" - Service.Name="Browser" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="CscService" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="DcomLaunch" LoadOrderGroup.Name="PlugPlay" - Service.Name="DeviceInstall" LoadOrderGroup.Name="TDI" - Service.Name="Dhcp" LoadOrderGroup.Name="TDI" - Service.Name="Dnscache" LoadOrderGroup.Name="TDI" - Service.Name="dot3svc" LoadOrderGroup.Name="Event Log" - Service.Name="EventLog" LoadOrderGroup.Name="AudioGroup" - Service.Name="FontCache" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="gpsvc" LoadOrderGroup.Name="TDI" - Service.Name="icssvc" LoadOrderGroup.Name="TDI" - Service.Name="irmon" LoadOrderGroup.Name="NetworkProvider" - Service.Name="LanmanWorkstation" LoadOrderGroup.Name="TDI" - Service.Name="lmhosts" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="LSM" LoadOrderGroup.Name="NetworkService" - Service.Name="MapsBroker" LoadOrderGroup.Name="NetworkProvider" - Service.Name="MpsSvc" LoadOrderGroup.Name="iSCSI" - Service.Name="MSiSCSI" LoadOrderGroup.Name="MS_WindowsRemoteValidation" - Service.Name="Netlogon" LoadOrderGroup.Name="Cryptography" - Service.Name="NgcCtnrSvc" LoadOrderGroup.Name="Cryptography" - Service.Name="NgcSvc" LoadOrderGroup.Name="PlugPlay" - Service.Name="PlugPlay" LoadOrderGroup.Name="Plugplay" - Service.Name="Power" LoadOrderGroup.Name="profsvc_group" - Service.Name="ProfSvc" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="RpcEptMapper" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="3ware" LoadOrderGroup.Name="Core" - SystemDriver.Name="ACPI" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AcpiDev" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="acpiex" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="acpitime" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="ADP80XX" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="AFD" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AmdK8" LoadOrderGroup.Name="Video" - SystemDriver.Name="amdkmdag" LoadOrderGroup.Name="Video" - SystemDriver.Name="amdkmdap" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AmdPPM" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdsata" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdsbs" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdxata" LoadOrderGroup.Name="FSFilter HSM" - SystemDriver.Name="AppvStrm" LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="AppvVemgr" LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="AppvVfs" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="arcsas" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="atapi" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="avchv" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="b06bdrv" LoadOrderGroup.Name="Video" - SystemDriver.Name="BasicDisplay" LoadOrderGroup.Name="Video" - SystemDriver.Name="BasicRender" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="bcmfn" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="bcmfn2" LoadOrderGroup.Name="NDIS Wrapper" - SystemDriver.Name="BdfNdisf" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="bdfwfpf" LoadOrderGroup.Name="Base" - SystemDriver.Name="Beep" LoadOrderGroup.Name="Network" - SystemDriver.Name="bowser" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="BthAvrcpTg" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="BthHFEnum" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="cdfs" LoadOrderGroup.Name="SCSI CDROM Class" - SystemDriver.Name="cdrom" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="cht4iscsi" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="cht4vbd" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="circlass" LoadOrderGroup.Name="Filter" - SystemDriver.Name="CLBStor" LoadOrderGroup.Name="File System" - SystemDriver.Name="CLBUDF" LoadOrderGroup.Name="Filter" - SystemDriver.Name="CLFS" LoadOrderGroup.Name="base" - SystemDriver.Name="clreg" LoadOrderGroup.Name="COM Infrastructure" - Service.Name="RpcSs" LoadOrderGroup.Name="PlugPlay" - Service.Name="RtkAudioService" LoadOrderGroup.Name="MS_WindowsLocalValidation" - Service.Name="SamSs" LoadOrderGroup.Name="SmartCardGroup" - Service.Name="SCardSvr" LoadOrderGroup.Name="SchedulerGroup" - Service.Name="Schedule" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="SENS" LoadOrderGroup.Name="ShellSvcGroup" - Service.Name="ShellHWDetection" LoadOrderGroup.Name="SpoolerGroup" - Service.Name="Spooler" LoadOrderGroup.Name="PlugPlay" - Service.Name="TabletInputService" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="Themes" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="TrustedInstaller" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="CLVirtualBus01" LoadOrderGroup.Name="Core" - SystemDriver.Name="CNG" LoadOrderGroup.Name="Base" - SystemDriver.Name="cnghwassist" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="CompositeBus" LoadOrderGroup.Name="Base" - SystemDriver.Name="condrv" LoadOrderGroup.Name="network" - SystemDriver.Name="CSC" LoadOrderGroup.Name="Network" - SystemDriver.Name="Dfsc" LoadOrderGroup.Name="Base" - SystemDriver.Name="dg_ssudbus" LoadOrderGroup.Name="Video Init" - SystemDriver.Name="DXGKrnl" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="ebdrv" LoadOrderGroup.Name="SCSI Class" - SystemDriver.Name="EhStorClass" LoadOrderGroup.Name="SCSI Class" - SystemDriver.Name="EhStorTcgDrv" LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="epp" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="ErrDev" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="exfat" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="fastfat" LoadOrderGroup.Name="FSFilter Encryption" - SystemDriver.Name="FileCrypt" LoadOrderGroup.Name="FSFilter Bottom" - SystemDriver.Name="FileInfo" LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="Filetrace" LoadOrderGroup.Name="FSFilter Continuous Backup" - SystemDriver.Name="file_tracker" LoadOrderGroup.Name="FSFilter Infrastructure" - SystemDriver.Name="FltMgr" LoadOrderGroup.Name="Filter" - SystemDriver.Name="fltsrv" LoadOrderGroup.Name="FSFilter Top" - SystemDriver.Name="FsDepends" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="fvevol" LoadOrderGroup.Name="Base" - SystemDriver.Name="genericusbfn" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="GPIOClx0101" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="HDAudBus" LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidBth" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hidi2c" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hidinterrupt" LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidIr" LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidUsb" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="HpSAMD" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hvservice" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hyperkbd" LoadOrderGroup.Name="Keyboard Port" - SystemDriver.Name="i8042prt" LoadOrderGroup.Name="Base" - SystemDriver.Name="iai2c" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iaLPSS2i_GPIO2" LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="UevAgentService" LoadOrderGroup.Name="SmartCardGroup" - Service.Name="WbioSrvc" LoadOrderGroup.Name="TDI" - Service.Name="Wcmsvc" LoadOrderGroup.Name="NetworkProvider" - Service.Name="WebClient" LoadOrderGroup.Name="TDI" - Service.Name="WlanSvc" LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSS2i_I2C" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iaLPSSi_GPIO" LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSSi_I2C" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="iaStorAV" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="iaStorV" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="ibbus" LoadOrderGroup.Name="Base" - SystemDriver.Name="IndirectKmd" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="intelide" LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="intelpep" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="intelppm" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="iorate" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="irda" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="isapnp" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="kdnic" LoadOrderGroup.Name="Base" - SystemDriver.Name="KSecDD" LoadOrderGroup.Name="Cryptography" - SystemDriver.Name="KSecPkg" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="ksthunk" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="L1C" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="lltdio" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS2i" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS3i" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SSS" LoadOrderGroup.Name="FSFilter Virtualization" - SystemDriver.Name="luafv" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasas" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasr" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="mlx4_bus" LoadOrderGroup.Name="Extended base" - SystemDriver.Name="Modem" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="mountmgr" LoadOrderGroup.Name="network" - SystemDriver.Name="mpsdrv" LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb" LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb10" LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb20" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="MsBridge" LoadOrderGroup.Name="File system" - SystemDriver.Name="Msfs" LoadOrderGroup.Name="LocalService" - Service.Name="workfolderssvc" LoadOrderGroup.Name="PlugPlay" - Service.Name="wudfsvc" LoadOrderGroup.Name="TDI" - Service.Name="WwanSvc" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="msgpiowin32" LoadOrderGroup.Name="Base" - SystemDriver.Name="mshidkmdf" LoadOrderGroup.Name="Base" - SystemDriver.Name="mshidumdf" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="msisadrv" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSKSSRV" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="MsLldp" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSPCLOCK" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSPQM" LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="MsSecFlt" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSTEE" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MTConfig" LoadOrderGroup.Name="Network" - SystemDriver.Name="Mup" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="mvumis" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NativeWifiP" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="ndfltr" LoadOrderGroup.Name="NDIS Wrapper" - SystemDriver.Name="NDIS" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NdisCap" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NdisTapi" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="Ndisuio" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="ndiswanlegacy" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="ndproxy" LoadOrderGroup.Name="NetBIOSGroup" - SystemDriver.Name="NetBIOS" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="NetBT" LoadOrderGroup.Name="File system" - SystemDriver.Name="Npfs" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="NTFS" LoadOrderGroup.Name="Base" - SystemDriver.Name="Null" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="nvraid" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="nvstor" LoadOrderGroup.Name="Parallel arbitrator" - SystemDriver.Name="Parport" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="partmgr" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="pci" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="pciide" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="pcmcia" LoadOrderGroup.Name="System Reserved" - SystemDriver.Name="pcw" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="pdc" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="percsas2i" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="percsas3i" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="Processor" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="prwntdrv" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="Psched" LoadOrderGroup.Name="Streams Drivers" - SystemDriver.Name="RasAcd" LoadOrderGroup.Name="Network" - SystemDriver.Name="rdbss" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="rdyboost" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="ReFSv1" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="rspndr" LoadOrderGroup.Name="Video" - SystemDriver.Name="s3cap" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="scfilter" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="sdbus" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="Serenum" LoadOrderGroup.Name="Extended base" - SystemDriver.Name="Serial" LoadOrderGroup.Name="Pointer Port" - SystemDriver.Name="sermouse" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="SiSRaid2" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="SiSRaid4" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="spaceport" LoadOrderGroup.Name="Network" - SystemDriver.Name="srv" LoadOrderGroup.Name="Network" - SystemDriver.Name="srv2" LoadOrderGroup.Name="Network" - SystemDriver.Name="srvnet" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="stexstor" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="storahci" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="storflt" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="stornvme" LoadOrderGroup.Name="FSFilter Quota Management" - SystemDriver.Name="storqosflt" LoadOrderGroup.Name="Base" - SystemDriver.Name="storvsc" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="swenum" LoadOrderGroup.Name="Video Init" - SystemDriver.Name="Synth3dVsc" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="Tcpip" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="tdx" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="terminpt" LoadOrderGroup.Name="Filter" - SystemDriver.Name="tib" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="tnd" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="TPM" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="TsUsbGD" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="tsusbhub" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="tunnel" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UcmCx0101" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UcmTcpciCx0101" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="Ucx01000" LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="udfs" LoadOrderGroup.Name="FSFilter Top" - SystemDriver.Name="UevAgentDriver" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="Ufx01000" LoadOrderGroup.Name="Base" - SystemDriver.Name="UfxChipidea" LoadOrderGroup.Name="Base" - SystemDriver.Name="ufxsynopsys" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="umbus" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="UmPass" LoadOrderGroup.Name="Base" - SystemDriver.Name="UrsChipidea" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UrsCx01000" LoadOrderGroup.Name="Base" - SystemDriver.Name="UrsSynopsys" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbccgp" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="usbcir" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbehci" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbhub" LoadOrderGroup.Name="Base" - SystemDriver.Name="USBHUB3" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbohci" LoadOrderGroup.Name="extended base" - SystemDriver.Name="usbprint" LoadOrderGroup.Name="Base" - SystemDriver.Name="usbuhci" LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="vdrvroot" LoadOrderGroup.Name="WdfLoadGroup" - SystemDriver.Name="VerifierExt" LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="vhdmp" LoadOrderGroup.Name="Base" - SystemDriver.Name="vhf" LoadOrderGroup.Name="Filter" - SystemDriver.Name="virtual_file" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="vmbus" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="VMBusHID" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="volmgr" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="volmgrx" LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="vpci" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="vsmraid" LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="VSTXRAID" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="vwififlt" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WacomPen" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wanarp" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wanarpv6" LoadOrderGroup.Name="FSFilter Virtualization" - SystemDriver.Name="wcifs" LoadOrderGroup.Name="FSFilter Top" - SystemDriver.Name="wcnfs" LoadOrderGroup.Name="Early-Launch" - SystemDriver.Name="WdBoot" LoadOrderGroup.Name="WdfLoadGroup" - SystemDriver.Name="Wdf01000" LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="WdFilter" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="WFPLWFS" LoadOrderGroup.Name="FSFilter Infrastructure" - SystemDriver.Name="WIMMount" LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="WindowsTrustedRT" LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="WindowsTrustedRTProxy" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="WinMad" LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="WinVerbs" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WmiAcpi" LoadOrderGroup.Name="FSFilter Compression" - SystemDriver.Name="Wof" LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="WpdUpFltr" LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="ws2ifsl" LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WSDPrintDevice" LoadOrderGroup.Name="Base" - SystemDriver.Name="WSDScan" LoadOrderGroup.Name="base" - SystemDriver.Name="WudfPf" LoadOrderGroup.Name="base" - SystemDriver.Name="WUDFRd" LoadOrderGroup.Name="NDIS" - SystemDriver.Name="xboxgip" LoadOrderGroup.Name="Base" - SystemDriver.Name="xinputhid" ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service R0 - 3ware () -> System32\drivers\3ware.sys R0 - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys R0 - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys R0 - ADP80XX () -> System32\drivers\ADP80XX.SYS R0 - amdsata () -> System32\drivers\amdsata.sys R0 - amdsbs () -> System32\drivers\amdsbs.sys R0 - amdxata () -> System32\drivers\amdxata.sys R0 - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys R0 - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys R0 - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD) -> System32\drivers\bxvbda.sys R0 - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys R0 - CNG () -> System32\Drivers\cng.sys S0 - Compbatt () -> (?) R0 - disk (@disk.inf,%disk_ServiceDesc%;Disk Driver) -> System32\drivers\disk.sys R0 - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys S0 - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys R0 - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys R0 - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys R0 - file_tracker (Acronis File Tracker Driver) -> system32\DRIVERS\file_tracker.sys R0 - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys R0 - fltsrv (Acronis Storage Filter Management) -> system32\DRIVERS\fltsrv.sys S0 - Fs_Rec () -> (?) R0 - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys R0 - HpSAMD () -> System32\drivers\HpSAMD.sys S0 - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys R0 - iaStorAV (@iastorav.inf,%iaStorAV.DeviceDesc%;Intel(R) SATA RAID Controller Windows) -> System32\drivers\iaStorAV.sys R0 - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys R0 - intelide () -> System32\drivers\intelide.sys R0 - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys R0 - iorate (@%SystemRoot%\system32\drivers\iorate.sys,-100) -> system32\drivers\iorate.sys R0 - isapnp () -> System32\drivers\isapnp.sys R0 - KSecDD () -> System32\Drivers\ksecdd.sys R0 - KSecPkg () -> System32\Drivers\ksecpkg.sys R0 - LSI_SAS () -> System32\drivers\lsi_sas.sys R0 - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys R0 - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys R0 - LSI_SSS () -> System32\drivers\lsi_sss.sys R0 - megasas () -> System32\drivers\megasas.sys R0 - megasr () -> System32\drivers\megasr.sys R0 - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys R0 - msisadrv () -> System32\drivers\msisadrv.sys R0 - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys R0 - mvumis () -> System32\drivers\mvumis.sys R0 - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys R0 - nvraid () -> System32\drivers\nvraid.sys R0 - nvstor () -> System32\drivers\nvstor.sys R0 - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys R0 - pci (@pci.inf,%pci_svcdesc%;PCI Bus Driver) -> System32\drivers\pci.sys R0 - pciide () -> System32\drivers\pciide.sys R0 - pcmcia () -> System32\drivers\pcmcia.sys R0 - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys R0 - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys R0 - percsas2i () -> System32\drivers\percsas2i.sys R0 - percsas3i () -> System32\drivers\percsas3i.sys R0 - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys R0 - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys R0 - scmbus (@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver) -> System32\drivers\scmbus.sys R0 - SiSRaid2 () -> System32\drivers\SiSRaid2.sys R0 - SiSRaid4 () -> System32\drivers\sisraid4.sys S0 - snapman (Acronis Snapshots Manager) -> system32\DRIVERS\snapman.sys R0 - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys R0 - stexstor () -> System32\drivers\stexstor.sys R0 - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys R0 - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys R0 - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys R0 - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys R0 - storvsc () -> System32\drivers\storvsc.sys R0 - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys R0 - tib (Acronis TIB Manager) -> system32\DRIVERS\tib.sys R0 - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys R0 - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys R0 - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys R0 - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys R0 - volsnap (@%SystemRoot%\system32\drivers\volsnap.sys,-100) -> System32\drivers\volsnap.sys R0 - volume (@volume.inf,%VolumeServiceDesc%;Volume driver) -> System32\drivers\volume.sys R0 - vsmraid () -> System32\drivers\vsmraid.sys R0 - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys S0 - WdBoot (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390) -> system32\drivers\WdBoot.sys R0 - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys S0 - WdFilter (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330) -> system32\drivers\WdFilter.sys R0 - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys R0 - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys R0 - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys R0 - Wof (Windows Overlay File System Filter Driver) -> (?) R1 - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys R1 - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys R1 - BasicDisplay () -> \SystemRoot\System32\drivers\BasicDisplay.sys R1 - BasicRender () -> \SystemRoot\System32\drivers\BasicRender.sys R1 - BdfNdisf (@oem63.inf,%BdfNdisf_Desc%;BitDefender Firewall NDIS 6 Filter Driver) -> \SystemRoot\system32\DRIVERS\bdfndisf6.sys S1 - bdfwfpf (bdfwfpf) -> \??\C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.1.0\Drivers\bdfwfpf.sys R1 - Beep (Beep) -> (?) R1 - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys R1 - CLBStor (InstantBurn Storage Helper Driver) -> system32\DRIVERS\CLBStor.sys R1 - CSC (@%systemroot%\system32\cscsvc.dll,-202) -> system32\drivers\csc.sys S1 - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys R1 - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys S1 - epp (epp) -> \??\G:\100% sécurisé finalis - padam-sirtaki of lfs ultra, barrow 2 & widen\bin64\epp.sys S1 - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys S1 - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys R1 - Msfs () -> (?) R1 - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys R1 - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys R1 - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys R1 - Npfs () -> (?) S1 - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys R1 - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys R1 - Null () -> (?) R1 - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys R1 - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys R1 - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys R1 - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys S2 - AcrSch2Svc (Acronis Scheduler2 Service) -> "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe" S2 - ADAM_GFIDirectoryDataStore (GFIDirectoryDataStore) -> %SystemRoot%\System32\dsamain.exe -sn:GFIDirectoryDataStore S2 - afcdpsrv (Acronis Nonstop Backup Service) -> C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe S2 - agp440 () -> (?) S2 - AMD External Events Utility () -> %SystemRoot%\system32\atiesrxx.exe S2 - AMD FUEL Service (AMD FUEL Service) -> "C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService S2 - AppHostSvc (@%windir%\system32\inetsrv\iisres.dll,-30011) -> %windir%\system32\svchost.exe -k apphost S2 - AudioEndpointBuilder (@%SystemRoot%\system32\AudioEndpointBuilder.dll,-204) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S2 - Audiosrv (@%SystemRoot%\system32\audiosrv.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - BFE (@%SystemRoot%\system32\bfe.dll,-1001) -> %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork S2 - BingDesktopUpdate (Bing Desktop Update service) -> "C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe" S2 - BITS (@%SystemRoot%\system32\qmgr.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k netsvcs R2 - BrokerInfrastructure (@%windir%\system32\bisrv.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S2 - CDPSvc (@%SystemRoot%\system32\cdpsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S2 - CDPUserSvc (@%SystemRoot%\system32\cdpusersvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S2 - CDPUserSvc_23c35 (CDPUserSvc_23c35) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S2 - CLBUDF (CyberLink InstantBurn UDF Filesystem) -> (?) S2 - clreg (@%SystemRoot%\system32\drivers\registry.sys,-100) -> \SystemRoot\System32\drivers\registry.sys R2 - CoreMessagingRegistrar (@%SystemRoot%\system32\coremessaging.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork R2 - CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k NetworkService R2 - DcomLaunch (@combase.dll,-5012) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S2 - DeviceAssociationService (@%SystemRoot%\system32\das.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - Dhcp (@%SystemRoot%\system32\dhcpcore.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S2 - DiagTrack (@%SystemRoot%\system32\diagtrack.dll,-3001) -> %SystemRoot%\System32\svchost.exe -k utcsvc R2 - Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101) -> %SystemRoot%\system32\svchost.exe -k NetworkService S2 - DoSvc (@%systemroot%\system32\dosvc.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - DPS (@%systemroot%\system32\dps.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork R2 - EapHost (@%systemroot%\system32\eapsvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k netsvcs S2 - ERSvc () -> (?) R2 - EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted S2 - EventSystem (@comres.dll,-2450) -> %SystemRoot%\system32\svchost.exe -k LocalService S2 - FileMarkerApplyIconService (FileMarker.NET Apply Icon Service) -> C:\Program Files (x86)\FileMarker.NET\FileMarkerService.exe S2 - FontCache (@%systemroot%\system32\FntCache.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S2 - GFIDS (GFI Directory Services) -> C:\Program Files\GFI\GFIDirectory\Directory\bin\GFI.DS.exe -service S2 - GFIProxy (GFI Proxy) -> "C:\Program Files\GFI\WebMonitor\GFiProxy.exe" S2 - gfi_lanss12_attservice (GFI LanGuard 12 Attendant Service) -> "C:\Program Files (x86)\GFI\LanGuard 12 Agent\lnssatt.exe" -service S2 - gfi_lanss12_winservice (GFI LanGuard 12 Service) -> "C:\Program Files (x86)\GFI\LanGuard 12\LnssWinService.exe" S2 - gpsvc (@gpapi.dll,-112) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - HPRegistrationSvc (HP Registration Service) -> "c:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HPRegistrationService.exe" S2 - IAStorDataMgrsvc () -> (?) R2 - IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500) -> %SystemRoot%\System32\svchost.exe -k NetSvcs S2 - LanmanServer (@%systemroot%\system32\srvsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k NetworkService S2 - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys R2 - lmhosts (@%SystemRoot%\system32\lmhsvc.dll,-101) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - LSM (@%windir%\system32\lsm.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S2 - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys S2 - MapsBroker (@%SystemRoot%\System32\moshost.dll,-100) -> %SystemRoot%\System32\svchost.exe -k NetworkService S2 - MARCore (GFI Archiver Core Service) -> "C:\Program Files\GFI\Archiver\Core\bin\MArc.Core.exe" -service S2 - MARIMAP (GFI Archiver IMAP Service) -> "C:\Program Files\GFI\Archiver\IMAP\bin\MArc.Imap.exe" -service S2 - MARMAIS (GFI Archiver Import Service) -> "C:\Program Files\GFI\Archiver\MAIS\bin\MArc.MAIS.exe" -service S2 - MARSearch (GFI Archiver Search Service) -> "C:\Program Files\GFI\Archiver\Search\bin\MArc.Search.exe" -service S2 - MARStore (GFI Archiver Store Service) -> "C:\Program Files\GFI\Archiver\Store\bin\MArc.Store.exe" -service S2 - MARVSS (GFI Archiver VSS Writer Service) -> "C:\Program Files\GFI\Archiver\VSS\bin\MArc.VSS.exe" -service S2 - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys S2 - mmsminisrv (Acronis Managed Machine Service Mini) -> "C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe" R2 - MpsSvc (@%SystemRoot%\system32\FirewallAPI.dll,-23090) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork R2 - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys S2 - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys S2 - MSSQL$SQLEXPRESS (SQL Server (SQLEXPRESS)) -> "c:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS S2 - NAUpdate (@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200) -> "C:\Program Files (x86)\Nero\Update\NASvc.exe" S2 - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys S2 - NIHardwareService () -> (?) R2 - NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k NetworkService R2 - nsi (@%SystemRoot%\system32\nsisvc.dll,-200) -> %systemroot%\system32\svchost.exe -k LocalService S2 - NVSvc () -> (?) S2 - OneSyncSvc (@%SystemRoot%\system32\APHostRes.dll,-10002) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S2 - OneSyncSvc_23c35 (Hôte de synchronisation_23c35) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S2 - Parvdm () -> (?) S2 - PcaSvc (@%SystemRoot%\system32\pcasvc.dll,-1) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S2 - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys R2 - PlugPlay (@%SystemRoot%\system32\umpnpmgr.dll,-200) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - Power (@%SystemRoot%\system32\umpo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - ProfSvc (@%systemroot%\system32\profsvc.dll,-300) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - RichVideo64 (Cyberlink RichVideo64 Service(CRVS)) -> "C:\Program Files\CyberLink\Shared files\RichVideo64.exe" R2 - RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k RPCSS R2 - RpcSs (@combase.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k rpcss S2 - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys S2 - RtkAudioService (Realtek Audio Service) -> C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe S2 - SamSs (@%SystemRoot%\system32\samsrv.dll,-1) -> %SystemRoot%\system32\lsass.exe S2 - Schedule (@%SystemRoot%\system32\schedsvc.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - SENS (@%SystemRoot%\system32\Sens.dll,-200) -> %SystemRoot%\system32\svchost.exe -k netsvcs S2 - SharedAccess (@%SystemRoot%\system32\ipnathlp.dll,-106) -> %SystemRoot%\System32\svchost.exe -k netsvcs S2 - ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288) -> %SystemRoot%\System32\svchost.exe -k netsvcs S2 - Spooler (@%systemroot%\system32\spoolsv.exe,-1) -> %SystemRoot%\System32\spoolsv.exe S2 - sppsvc (@%SystemRoot%\system32\sppsvc.exe,-101) -> %SystemRoot%\system32\sppsvc.exe S2 - SQLWriter (SQL Server VSS Writer) -> "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" S2 - srService () -> (?) S2 - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys S2 - stisvc (@%SystemRoot%\system32\wiaservc.dll,-9) -> %SystemRoot%\system32\svchost.exe -k imgsvc S2 - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys S2 - syncagentsrv (Acronis Sync Agent Service) -> "C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe" S2 - SysMain (@%SystemRoot%\system32\sysmain.dll,-1000) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - SystemEventsBroker (@%windir%\system32\SystemEventsBrokerServer.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S2 - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys S2 - Themes (@%SystemRoot%\System32\themeservice.dll,-8192) -> %SystemRoot%\System32\svchost.exe -k netsvcs S2 - tib_mounter (Acronis TIB Mounter) -> \SystemRoot\system32\DRIVERS\tib_mounter.sys R2 - tiledatamodelsvc (@%SystemRoot%\system32\tileobjserver.dll,-1) -> %systemroot%\system32\svchost.exe -k appmodel S2 - TrkWks (@%SystemRoot%\system32\trkwks.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R2 - UserManager (@%systemroot%\system32\usermgr.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S2 - virtual_file (Acronis Virtual File Driver) -> system32\DRIVERS\virtual_file.sys S2 - W3SVC (@%windir%\system32\inetsrv\iisres.dll,-30003) -> %windir%\system32\svchost.exe -k iissvcs S2 - WbioSrvc (@%systemroot%\system32\wbiosrvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k WbioSvcGroup S2 - wcifs (@%systemroot%\system32\drivers\wcifs.sys,-100) -> \SystemRoot\system32\drivers\wcifs.sys R2 - Wcmsvc (@%SystemRoot%\System32\wcmsvc.dll,-4097) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S2 - wcnfs (@%systemroot%\system32\drivers\wcnfs.sys,-100) -> \SystemRoot\system32\drivers\wcnfs.sys S2 - WebMonService (GFI WebMonitor Core Service) -> "C:\Program Files\GFI\WebMonitor\WebMon.WinService.exe" S2 - WerSvc (@%SystemRoot%\System32\wersvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k WerSvcGroup R2 - WinDefend (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310) -> "%ProgramFiles%\Windows Defender\MsMpEng.exe" R2 - Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - WlanSvc (@%SystemRoot%\System32\wlansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S2 - WMPNetworkSvc (@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101) -> "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" S2 - WpnService (@%SystemRoot%\system32\wpnservice.dll,-1) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - wscsvc (@%SystemRoot%\System32\wscsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted S2 - WSearch (@%systemroot%\system32\SearchIndexer.exe,-103) -> %systemroot%\system32\SearchIndexer.exe /Embedding S2 - wuauserv (@%systemroot%\system32\wuaueng.dll,-105) -> %systemroot%\system32\svchost.exe -k netsvcs S2 - {41E8078B-96D9-42DC-8789-A1CF102CD880} (Power Control [2016/08/14 22:02:30]) -> \??\C:\Program Files (x86)\CyberLink\PowerDVD16\Common\NavFilter\000.fcl S3 - 1394ohci (@1394.inf,%PCI\CC_0C0010.DeviceDesc%;1394 OHCI Compliant Host Controller) -> \SystemRoot\System32\drivers\1394ohci.sys S3 - AcpiDev (@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver) -> \SystemRoot\System32\drivers\AcpiDev.sys S3 - acpipagr (@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver) -> \SystemRoot\System32\drivers\acpipagr.sys S3 - AcpiPmi (@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver) -> \SystemRoot\System32\drivers\acpipmi.sys S3 - acpitime (@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver) -> \SystemRoot\System32\drivers\acpitime.sys S3 - AdobeFlashPlayerUpdateSvc (Adobe Flash Player Update Service) -> C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe S3 - AJRouter (@%SystemRoot%\system32\AJRouter.dll,-2) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - ALG (@%SystemRoot%\system32\Alg.exe,-112) -> %SystemRoot%\System32\alg.exe S3 - AmdK8 (@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver) -> \SystemRoot\System32\drivers\amdk8.sys S3 - amdkmdag () -> \SystemRoot\system32\DRIVERS\atikmdag.sys S3 - amdkmdap () -> \SystemRoot\system32\DRIVERS\atikmpag.sys S3 - AmdPPM (@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver) -> \SystemRoot\System32\drivers\amdppm.sys S3 - AppID (@%systemroot%\system32\srpapi.dll,-100) -> system32\drivers\appid.sys S3 - AppIDSvc (@%systemroot%\system32\appidsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - Appinfo (@%systemroot%\system32\appinfo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - applockerfltr (@%systemroot%\system32\srpapi.dll,-102) -> system32\drivers\applockerfltr.sys S3 - AppMgmt (@appmgmts.dll,-3250) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - AppReadiness (@%SystemRoot%\System32\AppReadiness.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k AppReadiness S3 - AppvStrm (@%systemroot%\system32\drivers\AppvStrm.sys,-101) -> \SystemRoot\system32\drivers\AppvStrm.sys S3 - AppvVemgr (@%systemroot%\system32\drivers\AppvVemgr.sys,-101) -> \SystemRoot\system32\drivers\AppvVemgr.sys S3 - AppvVfs (@%systemroot%\system32\drivers\AppvVfs.sys,-101) -> \SystemRoot\system32\drivers\AppvVfs.sys S3 - AppXSvc (@%SystemRoot%\system32\appxdeploymentserver.dll,-1) -> %systemroot%\system32\svchost.exe -k wsappx S3 - aspnet_state (@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1) -> %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe S3 - AsyncMac (@%systemroot%\system32\mprmsg.dll,-32000) -> \SystemRoot\System32\drivers\asyncmac.sys S3 - avchv (@oem62.inf,%ServiceDesc%;avchv Function Driver) -> \SystemRoot\system32\DRIVERS\avchv.sys S3 - AxInstSV (@%SystemRoot%\system32\AxInstSV.dll,-103) -> %SystemRoot%\system32\svchost.exe -k AxInstSVGroup S3 - bcmfn (@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service) -> \SystemRoot\System32\drivers\bcmfn.sys S3 - bcmfn2 (@bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service) -> \SystemRoot\System32\drivers\bcmfn2.sys S3 - BDESVC (@%SystemRoot%\system32\bdesvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs R3 - bowser (@%systemroot%\system32\browser.dll,-102) -> system32\DRIVERS\bowser.sys S3 - Browser (@%systemroot%\system32\browser.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - BthAvrcpTg (@bthaudhid.inf,%BthAvrcpTg_SvcDesc%;Bluetooth Audio/Video Remote Control HID) -> \SystemRoot\System32\drivers\BthAvrcpTg.sys S3 - BthHFEnum (@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio and Call Control HID Enumerator) -> \SystemRoot\System32\drivers\bthhfenum.sys S3 - bthhfhid (@bthaudhid.inf,%BthAudioHFHid.SVCDESC%;Bluetooth Hands-Free Call Control HID) -> \SystemRoot\System32\drivers\BthHFHid.sys S3 - BthHFSrv (@%SystemRoot%\System32\BthHFSrv.dll,-103) -> %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation S3 - BTHMODEM (@mdmbtmdm.inf,%BthModem.DisplayName%;Bluetooth Modem Communications Driver) -> \SystemRoot\System32\drivers\bthmodem.sys S3 - bthserv (@%SystemRoot%\System32\bthserv.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - buttonconverter (@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices) -> \SystemRoot\System32\drivers\buttonconverter.sys S3 - CapImg (@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen) -> \SystemRoot\System32\drivers\capimg.sys S3 - CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - cht4iscsi () -> System32\drivers\cht4sx64.sys S3 - cht4vbd (@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver) -> \SystemRoot\System32\drivers\cht4vx64.sys S3 - circlass (@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices) -> \SystemRoot\System32\drivers\circlass.sys S3 - ClipSVC (@%SystemRoot%\system32\ClipSVC.dll,-103) -> %SystemRoot%\System32\svchost.exe -k wsappx R3 - CLVirtualBus01 (@oem65.inf,%CLVirtualBus01.SVCDESC%;CyberLink Virtual CDROM Bus Enumerator) -> \SystemRoot\System32\drivers\CLVirtualBus01.sys S3 - CmBatt (@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver) -> \SystemRoot\System32\drivers\CmBatt.sys R3 - CompositeBus (@compositebus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver) -> \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys S3 - COMSysApp (@comres.dll,-947) -> %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} R3 - condrv (Console Driver) -> System32\drivers\condrv.sys S3 - CscService (@%systemroot%\system32\cscsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - DcpSvc (@%SystemRoot%\system32\dcpsvc.dll,-3001) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - defragsvc (@%SystemRoot%\system32\defragsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k defragsvc S3 - DeviceInstall (@%SystemRoot%\system32\umpnpmgr.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch S3 - DevQueryBroker (@%SystemRoot%\system32\DevQueryBroker.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - DfSdkS () -> (?) S3 - dg_ssudbus (@oem4.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)) -> \SystemRoot\system32\DRIVERS\ssudbus.sys S3 - diagnosticshub.standardcollector.service (@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000) -> %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe S3 - DmEnrollmentSvc (@%systemroot%\system32\Windows.Internal.Management.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - dmvsc () -> \SystemRoot\System32\drivers\dmvsc.sys S3 - dmwappushservice (@%SystemRoot%\system32\dmwappushsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - dot3svc (@%systemroot%\system32\dot3svc.dll,-1102) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - drmkaud (@wdmaudio.inf,%drmkaud.SvcDesc%;Pilotes audio approuvés par Microsoft) -> \SystemRoot\system32\DRIVERS\drmkaud.sys S3 - DsmSvc (@%SystemRoot%\system32\DeviceSetupManager.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - DsRoleSvc (@%SystemRoot%\System32\dsrolesrv.dll,-1) -> %SystemRoot%\System32\lsass.exe S3 - DsSvc (@%SystemRoot%\system32\dssvc.dll,-10003) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R3 - DXGKrnl (LDDM Graphics Subsystem) -> \SystemRoot\System32\drivers\dxgkrnl.sys S3 - EFS (@%SystemRoot%\system32\efssvc.dll,-100) -> %SystemRoot%\System32\lsass.exe S3 - embeddedmode (@%SystemRoot%\system32\embeddedmodesvc.dll,-201) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - EntAppSvc (@EnterpriseAppMgmtSvc.dll,-1) -> %systemroot%\system32\svchost.exe -k appmodel S3 - ErrDev (@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver) -> \SystemRoot\System32\drivers\errdev.sys S3 - exfat (exFAT File System Driver) -> (?) R3 - fastfat (FAT12/16/32 File System Driver) -> (?) S3 - Fax (@%systemroot%\system32\fxsresm.dll,-118) -> %systemroot%\system32\fxssvc.exe S3 - fdc (@fdc.inf,%fdc_ServiceDesc%;Floppy Disk Controller Driver) -> \SystemRoot\System32\drivers\fdc.sys S3 - fdPHost (@%systemroot%\system32\fdPHost.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - FDResPub (@%systemroot%\system32\fdrespub.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - fhsvc (@%systemroot%\system32\fhsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - Filetrace (@%SystemRoot%\system32\drivers\filetrace.sys,-10001) -> system32\drivers\filetrace.sys S3 - flpydisk (@flpydisk.inf,%floppy_ServiceDesc%;Floppy Disk Driver) -> \SystemRoot\System32\drivers\flpydisk.sys S3 - FontCache3.0.0.0 (@%SystemRoot%\system32\PresentationHost.exe,-3309) -> %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe S3 - FrameServer (@%systemroot%\system32\FrameServer.dll,-100) -> %SystemRoot%\System32\svchost.exe -k Camera S3 - FsDepends (@%SystemRoot%\system32\drivers\fsdepends.sys,-10001) -> System32\drivers\FsDepends.sys S3 - gencounter (@wgencounter.inf,%GenCounter.SVCDESC%;Microsoft Hyper-V Generation Counter) -> \SystemRoot\System32\drivers\vmgencounter.sys S3 - genericusbfn (@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class) -> \SystemRoot\System32\drivers\genericusbfn.sys S3 - GPIOClx0101 (Microsoft GPIO Class Extension Driver) -> System32\Drivers\msgpioclx.sys R3 - HDAudBus (@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio) -> \SystemRoot\System32\drivers\HDAudBus.sys S3 - HidBatt (@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver) -> \SystemRoot\System32\drivers\HidBatt.sys S3 - HidBth (@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport) -> \SystemRoot\System32\drivers\hidbth.sys S3 - hidi2c (@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver) -> \SystemRoot\System32\drivers\hidi2c.sys S3 - hidinterrupt (@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts) -> \SystemRoot\System32\drivers\hidinterrupt.sys S3 - HidIr (@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver) -> \SystemRoot\System32\drivers\hidir.sys S3 - hidserv (@%SystemRoot%\System32\hidserv.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R3 - HidUsb (@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver) -> \SystemRoot\System32\drivers\hidusb.sys S3 - HomeGroupListener (@%SystemRoot%\System32\ListSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - HomeGroupProvider (@%SystemRoot%\System32\provsvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted S3 - HTTP (@%SystemRoot%\system32\drivers\http.sys,-1) -> system32\drivers\HTTP.sys S3 - HvHost (@%SystemRoot%\system32\hvhostsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - hvservice (@%SystemRoot%\system32\drivers\hvservice.sys,-16) -> system32\drivers\hvservice.sys S3 - hyperkbd () -> \SystemRoot\System32\drivers\hyperkbd.sys S3 - i8042prt (@msmouse.inf,%i8042prt.SvcDesc%;PS/2 Keyboard and Mouse Port Driver) -> \SystemRoot\System32\drivers\i8042prt.sys S3 - iagpio (@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver) -> \SystemRoot\System32\drivers\iagpio.sys S3 - iai2c (@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller) -> \SystemRoot\System32\drivers\iai2c.sys S3 - iaLPSS2i_GPIO2 (@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys S3 - iaLPSS2i_I2C (@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_I2C.sys S3 - iaLPSSi_GPIO (@ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Controller Driver) -> \SystemRoot\System32\drivers\iaLPSSi_GPIO.sys S3 - iaLPSSi_I2C (@ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel(R) Serial IO I2C Controller Driver) -> \SystemRoot\System32\drivers\iaLPSSi_I2C.sys S3 - ibbus (@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver)) -> \SystemRoot\System32\drivers\ibbus.sys S3 - icssvc (@%SystemRoot%\System32\tetheringservice.dll,-4097) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - IndirectKmd (@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100) -> \SystemRoot\System32\drivers\IndirectKmd.sys S3 - IntcAzAudAddService (Service for Realtek HD Audio (WDM)) -> \SystemRoot\system32\drivers\RTKVHD64.sys S3 - intelppm (@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver) -> \SystemRoot\System32\drivers\intelppm.sys S3 - IpFilterDriver (@%systemroot%\system32\mprmsg.dll,-32013) -> system32\DRIVERS\ipfltdrv.sys S3 - IPMIDRV () -> \SystemRoot\System32\drivers\IPMIDrv.sys S3 - IPNAT (IP Network Address Translator) -> System32\drivers\ipnat.sys S3 - irda (IrDA) -> \SystemRoot\system32\drivers\irda.sys S3 - IRENUM (@%SystemRoot%\system32\drivers\irenum.sys,-100) -> system32\drivers\irenum.sys S3 - irmon (@%SystemRoot%\System32\irmon.dll,-2000) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - iScsiPrt (@iscsi.inf,%iScsiPortName%;iScsiPort Driver) -> \SystemRoot\System32\drivers\msiscsi.sys R3 - kbdclass (@keyboard.inf,%kbdclass.SvcDesc%;Keyboard Class Driver) -> \SystemRoot\System32\drivers\kbdclass.sys R3 - kbdhid (@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver) -> \SystemRoot\System32\drivers\kbdhid.sys R3 - kdnic (@kdnic.inf,%KdNic.Service.DispName%;Microsoft Kernel Debug Network Miniport (NDIS 6.20)) -> \SystemRoot\System32\drivers\kdnic.sys R3 - KeyIso (@keyiso.dll,-100) -> %SystemRoot%\system32\lsass.exe S3 - ksthunk (Kernel Streaming Thunks) -> \SystemRoot\system32\drivers\ksthunk.sys S3 - KtmRm (@comres.dll,-2946) -> %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation R3 - L1C (@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller) -> \SystemRoot\System32\drivers\L1C63x64.sys S3 - lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - LicenseManager (@%SystemRoot%\system32\licensemanagersvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - lltdsvc (@%SystemRoot%\system32\lltdres.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - lvrs64 (@oem7.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver) -> \SystemRoot\system32\DRIVERS\lvrs64.sys S3 - LVUVC64 (@oem6.inf,%PID_081B_DD%(UVC);Logitech HD Webcam C310(UVC)) -> \SystemRoot\system32\DRIVERS\lvuvc64.sys S3 - MDA_NTDRV (MDA_NTDRV) -> \??\C:\WINDOWS\system32\MDA_NTDRV.sys S3 - MessagingService (@%SystemRoot%\system32\MessagingService.dll,-100) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - MessagingService_23c35 (MessagingService_23c35) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - mlx4_bus (@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator) -> \SystemRoot\System32\drivers\mlx4_bus.sys S3 - Modem () -> system32\drivers\modem.sys S3 - monitor (@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service) -> \SystemRoot\System32\drivers\monitor.sys R3 - mouclass (@msmouse.inf,%mouclass.SvcDesc%;Mouse Class Driver) -> \SystemRoot\System32\drivers\mouclass.sys R3 - mouhid (@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver) -> \SystemRoot\System32\drivers\mouhid.sys R3 - mpsdrv (@%SystemRoot%\system32\drivers\mpsdrv.sys,-23092) -> System32\drivers\mpsdrv.sys S3 - MRxDAV (@%systemroot%\system32\webclnt.dll,-104) -> \SystemRoot\system32\drivers\mrxdav.sys R3 - mrxsmb (@%systemroot%\system32\wkssvc.dll,-1002) -> system32\DRIVERS\mrxsmb.sys R3 - mrxsmb20 (@%systemroot%\system32\wkssvc.dll,-1006) -> system32\DRIVERS\mrxsmb20.sys S3 - MsBridge (@%SystemRoot%\system32\bridgeres.dll,-1) -> System32\drivers\bridge.sys S3 - MSDTC (@comres.dll,-2797) -> %SystemRoot%\System32\msdtc.exe S3 - msgpiowin32 (@msgpiowin32.inf,%GPIO.SvcDesc%;Common Driver for Buttons, DockMode and Laptop/Slate Indicator) -> \SystemRoot\System32\drivers\msgpiowin32.sys S3 - mshidkmdf (@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100) -> \SystemRoot\System32\drivers\mshidkmdf.sys S3 - mshidumdf (@%SystemRoot%\system32\drivers\mshidumdf.sys,-100) -> \SystemRoot\System32\drivers\mshidumdf.sys S3 - MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - msiserver (@%SystemRoot%\system32\msimsg.dll,-27) -> %systemroot%\system32\msiexec.exe /V S3 - MSKSSRV (@ksfilter.inf,%MSKSSRV.DeviceDesc%;Microsoft Streaming Service Proxy) -> \SystemRoot\system32\DRIVERS\MSKSSRV.sys S3 - MSPCLOCK (@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Microsoft Streaming Clock Proxy) -> \SystemRoot\system32\DRIVERS\MSPCLOCK.sys S3 - MSPQM (@ksfilter.inf,%MSPQM.DeviceDesc%;Microsoft Streaming Quality Manager Proxy) -> \SystemRoot\system32\DRIVERS\MSPQM.sys S3 - MsRPC () -> (?) S3 - MsSecFlt (@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001) -> system32\drivers\mssecflt.sys S3 - MSTEE (@ksfilter.inf,%MSTEE.DeviceDesc%;Microsoft Streaming Tee/Sink-to-Sink Converter) -> \SystemRoot\system32\DRIVERS\MSTEE.sys S3 - MTConfig (@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver) -> \SystemRoot\System32\drivers\MTConfig.sys R3 - NativeWifiP (@%SystemRoot%\System32\drivers\nwifi.sys,-101) -> system32\DRIVERS\nwifi.sys S3 - NcaSvc (@%SystemRoot%\system32\ncasvc.dll,-3009) -> %SystemRoot%\System32\svchost.exe -k NetSvcs S3 - NcbService (@%SystemRoot%\system32\ncbservice.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - NcdAutoSetup (@%SystemRoot%\system32\NcdAutoSetup.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork S3 - ndfltr (@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service) -> \SystemRoot\System32\drivers\ndfltr.sys S3 - NdisCap (@%SystemRoot%\System32\drivers\ndiscap.sys,-5000) -> System32\drivers\ndiscap.sys S3 - NdisImPlatform (@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501) -> System32\drivers\NdisImPlatform.sys S3 - NdisTapi (@%systemroot%\system32\mprmsg.dll,-32001) -> System32\DRIVERS\ndistapi.sys R3 - Ndisuio (NDIS Usermode I/O Protocol) -> system32\drivers\ndisuio.sys R3 - NdisVirtualBus (@%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200) -> \SystemRoot\System32\drivers\NdisVirtualBus.sys S3 - NdisWan (@%systemroot%\system32\mprmsg.dll,-32002) -> \SystemRoot\System32\drivers\ndiswan.sys S3 - ndiswanlegacy (@%systemroot%\system32\mprmsg.dll,-32014) -> System32\DRIVERS\ndiswan.sys S3 - ndproxy (@%SystemRoot%\system32\drivers\todo.sys,-101;NDIS Proxy) -> System32\DRIVERS\NDProxy.sys S3 - NetAdapterCx (Network Adapter Wdf Class Extension Library) -> system32\drivers\NetAdapterCx.sys S3 - Netlogon (@%SystemRoot%\System32\netlogon.dll,-102) -> %systemroot%\system32\lsass.exe R3 - Netman (@%SystemRoot%\system32\netman.dll,-109) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R3 - netprofm (@%SystemRoot%\system32\netprofmsvc.dll,-202) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - NetSetupSvc (@%SystemRoot%\system32\NetSetupSvc.dll,-3) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - NgcCtnrSvc (@%SystemRoot%\System32\NgcCtnrSvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - NgcSvc (@%SystemRoot%\System32\ngcsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R3 - NTFS () -> (?) S3 - p2pimsvc (@%SystemRoot%\system32\pnrpsvc.dll,-8004) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - p2psvc (@%SystemRoot%\system32\p2psvc.dll,-8006) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - Parport (@msports.inf,%Parport.SVCDESC%;Parallel port driver) -> \SystemRoot\System32\drivers\parport.sys S3 - PeerDistSvc (@%SystemRoot%\system32\peerdistsvc.dll,-9000) -> %SystemRoot%\System32\svchost.exe -k PeerDist S3 - PerfHost (@%systemroot%\sysWow64\perfhost.exe,-2) -> %SystemRoot%\SysWow64\perfhost.exe S3 - PhoneSvc (@%SystemRoot%\system32\PhoneserviceRes.dll,-10000) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - PimIndexMaintenanceSvc (@%SystemRoot%\system32\UserDataAccessRes.dll,-15001) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - PimIndexMaintenanceSvc_23c35 (Données de contacts_23c35) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - pla (@%systemroot%\system32\pla.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork S3 - PNRPAutoReg (@%SystemRoot%\system32\pnrpauto.dll,-8002) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - PNRPsvc (@%SystemRoot%\system32\pnrpsvc.dll,-8000) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet S3 - PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted S3 - PptpMiniport (@%systemroot%\system32\mprmsg.dll,-32006) -> \SystemRoot\System32\drivers\raspptp.sys S3 - PrintNotify (@C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll,-1) -> %SystemRoot%\system32\svchost.exe -k print S3 - Processor (@cpu.inf,%Processor.SvcDesc%;Processor Driver) -> \SystemRoot\System32\drivers\processr.sys S3 - prwntdrv (prwntdrv) -> \??\C:\WINDOWS\system32\prwntdrv.sys S3 - QWAVE (@%SystemRoot%\system32\qwave.dll,-1) -> %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - QWAVEdrv (@%SystemRoot%\system32\drivers\qwavedrv.sys,-1) -> \SystemRoot\system32\drivers\qwavedrv.sys S3 - RasAcd (Remote Access Auto Connection Driver) -> System32\DRIVERS\rasacd.sys S3 - RasAgileVpn (@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2)) -> \SystemRoot\System32\drivers\AgileVpn.sys S3 - RasAuto (@%Systemroot%\system32\rasauto.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - Rasl2tp (@%systemroot%\system32\mprmsg.dll,-32005) -> \SystemRoot\System32\drivers\rasl2tp.sys S3 - RasMan (@%Systemroot%\system32\rasmans.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - RasPppoe (@%systemroot%\system32\mprmsg.dll,-32007) -> System32\DRIVERS\raspppoe.sys S3 - RasSstp (@%systemroot%\system32\sstpsvc.dll,-202) -> \SystemRoot\System32\drivers\rassstp.sys R3 - rdpbus (@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver) -> \SystemRoot\System32\drivers\rdpbus.sys S3 - RDPDR (@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100) -> System32\drivers\rdpdr.sys S3 - RdpVideoMiniport (Remote Desktop Video Miniport Driver) -> System32\drivers\rdpvideominiport.sys S3 - ReFSv1 () -> (?) S3 - RetailDemo (@%SystemRoot%\System32\RDXService.dll,-256) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - RmSvc (@%SystemRoot%\system32\RMapi.dll,-1001) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted S3 - RpcLocator (@%systemroot%\system32\Locator.exe,-2) -> %SystemRoot%\system32\locator.exe S3 - s3cap () -> \SystemRoot\System32\drivers\vms3cap.sys S3 - ScDeviceEnum (@%SystemRoot%\System32\ScDeviceEnum.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - scfilter (@%SystemRoot%\System32\drivers\scfilter.sys,-11) -> System32\DRIVERS\scfilter.sys S3 - scmdisk0101 (@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver) -> \SystemRoot\System32\drivers\scmdisk0101.sys S3 - SCPolicySvc (@%SystemRoot%\System32\certprop.dll,-13) -> %SystemRoot%\system32\svchost.exe -k netsvcs R3 - sdbus () -> \SystemRoot\System32\drivers\sdbus.sys S3 - SDRSVC (@%SystemRoot%\system32\sdrsvc.dll,-107) -> %SystemRoot%\system32\svchost.exe -k SDRSVC R3 - sdstor (@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver) -> \SystemRoot\System32\drivers\sdstor.sys S3 - seclogon (@%SystemRoot%\system32\seclogon.dll,-7001) -> %windir%\system32\svchost.exe -k netsvcs S3 - Sense (@%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001) -> "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe" S3 - SensorDataService (@%SystemRoot%\system32\SensorDataService.exe,-101) -> %SystemRoot%\System32\SensorDataService.exe S3 - SensorService (@%SystemRoot%\System32\sensorservice.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - SensrSvc (@%SystemRoot%\System32\sensrsvc.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - SerCx (Serial UART Support Library) -> system32\drivers\SerCx.sys S3 - SerCx2 (Serial UART Support Library) -> system32\drivers\SerCx2.sys S3 - Serenum (@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver) -> \SystemRoot\System32\drivers\serenum.sys S3 - Serial (@msports.inf,%Serial.SVCDESC%;Serial port driver) -> \SystemRoot\System32\drivers\serial.sys S3 - sermouse (@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver) -> \SystemRoot\System32\drivers\sermouse.sys S3 - SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - sfloppy (@flpydisk.inf,%sfloppy_devdesc%;High-Capacity Floppy Disk Drive) -> \SystemRoot\System32\drivers\sfloppy.sys S3 - smphost (@%SystemRoot%\System32\smphost.dll,-102) -> %SystemRoot%\System32\svchost.exe -k smphost S3 - SmsRouter (@%SystemRoot%\System32\SmsRouterSvc.dll,-10001) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - SNMPTRAP (@%SystemRoot%\system32\snmptrap.exe,-3) -> %SystemRoot%\System32\snmptrap.exe S3 - SpbCx (Simple Peripheral Bus Support Library) -> system32\drivers\SpbCx.sys S3 - srv2 (@%systemroot%\system32\srvsvc.dll,-104) -> System32\DRIVERS\srv2.sys S3 - srvnet () -> System32\DRIVERS\srvnet.sys S3 - SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - SstpSvc (@%SystemRoot%\system32\sstpsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService R3 - StateRepository (@%SystemRoot%\system32\windows.staterepository.dll,-1) -> %SystemRoot%\system32\svchost.exe -k appmodel S3 - StorSvc (@%SystemRoot%\System32\StorSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - svsvc (@%SystemRoot%\system32\svsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R3 - swenum (@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver) -> \SystemRoot\System32\drivers\swenum.sys S3 - swprv (@%SystemRoot%\System32\swprv.dll,-103) -> %SystemRoot%\System32\svchost.exe -k swprv S3 - Synth3dVsc () -> \SystemRoot\System32\drivers\Synth3dVsc.sys S3 - TabletInputService (@%SystemRoot%\system32\TabSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - TapiSrv (@%SystemRoot%\system32\tapisrv.dll,-10100) -> %SystemRoot%\System32\svchost.exe -k NetworkService S3 - Tcpip6 (@todo.dll,-100;Microsoft IPv6 Protocol Driver) -> System32\drivers\tcpip.sys S3 - terminpt (@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver) -> \SystemRoot\System32\drivers\terminpt.sys S3 - TermService (@%SystemRoot%\System32\termsrv.dll,-268) -> %SystemRoot%\System32\svchost.exe -k NetworkService S3 - TieringEngineService (@%SystemRoot%\system32\TieringEngineService.exe,-702) -> %SystemRoot%\system32\TieringEngineService.exe S3 - TimeBrokerSvc (@%windir%\system32\TimeBrokerServer.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - tnd (Acronis Try&Decide filter) -> \SystemRoot\system32\DRIVERS\tnd.sys S3 - TPM (@tpm.inf,%TPM%;TPM) -> \SystemRoot\System32\drivers\tpm.sys S3 - TrueSight () -> \??\C:\Windows\System32\drivers\TrueSight.sys S3 - TrustedInstaller (@%SystemRoot%\servicing\TrustedInstaller.exe,-100) -> %SystemRoot%\servicing\TrustedInstaller.exe S3 - tsusbflt (@%SystemRoot%\system32\drivers\tsusbflt.sys,-1000) -> System32\drivers\TsUsbFlt.sys S3 - TsUsbGD (@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device) -> \SystemRoot\System32\drivers\TsUsbGD.sys S3 - tsusbhub (@%SystemRoot%\system32\drivers\tsusbhub.sys,-1) -> system32\drivers\tsusbhub.sys S3 - tunnel (@nettun.inf,%TUNNEL.Service.DisplayName%;Microsoft Tunnel Miniport Adapter Driver) -> \SystemRoot\System32\drivers\tunnel.sys R3 - UASPStor (@uaspstor.inf,%UASPortName%;USB Attached SCSI (UAS) Driver) -> \SystemRoot\System32\drivers\uaspstor.sys S3 - UcmCx0101 (USB Connector Manager KMDF Class Extension) -> System32\Drivers\UcmCx.sys S3 - UcmTcpciCx0101 (UCM-TCPCI KMDF Class Extension) -> System32\Drivers\UcmTcpciCx.sys S3 - UcmUcsi (@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client) -> \SystemRoot\System32\drivers\UcmUcsi.sys R3 - Ucx01000 (USB Host Support Library) -> system32\drivers\ucx01000.sys S3 - UdeCx (USB Device Emulation Support Library) -> system32\drivers\udecx.sys S3 - UEFI (@uefi.inf,%UEFI.SvcDesc%;Microsoft UEFI Driver) -> \SystemRoot\System32\drivers\UEFI.sys S3 - Ufx01000 (USB Function Class Extension) -> system32\drivers\ufx01000.sys S3 - UfxChipidea (@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller) -> \SystemRoot\System32\drivers\UfxChipidea.sys S3 - ufxsynopsys (@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller) -> \SystemRoot\System32\drivers\ufxsynopsys.sys S3 - UI0Detect (@%SystemRoot%\system32\ui0detect.exe,-101) -> %SystemRoot%\system32\UI0Detect.exe R3 - umbus (@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver) -> \SystemRoot\System32\drivers\umbus.sys S3 - UmPass (@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver) -> \SystemRoot\System32\drivers\umpass.sys S3 - UmRdpService (@%SystemRoot%\system32\umrdp.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - UnistoreSvc (@%SystemRoot%\system32\UserDataAccessRes.dll,-10003) -> %SystemRoot%\System32\svchost.exe -k UnistackSvcGroup S3 - UnistoreSvc_23c35 (Stockage des données utilisateur_23c35) -> C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup S3 - upnphost (@%systemroot%\system32\upnphost.dll,-213) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S3 - UrsChipidea (@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver) -> \SystemRoot\System32\drivers\urschipidea.sys S3 - UrsCx01000 (USB Role-Switch Support Library) -> system32\drivers\urscx01000.sys S3 - UrsSynopsys (@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver) -> \SystemRoot\System32\drivers\urssynopsys.sys S3 - usbaudio (@wdma_usb.inf,%USBAudio.SvcDesc%;Pilote USB audio (WDM)) -> \SystemRoot\system32\drivers\usbaudio.sys R3 - usbccgp (@usb.inf,%GenericParent.SvcDesc%;Pilote parent générique USB Microsoft) -> \SystemRoot\System32\drivers\usbccgp.sys S3 - usbcir (@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR)) -> \SystemRoot\System32\drivers\usbcir.sys R3 - usbehci (@usbport.inf,%EHCIMP.SvcDesc%;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbehci.sys R3 - usbhub (@usbport.inf,%ROOTHUB.SvcDesc%;Microsoft USB Standard Hub Driver) -> \SystemRoot\System32\drivers\usbhub.sys R3 - USBHUB3 (@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub) -> \SystemRoot\System32\drivers\UsbHub3.sys R3 - usbohci (@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbohci.sys S3 - usbprint (@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class) -> \SystemRoot\System32\drivers\usbprint.sys S3 - usbser (@usbser.inf,%UsbSerial.DriverDesc%;Pilote série USB Microsoft) -> \SystemRoot\System32\drivers\usbser.sys R3 - USBSTOR (@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver) -> \SystemRoot\System32\drivers\USBSTOR.SYS S3 - usbuhci (@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbuhci.sys R3 - USBXHCI (@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller) -> \SystemRoot\System32\drivers\USBXHCI.SYS S3 - UserDataSvc (@%SystemRoot%\system32\UserDataAccessRes.dll,-14001) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - UserDataSvc_23c35 (Accès aux données utilisateur_23c35) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - UsoSvc (@%systemroot%\system32\usocore.dll,-102) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - VaultSvc (@%SystemRoot%\system32\vaultsvc.dll,-1003) -> %SystemRoot%\system32\lsass.exe S3 - vds (@%SystemRoot%\system32\vds.exe,-100) -> %SystemRoot%\System32\vds.exe S3 - VerifierExt (@%SystemRoot%\system32\drivers\VerifierExt.sys,-1000) -> system32\drivers\VerifierExt.sys S3 - vhdmp () -> \SystemRoot\System32\drivers\vhdmp.sys S3 - vhf (@%SystemRoot%\system32\drivers\vhf.sys,-100) -> \SystemRoot\System32\drivers\vhf.sys S3 - VMBusHID () -> \SystemRoot\System32\drivers\VMBusHID.sys S3 - vmgid (@wvmgid.inf,%VmGid.SVCDESC%;Microsoft Hyper-V Guest Infrastructure Driver) -> \SystemRoot\System32\drivers\vmgid.sys S3 - vmicguestinterface (@%systemroot%\system32\icsvc.dll,-801) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmicheartbeat (@%systemroot%\system32\icsvc.dll,-101) -> %systemroot%\system32\svchost.exe -k ICService S3 - vmickvpexchange (@%systemroot%\system32\icsvc.dll,-201) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmicrdv (@%systemroot%\system32\icsvcext.dll,-601) -> %systemroot%\system32\svchost.exe -k ICService S3 - vmicshutdown (@%systemroot%\system32\icsvc.dll,-301) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmictimesync (@%systemroot%\system32\icsvc.dll,-401) -> %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted S3 - vmicvmsession (@%systemroot%\system32\icsvc.dll,-901) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vmicvss (@%systemroot%\system32\icsvcext.dll,-501) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - vpci (@wvpci.inf,%vpci.SVCDESC%;Microsoft Hyper-V Virtual PCI Bus) -> \SystemRoot\System32\drivers\vpci.sys S3 - VSS (@%systemroot%\system32\vssvc.exe,-102) -> %systemroot%\system32\vssvc.exe S3 - vwifibus (@%SystemRoot%\System32\drivers\vwifibus.sys,-257) -> \SystemRoot\System32\drivers\vwifibus.sys S3 - W32Time (@%SystemRoot%\system32\w32time.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - w3logsvc (@%windir%\system32\inetsrv\iisres.dll,-30014) -> %windir%\system32\svchost.exe -k apphost S3 - WacomPen (@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver) -> \SystemRoot\System32\drivers\wacompen.sys S3 - WalletService (@%SystemRoot%\System32\WalletService.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k appmodel S3 - wanarp (@%systemroot%\system32\mprmsg.dll,-32011) -> System32\DRIVERS\wanarp.sys S3 - wanarpv6 (@%systemroot%\system32\mprmsg.dll,-32012) -> System32\DRIVERS\wanarp.sys S3 - WAS (@%windir%\system32\inetsrv\iisres.dll,-30001) -> %windir%\system32\svchost.exe -k iissvcs S3 - wbengine (@%systemroot%\system32\wbengine.exe,-104) -> "%systemroot%\system32\wbengine.exe" S3 - wcncsvc (@%SystemRoot%\system32\wcncsvc.dll,-3) -> %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation S3 - WDC_SAM (@oem9.inf,%WDC_SAM_ServiceName%;WD SCSI Pass Thru driver) -> \SystemRoot\System32\drivers\wdcsam64.sys S3 - WdiServiceHost (@%systemroot%\system32\wdi.dll,-502) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - WdiSystemHost (@%systemroot%\system32\wdi.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted S3 - wdiwifi (WDI Driver Framework) -> system32\DRIVERS\wdiwifi.sys S3 - WdNisDrv (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-370) -> system32\Drivers\WdNisDrv.sys S3 - WdNisSvc (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320) -> "%ProgramFiles%\Windows Defender\NisSrv.exe" S3 - WebClient (@%systemroot%\system32\webclnt.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - Wecsvc (@%SystemRoot%\system32\wecsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k NetworkService S3 - WEPHOSTSVC (@%systemroot%\system32\wephostsvc.dll,-100) -> %systemroot%\system32\svchost.exe -k WepHostSvcGroup S3 - wercplsupport (@%SystemRoot%\System32\wercplsupport.dll,-101) -> %SystemRoot%\System32\svchost.exe -k netsvcs S3 - WiaRpc (@%SystemRoot%\system32\wiarpc.dll,-2) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - WIMMount (@%SystemRoot%\system32\drivers\wimmount.sys,-101) -> system32\drivers\wimmount.sys S3 - WinHttpAutoProxySvc (@%SystemRoot%\system32\winhttp.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService S3 - WinMad (@mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service) -> \SystemRoot\System32\drivers\winmad.sys S3 - WinRM (@%Systemroot%\system32\wsmsvc.dll,-101) -> %SystemRoot%\System32\svchost.exe -k NetworkService S3 - WINUSB (@winusb.inf,%WINUSB_SvcDesc%;WinUsb Driver) -> \SystemRoot\System32\drivers\WinUSB.SYS S3 - WinVerbs (@mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service) -> \SystemRoot\System32\drivers\winverbs.sys S3 - wisvc (@%SystemRoot%\system32\flightsettings.dll,-104) -> %systemroot%\system32\svchost.exe -k netsvcs S3 - wlidsvc (@%SystemRoot%\system32\wlidsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - WmiAcpi (@wmiacpi.inf,%WMIMAP.SvcDesc%;Microsoft Windows Management Interface for ACPI) -> \SystemRoot\System32\drivers\wmiacpi.sys S3 - wmiApSrv (@%Systemroot%\system32\wbem\wmiapsrv.exe,-110) -> %systemroot%\system32\wbem\WmiApSrv.exe S3 - workfolderssvc (@%systemroot%\system32\workfolderssvc.dll,-102) -> %SystemRoot%\System32\svchost.exe -k LocalService S3 - WPDBusEnum (@%SystemRoot%\system32\wpdbusenum.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - WpdUpFltr (@%systemroot%\System32\drivers\WpdUpFltr.sys,-100) -> System32\drivers\WpdUpFltr.sys S3 - WpnUserService (@%SystemRoot%\system32\WpnUserService.dll,-1) -> %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup S3 - WpnUserService_23c35 (Service utilisateur de notifications Push Windows_23c35) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup S3 - WSDPrintDevice (@wsdprint.inf,%WSDPrintDevice.SVCDESC%;WSD Print Support) -> \SystemRoot\System32\drivers\WSDPrint.sys S3 - WSDScan (@sti.inf,%WSDScan.SvcDesc%;Prise en charge de la numérisation WSD) -> \SystemRoot\system32\DRIVERS\WSDScan.sys R3 - WudfPf (@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000) -> system32\drivers\WudfPf.sys S3 - WUDFRd (@%SystemRoot%\system32\drivers\WudfRd.sys,-1000) -> system32\drivers\WudfRd.sys R3 - wudfsvc (@%SystemRoot%\system32\wudfsvc.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted S3 - WUDFWpdFs () -> \SystemRoot\system32\DRIVERS\WUDFRd.sys S3 - WUDFWpdMtp () -> \SystemRoot\system32\DRIVERS\WUDFRd.sys S3 - WwanSvc (@%SystemRoot%\System32\wwansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork S3 - XblAuthManager (@%systemroot%\system32\XblAuthManager.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - XblGameSave (@%systemroot%\system32\XblGameSave.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - xboxgip (@xboxgip.inf,%XBOXGIP_Desc%;Xbox Game Input Protocol Driver) -> \SystemRoot\System32\drivers\xboxgip.sys S3 - XboxNetApiSvc (@%systemroot%\system32\XboxNetApiSvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs S3 - xinputhid (@xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver) -> \SystemRoot\System32\drivers\xinputhid.sys S4 - AppVClient (@%systemroot%\system32\AppVClient.exe,-102) -> %systemroot%\system32\AppVClient.exe R4 - cdfs (CD/DVD File System Reader) -> system32\DRIVERS\cdfs.sys S4 - cnghwassist (@%SystemRoot%\system32\drivers\cnghwassist.sys,-100) -> System32\DRIVERS\cnghwassist.sys S4 - NetTcpPortSharing (@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201) -> %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe S4 - RemoteAccess (@%Systemroot%\system32\mprdim.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs S4 - RemoteRegistry (@regsvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k localService S4 - SCardSvr (@%SystemRoot%\System32\SCardSvr.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation S4 - shpamsvc (@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs S4 - SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) -> "c:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -i SQLEXPRESS S4 - SQLBrowser (SQL Server Browser) -> "c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe" S4 - tzautoupdate (@%SystemRoot%\system32\tzautoupdate.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService S4 - udfs (udfs) -> system32\DRIVERS\udfs.sys S4 - UevAgentDriver (@%systemroot%\system32\drivers\UevAgentDriver.sys,-101) -> \SystemRoot\system32\drivers\UevAgentDriver.sys S4 - UevAgentService (@%systemroot%\system32\AgentService.exe,-102) -> %systemroot%\system32\AgentService.exe S4 - ws2ifsl (@%systemroot%\System32\drivers\ws2ifsl.sys,-1000) -> \SystemRoot\system32\drivers\ws2ifsl.sys ---------- | System files (Microsoft Files whitelisted) [MD5.EE1CCC54F75C24727A218F98FC5349DA] - [16/07/2016 13:41:53] - (.Copyright (c) 2011 LSI - LSI 3ware SCSI Storport Driver.) - [104.84 Ko] - (5.1.0.51) - C:\WINDOWS\System32\Drivers\3ware.sys [MD5.49B9DB97AFC85DCCBDACDAB2E90085B7] - [16/07/2016 13:41:53] - (.Copyright (C) PMC-Sierra 2001-2014 - PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller.) - [1108.84 Ko] - (1.3.0.10769) - C:\WINDOWS\System32\Drivers\adp80xx.sys [MD5.74FFBC43B4B899C9A8CA06A892F2CE73] - [16/07/2016 13:41:53] - (.Copyright © 2008-2015 AMD, Inc. - AHCI 1.3 Device Driver.) - [81.34 Ko] - (1.1.3.277) - C:\WINDOWS\System32\Drivers\amdsata.sys [MD5.AAB0F1D8D7E54761ABAB13AF161F1680] - [16/07/2016 13:41:53] - (.2012 Advanced Micro Devices, Inc. - AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform.) - [253.34 Ko] - (3.7.1540.43) - C:\WINDOWS\System32\Drivers\amdsbs.sys [MD5.F91BAAC4237C40352A807000F3B716F9] - [16/07/2016 13:41:53] - (.Copyright © 2008-2015 AMD, Inc. - Storage Filter Driver.) - [26.34 Ko] - (1.1.3.277) - C:\WINDOWS\System32\Drivers\amdxata.sys [MD5.E6AB1F0B4C3D4E0D2A88332D76FECD03] - [16/07/2016 13:41:53] - (.Copyright 2014 PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) - [128.84 Ko] - (7.5.0.32048) - C:\WINDOWS\System32\Drivers\arcsas.sys [MD5.D1F059A530620DCF71303B525D52CA97] - [13/08/2016 22:54:46] - (.Copyright (C) 1998-2012 Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) - [21141.48 Ko] - (8.1.1.1500) - C:\WINDOWS\System32\Drivers\atikmdag.sys [MD5.AD96CC96B6A0CEE8910A13679426C970] - [13/08/2016 22:54:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) - [658.48 Ko] - (8.14.1.6463) - C:\WINDOWS\System32\Drivers\atikmpag.sys [MD5.3F5523DCEFE42B385659C5CB46A6B810] - [16/07/2016 13:41:53] - (.© Broadcom Corporation. - BCM Function 2 Device Driver.) - [9.5 Ko] - (6.3.9477.0) - C:\WINDOWS\System32\Drivers\bcmfn.sys [MD5.0B750A6A6D847E73CA48ADD7A0F5A393] - [16/07/2016 13:41:53] - (.© Broadcom Corporation. - BCM Function 2 Device Driver.) - [9.5 Ko] - (6.3.9391.6) - C:\WINDOWS\System32\Drivers\bcmfn2.sys [MD5.AF3E1ABAB951FC9064267ED76268F41B] - [16/02/2016 16:52:38] - (.Copyright (C) BitDefender LLC - BitDefender Firewall NDIS6 Filter Driver.) - [104.98 Ko] - (7.0.0.12) - C:\WINDOWS\System32\Drivers\bdfndisf6.sys [MD5.61BAC67048CA5C1D08C48FCC8012B613] - [16/07/2016 13:41:52] - (.(c) COPYRIGHT 2014-2016 QLogic Corporation - QLogic Gigabit Ethernet VBD.) - [521.34 Ko] - (7.12.31.105) - C:\WINDOWS\System32\Drivers\bxvbda.sys [MD5.48BC8B59BF348BD8C8702B93171008F2] - [16/07/2016 13:41:53] - (.Copyright © 2016 Chelsio Communications. - Chelsio iSCSI Crash Dump Driver.) - [100.34 Ko] - (6.1.14.200) - C:\WINDOWS\System32\Drivers\cht4dx64.sys [MD5.0AED948DA8D5F08B3D6F12E4E2089736] - [16/07/2016 13:41:53] - (.Copyright © 2016 Chelsio Communications. - Chelsio iSCSI VMiniport Driver.) - [338.84 Ko] - (6.1.14.200) - C:\WINDOWS\System32\Drivers\cht4sx64.sys [MD5.0002A0FDE087C1657AB31CE73077539C] - [16/07/2016 13:41:53] - (.Copyright © 2010 Chelsio Communications. - Virtual Bus Driver for Chelsio ® T4 Chipset.) - [2054.84 Ko] - (6.1.14.200) - C:\WINDOWS\System32\Drivers\cht4vx64.sys [MD5.19863788DFFBE37CB63BF19D1FD5C247] - [14/08/2016 21:32:28] - (.Copyright(C) Cyberlink Co.,Ltd. - Cyberlink Storage Helper Driver (WindowsNT5.x).) - [25.26 Ko] - (5.0.0.10524) - C:\WINDOWS\System32\Drivers\CLBStor.sys [MD5.C3EE731B310E6C563A47F80C0ADD39CD] - [14/08/2016 21:32:32] - (.Copyright (C) CyberLink Corporation. - UDF File System Driver.) - [370.26 Ko] - (5.0.0.10524) - C:\WINDOWS\System32\Drivers\CLBUDF.sys [MD5.0C7626AFB2419207B2ABCB6F8AEA334F] - [14/08/2016 21:43:13] - (.Copyright (C) 2014 CyberLink - CyberLink Virtual CDROM Bus Enumerator.) - [100.76 Ko] - (2.0.0.3505) - C:\WINDOWS\System32\Drivers\CLVirtualBus01.sys [MD5.2285B31039611D509F6120D691CA661F] - [05/03/2013 01:24:02] - (.@ 2012 Hewlett-Packard Development Company,L.P. - hpvhd 64bit support driver.) - [26.81 Ko] - (1.3.0.0) - C:\WINDOWS\System32\Drivers\cpqdfw.sys [MD5.7EC6FC0266D74BD47ABB130A328B70EC] - [16/07/2016 13:41:52] - (.(c) COPYRIGHT 2014-2016 QLogic Corporation - QLogic 10 GigE VBD.) - [3338.84 Ko] - (7.13.65.105) - C:\WINDOWS\System32\Drivers\evbda.sys [MD5.27B3C0F193F00D65F2D6B2C8C7FD22FF] - [21/08/2016 09:54:13] - (.Copyright © Acronis International GmbH, 2002-2013. - File tracker minifilter driver.) - [331.84 Ko] - (1.1.0.2350) - C:\WINDOWS\System32\Drivers\file_tracker.sys [MD5.4AD91299304A5E75084434F246DE0F9A] - [21/08/2016 09:52:21] - (.Copyright © Acronis International GmbH, 2002-2013. - Acronis Storage Filter Management Driver.) - [159.34 Ko] - (1.3.0.2243) - C:\WINDOWS\System32\Drivers\fltsrv.sys [MD5.F5CA18197B4646E04DB9EB2D6642CC4D] - [16/07/2016 13:41:53] - (.Copyright (c) 2004-2011 Hewlett-Packard Development Company, L.P. - Smart Array SAS/SATA Controller Media Driver.) - [62.84 Ko] - (8.0.4.0) - C:\WINDOWS\System32\Drivers\HpSAMD.sys [MD5.C6B8743B213F06AA60943D8366FE968F] - [16/07/2016 13:41:54] - (.Copyright (C) 2013. - Intel(R) Serial IO GPIO Controller Driver.) - [32.5 Ko] - (604.10146.3023.12819) - C:\WINDOWS\System32\Drivers\iagpio.sys [MD5.9A2A2F3C69B9A30B6E78536F6D258BAD] - [16/07/2016 13:41:54] - (.Copyright (C) 2013. - Intel(R) Serial IO I2C Driver.) - [79.5 Ko] - (604.10146.2643.2818) - C:\WINDOWS\System32\Drivers\iai2c.sys [MD5.5A0E850F8CD17791A3E6A3CF81D0CA28] - [16/07/2016 13:41:54] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO GPIO Driver v2.) - [63 Ko] - (30.63.1610.8) - C:\WINDOWS\System32\Drivers\iaLPSS2i_GPIO2.sys [MD5.7508F1096803385D6376BFD0BD473AC4] - [16/07/2016 13:41:54] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO I2C Driver v2.) - [172.25 Ko] - (30.63.1610.8) - C:\WINDOWS\System32\Drivers\iaLPSS2i_I2C.sys [MD5.16A10CCEDCF5AC4CAAE43DC9FC40392F] - [16/07/2016 13:41:52] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO GPIO Controller Driver.) - [37.23 Ko] - (1.1.250.0) - C:\WINDOWS\System32\Drivers\iaLPSSi_GPIO.sys [MD5.EB82A11613326691508D9ED9A4FE29E7] - [16/07/2016 13:41:50] - (.Copyright © 2015, Intel Corporation. - Intel(R) Serial IO I2C Controller Driver.) - [110.5 Ko] - (1.1.253.0) - C:\WINDOWS\System32\Drivers\iaLPSSi_I2C.sys [MD5.97E553D03219D3D51705C7235D9EAEBD] - [16/07/2016 13:41:53] - (.Copyright (C), Intel Corporation. - Intel(R) Rapid Storage Technology driver (inbox) - x64.) - [657.34 Ko] - (13.2.0.1022) - C:\WINDOWS\System32\Drivers\iaStorAV.sys [MD5.8350FE3BCDE3428BC040877BB7E9EAEB] - [16/07/2016 13:41:53] - (.Copyright(C) Intel Corporation 1994-2008 - Intel Matrix Storage Manager driver - x64.) - [402.34 Ko] - (8.6.2.1019) - C:\WINDOWS\System32\Drivers\iaStorV.sys [MD5.3BA03F7C7700DDF4C383DDE9252F5817] - [16/07/2016 13:41:53] - (.Copyright© 2009 Mellanox Technologies Ltd - InfiniBand Fabric Bus Driver.) - [513.84 Ko] - (5.1.11548.0) - C:\WINDOWS\System32\Drivers\ibbus.sys [MD5.4E444F41E69BBE2E0BAE34D5DFCB5732] - [16/07/2016 13:41:53] - (.2001-2012 Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabit Ethernet Controller.) - [118.5 Ko] - (2.1.0.16) - C:\WINDOWS\System32\Drivers\L1C63x64.sys [MD5.8E1B0946948CCC0BC1FA3CB70374A795] - [16/07/2016 13:41:53] - (.Copyright © LSI Corporation 2010 - LSI Fusion-MPT SAS Driver (StorPort).) - [106.34 Ko] - (1.34.3.83) - C:\WINDOWS\System32\Drivers\lsi_sas.sys [MD5.4F68163FC04C973500DC4DA0946917B0] - [16/07/2016 13:41:53] - (.Copyright © LSI Corporation 2012 - LSI SAS Gen2 Driver (StorPort).) - [103.34 Ko] - (2.0.79.80) - C:\WINDOWS\System32\Drivers\lsi_sas2i.sys [MD5.E5AC5F2815938651CDCC27F425474673] - [16/07/2016 13:41:53] - (.Copyright © Avago Technologies 2015 - Avago SAS Gen3 Driver (StorPort).) - [98.84 Ko] - (2.51.12.80) - C:\WINDOWS\System32\Drivers\lsi_sas3i.sys [MD5.CCF6EC9FB9B8F18E05B4253E81013E48] - [16/07/2016 13:41:53] - (.Copyright © LSI Corporation 2012 - LSI SSS PCIe/Flash Driver (StorPort).) - [80.84 Ko] - (2.10.61.81) - C:\WINDOWS\System32\Drivers\lsi_sss.sys [MD5.A0A527569856B9814E8920F52EBB67F5] - [26/10/2012 16:42:22] - (.(c) 1996-2012 Logitech. - Logitech Kernel Audio Improvement Filter Driver.) - [343.28 Ko] - (13.80.853.0) - C:\WINDOWS\System32\Drivers\lvrs64.sys [MD5.415E344294D1C0D04627B29146F68481] - [26/10/2012 16:42:22] - (.(c) 1996-2012 Logitech. - Logitech USB Video Class Driver.) - [4646.66 Ko] - (13.80.853.0) - C:\WINDOWS\System32\Drivers\lvuvc64.sys [MD5.C3CDCCF07486BD2616A7B82946E07AC0] - [16/07/2016 13:41:53] - (.Copyright © Avago Technologies2013 - MEGASAS RAID Controller Driver for Windows.) - [58.34 Ko] - (6.706.6.0) - C:\WINDOWS\System32\Drivers\megasas.sys [MD5.FADB2FE017E69EECE0E1BA78661C2E8C] - [16/07/2016 13:41:53] - (.Copyright (C) 2007 LSI Corporation. - LSI MegaRAID Software RAID Driver.) - [562.34 Ko] - (15.2.2013.129) - C:\WINDOWS\System32\Drivers\megasr.sys [MD5.FD60818B66B2E8A5415EA840E99A9D8F] - [16/07/2016 13:41:53] - (.Copyright© 2009 Mellanox Technologies Ltd - MLX4 Bus Driver.) - [822.84 Ko] - (5.1.11548.0) - C:\WINDOWS\System32\Drivers\mlx4_bus.sys [MD5.3D2C5B4995CA0751D32DEA0DE9FDFE44] - [16/07/2016 13:41:53] - (.Copyright (c) Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) - [62.34 Ko] - (1.0.5.1016) - C:\WINDOWS\System32\Drivers\mvumis.sys [MD5.629CB21AC49C8867E0F29DF1C16DB7B4] - [16/07/2016 13:41:53] - (.Copyright© 2009 Mellanox Technologies Ltd - NetworkDirect Support Filter Driver.) - [106.34 Ko] - (5.1.11548.0) - C:\WINDOWS\System32\Drivers\ndfltr.sys [MD5.6C76780A01FC2B885BD6E957B5C36B02] - [16/07/2016 13:42:03] - (.-.) - [88.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Drivers\NetAdapterCx.sys [MD5.D261DF41F0840F734856A2B4F5E072C7] - [16/07/2016 13:41:53] - (.Copyright(C) 2001-2011 NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) - [146.84 Ko] - (10.6.0.23) - C:\WINDOWS\System32\Drivers\nvraid.sys [MD5.23B702B555EB0436B9DAA0BC63DA65CE] - [16/07/2016 13:41:53] - (.Copyright(C) 2001-2011 NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) - [162.34 Ko] - (10.6.0.23) - C:\WINDOWS\System32\Drivers\nvstor.sys [MD5.540116170E2135FCD5DDE77702166B67] - [16/07/2016 13:41:53] - (.Copyright © Avago Technologies2013 - MEGASAS RAID Controller Driver for Windows.) - [57.34 Ko] - (6.805.3.0) - C:\WINDOWS\System32\Drivers\percsas2i.sys [MD5.8356F87553BF49C703CF382033815898] - [16/07/2016 13:41:53] - (.Copyright © Avago Technologies2013 - MEGASAS RAID Controller Driver for Windows.) - [60.34 Ko] - (6.603.6.0) - C:\WINDOWS\System32\Drivers\percsas3i.sys [MD5.E9740A3BC0AE6EA035FF7ECE3A1B27B6] - [14/08/2016 07:58:56] - (.Copyright (c) Realtek Semiconductor Corp.1998-2013 - Realtek(r) High Definition Audio Function Driver.) - [3480.84 Ko] - (6.0.1.7004) - C:\WINDOWS\System32\Drivers\RTKVHD64.sys [MD5.A34CE1830E45DA98932295FDE4B7908A] - [16/07/2016 13:41:53] - (.Copyright (c) SiS Corp. 2000-2010 - SiS RAID Stor Miniport Driver.) - [43.84 Ko] - (5.1.1039.2600) - C:\WINDOWS\System32\Drivers\sisraid2.sys [MD5.A7B5C670770E908DA5FEF5BF1136E933] - [16/07/2016 13:41:53] - (.Copyright (c) SiS Corp. 2007-2013 - SiS AHCI Stor-Miniport Driver.) - [79.84 Ko] - (5.1.1039.3600) - C:\WINDOWS\System32\Drivers\sisraid4.sys [MD5.67E7E7DB39769F2D8C4DC7BD4EBA02E6] - [21/08/2016 09:52:25] - (.Copyright © Acronis International GmbH, 2002-2013. - Acronis Snapshot API.) - [332.34 Ko] - (4.7.0.2500) - C:\WINDOWS\System32\Drivers\snapman.sys [MD5.0F4A5D01156B948B54550375498B08A2] - [22/07/2016 05:51:36] - (.Copyright ⓒ SAMSUNG - SAMSUNG USB Composite Device Driver.) - [127.63 Ko] - (2.12.3.0) - C:\WINDOWS\System32\Drivers\ssudbus.sys [MD5.29D26E1347AE1BBD4201014E19880B2C] - [16/07/2016 13:41:53] - (.© Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) - [30.34 Ko] - (5.1.0.10) - C:\WINDOWS\System32\Drivers\stexstor.sys [MD5.D66C989F0C86A11472A57963841643D4] - [21/08/2016 09:52:32] - (.Copyright © Acronis International GmbH, 2002-2013. - Acronis Backup Archive Explorer.) - [1237.84 Ko] - (1.0.0.1163) - C:\WINDOWS\System32\Drivers\tib.sys [MD5.0F9FD35675C7B29AA01DF7CA038FC18C] - [21/08/2016 09:52:35] - (.Copyright © Acronis International GmbH, 2002-2015. - Acronis TIB Mounter Driver.) - [188.84 Ko] - (5.0.0.2561) - C:\WINDOWS\System32\Drivers\tib_mounter.sys [MD5.21AFBEAC264AB4C6A399E41EF7B2A500] - [21/08/2016 09:52:39] - (.Copyright © Acronis International GmbH, 2002-2013. - Acronis Try&Decide Volume Filter Driver.) - [587.34 Ko] - (1.1.0.2347) - C:\WINDOWS\System32\Drivers\tnd.sys [MD5.0D5A09B08568760AE85A801FCBC0F83D] - [19/08/2016 06:17:54] - (.-.) - [27.61 Ko] - (2.0.2.0) - C:\WINDOWS\System32\Drivers\TrueSight.sys [MD5.4875DC63E548812C75D4FDEF84970C89] - [17/07/2012 04:36:29] - (.Copyright © 2011-2012 AMD, Inc. - AMD USB Filter Driver.) - [55.66 Ko] - (2.0.10.262) - C:\WINDOWS\System32\Drivers\usbfilter.sys [MD5.593D66A1424176B07E1E04B581C636C2] - [21/08/2016 09:52:42] - (.Copyright © Acronis International GmbH, 2002-2014. - Acronis Virtual File.) - [272.84 Ko] - (2.0.0.2305) - C:\WINDOWS\System32\Drivers\virtual_file.sys [MD5.FD9BCB8920973CEAD4D49DC7A6D8A618] - [16/07/2016 13:41:53] - (.Copyright (C) VIA Technologies 1992-2007 - VIA RAID DRIVER FOR AMD-X86-64.) - [162.84 Ko] - (7.0.9600.6352) - C:\WINDOWS\System32\Drivers\vsmraid.sys [MD5.0C111F220798CCE80484026E06822379] - [16/07/2016 13:41:53] - (.Copyright (C) 2008 VIA Corporation - VIA StorX RAID Controller Driver.) - [298.34 Ko] - (8.0.9200.8110) - C:\WINDOWS\System32\Drivers\VSTXRAID.SYS [MD5.A556768CC1FA4F36022BEE2F0EDE2566] - [13/08/2016 22:56:54] - (.© 2006-2015 Western Digital Technologies, Inc. - Western Digital SCSI Architecture Model (SAM) driver.) - [26.25 Ko] - (1.1.0.0) - C:\WINDOWS\System32\Drivers\wdcsam64.sys [MD5.F95DE20312ACCA7761446DE152BD1F7C] - [16/07/2016 13:41:53] - (.Copyright© 2009 Mellanox Technologies Ltd - Kernel WinMad.) - [31.34 Ko] - (5.1.11548.0) - C:\WINDOWS\System32\Drivers\winmad.sys [MD5.8B9AFF5F08E66A6F1F1063DEC9457FB6] - [16/07/2016 13:41:53] - (.Copyright© 2009 Mellanox Technologies Ltd - Kernel WinVerbs.) - [63.34 Ko] - (5.1.11548.0) - C:\WINDOWS\System32\Drivers\winverbs.sys ---------- | Uninstall [HKU\S-1-5-21-3042704910-407304991-3750219112-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\VideoWatermarkPro] : (Video Watermark Pro.-.WonderFox Soft, Inc.) -> "C:\Users\Jean-Marie\Documents\AoaoPhoto Digital Studio\Video Watermark Pro\unin00000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DivX Setup] : (Configuration DivX.-.DivX, LLC) -> C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\EPSON XP-710 Series] : (EPSON XP-710 Series Printer Uninstall.-.SEIKO EPSON Corporation) -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IINSLPE.EXE /R /APD /P:"EPSON XP-710 Series" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\proDAD-Adorage-3.0] : (proDAD Adorage 3.0 (64bit).-.proDAD GmbH) -> "C:\Program Files\proDAD\Adorage-3.0\uninstall.exe" uninstall spcp PATHVERSION "3.0" MAINNAME "Adorage" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Wondershare Filmora_is1] : (Wondershare Filmora(Build 7.5.0).-.Wondershare Software) -> "C:\Program Files\Wondershare\Filmora\unins000.exe" [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}] : (ccc-utility64.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{0FA995CC-C849-4755-B14B-5404CC75DC24}] : (Energy Star.-.Hewlett-Packard) -> MsiExec.exe /I{0FA995CC-C849-4755-B14B-5404CC75DC24} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39}] : (GFI Directory.-.GFI Software Development Ltd) -> MsiExec.exe /X{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2E58F5E0-B5EF-844C-5B18-4C21F800CAD6}] : (ccc-utility64.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3F31FAA8-6CC1-4FFE-894C-D31E54067C8A}] : (GFI WebMonitor 10.-.GFI Software Ltd) -> MsiExec.exe /X{3F31FAA8-6CC1-4FFE-894C-D31E54067C8A} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{503F672D-6C84-448A-8F8F-4BC35AC83441}] : (AMD APP SDK Runtime.-.Advanced Micro Devices Inc.) -> MsiExec.exe /I{503F672D-6C84-448A-8F8F-4BC35AC83441} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}] : (AMD Catalyst Install Manager.-.Advanced Micro Devices, Inc.) -> msiexec /q/x{5F769CF4-5263-4C7B-AEB2-C06A73AE4428} REBOOT=ReallySuppress [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}] : (HP Postscript Converter.-.Hewlett-Packard) -> MsiExec.exe /I{6E14E6D6-3175-4E1A-B934-CAB5A86367CD} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464}] : (GFI Archiver.-.GFI Software Development Ltd) -> MsiExec.exe /X{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A5A0E0B5-578C-43CE-B201-1C01A0388DA9}_is1] : (FileMarker.NET Pro v 1.0.-.ArcticLine Software) -> "C:\Program Files (x86)\FileMarker.NET\unins000.exe" [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E7366CA8-7179-77AE-E712-BA18D70A0A07}] : (AMD Fuel.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] : (Adobe Flash Player 22 NPAPI.-.Adobe Systems Incorporated) -> C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_22_0_0_209_Plugin.exe -maintain plugin [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EaseUS Partition Recovery_is1] : (EaseUS Partition Recovery 8.5.-.EaseUS) -> "C:\Program Files (x86)\EaseUS\EaseUS Partition Recovery 8.5\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EaseUS Todo PCTrans_is1] : (EaseUS Todo PCTrans 9.0.-.EaseUS) -> "C:\Program Files (x86)\EaseUS\EaseUS Todo PCTrans\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IM_Magic_PR] : (IM-Magic Partition Resizer Free 2016.-.IM-Magic Inc.) -> C:\Program Files\IM-Magic\Partition Resizer\uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{0c8ebb00-4909-459c-8347-b2068b7f0319}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{0c8ebb00-4909-459c-8347-b2068b7f0319}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}] : (CyberLink Media Suite 14.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{ADD5DB49-72CF-11D8-9D75-000129760D75}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}] : (CyberLink LabelPrint.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}] : (CyberLink PowerDVD.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Microsoft SQL Server 11] : (Microsoft SQL Server 2012.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Video Essentials for Windows] : (NewBlue Video Essentials for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Video Essentials for Windows\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Usbfix] : (UsbFix.-.El Desaparecido - www.usb-antivirus.com - www.sosvirus.net) -> C:\UsbFix\Un-UsbFix.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Video to GIF] : (Video to GIF 5.3.-.AoaoPhoto Digital Studio.) -> C:\Program Files (x86)\AoaoPhoto Digital Studio\Video to GIF\unins000.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Vivaldi] : (Vivaldi.-.Vivaldi) -> "C:\Program Files (x86)\Vivaldi\Application\1.3.551.30\Installer\setup.exe" --uninstall --system-level --vivaldi [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wondershare TidyMyMusic_is1] : (Wondershare TidyMyMusic(Build 1.5.0.1).-.Wondershare Software) -> "C:\Program Files (x86)\Wondershare\TidyMyMusic\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WUCCCApp] : (AMD Catalyst Control Center.-.AMD) -> "C:\AMD\WU-CCC2\ccc2_install\WULaunchApp.exe" -uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}] : (Nero 2016 Content Pack.-.Nero AG) -> MsiExec.exe /I{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{05C6B128-1B40-4495-9CB9-090B368BFA0A}] : (Nero Video Samples.-.Nero AG) -> MsiExec.exe /X{05C6B128-1B40-4495-9CB9-090B368BFA0A} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{07326A3E-02B3-1078-25D7-B8666BA8FE15}] : (CCC Help Korean.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{07FA4960-B038-49EB-891B-9F95930AA544}] : (HP Customer Experience Enhancements.-.Hewlett-Packard) -> MsiExec.exe /X{07FA4960-B038-49EB-891B-9F95930AA544} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}] : (CCC Help Finnish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{09BE17DC-59D2-FD28-371D-DCE0AE76CE75}] : (CCC Help Korean.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0C5A57BA-435E-43F3-8040-ADF08D715C8A}] : (CyberLink Travel Pack 3.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{0C5A57BA-435E-43F3-8040-ADF08D715C8A}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{0C5A57BA-435E-43F3-8040-ADF08D715C8A} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0c8ebb00-4909-459c-8347-b2068b7f0319}] : (CyberLink OEM Share Pack 2.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{0c8ebb00-4909-459c-8347-b2068b7f0319}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{104D7F23-A414-EE6D-315E-A07CB75ADEEE}] : (CCC Help English.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{11087D24-567D-7D88-69C6-D7A08B5F4C47}] : (Catalyst Control Center - Branding.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /I{11087D24-567D-7D88-69C6-D7A08B5F4C47} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{150D88F1-40AF-4678-A39D-BCE2332F34E5}] : (Nero Abstract Themes.-.Nero AG) -> MsiExec.exe /X{150D88F1-40AF-4678-A39D-BCE2332F34E5} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{160301DE-306A-4ADE-8A47-BC5790AF0486}] : (GFI LanGuard 12 Agent.-.GFI Software Development Ltd.) -> MsiExec.exe /X{160301DE-306A-4ADE-8A47-BC5790AF0486} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}\Setup.exe" -uninstall -l0x40c [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1A7CF3BE-0D4A-33DF-DFD9-824487726365}] : (CCC Help German.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1AD99E77-37CC-744E-39CA-67F6FD34565A}] : (Catalyst Control Center Localization All.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1B6F5E51-575E-4693-BCA2-7543570D076D}] : (Nero Kwik Themes Basic.-.Nero AG) -> MsiExec.exe /X{1B6F5E51-575E-4693-BCA2-7543570D076D} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}] : (CCC Help English.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1BC4C58D-D726-172B-DA2C-BBE6AE5DEB76}] : (CCC Help Finnish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1C63279A-BF36-4852-9924-B1978D6585A6}] : (Nero Device Updates.-.Nero AG) -> MsiExec.exe /X{1C63279A-BF36-4852-9924-B1978D6585A6} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1E6AF4B4-0910-4821-CB20-F8FD7AA09CCB}] : (CCC Help Russian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}] : (CCC Help French.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}] : (CyberLink Media Suite 14.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}] : (Nero Video Transitions 1.-.Nero AG) -> MsiExec.exe /X{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2432E589-6256-4513-B0BF-EFA8E325D5F0}] : (Nero SharedVideoCodecs.-.Nero AG) -> MsiExec.exe /X{2432E589-6256-4513-B0BF-EFA8E325D5F0} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}] : (CCC Help Russian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}] : (Nero Cliparts.-.Nero AG) -> MsiExec.exe /X{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{29F67D84-3A70-456E-806A-52301B02070B}] : (Nero Effects Basic.-.Nero AG) -> MsiExec.exe /X{29F67D84-3A70-456E-806A-52301B02070B} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}] : (CCC Help Hungarian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2E2526C8-51A8-F6EB-8289-6787E880CE27}] : (Catalyst Control Center Localization All.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}] : (CyberLink WaveEditor 2.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}] : (CCC Help Spanish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}] : (CCC Help Chinese Standard.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{38FCF27C-71A7-442D-A4AA-274C4394044C}] : (GFI LanGuard.-.GFI Software Development Ltd.) -> MsiExec.exe /X{38FCF27C-71A7-442D-A4AA-274C4394044C} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{43B5FB0A-9900-43B0-BD46-9E7F89C88A98}] : (Acronis True Image.-.Acronis) -> MsiExec.exe /X{43B5FB0A-9900-43B0-BD46-9E7F89C88A98} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{43B5FB0A-9900-43B0-BD46-9E7F89C88A98}Visible] : (Acronis True Image.-.Acronis) -> "C:\Program Files (x86)\Acronis\TrueImageHome\Uninstall.exe" {43B5FB0A-9900-43B0-BD46-9E7F89C88A98} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}] : (Recovery Manager.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4D25D881-7183-462F-95C8-990CA1944E0B}] : (Nero PiP Effects 1.-.Nero AG) -> MsiExec.exe /X{4D25D881-7183-462F-95C8-990CA1944E0B} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}] : (Nero Holiday and Sports Themes.-.Nero AG) -> MsiExec.exe /X{504D84ED-AE75-4F85-A68B-BB3D4CB3E169} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1] : (Wondershare Helper Compact 2.5.0.-.Wondershare) -> "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{55B464FA-16DE-4127-A7B8-D49CD2768E63}_is1] : (Turbo View & Convert.-.IMSI/Design, LLC) -> "C:\Program Files (x86)\IMSIDesign\Turbo View & Convert\unins001.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5AD25D5C-C813-146B-4FB0-76561F7875B7}] : (CCC Help Hungarian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5B4886EE-5A95-C257-A68F-2DCADE47A273}] : (CCC Help Norwegian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5DB58618-7021-C650-EE8A-58CD1FAA95F9}] : (CCC Help Thai.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}] : (Prerequisite installer.-.Nero AG) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5F5ACD0C-A454-32A7-E206-EE89B1510128}] : (CCC Help Danish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60251665-84B4-41D6-84BF-6D50CE68DD08}] : (Nero Express.-.Nero AG) -> MsiExec.exe /X{60251665-84B4-41D6-84BF-6D50CE68DD08} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{64D5A142-BD50-726E-ED9E-D2508D2A17E2}] : (Catalyst Control Center InstallProxy.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}] : (Nero Update.-.Nero AG) -> MsiExec.exe /X{65BB0407-4CC8-4DC7-952E-3EEFDF05602A} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{67087BB4-19B4-C169-3E52-2BED796D8AB3}] : (CCC Help Swedish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6861C1AD-9829-4DE4-8647-4785ECEA421A}] : (Nero Video.-.Nero AG) -> MsiExec.exe /X{6861C1AD-9829-4DE4-8647-4785ECEA421A} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6AE04BB9-A455-16ED-5806-DCFBB14505D6}] : (CCC Help Dutch.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6BADCD73-E925-46F7-A295-FF2448632728}] : (CyberLink PowerDirector 14.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{6BADCD73-E925-46F7-A295-FF2448632728}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{6BADCD73-E925-46F7-A295-FF2448632728} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}] : (Hewlett-Packard ACLM.NET v1.2.0.0.-.Hewlett-Packard Company) -> MsiExec.exe /I{6F340107-F9AA-47C6-B54C-C3A19F11553F} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}] : (CCC Help German.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB}] : (CyberLink Wedding Pack.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7474548C-E456-4818-8ED0-4A1F00EF77A1}] : (Catalyst Control Center - Branding.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /I{7474548C-E456-4818-8ED0-4A1F00EF77A1} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{76DFBEB9-9E55-8CC6-B99A-9CEFAC573A1F}] : (CCC Help Spanish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7984FCA5-1BB6-46e6-91E2-ED5C301AF11A}] : (CyberLink PhotoDirector 7.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{7984FCA5-1BB6-46e6-91E2-ED5C301AF11A}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{7984FCA5-1BB6-46e6-91E2-ED5C301AF11A} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}] : (CCC Help Chinese Traditional.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7B63B2922B174135AFC0E1377DD81EC2}] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}] : (Nero Football (Soccer) Themes.-.Nero AG) -> MsiExec.exe /X{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}] : (CyberLink PowerDVD 16.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7E2D87F3-F3BC-4fa5-9F72-BF021ED66CB3}] : (CyberLink Power2Go 10.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{7E2D87F3-F3BC-4fa5-9F72-BF021ED66CB3}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{7E2D87F3-F3BC-4fa5-9F72-BF021ED66CB3} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}] : (Nero MediaHome.-.Nero AG) -> MsiExec.exe /X{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7F22DD97-256D-491D-9090-743FADC79BBE}] : (Nero RescueAgent.-.Nero AG) -> MsiExec.exe /X{7F22DD97-256D-491D-9090-743FADC79BBE} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82CA1714-13EA-F419-91FE-12834424745E}] : (CCC Help Italian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{839D1577-5415-6C89-6642-515DFFE6432F}] : (CCC Help Czech.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}] : (Nero Retro Film Themes.-.Nero AG) -> MsiExec.exe /X{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{84B13BF6-F7AF-198E-0E77-DCA4027B9D19}] : (CCC Help Japanese.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}] : (Nero Platinum Effects 12.-.Nero AG) -> MsiExec.exe /X{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}] : (CCC Help Turkish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8D149BE2-6542-4F6A-AEC4-7D61E6DCAEFB}] : (CyberLink MediaEspresso 7.5.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{8D149BE2-6542-4F6A-AEC4-7D61E6DCAEFB}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{8D149BE2-6542-4F6A-AEC4-7D61E6DCAEFB} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}] : (CyberLink MediaShow 6.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}] : (CCC Help Swedish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{910B539D-F257-46C8-9CB8-6C95EFF9CF22}] : (Stashimi Stub Installer.-.Nero AG) -> MsiExec.exe /X{910B539D-F257-46C8-9CB8-6C95EFF9CF22} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{918D30D3-AD9B-43A8-9EF7-463075DC93CD}_is1] : (System Checkup 4.0.-.iolo technologies, LLC) -> C:\Program Files (x86)\iolo\System Checkup\uninstsms.exe /uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{918D30D3-AD9B-43A8-9EF7-463075DC93CD}_is1_is1] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{92EBE575-0C6E-4713-B095-34BB927E5AC6}] : (Nero CoverDesigner.-.Nero AG) -> MsiExec.exe /X{92EBE575-0C6E-4713-B095-34BB927E5AC6} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{933B4015-4618-4716-A828-5289FC03165F}] : (VC80CRTRedist - 8.0.50727.6195.-.DivX, Inc) -> MsiExec.exe /I{933B4015-4618-4716-A828-5289FC03165F} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{955BF340-C379-4375-AA2F-F3BCB2A498AB}] : (Nero Family and Events Themes.-.Nero AG) -> MsiExec.exe /X{955BF340-C379-4375-AA2F-F3BCB2A498AB} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9C637A56-4287-487F-95BF-1422FC1AA879}] : (Nero 2016.-.Nero AG) -> MsiExec.exe /I{9C637A56-4287-487F-95BF-1422FC1AA879} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A163159C-B476-4501-B163-3F77809AC833}] : (Nero Burning Core.-.Nero AG) -> MsiExec.exe /X{A163159C-B476-4501-B163-3F77809AC833} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}] : (CCC Help Norwegian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A666A6E7-3A51-E289-559B-BF3486036ABF}] : (CCC Help Turkish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}] : (CCC Help Thai.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ABA39912-380C-0EF3-C820-868115EB1DAC}] : (Catalyst Control Center InstallProxy.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ABC88553-8770-4B97-B43E-5A90647A5B63}] : (Nero ControlCenter.-.Nero AG) -> MsiExec.exe /X{ABC88553-8770-4B97-B43E-5A90647A5B63} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC7A441A-353F-75F6-6ABA-3BF98161B530}] : (CCC Help Greek.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ACE49D50-19CD-44A6-B192-46F985283B26}] : (Nero PiP Effects Basic.-.Nero AG) -> MsiExec.exe /X{ACE49D50-19CD-44A6-B192-46F985283B26} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ADD5DB49-72CF-11D8-9D75-000129760D75}] : (CyberLink PowerBackup 2.6.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}] : (AMD Catalyst Control Center.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}] : (Nero Recode.-.Nero AG) -> MsiExec.exe /X{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B6480ED1-448E-813B-4FE0-BED811D1C01F}] : (CCC Help French.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B839153C-D4D2-F89C-5033-0A160C62706B}] : (CCC Help Portuguese.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}] : (Nero Disc to Device.-.Nero AG) -> MsiExec.exe /X{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BDBF9803-B57C-AB2A-8830-CBED34703840}] : (Catalyst Control Center Graphics Previews Common.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}] : (Nero Core Components.-.Nero AG) -> MsiExec.exe /X{BEBEE34D-84A2-4EDD-8BEA-96CC54371263} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BFB6DE5F-9BEA-1FBB-3584-2C78639CE59A}] : (CCC Help Polish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C1EA3764-1138-AE27-AD63-549BAD99BA15}] : (CCC Help Japanese.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C257E434-E8F1-4E06-A616-598E4933553E}_is1] : (File Identifier.-.Sharpened Productions) -> "C:\Program Files (x86)\File Identifier\unins000.exe" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}] : (CCC Help Czech.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}] : (Nero Image Samples.-.Nero AG) -> MsiExec.exe /X{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243}] : (CyberLink LabelPrint.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}] : (CCC Help Dutch.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CE675FBD-75C3-45F1-B6AF-8D250861D536}] : (Nero Disc Menus 3.-.Nero AG) -> MsiExec.exe /X{CE675FBD-75C3-45F1-B6AF-8D250861D536} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}] : (Nero Burning ROM.-.Nero AG) -> MsiExec.exe /X{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D36DD326-7280-11D8-97C8-000129760CBE}] : (PhotoNow.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}] : (CyberLink PowerProducer 6.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DD35ECFB-5C95-398B-CAFA-B5E8881363C3}] : (CCC Help Italian.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}] : (CyberLink PowerDVD.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}] : (Nero Disc Menus Basic.-.Nero AG) -> MsiExec.exe /X{E17BCB76-9924-4BD5-B6D6-50D3407B4E74} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E3D04529-6EDB-11D8-A372-0050BAE317E1}] : (CyberLink PowerDVD Copy 1.5.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\Setup.exe" /z-uninstall [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E817E580-6318-AFC8-2102-322C73117EC4}] : (CCC Help Polish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E8406BA9-5D47-4A62-08C3-759EA677229A}] : (AMD VISION Engine Control Center.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EEBF1676-AF87-4266-93D8-0C14A34C4217}] : (Nero Disc Menus 1.-.Nero AG) -> MsiExec.exe /X{EEBF1676-AF87-4266-93D8-0C14A34C4217} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EF0BA418-AF37-471E-9594-EAE5913F4681}] : (Nero Launcher.-.Nero AG) -> MsiExec.exe /X{EF0BA418-AF37-471E-9594-EAE5913F4681} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F030BFE8-8476-4C08-A553-233DE80A2BE1}] : (Nero Info.-.Nero AG) -> MsiExec.exe /X{F030BFE8-8476-4C08-A553-233DE80A2BE1} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}] : (Realtek High Definition Audio Driver.-.Realtek Semiconductor Corp.) -> C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709 [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F193812F-83C0-3CED-1EDE-BE2525267303}] : (CCC Help Chinese Traditional.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F754BC24-2C04-F76E-C403-0175F0954560}] : (CCC Help Chinese Standard.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F77474EE-EB6C-C87B-88AF-3310C848E068}] : (CCC Help Greek.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}] : (CCC Help Danish.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FC216422-E2C7-47BF-8010-F858811CC86C}] : (CyberLink Holiday Pack vol 7.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{FC216422-E2C7-47BF-8010-F858811CC86C}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{FC216422-E2C7-47BF-8010-F858811CC86C} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FC62C740-2339-618C-467B-36CE6D409E5F}] : (CCC Help Portuguese.-.Advanced Micro Devices, Inc.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}] : (Nero Disc Menus 2.-.Nero AG) -> MsiExec.exe /X{FE81E6B5-652B-40E7-B3B2-7171C6F297DA} ---------- | Ports ---------- | Microsoft Specifications CheckID: AutoPlay999{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: FileAssociations999{ABC88553-8770-4B97-B43E-5A90647A5B63} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{60251665-84B4-41D6-84BF-6D50CE68DD08} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{60251665-84B4-41D6-84BF-6D50CE68DD08} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{92EBE575-0C6E-4713-B095-34BB927E5AC6} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{92EBE575-0C6E-4713-B095-34BB927E5AC6} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: GAC_NGEN_ALL_Feature0{3FE312D5-B862-40CE-8E4E-A6D8ABF62736} - NOT VersionNT64 -> GAC_NGEN_ALL_Feature CheckID: AutoPlay999{7F22DD97-256D-491D-9090-743FADC79BBE} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{7F22DD97-256D-491D-9090-743FADC79BBE} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{EF0BA418-AF37-471E-9594-EAE5913F4681} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{EF0BA418-AF37-471E-9594-EAE5913F4681} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{F030BFE8-8476-4C08-A553-233DE80A2BE1} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{F030BFE8-8476-4C08-A553-233DE80A2BE1} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{1C63279A-BF36-4852-9924-B1978D6585A6} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{1C63279A-BF36-4852-9924-B1978D6585A6} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: EnglishFiles0{38FCF27C-71A7-442D-A4AA-274C4394044C} - ProductLanguage <> 1033 -> EnglishFiles CheckID: AutoPlay999{A163159C-B476-4501-B163-3F77809AC833} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{A163159C-B476-4501-B163-3F77809AC833} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{910B539D-F257-46C8-9CB8-6C95EFF9CF22} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{910B539D-F257-46C8-9CB8-6C95EFF9CF22} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{6861C1AD-9829-4DE4-8647-4785ECEA421A} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{6861C1AD-9829-4DE4-8647-4785ECEA421A} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations CheckID: AutoPlay999{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlay CheckID: FileAssociations999{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociations ---------- | CLSID ---------- | Listing No Microsoft signed files | system32 (Not necessary Malwares) [MD5.82C37C3E27020AF6C2E018E944284676] - |D| - [16/07/2016 13:42:35] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@AudioToastIcon.png [MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |D| - [16/07/2016 13:42:05] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@BackgroundAccessToastIcon.png [MD5.C65F3DD5C512B0E73984DB406B5512F7] - |D| - [16/07/2016 13:42:19] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@edptoastimage.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |D| - [16/07/2016 13:42:38] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@EnrollmentToastIcon.png [MD5.373CF57FF3DAAEEB629F90CE7226B30D] - |D| - [16/07/2016 13:42:41] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@language_notification_icon.png [MD5.46DACDA5036EBECEDF08427407E3017C] - |D| - [16/07/2016 13:42:40] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@optionalfeatures.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |D| - [16/07/2016 13:42:38] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@VpnToastIcon.png [MD5.7AC3EA1A5175106ED6467FF0C5315541] - |D| - [16/07/2016 13:42:38] - (.-.) - [14.75 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@WiFiNotificationIcon.png [MD5.58B6CB6A8528BA1B267CFAE325E6B834] - |D| - [16/07/2016 13:42:23] - (.-.) - [20.3 Ko] - (0.0.0.0) - C:\WINDOWS\system32\@WindowsHelloFaceToastIcon.png [MD5.4B10D8998C824DD84AD597F9E058F6F0] - |D| - [13/08/2016 22:54:39] - (.-.) - [171.53 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amde31a.dat [MD5.C7628FE6341B7919D2F62DB9057DB4FC] - |D| - [13/08/2016 22:54:39] - (.-.) - [208.48 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amdgfxinfo64.dll [MD5.AF1928F5E15921A29877C2E18626F80E] - |D| - [13/08/2016 22:54:39] - (.-.) - [139.98 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amdhdl64.dll [MD5.DDEB20626133878B0CE79CCE29B031B9] - |D| - [13/08/2016 22:54:39] - (.-.) - [814.26 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amdicdxx.dat [MD5.82CAB4EAF1E1CBA85AE5DEBB4C068EE2] - |D| - [13/08/2016 22:54:39] - (.Advanced Micro Devices, Inc. Copyright (C) 2015 - LiquidVR SDK 1.0.) - [616.48 Ko] - (1.0.3.8) - C:\WINDOWS\system32\amdlvr64.dll [MD5.C366C5A2EE8F1F586691E4511AB56040] - |D| - [13/08/2016 22:54:39] - (.Copyright (C) 2013 AMD Inc. - Mantle driver, support for SI family and above.) - [6529.48 Ko] - (9.1.10.83) - C:\WINDOWS\system32\amdmantle64.dll [MD5.3960C946E67311C9831550AEDC649C3A] - |D| - [13/08/2016 22:54:39] - (.-.) - [460.27 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amdmiracast.dll [MD5.4CA9A0DF33972919623BBFF8FBD1A501] - |D| - [13/08/2016 22:54:39] - (.Copyright (c) 2013 Advanced Micro Devices, Inc. - Radeon MMOCL Universal Driver.) - [57.98 Ko] - (1.6.0.0) - C:\WINDOWS\system32\amdmmcl6.dll [MD5.7BA9A6BBF176D945D7B201865897E158] - |D| - [13/08/2016 22:54:41] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD COMPILER OpenCL 1.1 Compiler.) - [26898.98 Ko] - (0.8.0.0) - C:\WINDOWS\system32\amdocl12cl64.dll [MD5.AFF92249DA8E62FF8C6D2B89977D3245] - |D| - [13/08/2016 22:54:42] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OpenCL 2.0 Runtime.) - [46673.98 Ko] - (10.0.1800.11) - C:\WINDOWS\system32\amdocl64.dll [MD5.8305AA2FEBE5CAD45AB8D208C17DA930] - |D| - [13/08/2016 22:54:43] - (.-.) - [1168 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amdocl_as64.exe [MD5.187EB6A72565FAAF01AAE0CDD63DE56F] - |D| - [13/08/2016 22:54:44] - (.-.) - [1045.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\amdocl_ld64.exe [MD5.2B79CD2445F85D54959702583ECBCC04] - |D| - [13/08/2016 22:54:44] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [85.94 Ko] - (8.14.10.23) - C:\WINDOWS\system32\amdpcom64.dll [MD5.267B865E69E89A8A1359FF5A965D64D9] - |D| - [16/07/2016 13:42:12] - (.-.) - [424.9 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ApnDatabase.xml [MD5.F94192B47ACA96AFFEBC1073891EBB42] - |D| - [16/07/2016 13:43:20] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\system32\AppVStreamingUX.exe.config [MD5.567BF499D25205A659A059184B458DB7] - |D| - [16/07/2016 13:42:34] - (.-.) - [2.65 Ko] - (0.0.0.0) - C:\WINDOWS\system32\AppxProvisioning.xml [MD5.28DF09388444100467873AC906FD6CB2] - |D| - [13/08/2016 22:54:45] - (.Copyright (C) 2008-2014 Advanced Micro Devices, Inc. - ADL.) - [1226.98 Ko] - (7.15.20.1301) - C:\WINDOWS\system32\atiadlxx.dll [MD5.53650482B8E621276DC55E50C9FB2FEE] - |D| - [13/08/2016 22:54:45] - (.-.) - [646.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\atiapfxx.blb [MD5.CC2470CA903EA355A24F05520D79BDB8] - |D| - [13/08/2016 22:54:45] - (.Copyright (C) 2009 Advanced Micro Devices, Inc. - atiapfxx Application.) - [366.98 Ko] - (6.14.10.1001) - C:\WINDOWS\system32\atiapfxx.exe [MD5.279066332FA267076E3BEE81C4297F87] - |D| - [13/08/2016 22:54:45] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL compiler runtime.) - [62.98 Ko] - (6.14.10.1848) - C:\WINDOWS\system32\aticalcl64.dll [MD5.3A0F17C7C8E37DCEAE1DA76B7D761702] - |D| - [13/08/2016 22:54:45] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL DD.) - [15356.98 Ko] - (6.14.10.1848) - C:\WINDOWS\system32\aticaldd64.dll [MD5.D22A08EE217DE15B6A41AE518B4F4FBE] - |D| - [13/08/2016 22:54:45] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL runtime.) - [69.48 Ko] - (6.14.10.1848) - C:\WINDOWS\system32\aticalrt64.dll [MD5.BE92AD0155D4A23D0073AF51BE808B29] - |D| - [13/08/2016 22:54:45] - (.Copyright (C) 1998-2012 AMD Inc. - aticfx64.dll.) - [1445.13 Ko] - (8.17.10.1404) - C:\WINDOWS\system32\aticfx64.dll [MD5.B565601728AF96EEFCF7E9CDE3CDD2BE] - |D| - [13/08/2016 22:54:45] - (.2002-2012 - Graphics DEM.) - [440.48 Ko] - (4.5.5711.37472) - C:\WINDOWS\system32\atidemgy.dll [MD5.8700278344BED8D4A3A5AC2875359584] - |D| - [13/08/2016 22:54:46] - (.Copyright (C) 1998-2011 AMD Inc. - atidxx64.dll.) - [11804.69 Ko] - (8.17.10.625) - C:\WINDOWS\system32\atidxx64.dll [MD5.69F82C40A189962A65F6D5A02DF8599F] - |D| - [13/08/2016 22:54:46] - (.-.) - [164.98 Ko] - (0.0.0.0) - C:\WINDOWS\system32\atieah64.exe [MD5.B96BD9F5B2B0CD6549EE59FD242A6D56] - |D| - [13/08/2016 22:54:46] - (.Copyright © 2008-2009 AMD - AMD External Events Client Module.) - [667.48 Ko] - (6.14.11.1199) - C:\WINDOWS\system32\atieclxx.exe [MD5.521248FA26458669BAAE6AB7DB21F3AC] - |D| - [13/08/2016 22:54:46] - (.Copyright © 2008-2009 AMD - AMD External Events Service Module.) - [249.48 Ko] - (6.14.11.1199) - C:\WINDOWS\system32\atiesrxx.exe [MD5.E4F96DFF0501430BF7C6E90841A7282D] - |D| - [13/08/2016 22:54:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiglpxx.dll.) - [81.98 Ko] - (8.14.1.6463) - C:\WINDOWS\system32\atig6pxx.dll [MD5.86F2AE002AF9222F34937823B98753C2] - |D| - [13/08/2016 22:54:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atigktxx.dll.) - [161.48 Ko] - (8.14.1.6463) - C:\WINDOWS\system32\atig6txx.dll [MD5.0C3156664885AF41100B63853EBCE037] - |D| - [13/08/2016 22:54:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiglpxx.dll.) - [76.48 Ko] - (8.14.1.6463) - C:\WINDOWS\system32\atiglpxx.dll [MD5.079EFFD5BECB418FE6596229B28D7324] - |D| - [13/08/2016 22:54:46] - (.-.) - [720.13 Ko] - (0.0.0.0) - C:\WINDOWS\system32\atiicdxx.dat [MD5.FE4E7138E51DA7EF01E51F28128A7F53] - |D| - [13/08/2016 22:54:46] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [85.94 Ko] - (8.14.10.23) - C:\WINDOWS\system32\atimpc64.dll [MD5.C84C24F13663EF5A59C1E598A350C8C3] - |D| - [13/08/2016 22:54:46] - (.Copyright ฉ 2009 AMD - Multi-language DPPE DLL.) - [37.48 Ko] - (6.14.10.1002) - C:\WINDOWS\system32\atimuixx.dll [MD5.7D9CCB5DD8837D6AC954956A5812112C] - |D| - [13/08/2016 22:54:46] - (.Copyright (C) 1998-2011 Advanced Micro Devices, Inc. - AMD OpenGL driver.) - [30054.98 Ko] - (6.14.10.13399) - C:\WINDOWS\system32\atio6axx.dll [MD5.0E89795F721B2BC02D0A12C470750DF6] - |D| - [13/08/2016 22:54:47] - (.Copyright (C) 2008 - ATIODCLI Application.) - [58.48 Ko] - (1.0.0.1) - C:\WINDOWS\system32\ATIODCLI.exe [MD5.C7A506822BE45CD42415710979CDAE7F] - |D| - [13/08/2016 22:54:47] - (.Copyright (C) 2008 - ATIODE Application.) - [333.48 Ko] - (1.0.0.1) - C:\WINDOWS\system32\ATIODE.exe [MD5.3FE40633FC3BC5AE41EACDA0E1BA72FE] - |D| - [13/08/2016 22:54:47] - (.Copy Right © 2012 Advanced Micro Devices, Inc - TMM Clone Control Module.) - [194.98 Ko] - (6.14.11.25) - C:\WINDOWS\system32\atitmm64.dll [MD5.067CED045532C58B46E6527BCE3CB47F] - |D| - [13/08/2016 22:54:47] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiu9pag.dll.) - [127.02 Ko] - (8.14.1.6463) - C:\WINDOWS\system32\atiu9p64.dll [MD5.AC6970C74B7457B291BB2C0035AA7DAE] - |D| - [13/08/2016 22:54:47] - (.Copyright (C) 1998-2011 AMD Inc. - atiumd64.dll.) - [8657.15 Ko] - (9.14.10.1128) - C:\WINDOWS\system32\atiumd64.dll [MD5.486D6985E7B7826DBBEAE12755851027] - |D| - [13/08/2016 22:54:47] - (.-.) - [3357.06 Ko] - (0.0.0.0) - C:\WINDOWS\system32\atiumd6a.cap [MD5.0A9CA09952D768F768D2903F984102DC] - |D| - [13/08/2016 22:54:47] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon Video Acceleration Universal Driver.) - [8771.91 Ko] - (8.14.10.513) - C:\WINDOWS\system32\atiumd6a.dll [MD5.AE81C76C930DD6875E5D9C6BEA2F0966] - |D| - [13/08/2016 22:54:48] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiuxpag.dll.) - [158.43 Ko] - (8.14.1.6463) - C:\WINDOWS\system32\atiuxp64.dll [MD5.EFA5E3D55F1CC185BC690B7D79D015A9] - |D| - [13/08/2016 22:54:48] - (.-.) - [98.45 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativce02.dat [MD5.B974290EEE645249EE212FF62DD0824A] - |D| - [13/08/2016 22:54:48] - (.-.) - [173.19 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativce03.dat [MD5.5EBC73A78E5903E7CE6F6B25E4A6BE8F] - |D| - [13/08/2016 22:54:48] - (.-.) - [228.93 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_cik.dat [MD5.C55D2CBC17AAE1FBAC9135E7C31A4D31] - |D| - [13/08/2016 22:54:48] - (.-.) - [227.3 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_cik_nd.dat [MD5.0770A5AB5218E6D3134A7A7239B9A216] - |D| - [13/08/2016 22:54:48] - (.-.) - [249.81 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_cz_nd.dat [MD5.A81F68A0D3387A06182EFA3880D3F0BD] - |D| - [13/08/2016 22:54:48] - (.-.) - [245 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_FJ.dat [MD5.7EE8F6853798F7A900DB15F3054A0277] - |D| - [13/08/2016 22:54:48] - (.-.) - [243.25 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_FJ_nd.dat [MD5.11355CAC5334C8999211C09CAAE194EF] - |D| - [13/08/2016 22:54:48] - (.-.) - [315.3 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_vi.dat [MD5.3544D6AF6E0C9783C2CF6FA9CE42D520] - |D| - [13/08/2016 22:54:48] - (.-.) - [313.67 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvaxy_vi_nd.dat [MD5.7C163EDE63854539828F5B2C1BC529FD] - |D| - [13/08/2016 22:54:48] - (.-.) - [153.46 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvsva.dat [MD5.219D7091DD1D93728392337FE9C7ADD6] - |D| - [13/08/2016 22:54:48] - (.-.) - [200.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ativvsvl.dat [MD5.22D9945B4AAE36DD59620A918F2E65F4] - |D| - [16/07/2016 13:42:16] - (.-.) - [3096 Ko] - (0.0.0.0) - C:\WINDOWS\system32\boot.sdi [MD5.405E1EF8E3C88E9BCD2853382BB12430] - |D| - [16/07/2016 13:43:51] - (.-.) - [22.45 Ko] - (0.0.0.0) - C:\WINDOWS\system32\bopomofo.uce [MD5.31ABC8C02F1CCE0DA39550D763384184] - |D| - [16/07/2016 13:42:12] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [91.5 Ko] - (1.0.0.1) - C:\WINDOWS\system32\BthpanContextHandler.dll [MD5.D648218198F82322FC1FED1DA95AD749] - |D| - [16/07/2016 13:42:40] - (.Copyright (C) 2008 - Application ContextH.) - [62 Ko] - (1.0.0.1) - C:\WINDOWS\system32\BWContextHandler.dll [MD5.06306B081901E75597973043301128D7] - |D| - [16/07/2016 13:42:16] - (.-.) - [127 Ko] - (5.0.1.1) - C:\WINDOWS\system32\chartv.dll [MD5.CCEAEFAA4DF2F399E9A179D942FEB23C] - |D| - [16/07/2016 13:42:09] - (.-.) - [163.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\chs_singlechar_pinyin.dat [MD5.F2D598B11C294EE360FDA0D3E81DA7EC] - |D| - [13/08/2016 22:54:54] - (.-.) - [237.98 Ko] - (0.0.0.0) - C:\WINDOWS\system32\clinfo.exe [MD5.A0E91D21C945781D03EA0BA1C95F821E] - |D| - [13/08/2016 22:54:54] - (.AMD. - CoInstaller DLL.) - [853.98 Ko] - (1.0.5.9) - C:\WINDOWS\system32\coinst_15.20.dll [MD5.A797EED94B22B29D3974CB20B66BE6C6] - |D| - [14/08/2016 07:58:36] - (.2012 © Real Sound Lab SIA, iSoft Solutions - CONEQ™ Media Suite APO GUI Library.) - [108 Ko] - (1.0.0.2) - C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll [MD5.5D382D13050A98C40176E00E103047A5] - |D| - [16/07/2016 13:42:06] - (.-.) - [2618.36 Ko] - (0.0.0.0) - C:\WINDOWS\system32\CoreUIComponents.dll [MD5.306B90493D00011EB635E161C6C024B8] - |D| - [16/07/2016 13:42:22] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DefaultHrtfs.bin [MD5.664AA698FC0106A2B075A641E8DC6302] - |D| - [16/07/2016 13:47:52] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DefaultQuestions.json [MD5.83B391D95E7E785DED8EAE7102319753] - |D| - [16/07/2016 13:43:16] - (.-.) - [4.87 Ko] - (0.0.0.0) - C:\WINDOWS\system32\delegwiz.inf [MD5.46BBA24DEED94A68F244D5DBA4161948] - |D| - [30/07/2015 23:55:12] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DESKTOP-VRKVT78_Administrator_HistoryPrediction.bin [MD5.B227DF8720C51EE0A80CB23CCCEF1EC6] - |D| - [26/10/2012 16:42:24] - (.-.) - [328.35 Ko] - (13.80.853.0) - C:\WINDOWS\system32\DevManagerCore.dll [MD5.8B5F7B8C2EFE38CA571FBE24658DF11F] - |D| - [16/07/2016 13:42:36] - (.-.) - [90.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\DiskSnapshot.conf [MD5.8C6F56F4CDDE6A1FD01F4FCF2773298E] - |D| - [16/07/2016 13:47:52] - (.-.) - [210.88 Ko] - (0.0.0.0) - C:\WINDOWS\system32\dssec.dat [MD5.F4B28B1D1CF0E80E78CE0921D3E45F72] - |D| - [16/07/2016 13:42:19] - (.-.) - [157 Ko] - (0.0.0.0) - C:\WINDOWS\system32\EditionUpgradeHelper.dll [MD5.EE0AB41397CE31A426336479224D3FFF] - |D| - [16/07/2016 13:42:19] - (.-.) - [38.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\efsext.dll [MD5.097C96CC5CFAA6A0CD0D0A50E327EAC4] - |D| - [13/08/2016 21:44:13] - (.-.) - [22.66 Ko] - (0.0.0.0) - C:\WINDOWS\system32\emptyregdb.dat [MD5.93E76CF7B04EC33A1E9E0FD7546D3603] - |D| - [16/07/2016 13:42:13] - (.-.) - [17.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\EventViewer_EventDetails.xsl [MD5.BAC5074667751F72A9CE48CDC31BAC48] - |D| - [14/08/2016 19:02:22] - (.Copyright (C) 2007 SEIKO EPSON CORP. - E_GCINST.) - [10.5 Ko] - (1.0.0.6) - C:\WINDOWS\system32\E_GCINST.DLL [MD5.8159960E8BA20F1C4A4EBCF0DAEC60E5] - |D| - [14/08/2016 19:01:39] - (.Copyright (C) SEIKO EPSON CORPORATION 2005-2010. - ECBTEGB AMD64.) - [82 Ko] - (3.3.0.0) - C:\WINDOWS\system32\E_ID4BLPE.DLL [MD5.2E21840342850A8A7F28D28D6DD3A1CD] - |D| - [14/08/2016 19:01:40] - (.Copyright (C) SEIKO EPSON CORPORATION 2005-2013. - EPSON Bi-directional Monitor AMD64.) - [175.5 Ko] - (4.4.0.0) - C:\WINDOWS\system32\E_ILMBLPE.DLL [MD5.4F575C282EE093323D00A4FD86762000] - |D| - [14/08/2016 09:55:40] - (.-.) - [201.7 Ko] - (0.0.0.0) - C:\WINDOWS\system32\FNTCACHE.DAT [MD5.AF3851142081D5ACC3FC46971F9FFEAD] - |D| - [14/08/2016 18:41:03] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\system32\fsdbcrpt.kar.{4d726ee4-96ff-4771-b054-fa7322787611} [MD5.8E7AFBED04DAF976A9E46D3724A93284] - |D| - [16/07/2016 13:42:35] - (.-.) - [24.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\GamePanelExternalHook.dll [MD5.D07F2281427BD098356EE74B6CB26B86] - |D| - [16/07/2016 13:42:12] - (.-.) - [89 Ko] - (0.0.0.0) - C:\WINDOWS\system32\gatherNetworkInfo.vbs [MD5.4FDED87068052EEB9B72A97FDBC141DB] - |D| - [16/07/2016 13:43:51] - (.-.) - [23.44 Ko] - (0.0.0.0) - C:\WINDOWS\system32\gb2312.uce [MD5.67FC2C86490CB84F4AD74B6F5AF3A89C] - |D| - [05/03/2013 01:35:48] - (.© Copyright 2012 HPDC - Port Monitor Server DLL.) - [347.5 Ko] - (0.3.1282.3591) - C:\WINDOWS\system32\hpbprtmon.dll [MD5.D0519B40392DB0D156B61502D5F650F4] - |D| - [05/03/2013 01:35:48] - (.© Copyright 2012 HPDC - Port Monitor UI DLL.) - [166.5 Ko] - (0.3.1282.3591) - C:\WINDOWS\system32\hpbprtmonui.dll [MD5.06F13BD51FB6A9B199B73C1605238BBF] - |D| - [05/03/2013 01:35:48] - (.© Copyright 2012 HPDC - Real Port Monitor DLL.) - [368.5 Ko] - (0.3.1282.3591) - C:\WINDOWS\system32\hpbrprtmon.dll [MD5.D41D8CD98F00B204E9800998ECF8427E] - |D| - [05/03/2013 01:53:16] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\system32\HPCheckOA21.err [MD5.3083DEF0BC30D66A5D320B9979C178EC] - |D| - [05/03/2013 01:53:16] - (.-.) - [0.04 Ko] - (0.0.0.0) - C:\WINDOWS\system32\HPCheckOA21.txt [MD5.1A4695BDC5017B37E6D23A88CFEC0760] - |D| - [05/03/2013 01:14:27] - (.Copyright (C) 2011 -.) - [114.5 Ko] - (1.3.0.0) - C:\WINDOWS\system32\HPMUIDir.exe [MD5.12F3190C25CFFB03A5CA58E949AE3E55] - |D| - [16/07/2016 13:42:22] - (.-.) - [353.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\HrtfApo.dll [MD5.77071BF934BEF16D5F02E31624258A91] - |D| - [13/08/2016 22:54:54] - (.-.) - [108.98 Ko] - (0.0.0.0) - C:\WINDOWS\system32\hsa-thunk64.dll [MD5.2A571B7728F23E83A800527879105180] - |D| - [16/07/2016 13:42:04] - (.-.) - [44.17 Ko] - (0.0.0.0) - C:\WINDOWS\system32\hypervisor.mof [MD5.038F6AD6CEE43585D814CDBC7CDFD3EC] - |D| - [16/07/2016 13:43:51] - (.-.) - [59.04 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ideograf.uce [MD5.6B31D08801D3A3F51B59FB1DB14E4A01] - |D| - [16/07/2016 13:43:08] - (.-.) - [3.38 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ieuinit.inf [MD5.7CAACE1DF07B3656E458D07115A71600] - |D| - [25/07/2012 22:22:54] - (.-.) - [429.01 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igcompkrng500.bin [MD5.385B8EFE468E3A4A3E2E65FC8764E4BF] - |D| - [25/07/2012 22:22:54] - (.-.) - [90.19 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igfcg500m.bin [MD5.C4CF4FA6C9399B277E86D602BF251A11] - |D| - [25/07/2012 22:22:54] - (.-.) - [959.22 Ko] - (0.0.0.0) - C:\WINDOWS\system32\igkrng500.bin [MD5.9A014CE65642722D72588D5196F147CE] - |D| - [25/07/2012 22:22:54] - (.-.) - [1945.25 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxa64.cpa [MD5.DB945DDE9D7825BB4A173CD108193C49] - |D| - [25/07/2012 22:22:56] - (.-.) - [1.06 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxa64.vp [MD5.A980B0ED5543E3DFD1C21058B06C5A65] - |D| - [25/07/2012 22:22:56] - (.-.) - [58.81 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxc64.vp [MD5.82001B2CC6728CE282EF036ABC2BC975] - |D| - [25/07/2012 22:22:56] - (.-.) - [58.84 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxg64.vp [MD5.3B6C78580EC3B9A0346D2AD63EC7906A] - |D| - [25/07/2012 22:22:56] - (.-.) - [58.61 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxo64.vp [MD5.0E74C595B6F7276F41425F50D414B680] - |D| - [25/07/2012 22:22:56] - (.-.) - [5.3 Ko] - (0.0.0.0) - C:\WINDOWS\system32\iglhxs64.vp [MD5.8898B09A8D08E138F238224648DF0739] - |D| - [16/07/2016 13:42:35] - (.-.) - [170.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\IHDS.dll [MD5.D13EA5B1CC8BA39847B56DE96880B8DB] - |D| - [12/08/2016 08:00:18] - (.-.) - [681.92 Ko] - (0.0.0.0) - C:\WINDOWS\system32\im-fre.exe [MD5.D506921989872994B9C5615D4761882C] - |D| - [19/08/2016 08:02:48] - (.Copyright © 2005-2016 - IObit Smart Defrag Extension.) - [125.28 Ko] - (1.0.0.25) - C:\WINDOWS\system32\IObitSmartDefragExtension.dll [MD5.5EA855B4A875E08AD93FF901B5D9E275] - |D| - [16/07/2016 13:42:09] - (.-.) - [226 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ism32k.dll [MD5.7C0C25F4BA1084C4ABBEEA2C74194C5F] - |D| - [16/07/2016 13:43:51] - (.-.) - [6.79 Ko] - (0.0.0.0) - C:\WINDOWS\system32\kanji_1.uce [MD5.529BBD63519BBD654EF328454019693F] - |D| - [16/07/2016 13:43:51] - (.-.) - [8.29 Ko] - (0.0.0.0) - C:\WINDOWS\system32\kanji_2.uce [MD5.7A7A04370A6030B9B0E8178DAD4A6E41] - |D| - [16/07/2016 13:43:51] - (.-.) - [12.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\korean.uce [MD5.49F46049D3729F9CD510CCFF1E091F90] - |D| - [16/07/2016 13:42:02] - (.Copyright © 1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS - MPEG Layer-3 Audio Codec for MSACM.) - [85 Ko] - (1.9.0.401) - C:\WINDOWS\system32\l3codeca.acm [MD5.F720CF1C7BCBC3B9897F2F36EBE96136] - |D| - [16/07/2016 13:42:02] - (.Copyright © 2004 Fraunhofer IIS - MPEG Audio Layer-3 Codec for MSACM.) - [179 Ko] - (3.4.0.0) - C:\WINDOWS\system32\l3codecp.acm [MD5.050BC9351A3386458B696F8BCA78B27B] - |D| - [16/07/2016 13:42:22] - (.-.) - [145.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\LargeRoom.bin [MD5.531FE5A2634D87A078017259F21D9736] - |D| - [16/07/2016 13:42:43] - (.-.) - [206.97 Ko] - (0.0.0.0) - C:\WINDOWS\system32\lcphrase.tbl [MD5.D3C85593F8C4576FCF9B42AC48CA4368] - |D| - [16/07/2016 13:42:43] - (.-.) - [23.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\lcptr.tbl [MD5.84B686AFB958D7ECDC2A1FA5D87353E1] - |D| - [14/08/2016 10:54:08] - (.-.) - [51.1 Ko] - (0.0.0.0) - C:\WINDOWS\system32\license.rtf [MD5.B65E8E52916A527F88486875EE291AA8] - |D| - [26/10/2012 16:42:22] - (.-.) - [10663.85 Ko] - (13.80.853.0) - C:\WINDOWS\system32\LogiDPP.dll [MD5.24764C249F769991079F6D4B14B822AF] - |D| - [26/10/2012 16:42:22] - (.-.) - [100.85 Ko] - (13.80.853.0) - C:\WINDOWS\system32\LogiDPPApp.exe [MD5.4D4248F6D008D86D5575EE5B154971AE] - |D| - [26/10/2012 16:42:22] - (.(c) 1996-2012 Logitech. - Logitech Co-Installer.) - [256.28 Ko] - (13.80.853.0) - C:\WINDOWS\system32\lvco1380853.dll [MD5.FF510CF2A7FA73192E7DB06D7C311799] - |D| - [26/10/2012 16:42:24] - (.(c) 1996-2012 Logitech. - Video Codec.) - [171.28 Ko] - (13.80.853.0) - C:\WINDOWS\system32\lvcod64.dll [MD5.1A8AE8A66B6C289046276453768EF270] - |D| - [26/10/2012 16:42:24] - (.-.) - [28.8 Ko] - (0.0.0.0) - C:\WINDOWS\system32\lvcoin64.ini [MD5.D7EDFAF69B63B5247670BE8CBD669113] - |D| - [14/08/2016 09:59:07] - (.-.) - [7.63 Ko] - (0.0.0.0) - C:\WINDOWS\system32\lvcoinst.log [MD5.B4CD287DFAA6578AC763A3800F0C2DC8] - |D| - [26/10/2012 16:42:24] - (.(c) 1996-2012 Logitech. - Logitech Camera Property Pages.) - [750.28 Ko] - (13.80.853.0) - C:\WINDOWS\system32\LVUI64.dll [MD5.CCFDDF84B42198B0AAD27D11ACFD254E] - |D| - [26/10/2012 16:42:22] - (.(c) 1996-2012 Logitech. - Logitech Camera Property Pages.) - [547.28 Ko] - (13.80.853.0) - C:\WINDOWS\system32\LVUIRC64.dll [MD5.7A495CA1402C2F9F5D035092AD808669] - |D| - [16/07/2016 13:44:03] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\WINDOWS\system32\manage-bde.wsf [MD5.D3F4E00C322EDA78873848BE75ACC8A4] - |D| - [13/08/2016 22:54:54] - (.Copyright (C) 2013 AMD Inc. - Mantle loader.) - [132.98 Ko] - (9.1.10.83) - C:\WINDOWS\system32\mantle64.dll [MD5.EA33454E28EE1F3CA432DA87203DA24F] - |D| - [13/08/2016 22:54:54] - (.Copyright (C) 2013 AMD Inc. - Mantle extension library.) - [100.98 Ko] - (9.1.10.83) - C:\WINDOWS\system32\mantleaxl64.dll [MD5.39DFF42E57C53A58C162F4760A75EA84] - |D| - [20/05/2016 10:50:40] - (.-.) - [46 Ko] - (0.0.0.0) - C:\WINDOWS\system32\MDA_NTDRV.sys [MD5.BC74BDA8DC53F722C2CA686071600AE2] - |D| - [16/07/2016 13:42:22] - (.-.) - [107.45 Ko] - (0.0.0.0) - C:\WINDOWS\system32\MediumRoom.bin [MD5.ED434A3EBE29070A7E0138C42482EB93] - |D| - [16/07/2016 13:42:27] - (.-.) - [657.31 Ko] - (0.0.0.0) - C:\WINDOWS\system32\mlang.dat [MD5.754DDF1A87E7CF5FAFBF9F2C440E8558] - |D| - [14/08/2016 18:41:03] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\system32\msdbcrpt.kar.{4d726ee4-96ff-4771-b054-fa7322787611} [MD5.E7ED514B91CF343EEABF72233DDB2CB3] - |D| - [16/07/2016 13:42:14] - (.-.) - [361 Ko] - (5.0.1.3) - C:\WINDOWS\system32\msinfo32.exe [MD5.86166DAA04A6C154826508304CC6D4AC] - |D| - [16/07/2016 13:42:12] - (.-.) - [0.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NdfEventView.xml [MD5.9F72E06493E8E034E4F3E287B2F6D5D4] - |D| - [01/08/2012 19:10:05] - (.-.) - [1.06 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-303172.txt [MD5.EC3F2258DC5247436CF829AA405523A7] - |D| - [01/08/2012 19:03:24] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-40170.txt [MD5.E39F5B5F2F8E17B44BC73BFD6F5EEFE8] - |D| - [01/08/2012 19:03:24] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-40591.txt [MD5.0A742EBDEC323A1C158125EDDCD0ECB9] - |D| - [01/08/2012 19:03:25] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-40934.txt [MD5.363AB3B147EC26DE764E2FB32EA2041C] - |D| - [01/08/2012 19:03:25] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-41340.txt [MD5.670571AEA7547824368AAFF1210E5219] - |D| - [01/08/2012 19:03:25] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-41667.txt [MD5.876860348EF677B24E4070B6F0D0434B] - |D| - [01/08/2012 19:03:26] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-41933.txt [MD5.D9DF4A50BBA7175DDD31647FDD2E1C1E] - |D| - [01/08/2012 19:03:26] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-42213.txt [MD5.6B60C5E72A98FFD8AA3C3E79EB9EBC37] - |D| - [01/08/2012 19:03:26] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-42510.txt [MD5.FC2AE0A6CD9E5604723A4D73E3485D1B] - |D| - [01/08/2012 19:03:27] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-42947.txt [MD5.8CC3614DB50EB8B061D80657A5E43793] - |D| - [01/08/2012 19:03:27] - (.-.) - [0.18 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-43290.txt [MD5.E4843FF1AB51E26581AC8DB00AF1A4C5] - |D| - [01/08/2012 19:03:29] - (.-.) - [1.11 Ko] - (0.0.0.0) - C:\WINDOWS\system32\netcfg-44959.txt [MD5.BDD6CA90C01467DFC19A69C45161450F] - |D| - [14/08/2016 09:55:53] - (.-.) - [16.66 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NetSetupMig.log [MD5.C146E873B22C3B300B21A859FE66C27A] - |D| - [16/07/2016 13:42:12] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NetTrace.PLA.Diagnostics.xml [MD5.DE78E0C57BC478D47CC2F470B68E1A45] - |D| - [16/07/2016 13:47:53] - (.-.) - [0.72 Ko] - (0.0.0.0) - C:\WINDOWS\system32\NOISE.DAT [MD5.5D27362AF3BCAA75A418F5416A35934E] - |D| - [16/07/2016 13:42:20] - (.-.) - [0.26 Ko] - (0.0.0.0) - C:\WINDOWS\system32\odbcconf.rsp [MD5.FF69267A88A54A223B4357C41930449C] - |D| - [16/07/2016 13:47:53] - (.-.) - [15.1 Ko] - (0.0.0.0) - C:\WINDOWS\system32\OEMDefaultAssociations.xml [MD5.2901049544FDF863362FABA2363EB647] - |D| - [16/07/2016 13:42:11] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\system32\onlinesetup.cmd [MD5.F192E1998A5F6826BE6955F6EAE7CDA1] - |D| - [13/08/2016 22:54:45] - (.Copyright © The Khronos Group Inc 2014 - OpenCL Client DLL.) - [71.98 Ko] - (2.0.4.0) - C:\WINDOWS\system32\OpenCL.dll [MD5.FEA7C5495FA97FA85091260BA99F443A] - |D| - [08/08/2012 13:09:14] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OpenVideo 1.1 Runtime.) - [74 Ko] - (10.0.938.2) - C:\WINDOWS\system32\OpenVideo64.dll [MD5.42D2360079B1DF3230024AE920737367] - |D| - [16/07/2016 13:42:22] - (.-.) - [45.81 Ko] - (0.0.0.0) - C:\WINDOWS\system32\OutdoorAudioEnvironment.bin [MD5.FD4964DC69D2CA2F77872224A0F2EBBF] - |D| - [08/08/2012 13:09:02] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OVDecode 1.1 Runtime.) - [62 Ko] - (10.0.938.2) - C:\WINDOWS\system32\OVDecode64.dll [MD5.66D58077CC739E4B8166E33AB0BA4639] - |D| - [16/07/2016 13:42:39] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\system32\pcl.sep [MD5.F6564D9DA735FE51796114F4F6D2F1EA] - |D| - [16/07/2016 13:49:31] - (.-.) - [292.13 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfc009.dat [MD5.056170C4A425EC0374A64AD566945E60] - |D| - [17/07/2016 00:40:24] - (.-.) - [256.78 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfc00C.dat [MD5.32BC2E0CC95E2DCEE25B15BFB82D07B8] - |D| - [16/07/2016 13:49:35] - (.-.) - [32.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfd009.dat [MD5.AA180E09E4990FF71FBEAC8C4455CF47] - |D| - [17/07/2016 00:40:24] - (.-.) - [39.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfd00C.dat [MD5.C610D66B8A4AAA0010B1D8C36973D545] - |D| - [16/07/2016 13:49:31] - (.-.) - [1005.43 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfh009.dat [MD5.81179818A309555EE84C5A50AD56E43B] - |D| - [17/07/2016 00:40:24] - (.-.) - [1009.8 Ko] - (0.0.0.0) - C:\WINDOWS\system32\perfh00C.dat [MD5.9D02A2A9F1D2C7C7DBE55E7E1A95FA29] - |D| - [14/08/2016 10:03:20] - (.-.) - [2580.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\PerfStringBackup.INI [MD5.0225FC6F0D91F84B44CE252487D8D725] - |D| - [14/08/2016 21:56:20] - (.Copyright (C) 2008-2013 - Video-Codec by proDAD.) - [593.02 Ko] - (1.0.18.0) - C:\WINDOWS\system32\prodad-codec.dll [MD5.E5FCE41A5114E40EE573AB8631925BF3] - |D| - [14/08/2016 21:56:16] - (.Copyright (C) 2008 - Part of the proDAD.) - [367.52 Ko] - (1.0.4.0) - C:\WINDOWS\system32\proDAD-PA-Support.dll [MD5.C36C982BDDA232A84A664C25036C4BD0] - |D| - [20/08/2016 05:46:25] - (.-.) - [18.09 Ko] - (0.0.0.0) - C:\WINDOWS\system32\prwntdrv.sys [MD5.C09741B9886EF0D15EC3B1443352FB62] - |D| - [16/07/2016 13:42:39] - (.-.) - [0.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\pscript.sep [MD5.007893E8374C766471239EB291BA8C17] - |D| - [16/07/2016 13:42:31] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\system32\psmodulediscoveryprovider.mof [MD5.3A77C18665A4C8428768CE186A5BC1EF] - |D| - [16/07/2016 13:42:12] - (.-.) - [1.78 Ko] - (0.0.0.0) - C:\WINDOWS\system32\rasctrnm.h [MD5.5D9616D2A76F38EF94866248CA4EDB2C] - |D| - [16/07/2016 13:43:18] - (.Copyright (C) 2009 - RemoteFX Helper.) - [106 Ko] - (1.1.0.0) - C:\WINDOWS\system32\RDVGHelper.exe [MD5.692DC6EF573FFCDD9DFB55D1C783DB93] - |D| - [16/07/2016 13:42:04] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\system32\removehypervisor.mof [MD5.C6CA43573C21CA6392F57F238C8391FC] - |D| - [26/10/2012 16:42:22] - (.-.) - [39.45 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Repository.reg [MD5.D67CDB8D2584AAC165A77488C5A7A987] - |D| - [16/07/2016 13:42:37] - (.-.) - [8.92 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ResPriHMImageList [MD5.4FE9CE56EFA89779D81B988698D2454C] - |D| - [16/07/2016 13:42:37] - (.-.) - [8.4 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ResPriImageList [MD5.43E7D0AB6A8564F5BF375FBF0934FAD1] - |D| - [16/07/2016 13:42:15] - (.-.) - [0.7 Ko] - (0.0.0.0) - C:\WINDOWS\system32\RestartManager.mof [MD5.3F75A221A01F68D6CE67FE99A868BD8F] - |D| - [16/07/2016 13:42:15] - (.-.) - [0.17 Ko] - (0.0.0.0) - C:\WINDOWS\system32\RestartManagerUninstall.mof [MD5.E9D4A333DF15D06C68AC4BFB9B6581CB] - |D| - [14/08/2016 07:58:52] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x64.) - [302.84 Ko] - (6.0.6001.18) - C:\WINDOWS\system32\RP3DAA64.dll [MD5.B6FE01558CC03F3866C9AD0ED19261D8] - |D| - [14/08/2016 07:58:52] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x64.) - [302.84 Ko] - (6.0.6001.18) - C:\WINDOWS\system32\RP3DHT64.dll [MD5.A6286A6C7A1BBFCBA17AA54384A21D1C] - |D| - [14/08/2016 07:58:53] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x64.) - [199.34 Ko] - (6.1.6001.33) - C:\WINDOWS\system32\RTEED64A.dll [MD5.6F4CD493196100EEF349D7132CECAFD9] - |D| - [14/08/2016 07:58:53] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x64.) - [76.84 Ko] - (6.1.6001.33) - C:\WINDOWS\system32\RTEEG64A.dll [MD5.ECAEC5FBBBEF8612AF0A866AFA5F7EF2] - |D| - [14/08/2016 07:58:53] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x64.) - [98.84 Ko] - (6.1.6001.33) - C:\WINDOWS\system32\RTEEL64A.dll [MD5.D0D0D82B7366E691275E433CD34F89B2] - |D| - [14/08/2016 07:58:53] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x64.) - [366.34 Ko] - (6.1.6001.33) - C:\WINDOWS\system32\RTEEP64A.dll [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |D| - [16/07/2016 13:43:50] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ScavengeSpace.xml [MD5.00E5FCFD833151F7CBDE607E2F7AFEB4] - |D| - [16/07/2016 13:43:51] - (.-.) - [5.66 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SecurityAndMaintenance.png [MD5.5719BFC9CFDA7A9C059A71A47A0E6383] - |D| - [16/07/2016 13:43:51] - (.-.) - [2.56 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SecurityAndMaintenance_Alert.png [MD5.099BA37F81C044F6B2609537FDB7D872] - |D| - [16/07/2016 13:43:51] - (.-.) - [6.72 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SecurityAndMaintenance_Error.png [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |D| - [16/07/2016 13:42:34] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\system32\settings.dat [MD5.D225070308AB489DC307C91AC4C938CA] - |D| - [20/08/2016 05:46:25] - (.-.) - [96.09 Ko] - (0.0.0.0) - C:\WINDOWS\system32\setupprwdrvx64.exe [MD5.8CA32E9D986FA76F60EFBCFCD9D80A58] - |D| - [16/07/2016 13:43:51] - (.-.) - [16.35 Ko] - (0.0.0.0) - C:\WINDOWS\system32\ShiftJIS.uce [MD5.3903BCAB32A4A853DFA54962112D4D02] - |D| - [16/07/2016 13:42:20] - (.-.) - [139.55 Ko] - (0.0.0.0) - C:\WINDOWS\system32\slmgr.vbs [MD5.5DA94C1082B9331928DFC87F5E13EAB2] - |D| - [23/01/2012 15:15:14] - (.- SlotMaximizerAg.dll.) - [120 Ko] - (1.0.2.32) - C:\WINDOWS\system32\SlotMaximizerAg.dll [MD5.E93999885EA5519A5D4B1EEF6EA448B3] - |D| - [23/01/2012 15:15:14] - (.- SlotMaximizerBe.dll.) - [2420.5 Ko] - (1.0.2.32) - C:\WINDOWS\system32\SlotMaximizerBe.dll [MD5.1C6F12AA3D178A0A953E8005B3CD4CDE] - |D| - [16/07/2016 13:42:22] - (.-.) - [68.14 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SmallRoom.bin [MD5.D57880A3F9F22D67974EF0EB8B67021C] - |D| - [19/08/2016 08:02:46] - (.Copyright © 2005-2013 - SmartDefrag.) - [35.96 Ko] - (2.0.0.0) - C:\WINDOWS\system32\SmartDefragBootTime.exe [MD5.C1AA14DBA23EB5AE5044727DF182FE5C] - |D| - [16/07/2016 13:42:16] - (.-.) - [54.8 Ko] - (0.0.0.0) - C:\WINDOWS\system32\srms.dat [MD5.A88BE9A6C4E646A2B2A1BD3A7F4B58E7] - |D| - [14/08/2016 07:59:01] - (.(c) 2007 SRS Labs, Inc. - COM object implementing SRS Headphone 360.) - [194.23 Ko] - (1.1.0.0) - C:\WINDOWS\system32\SRSHP64.dll [MD5.A028717B791416182959B325D5B40679] - |D| - [14/08/2016 07:59:01] - (.Copyright (c) 2006 SRS Labs, Inc.. - TruSurround HD and HD4 COM object for Windows.) - [206.23 Ko] - (1.1.4.0) - C:\WINDOWS\system32\SRSTSH64.dll [MD5.018D3D2478754AA411DE6DA6DE5F8F21] - |D| - [14/08/2016 07:59:01] - (.Copyright 2002 SRS Labs, Inc. - TruSurroundXT Module.) - [506.73 Ko] - (3.2.0.0) - C:\WINDOWS\system32\SRSTSX64.dll [MD5.2FCADCC14F8E540F6ADE4BF92BD8AEDD] - |D| - [14/08/2016 07:59:01] - (.(c) 2006 SRS Labs, Inc. - WOW HD COM object for Windows.) - [152.23 Ko] - (1.1.3.0) - C:\WINDOWS\system32\SRSWOW64.dll [MD5.30F5568679A54042F99CA9EC1102EBCD] - |D| - [16/07/2016 13:43:51] - (.-.) - [91.51 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SubRange.uce [MD5.20C4FE2B130D9F0C92D7629E71AFBB66] - |D| - [16/07/2016 13:43:20] - (.-.) - [1.68 Ko] - (0.0.0.0) - C:\WINDOWS\system32\SyncAppvPublishingServer.vbs [MD5.81B14F1AD906AC1CF9102796C97A54FE] - |D| - [16/07/2016 13:42:39] - (.-.) - [3.24 Ko] - (0.0.0.0) - C:\WINDOWS\system32\sysprint.sep [MD5.58A67EC6B00A54A69DC364194CA171E0] - |D| - [16/07/2016 13:42:39] - (.-.) - [3.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\sysprtj.sep [MD5.31B010EF50D54D548B4B8B211F421318] - |D| - [16/07/2016 13:42:39] - (.-.) - [1.63 Ko] - (0.0.0.0) - C:\WINDOWS\system32\tcpbidi.xml [MD5.D602CA245CC6774A0981B607F0675609] - |D| - [16/07/2016 13:42:39] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\tcpmon.ini [MD5.C8F2952DAE3971614DBD0C509F35BE93] - |D| - [16/07/2016 13:42:38] - (.-.) - [10.29 Ko] - (0.0.0.0) - C:\WINDOWS\system32\TransformPPSToWlan.xslt [MD5.2F05390B798363D51EBE65D6320CD45E] - |D| - [16/07/2016 13:42:38] - (.-.) - [1.65 Ko] - (0.0.0.0) - C:\WINDOWS\system32\TransformPPSToWlanCredentials.xslt [MD5.D200497DD3A24F138123F0EB6C385D1D] - |D| - [16/07/2016 13:43:20] - (.-.) - [0.14 Ko] - (0.0.0.0) - C:\WINDOWS\system32\UevAppMonitor.exe.config [MD5.4AAEE8D86EC81DA2A1514ABC77E71F57] - |D| - [16/07/2016 13:43:20] - (.-.) - [3.34 Ko] - (0.0.0.0) - C:\WINDOWS\system32\UevCustomActionTypes.tlb [MD5.E7482D1D449217C8641762F5C38E157C] - |D| - [16/07/2016 13:42:12] - (.-.) - [9.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\VpnSohDesktop.dll [MD5.D59C14FBCB8BAEA992A737734CF01D0A] - |D| - [16/07/2016 13:42:09] - (.-.) - [319 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wc_storage.dll [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |D| - [16/07/2016 13:42:11] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WdsUnattendTemplate.xml [MD5.B3D9F747B963DC557D1D0BB049506D84] - |D| - [16/07/2016 13:42:31] - (.-.) - [230.95 Ko] - (0.0.0.0) - C:\WINDOWS\system32\weretw.dll [MD5.BB2D1DF427C9284DE64DC66A6F1CC2AD] - |D| - [16/07/2016 13:42:11] - (.-.) - [2.25 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WimBootCompress.ini [MD5.39B36FC36B577FDD2CDCDDD1C6D1D422] - |D| - [10/09/2015 07:58:39] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WIN-QRM73VC4CP6_Administrator_HistoryPrediction.bin [MD5.44412720DE9CA294B33930EC8B22114E] - |D| - [16/07/2016 13:42:06] - (.-.) - [408.5 Ko] - (0.0.0.0) - C:\WINDOWS\system32\Windows.Perception.Stub.dll [MD5.E0974EE3F592223A950B3B0C04797212] - |D| - [16/07/2016 13:44:01] - (.-.) - [1.61 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WindowsCodecsRaw.txt [MD5.7EF8F3CADE2DE177F96B5A5B581D73FF] - |D| - [16/07/2016 13:42:31] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\system32\winrm.cmd [MD5.9D7684F978EBD77E6A3EA7EF1330B946] - |D| - [16/07/2016 13:42:31] - (.-.) - [199.32 Ko] - (0.0.0.0) - C:\WINDOWS\system32\winrm.vbs [MD5.96C4CBD3C8DF0FA34591FEE057AF3E1F] - |D| - [16/07/2016 13:42:05] - (.http://www.sqlite.org/copyright.html - SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - [754.46 Ko] - (3.12.2.0) - C:\WINDOWS\system32\winsqlite3.dll [MD5.C30C621748C66CE751B19B2788559A3E] - |D| - [16/07/2016 13:42:35] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wpcmon.png [MD5.B6B479B04C64AF5EF36C24EBDF278302] - |D| - [16/07/2016 13:42:27] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wpr.config.xml [MD5.930423065AB3F5DB52D5726C7FC66385] - |D| - [16/07/2016 13:42:31] - (.-.) - [4.57 Ko] - (0.0.0.0) - C:\WINDOWS\system32\wsmanconfig_schema.xml [MD5.D6CBFA113B69C491DE370E85EBAC80E9] - |D| - [16/07/2016 13:42:31] - (.-.) - [1.52 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WsmPty.xsl [MD5.B2EDF82825D979928AE07CBE9C7A2160] - |D| - [16/07/2016 13:42:31] - (.-.) - [2.37 Ko] - (0.0.0.0) - C:\WINDOWS\system32\WsmTxt.xsl [MD5.9D6B8FC71167D22849424084F0F3D9E9] - |D| - [16/07/2016 13:44:03] - (.-.) - [74.28 Ko] - (0.0.0.0) - C:\WINDOWS\system32\xpsrchvw.xml [MD5.684DDBD6ED4066B10660A3A06655B59A] - |D| - [16/07/2016 13:42:11] - (.-.) - [3.92 Ko] - (0.0.0.0) - C:\WINDOWS\system32\xwizard.dtd ---------- | Installer [HKCR\Installer\Products\00bbe8c09094c95438742b60b8f73091] : OEM Share Pack -> C:\WINDOWS\Installer\{0c8ebb00-4909-459c-8347-b2068b7f0319}\ARPPRODUCTICON.exe [HKCR\Installer\Products\01D4F6DBE92E3E944879D154A45FEE8F] : Nero Disc to Device [HKCR\Installer\Products\043FB559973C5734AAF23FCB2B4A89BA] : Nero Family and Events Themes -> C:\WINDOWS\Installer\{955BF340-C379-4375-AA2F-F3BCB2A498AB}\ARPPRODUCTICON.exe [HKCR\Installer\Products\047C26CF9332C81664B763ECD604E9F5] : CCC Help Portuguese -> c:\windows\Installer\{FC62C740-2339-618C-467B-36CE6D409E5F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\05D94ECADC916A441B29649F5882B362] : Nero PiP Effects Basic -> C:\WINDOWS\Installer\{ACE49D50-19CD-44A6-B192-46F985283B26}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0694AF70830BBE9498B1F95939A05A44] : HP Customer Experience Enhancements -> C:\windows\Installer\{07FA4960-B038-49EB-891B-9F95930AA544}\ARPPRODUCTICON.exe [HKCR\Installer\Products\085E718E81368CFA122023C23711E74C] : CCC Help Polish -> C:\WINDOWS\Installer\{E817E580-6318-AFC8-2102-322C73117EC4}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0B8F248F2496039428F145E379B6C266] : MSVCRT110_amd64 [HKCR\Installer\Products\0BE6E9B4DEE047E449979F283C52F417] : SQL Server Browser for SQL Server 2012 -> c:\WINDOWS\Installer\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}\ARPIco [HKCR\Installer\Products\0CCA1DC70DD34984097CFBA231C670D4] : [HKCR\Installer\Products\0D4A6A5A500250A2E212948580FC59DE] : CCC Help Norwegian -> C:\WINDOWS\Installer\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0DDFD8EF345A38A47B9A4C113118495D] : Galerie de photos [HKCR\Installer\Products\0E5F85E2FE5BC448B581C4128F00AC6D] : ccc-utility64 -> c:\windows\Installer\{2E58F5E0-B5EF-844C-5B18-4C21F800CAD6}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0F76E360892CA2A8F06A481C35224A0E] : ccc-utility64 -> C:\WINDOWS\Installer\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}\ARPPRODUCTICON.exe [HKCR\Installer\Products\150520221991BE84B88EA73392AD7EDE] : IIS 7.5 Express -> C:\WINDOWS\Installer\{22025051-1991-48EB-8BE8-7A3329DAE7ED}\Icon_IisExpress [HKCR\Installer\Products\15E5F6B1E5753964CB2A573475D070D6] : Nero Kwik Themes Basic -> C:\WINDOWS\Installer\{1B6F5E51-575E-4693-BCA2-7543570D076D}\ARPPRODUCTICON.exe [HKCR\Installer\Products\188D52D43817F264598C99C01A49E4B0] : Nero PiP Effects 1 -> C:\WINDOWS\Installer\{4D25D881-7183-462F-95C8-990CA1944E0B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\19CF135DE4F67A949B215182D9506B8F] : Photo Common [HKCR\Installer\Products\1A15D4212C3FEA548B213DAC17420739] : SQL Server 2012 Common Files [HKCR\Installer\Products\1D5F27E1E3559FFC603AC8A55F70DDC1] : CCC Help French -> C:\WINDOWS\Installer\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}\ARPPRODUCTICON.exe [HKCR\Installer\Products\1DE0846BE844B318F40EEB8D111D0CF1] : CCC Help French -> c:\windows\Installer\{B6480ED1-448E-813B-4FE0-BED811D1C01F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\1F88D051FA0487643AD9CB2E33F2435E] : Nero Abstract Themes -> C:\WINDOWS\Installer\{150D88F1-40AF-4678-A39D-BCE2332F34E5}\ARPPRODUCTICON.exe [HKCR\Installer\Products\21993ABAC0833FE08C02681851BED1CA] : Catalyst Control Center InstallProxy -> c:\windows\Installer\{ABA39912-380C-0EF3-C820-868115EB1DAC}\ARPPRODUCTICON.exe [HKCR\Installer\Products\224612CF7C2EFB7408018F8518C18CC6] : [HKCR\Installer\Products\241A5D4605DBE627DEE92D05D8A2712E] : Catalyst Control Center InstallProxy -> C:\WINDOWS\Installer\{64D5A142-BD50-726E-ED9E-D2508D2A17E2}\ARPPRODUCTICON.exe [HKCR\Installer\Products\2C31622C4A7C16749A6011E6DCE44777] : SQL Server 2012 Database Engine Services [HKCR\Installer\Products\2EB941D82456A6F4EA4CD7166ECDEABF] : [HKCR\Installer\Products\2F12AC03A109BD444AF3CF13DCF04239] : Sql Server Customer Experience Improvement Program -> c:\WINDOWS\Installer\{30CA21F2-901A-44DB-A43F-FC31CD0F2493}\ARPIco [HKCR\Installer\Products\307BCCF8FBF37e944AF38AE1729D0BE7] : MediaShow -> C:\WINDOWS\Installer\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\ARPPRODUCTICON.exe [HKCR\Installer\Products\3089FBDBC75BA2BA8803BCDE43078304] : Catalyst Control Center Graphics Previews Common -> c:\windows\Installer\{BDBF9803-B57C-AB2A-8830-CBED34703840}\ARPPRODUCTICON.exe [HKCR\Installer\Products\32F7D401414AD6EE13E50AC77BA5EDEE] : CCC Help English -> c:\windows\Installer\{104D7F23-A414-EE6D-315E-A07CB75ADEEE}\ARPPRODUCTICON.exe [HKCR\Installer\Products\33305D78435EA394E889A094CB826FB4] : SQL Server 2012 Database Engine Services [HKCR\Installer\Products\35588CBA077879B44BE3A50946A7B536] : Nero ControlCenter -> C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ARPPRODUCTICON.exe [HKCR\Installer\Products\36DE92D79F487CE44BF999A4A313592B] : SQL Server 2012 Common Files [HKCR\Installer\Products\375E4A382C2EBF64D96AA6B2BB5F5A88] : Nero Retro Film Themes -> C:\WINDOWS\Installer\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}\ARPPRODUCTICON.exe [HKCR\Installer\Products\37DCDAB6529E7F642A59FF4284367282] : [HKCR\Installer\Products\37E58BB129D0A406A0FA7CAA5D3E3A6C] : CCC Help English -> C:\WINDOWS\Installer\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}\ARPPRODUCTICON.exe [HKCR\Installer\Products\384482F5D8EEE744EBEBB21FB3804CFB] : Prerequisite installer -> C:\WINDOWS\Installer\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}\ARPPRODUCTICON.exe [HKCR\Installer\Products\3A56CBC8BA0456EDC21B99A7DB8ADF86] : CCC Help Turkish -> C:\WINDOWS\Installer\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}\ARPPRODUCTICON.exe [HKCR\Installer\Products\3C1BCDF6CDE9CBC374C3DD58DEE54049] : CCC Help German -> C:\WINDOWS\Installer\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}\ARPPRODUCTICON.exe [HKCR\Installer\Products\3CB65822398FFBC4592F1E6FC32D1BBA] : Nero Video Transitions 1 -> C:\WINDOWS\Installer\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}\ARPPRODUCTICON.exe [HKCR\Installer\Products\3EFCAE7DA6CBbb842BC8D4FB1328523E] : PowerProducer -> C:\WINDOWS\Installer\{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}\ARPPRODUCTICON.exe [HKCR\Installer\Products\3F78D2E7CB3F5af4F927FB20E16DC63B] : [HKCR\Installer\Products\4171AC28AE31914F19EF2138444247E5] : CCC Help Italian -> C:\WINDOWS\Installer\{82CA1714-13EA-F419-91FE-12834424745E}\ARPPRODUCTICON.exe [HKCR\Installer\Products\42C6FBF1Df1C10144AB2C065F4E9E897] : [HKCR\Installer\Products\42CB457F40C2E67F4C3010570F595406] : CCC Help Chinese Standard -> c:\windows\Installer\{F754BC24-2C04-F76E-C403-0175F0954560}\ARPPRODUCTICON.exe [HKCR\Installer\Products\42D78011D76588D7966C7D0AB8F5C474] : Catalyst Control Center - Branding -> C:\WINDOWS\Installer\{11087D24-567D-7D88-69C6-D7A08B5F4C47}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4673AE1C831172EADA3645B9DA99AB51] : CCC Help Japanese -> C:\WINDOWS\Installer\{C1EA3764-1138-AE27-AD63-549BAD99BA15}\ARPPRODUCTICON.exe [HKCR\Installer\Products\48D76F9207A3E65408A62503B12070B0] : Nero Effects Basic -> C:\WINDOWS\Installer\{29F67D84-3A70-456E-806A-52301B02070B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4B4FA6E101901284BC028FDFA70AC9BC] : CCC Help Russian -> c:\windows\Installer\{1E6AF4B4-0910-4821-CB20-F8FD7AA09CCB}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4BB780764B91961CE325B2DE97D6A83B] : CCC Help Swedish -> c:\windows\Installer\{67087BB4-19B4-C169-3E52-2BED796D8AB3}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4F74DB53B91CF474AACC8E0CEB8341A8] : Photo Common [HKCR\Installer\Products\4FC967F53625B7C4EA2B0CA637EA4482] : AMD Catalyst Install Manager -> c:\windows\Installer\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}\ARPPRODUCTICON.exe [HKCR\Installer\Products\50848F456110F764783198D9CF742253] : SQL Server 2012 Database Engine Shared [HKCR\Installer\Products\5104B339816461748A822598CF3061F5] : VC80CRTRedist - 8.0.50727.6195 [HKCR\Installer\Products\52FD6C4C95E0EE642BB4FD78948DFFA3] : Nero Image Samples -> C:\WINDOWS\Installer\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\554590D7179DC4D4E9DFA96F6A85F4A3] : Bing Bureau -> C:\WINDOWS\Installer\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}\icon.ico [HKCR\Installer\Products\566152064B486D1448FBD605EC86DD80] : Nero Express -> C:\WINDOWS\Installer\{60251665-84B4-41D6-84BF-6D50CE68DD08}\ARPPRODUCTICON.exe [HKCR\Installer\Products\575EBE29E6C031740B5943BB29E7A56C] : Nero CoverDesigner -> C:\WINDOWS\Installer\{92EBE575-0C6E-4713-B095-34BB927E5AC6}\ARPPRODUCTICON.exe [HKCR\Installer\Products\59EBDD8FEBCD5B303595ED631041E612] : CCC Help Danish -> C:\WINDOWS\Installer\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}\ARPPRODUCTICON.exe [HKCR\Installer\Products\5ACF48976BB16e64192EDEC503A11FA1] : [HKCR\Installer\Products\5B6E18EFB2567E043B2B17176C2F79AD] : Nero Disc Menus 2 -> C:\WINDOWS\Installer\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}\ARPPRODUCTICON.exe [HKCR\Installer\Products\5E16E053C2C6C3F2A341E790A46B3D0A] : CCC Help Spanish -> C:\WINDOWS\Installer\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}\ARPPRODUCTICON.exe [HKCR\Installer\Products\623DD63D08278D11798C00109267C0EB] : PhotoNow -> C:\WINDOWS\Installer\{D36DD326-7280-11D8-97C8-000129760CBE}\ARPPRODUCTICON.exe [HKCR\Installer\Products\65A736C97824F78459FB4122CFA18A97] : Nero 2016 -> C:\WINDOWS\Installer\{9C637A56-4287-487F-95BF-1422FC1AA879}\ARPPRODUCTICON.exe [HKCR\Installer\Products\66122D971C874DA2407EDB22DB85DF64] : CCC Help Chinese Traditional -> C:\WINDOWS\Installer\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}\ARPPRODUCTICON.exe [HKCR\Installer\Products\6761FBEE78FA6624398DC0413AC42471] : Nero Disc Menus 1 -> C:\WINDOWS\Installer\{EEBF1676-AF87-4266-93D8-0C14A34C4217}\ARPPRODUCTICON.exe [HKCR\Installer\Products\67BCB71E42995DB46B6D053D04B7E447] : Nero Disc Menus Basic -> C:\WINDOWS\Installer\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}\ARPPRODUCTICON.exe [HKCR\Installer\Products\68ADF0FAB7E6C6A1154D34FA0581E12D] : AMD Catalyst Control Center -> C:\WINDOWS\Installer\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}\ARPPRODUCTICON.exe [HKCR\Installer\Products\6C1C2E92A67D3D1489F0E643A69A6A8A] : Nero Cliparts -> C:\WINDOWS\Installer\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}\ARPPRODUCTICON.exe [HKCR\Installer\Products\6D6E41E65713A1E49B43AC5B8A3676DC] : HP Postscript Converter [HKCR\Installer\Products\6FB31B48FA7FE891E077CD4A20B7D991] : CCC Help Japanese -> c:\windows\Installer\{84B13BF6-F7AF-198E-0E77-DCA4027B9D19}\ARPPRODUCTICON.exe [HKCR\Installer\Products\701043F6AA9F6C745BC43C1AF91155F3] : Hewlett-Packard ACLM.NET v1.2.0.0 -> C:\windows\Installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\7040BB568CC47CD459E2E3FEFD5006A2] : Nero Update -> C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\72BCCFF8D2EEF85DA5DBDEC5609BE118] : CCC Help Swedish -> C:\WINDOWS\Installer\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}\ARPPRODUCTICON.exe [HKCR\Installer\Products\73C44F0DB22A3374BB7A689C4F897852] : SQL Server 2012 Database Engine Shared [HKCR\Installer\Products\7751D938514598C6662415D5FF6E34F2] : CCC Help Czech -> c:\windows\Installer\{839D1577-5415-6C89-6642-515DFFE6432F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\77E99DA1CC73E44793AC766FDF4365A5] : Catalyst Control Center Localization All -> C:\WINDOWS\Installer\{1AD99E77-37CC-744E-39CA-67F6FD34565A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\797ECA52ADBEB4E090F6F99EA7E1A2F6] : CCC Help Russian -> C:\WINDOWS\Installer\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\79DD22F7D652D194090947F3DA7CB9EB] : Nero RescueAgent -> C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\ARPPRODUCTICON.exe [HKCR\Installer\Products\7BD4C90EC03660F46A13E87A329932FA] : D3DX10 [HKCR\Installer\Products\7CF988168379A934693B71FA89B1DDFE] : Movie Maker [HKCR\Installer\Products\7E6A666A15A3982E55B9FB436830A6FB] : CCC Help Turkish -> c:\windows\Installer\{A666A6E7-3A51-E289-559B-BF3486036ABF}\ARPPRODUCTICON.exe [HKCR\Installer\Products\814AB0FE73FAE1745949AE5E19F36418] : Nero Launcher -> C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\ARPPRODUCTICON.exe [HKCR\Installer\Products\81685BD51207056CEEA885DCF1AA599F] : CCC Help Thai -> c:\windows\Installer\{5DB58618-7021-C650-EE8A-58CD1FAA95F9}\ARPPRODUCTICON.exe [HKCR\Installer\Products\821B6C5004B15944C99B90B063B8AFA0] : Nero Video Samples -> C:\WINDOWS\Installer\{05C6B128-1B40-4495-9CB9-090B368BFA0A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\833DA5B8CBA7BCE4C9C286F748EADD1B] : Nero Platinum Effects 12 -> C:\WINDOWS\Installer\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8AAF13F31CC6EFF498C43DE14560C7A8] : GFI WebMonitor 10 -> C:\WINDOWS\Installer\{3F31FAA8-6CC1-4FFE-894C-D31E54067C8A}\MainExe.ico [HKCR\Installer\Products\8AC6637E9717EA777E21AB817DA0A070] : AMD Fuel -> C:\WINDOWS\Installer\{E7366CA8-7179-77AE-E712-BA18D70A0A07}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8BA31D3CA8644710D160BDA9EAA831B1] : CCC Help Czech -> C:\WINDOWS\Installer\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8C6252E28A15BE6F289876788E08EC72] : Catalyst Control Center Localization All -> c:\windows\Installer\{2E2526C8-51A8-F6EB-8289-6787E880CE27}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8CDD41E806AE81E43B3E917301D4B5AD] : MSVCRT110 [HKCR\Installer\Products\8EFB030F674880C45A3532D38EA0B21E] : Nero Info -> C:\WINDOWS\Installer\{F030BFE8-8476-4C08-A553-233DE80A2BE1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8F55E2B98AB554A46928CA6B2FCCD05A] : Photo Gallery [HKCR\Installer\Products\92540D3EBDE68D113A270005AB3E711E] : PowerDVD Copy -> C:\WINDOWS\Installer\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\94BD5DDAFC278D11D95700109267D057] : PowerBackup -> C:\WINDOWS\Installer\{ADD5DB49-72CF-11D8-9D75-000129760D75}\ARPPRODUCTICON.exe [HKCR\Installer\Products\985E2342652631540BFBFE8A3E525D0F] : Nero SharedVideoCodecs [HKCR\Installer\Products\9AB6048E74D526A4803C57E96A7722A9] : AMD VISION Engine Control Center -> c:\windows\Installer\{E8406BA9-5D47-4A62-08C3-759EA677229A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\9BB40EA6554ADE618560CDBF1B54506D] : CCC Help Dutch -> c:\windows\Installer\{6AE04BB9-A455-16ED-5806-DCFBB14505D6}\ARPPRODUCTICON.exe [HKCR\Installer\Products\9BEBFD6755E96CC89BA9C9FECA75A3F1] : CCC Help Spanish -> c:\windows\Installer\{76DFBEB9-9E55-8CC6-B99A-9CEFAC573A1F}\ARPPRODUCTICON.exe [HKCR\Installer\Products\A0BF5B3400990B34DB64E9F7988CA889] : Acronis True Image -> C:\WINDOWS\Installer\{43B5FB0A-9900-43B0-BD46-9E7F89C88A98}\product.ico [HKCR\Installer\Products\A144A7CAF3536F57A6ABB39F18165B03] : CCC Help Greek -> c:\windows\Installer\{AC7A441A-353F-75F6-6ABA-3BF98161B530}\ARPPRODUCTICON.exe [HKCR\Installer\Products\A5CAA931F8D66C64FAD5A722CF2AB693] : GFI Directory -> C:\WINDOWS\Installer\{139AAC5A-6D8F-46C6-AF5D-7A22FCA26B39}\ARPPRODUCTICON.exe [HKCR\Installer\Products\A6C64DD86500CEF47BA082BB611A1FF1] : MSVCRT [HKCR\Installer\Products\A748067A9D4CFE7E17F6706CBC6F1B74] : CCC Help Thai -> C:\WINDOWS\Installer\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}\ARPPRODUCTICON.exe [HKCR\Installer\Products\A97236C163FB258499421B79D856586A] : Nero Device Updates [HKCR\Installer\Products\AB75A5C0E5343F340804DA0FD817C5A8] : [HKCR\Installer\Products\ACDDA84BC6A18184F8CA4AB9A85EC556] : PCKAVLang.fr [HKCR\Installer\Products\B4BF8DE8C4EF4104D8009DDA5C944146] : GFI Archiver -> C:\WINDOWS\Installer\{8ED8FB4B-FE4C-4014-8D00-D9ADC5491464}\ARPPRODUCTICON.exe [HKCR\Installer\Products\B7E5D71BDDAF4BE45B73BCE73B33D379] : Nero Recode -> C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ARPPRODUCTICON.exe [HKCR\Installer\Products\BA0A2B44E214C8F40B851D8EEACCFD5F] : PowerRecover -> c:\windows\Installer\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\ARPPRODUCTICON.exe [HKCR\Installer\Products\BD536147AD63FCB4BB25F0C4C1E4D0BF] : Wedding Pack -> C:\WINDOWS\Installer\{741635DB-36DA-4BCF-BB52-0F4C1C4E0DFB}\ARPPRODUCTICON.exe [HKCR\Installer\Products\BFCE53DD59C5B893ACAF5B8E8831363C] : CCC Help Italian -> c:\windows\Installer\{DD35ECFB-5C95-398B-CAFA-B5E8881363C3}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C0DBE580E42F49BED633A222FE465CFC] : CCC Help Finnish -> C:\WINDOWS\Installer\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C0DCA5F5454A7A232E60EE981B151082] : CCC Help Danish -> c:\windows\Installer\{5F5ACD0C-A454-32A7-E206-EE89B1510128}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C351938B2D4DC98F0533A061C02607B6] : CCC Help Portuguese -> C:\WINDOWS\Installer\{B839153C-D4D2-F89C-5033-0A160C62706B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C51E70D24A9A6D8D3D1729CE78975E78] : CCC Help Hungarian -> C:\WINDOWS\Installer\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C5D52DA5318CB641F40B6765F187577B] : CCC Help Hungarian -> c:\windows\Installer\{5AD25D5C-C813-146B-4FB0-76561F7875B7}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C72FCF837A17D2444AAA72C4344940C4] : GFI LanGuard -> C:\WINDOWS\Installer\{38FCF27C-71A7-442D-A4AA-274C4394044C}\LanGuard.exe [HKCR\Installer\Products\C8454747654E8184E80DA4F100FE771A] : Catalyst Control Center - Branding -> c:\windows\Installer\{7474548C-E456-4818-8ED0-4A1F00EF77A1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C951361A674B10541B36F37708A98C33] : Nero Burning Core [HKCR\Installer\Products\C971C95CD8669A946BAE1012CCCF2134] : LabelPrint -> c:\windows\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe [HKCR\Installer\Products\CC599AF0948C55741BB44540CC57CD42] : Energy Star -> c:\windows\Installer\{0FA995CC-C849-4755-B14B-5404CC75DC24}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\CC67F423DD8D78D47BD74DFAE5A17A3B] : [HKCR\Installer\Products\CD71EB902D9582DF73D1CD0EEA67EC57] : CCC Help Korean -> c:\windows\Installer\{09BE17DC-59D2-FD28-371D-DCE0AE76CE75}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D276F30548C6A844F8F8B43CA58C4314] : AMD APP SDK Runtime -> c:\windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D43EEBEB2A48DDE4B8AE69CC45732136] : Nero Core Components [HKCR\Installer\Products\D73F0BFC7E2273F4F8EA3B915AA85C9B] : Nero Burning ROM -> C:\WINDOWS\Installer\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D85C4CB1627DB271ADC2BB6EEAD5BE67] : CCC Help Finnish -> c:\windows\Installer\{1BC4C58D-D726-172B-DA2C-BBE6AE5DEB76}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D935B019752F8C64C98BC659FE9FFC22] : Stashimi Stub Installer [HKCR\Installer\Products\DA1C168692894ED468747458CEAE24A1] : Nero Video -> C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DBF576EC3C571F546BFAD85280165D63] : Nero Disc Menus 3 -> C:\WINDOWS\Installer\{CE675FBD-75C3-45F1-B6AF-8D250861D536}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DE48D40557EA58F46AB8BBD3C43B1E96] : Nero Holiday and Sports Themes -> C:\WINDOWS\Installer\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DE532CED4A8571542A874CE1D8EABAB3] : PowerDVD -> c:\windows\Installer\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DED17A5318AD313153A2CEA8B072FDB3] : CCC Help Chinese Standard -> C:\WINDOWS\Installer\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DF78E77D420FBDF488BF385C97AA46B4] : PCKLang.fr [HKCR\Installer\Products\E3A623703B208701527D8B66B68AEF51] : CCC Help Korean -> C:\WINDOWS\Installer\{07326A3E-02B3-1078-25D7-B8666BA8FE15}\ARPPRODUCTICON.exe [HKCR\Installer\Products\E3B8D0C40F363774385F5C7B97B5F08B] : Photo Gallery [HKCR\Installer\Products\E45CB17D6E4A60E468C6DFE61EE61A78] : Movie Maker [HKCR\Installer\Products\E5AE57E7AF9DBD546964EE5A5CFB164D] : Nero MediaHome -> C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\NeroKwikMedia._63C8A7B0BBE5459F9AC436392B2FF50D.exe [HKCR\Installer\Products\EB3FC7A1A4D0FD33FD9D284478273656] : CCC Help German -> c:\windows\Installer\{1A7CF3BE-0D4A-33DF-DFD9-824487726365}\ARPPRODUCTICON.exe [HKCR\Installer\Products\ED103061A603EDA4A874CB7509FA4068] : GFI LanGuard 12 Agent [HKCR\Installer\Products\EE47477FC6BEB78C88FA33018C840E86] : CCC Help Greek -> C:\WINDOWS\Installer\{F77474EE-EB6C-C87B-88AF-3310C848E068}\ARPPRODUCTICON.exe [HKCR\Installer\Products\EE6884B559A5752C6AF8D2ACED742A37] : CCC Help Norwegian -> c:\windows\Installer\{5B4886EE-5A95-C257-A68F-2DCADE47A273}\ARPPRODUCTICON.exe [HKCR\Installer\Products\F218391F0C38DEC3E1EDEB5252623730] : CCC Help Chinese Traditional -> c:\windows\Installer\{F193812F-83C0-3CED-1EDE-BE2525267303}\ARPPRODUCTICON.exe [HKCR\Installer\Products\F5ED6BFBAEB9BBF15348C28736C95EA9] : CCC Help Polish -> c:\windows\Installer\{BFB6DE5F-9BEA-1FBB-3584-2C78639CE59A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\F64E64890E70FDB489A53EBF8A1C8577] : Movie Maker [HKCR\Installer\Products\F75D59AC3CF97DD0C76363F2478D0CE4] : CCC Help Dutch -> C:\WINDOWS\Installer\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}\ARPPRODUCTICON.exe [HKCR\Installer\Products\FB4A7DB746AEEFB49A3DF3CDB9E6CF32] : Nero Football (Soccer) Themes -> C:\WINDOWS\Installer\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}\ARPPRODUCTICON.exe [HKCR\Installer\Products\FFC5F60053DEFA14B9A25FB2F045B54F] : Nero 2016 Content Pack -> C:\WINDOWS\Installer\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}\ARPPRODUCTICON.exe ---------- | ADS @C:\ProgramData\Temp:5C321E34 ---------- | Drives Disk: 0 Size=954G Pos MBRndx Type/Name Size Active Hide Start Sector Sectors --- ------ ---------- ---- ------ ---- ------------ ------------ 0 0 EE-UNKNWN 954G No No 1 953,525,167 ---------- | MBR Windows Version: Professional Windows Information: (build 9200), 64-bit Base Board Manufacturer: Hewlett-Packard BIOS Manufacturer: AMI System Manufacturer: Hewlett-Packard System Product Name: CQ2904EF Logical Drives Mask: 0x01bffffc Analysis of file "C:\QuickDiag\MBR.bin": Unknown MBR code 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Internal event: Active Directory Lightweight Directory Services could not build the Address Book hierarchy table. The next attempt will occur at the following interval. Interval (minutes): 0 Address Book searches will be disabled on this domain controller during this interval. ------------ Le service ne peut pas être démarré. System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à GFiProxy.ProxyMonitor..ctor(HTTPClientSessionFactory sessionFactory, ErrorMessageWindow errorMessageWindow) à GFiProxy.GFiProxy.CreateProxyMonitor() à GFiProxy.GFiProxy.OnStart(String[] args) à System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) ------------ Le service ne peut pas être démarré. System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à WebMon.Core.ChainedNegotiateAuthenticatorModule.Start() à WebMon.WinService.MainService.OnStart(String[] args) à System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) ------------ Failed to start provider WebMon.Core.ChainedNegotiateAuthenticatorModule: System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à WebMon.Core.ChainedNegotiateAuthenticatorModule.Start() à WebMon.WinService.MainService.OnStart(String[] args) ------------ Le service ne peut pas être démarré. System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à GFiProxy.ProxyMonitor..ctor(HTTPClientSessionFactory sessionFactory, ErrorMessageWindow errorMessageWindow) à GFiProxy.GFiProxy.CreateProxyMonitor() à GFiProxy.GFiProxy.OnStart(String[] args) à System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) ------------ Nom de l’application défaillante svchost.exe, version : 10.0.14393.0, horodatage : 0x57899b1c Nom du module défaillant : ntdll.dll, version : 10.0.14393.0, horodatage : 0x578997b2 Code d’exception : 0xc0000008 Décalage d’erreur : 0x00000000000a8aaa ID du processus défaillant : 0xc58 Heure de début de l’application défaillante : 0x01d1fd6101144f97 Chemin d’accès de l’application défaillante : C:\WINDOWS\system32\svchost.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : b212b9f8-be48-4257-8603-979ba996024f Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Le service ne peut pas être démarré. System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à WebMon.Core.ChainedNegotiateAuthenticatorModule.Start() à WebMon.WinService.MainService.OnStart(String[] args) à System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) ------------ Failed to start provider WebMon.Core.ChainedNegotiateAuthenticatorModule: System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à WebMon.Core.ChainedNegotiateAuthenticatorModule.Start() à WebMon.WinService.MainService.OnStart(String[] args) ------------ Le service ne peut pas être démarré. System.IO.FileNotFoundException: Impossible de charger le fichier ou l'assembly 'spnegoauth.dll' ou une de ses dépendances. Le module spécifié est introuvable. Nom de fichier : 'spnegoauth.dll' à GFiProxy.ProxyMonitor..ctor(HTTPClientSessionFactory sessionFactory, ErrorMessageWindow errorMessageWindow) à GFiProxy.GFiProxy.CreateProxyMonitor() à GFiProxy.GFiProxy.OnStart(String[] args) à System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) ------------ ----------( EOF)---------- - 7901 | 21:16:14