--------------- QuickDiag | g3n-h@ckm@n | V3_01.07.17.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 22/07/2017 16:08:44 Updated 01/07/2017 | 11.30 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [Jean-Marie (Administrator)] - [LFSULTRA-WIDEN] (S-1-5-21-1766228302-1366166313-1596766668-1001) System: Microsoft Windows 10 Famille - - (10.0.15063) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> (1703) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Famille|C:\WINDOWS|\Device\Harddisk0\Partition3 Boot : SafeMode with network PC: CQ2904EF - Hewlett-Packard - IdNumber: 4CH3100VPJ - UUID: 2C238515-5AA2-7984-51F0-370493363EDB Processor : X64 - 1397 Mhz - AMD E1-1200 APU with Radeon(tm) HD Graphics 8.17 - fra - AMI - S/N: 4CH3100VPJ - 8.17 - HPQOEM - 1072009 CoreTemp : ? Celsius ----------| Extended ---------- | SoundDevice Realtek High Definition Audio - Status: Unknown - Manufacturer: Realtek - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0662&SUBSYS_103C2AE3&REV_1001\4&2070A159&0&0001 ---------- | Video AMD Radeon HD 7310 Graphics - Resolution: x - Colors: - RefreshRate: - Bits Per Pixel - DeviceID: VideoController1 - Drivers: aticfx64.dll,aticfx64.dll,aticfx64.dll,aticfx32,aticfx32,aticfx32,atiumd64.dll,atidxx64.dll,atidxx64.dll,atiumdag,atidxx32,atidxx32,atiumdva,atiumd6a.cap,atitmm64.dll - PNPDeviceID: PCI\VEN_1002&DEV_9809&SUBSYS_2AE3103C&REV_00\3&11583659&0&08 - AdapterCompatibility: Advanced Micro Devices, Inc. - RAM: 402653184 Inegrated Video Chipset DeviceName: AMD Radeon HD 7310 Graphics - DriverVersion: 8.14.01.6463 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\lvcod64.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 175392 - Manufacturer: Logitech Inc. - Status: OK c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 53760 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codecp.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 181248 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35760 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42488 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 84992 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 28160 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35208 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\prodad-codec.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 607256 - Manufacturer: proDAD GmbH - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK ---------- | CPU CPU #1 value:100 % CPU #2 value:100 % Total Overall CPU Usage value:100 % ---------- | Network Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller [NDIS 6.30] : SENT:32,758 bytes/sec / RECVD:32,758 bytes/sec Npcap Loopback Adapter : SENT:0 bytes/sec / RECVD:0 bytes/sec Overall -> SEND Maxium:32,758 bytes/sec, / RECEIVE Maximum:32,758 bytes/sec Microsoft Kernel Debug Network Adapter - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000 Windscribe VPN - Ethernet 802.3 - Windscribe.com - Status: - PnPID : ROOT\NET\0000 Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30) - Ethernet 802.3 - Qualcomm Atheros - Status: - PnPID : PCI\VEN_1969&DEV_2062&SUBSYS_2AE3103C&REV_C1\4&186C6B44&0&00A9 TeamViewer VPN Adapter - Ethernet 802.3 - TeamViewer GmbH - Status: - PnPID : ROOT\NET\0001 Npcap Loopback Adapter - Ethernet 802.3 - Microsoft - Status: - PnPID : ROOT\NET\0002 ---------- | Memory RAM = Total (MB) : 3748 | Free (MB) : 1421 Pagefile = Total (MB) : 7549 | Free (MB) : 4961 Virtual = Total (MB) : 4194 | Free (MB) : 3943 Physical Memory 0 : Capacity: 4294967296 - A1_DIMM0 - Posit.: 0 - Manufacturer: Micron - PartNumber: 8JTF51264AZ-1G6E1 - S/N: DEA02E9 ---------- | SID Users Administrateur : [S-1-5-21-1766228302-1366166313-1596766668-500] DefaultAccount : [S-1-5-21-1766228302-1366166313-1596766668-503] HomeGroupUser$ : [S-1-5-21-1766228302-1366166313-1596766668-1005] Invité : [S-1-5-21-1766228302-1366166313-1596766668-501] Jean-Marie : [S-1-5-21-1766228302-1366166313-1596766668-1001] Administrateurs : [S-1-5-32-544] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] AMD FUEL : [S-1-5-21-1766228302-1366166313-1596766668-1008] HomeUsers : [S-1-5-21-1766228302-1366166313-1596766668-1004] SQLServer2005SQLBrowserUser$LFSULTRA-WIDEN : [S-1-5-21-1766228302-1366166313-1596766668-1007] WinRMRemoteWMIUsers__ : [S-1-5-21-1766228302-1366166313-1596766668-1000] ---------- | SystemAccounts Name: Tout le monde - SID: S-1-1-0 - SIDType: 5 - Status: OK Name: LOCAL - SID: S-1-2-0 - SIDType: 5 - Status: OK Name: CREATEUR PROPRIETAIRE - SID: S-1-3-0 - SIDType: 5 - Status: OK Name: GROUPE CREATEUR - SID: S-1-3-1 - SIDType: 5 - Status: OK Name: CREATOR OWNER SERVER - SID: S-1-3-2 - SIDType: 5 - Status: OK Name: CREATOR GROUP SERVER - SID: S-1-3-3 - SIDType: 5 - Status: OK Name: DROITS DU PROPRIÉTAIRE - SID: S-1-3-4 - SIDType: 5 - Status: OK Name: LIGNE - SID: S-1-5-1 - SIDType: 5 - Status: OK Name: RESEAU - SID: S-1-5-2 - SIDType: 5 - Status: OK Name: TACHE - SID: S-1-5-3 - SIDType: 5 - Status: OK Name: INTERACTIF - SID: S-1-5-4 - SIDType: 5 - Status: OK Name: SERVICE - SID: S-1-5-6 - SIDType: 5 - Status: OK Name: ANONYMOUS LOGON - SID: S-1-5-7 - SIDType: 5 - Status: OK Name: Proxy - SID: S-1-5-8 - SIDType: 5 - Status: OK Name: Système - SID: S-1-5-18 - SIDType: 5 - Status: OK Name: ENTERPRISE DOMAIN CONTROLLERS - SID: S-1-5-9 - SIDType: 5 - Status: OK Name: SELF - SID: S-1-5-10 - SIDType: 5 - Status: OK Name: Utilisateurs authentifiés - SID: S-1-5-11 - SIDType: 5 - Status: OK Name: RESTRICTED - SID: S-1-5-12 - SIDType: 5 - Status: OK Name: UTILISATEUR TERMINAL SERVER - SID: S-1-5-13 - SIDType: 5 - Status: OK Name: REMOTE INTERACTIVE LOGON - SID: S-1-5-14 - SIDType: 5 - Status: OK Name: IUSR - SID: S-1-5-17 - SIDType: 5 - Status: OK Name: SERVICE LOCAL - SID: S-1-5-19 - SIDType: 5 - Status: OK Name: SERVICE RÉSEAU - SID: S-1-5-20 - SIDType: 5 - Status: OK Name: BUILTIN - SID: S-1-5-32 - SIDType: 3 - Status: OK ---------- | Drives C:\ -> [Fixed] | [OS] | Total : 553.61 Go | Free : 262.55 Go -> NTFS [SATA] D:\ -> [Removable] | [CUBUNTU] | Total : 7.2 Go | Free : 0.08 Go -> FAT32 [USB] E:\ -> [Removable] | [WINUSB W10] | Total : 3.69 Go | Free : 0.36 Go -> exFAT [USB] F:\ -> [CDROM] | [Acronis Media] | Total : 0.59 Go | Free : 0 Go -> CDFS [SATA] G:\ -> [Removable] | [RASPBIAN] | Total : 0.04 Go | Free : 0.02 Go -> FAT32 [USB] M:\ -> [Fixed] | [wd MY passport 2TO] | Total : 2794.49 Go | Free : 245.65 Go -> NTFS [USB] U:\ -> [Removable] | [FRAMA MINT] | Total : 116.79 Go | Free : 46.8 Go -> FAT32 [USB] Disk Usage Information [6 total Physical Disks] Physical Drive #0 [C:] : Read:0 bytes/sec, Written:440,290 bytes/sec Max Read:0 bytes/sec, Max Write:440,290 bytes/sec Physical Drive #1 [M:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #2 [U:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #3 [D:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #4 [G:, H:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Physical Drive #5 [E:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec Overall - Read Maximum:0 bytes/sec, Write Maximum:440,290 bytes/sec DeviceID: \\.\PHYSICALDRIVE4 - Status: OK - USB - Removable Media - 2 Part. - PnPID : USBSTOR\DISK&VEN_GENERIC&PROD_STORAGE_DEVICE&REV_0815\000000000004&33 DeviceID: \\.\PHYSICALDRIVE1 - Status: OK - USB - External hard disk media - 1 Part. - PnPID : USBSTOR\DISK&VEN_WD&PROD_MY_PASSPORT_0827&REV_1012\575831314438354450483744&0 DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 6 Part. - PnPID : SCSI\DISK&VEN_WDC&PROD_WD10EZEX-60ZF5A0\4&32E8E4A0&0&000000 DeviceID: \\.\PHYSICALDRIVE3 - Status: OK - USB - Removable Media - 1 Part. - PnPID : USBSTOR\DISK&VEN_TOSHIBA&PROD_TRANSMEMORY&REV_1.00\0022CFF6BDF8C080958BAE56&0 DeviceID: \\.\PHYSICALDRIVE2 - Status: OK - USB - Removable Media - 1 Part. - PnPID : USBSTOR\DISK&VEN_MASS&PROD_STORAGE_DEVICE&REV_1.00\121220130416&0 DeviceID: \\.\PHYSICALDRIVE5 - Status: OK - USB - Removable Media - 1 Part. - PnPID : USBSTOR\DISK&VEN_GENERIC&PROD_STORAGE_DEVICE&REV_9454\&23 ---------- | Windows updates ---------- | Browsers IE : 11.0.15063.0 (© Microsoft Corporation. Tous droits réservés.) FF : 54.0.1.6388 (©Firefox and Mozilla Developers; available under the MPL 2 license.) GC : 59.0.3071.115 (Copyright 2016 Google Inc. All rights reserved.) OP : 46.0.2597.39 (Copyright Opera Software 2017) Default : "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "" ---------- | FlashPlayer FlashPlayer ActiveX : 26.0.0.137 ---------- | Security AV : Advanced SystemCare Ultimate Disabled AS : 360 Total Security Enabled AM : Malwarebytes' Anti-Malware ( 2.3.173.0) [Update : 11/07/2017 09:07:04] FW : COMODO Firewall Enabled WMI : OK WU: Windows Update Service [Auto(2)] = stopped AS: Windows Defender [Manual(3)] = stopped WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 504 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.15063.0) = C:\Windows\System32\smss.exe [18/03/2017 22:57:38] CPU Usage:0 % 668 | [Owner : Système | Parent : 652() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.15063.0) = C:\Windows\System32\csrss.exe [18/03/2017 22:57:38] CPU Usage:0 % 736 | [Owner : Système | Parent : 652() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.15063.483) = C:\Windows\System32\wininit.exe [11/07/2017 23:02:57] CPU Usage:0 % 744 | [Owner : Système | Parent : 728() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.15063.0) = C:\Windows\System32\csrss.exe [18/03/2017 22:57:38] CPU Usage:0 % 804 | [Owner : Système | Parent : 728() | 10.35 Mo] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.15063.483) = C:\Windows\System32\winlogon.exe [11/07/2017 23:03:22] CPU Usage:0 % 888 | [Owner : Système | Parent : 736(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.15063.0) = C:\Windows\System32\services.exe [18/03/2017 22:57:39] CPU Usage:0 % 904 | [Owner : Système | Parent : 736(wininit.exe) | 13.33 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.15063.483) = C:\Windows\System32\lsass.exe [11/07/2017 23:03:30] CPU Usage:0 % 984 | [Owner : Système | Parent : 888(services.exe) | 3.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1004 | [Owner : Système | Parent : 888(services.exe) | 20.15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 68 | [Owner : UMFD-1 | Parent : 804(winlogon.exe) | 12.44 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.15063.483) = C:\Windows\System32\fontdrvhost.exe [11/07/2017 23:02:39] CPU Usage:0 % 64 | [Owner : UMFD-0 | Parent : 736(wininit.exe) | 4.06 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.15063.483) = C:\Windows\System32\fontdrvhost.exe [11/07/2017 23:02:39] CPU Usage:0 % 732 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 11.04 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1020 | [Owner : Système | Parent : 888(services.exe) | 8.39 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1076 | [Owner : DWM-1 | Parent : 804(winlogon.exe) | 107.25 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (10.0.15063.0) = C:\Windows\System32\dwm.exe [18/03/2017 22:58:21] CPU Usage:4 % 1160 | [Owner : Système | Parent : 888(services.exe) | 10.66 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1196 | [Owner : Système | Parent : 888(services.exe) | 11.93 Mo] - (.IObit - Advanced SystemCare Ultimate Service.) - (10.0.0.8112) = C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe [21/07/2017 17:17:03] CPU Usage:0 % 1204 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.75 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1260 | [Owner : Système | Parent : 888(services.exe) | 8.03 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1332 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 23.96 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1424 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 12.36 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1460 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 7.09 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1484 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 5.82 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1492 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 8.61 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1500 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 7.62 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1616 | [Owner : Système | Parent : 888(services.exe) | 13.06 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1648 | [Owner : Système | Parent : 1196(ASCAvSvc.exe) | 7.96 Mo] - (.IObit - Advanced SystemCare Ultimate Wsc.) - (10.0.0.8071) = C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCAvWsc.exe [21/07/2017 17:17:05] CPU Usage:0 % 1740 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 8.23 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1792 | [Owner : Système | Parent : 888(services.exe) | 15.46 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 2024 | [Owner : Système | Parent : 888(services.exe) | 10.85 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 2032 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 10.93 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 2040 | [Owner : Système | Parent : 888(services.exe) | 7.89 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1032 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 14.35 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1656 | [Owner : Système | Parent : 888(services.exe) | 15.54 Mo] - (.IObit - StartMenu8 Services.) - (1.0.0.0) = C:\Program Files (x86)\IObit\Classic Start\SMService.exe [06/07/2017 16:10:31] CPU Usage:0 % 2072 | [Owner : Système | Parent : 888(services.exe) | 7.51 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 2316 | [Owner : Système | Parent : 888(services.exe) | 16.18 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 3040 | [Owner : Jean-Marie | Parent : 1260(svchost.exe) | 22.08 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.15063.0) = C:\Windows\System32\sihost.exe [18/03/2017 22:58:10] CPU Usage:0 % 2480 | [Owner : Jean-Marie | Parent : 1656(SMService.exe) | 179.82 Mo] - (.IObit - .) - (4.0.2.1) = C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe [06/07/2017 16:10:40] CPU Usage:0 % 2996 | [Owner : Système | Parent : 1656(SMService.exe) | 12.04 Mo] - (.IObit - .) - (2.0.0.0) = C:\Program Files (x86)\IObit\Classic Start\StartMenu_Hook.exe [06/07/2017 16:10:37] CPU Usage:0 % 2388 | [Owner : Jean-Marie | Parent : 2204() | 12.71 Mo] - (.Microsoft Corporation - Chargeur CTF.) - (10.0.15063.0) = C:\Windows\System32\ctfmon.exe [18/03/2017 22:58:37] CPU Usage:0 % 2092 | [Owner : Jean-Marie | Parent : 2204() | 7.16 Mo] - (. - .) - (0.0.0.0) = C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EaseUSEverySyncCache.exe [23/04/2017 13:47:13] CPU Usage:0 % 2984 | [Owner : Jean-Marie | Parent : 1004(svchost.exe) | 14.6 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.15063.0) = C:\Windows\System32\dllhost.exe [18/03/2017 22:58:21] CPU Usage:0 % 3212 | [Owner : Jean-Marie | Parent : 1004(svchost.exe) | 25.04 Mo] - (.Microsoft Corporation - Aide et support Microsoft.) - (10.0.15063.413) = C:\Windows\HelpPane.exe [06/07/2017 18:34:10] CPU Usage:0 % 3312 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 8.9 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 3928 | [Owner : Jean-Marie | Parent : 2480(ClassicStart.exe) | 17.27 Mo] - (.IObit - StartMenu8 InstallServices.) - (2.0.0.11) = C:\Program Files (x86)\IObit\Classic Start\InstallServices.exe [21/07/2017 16:46:26] CPU Usage:0 % 2916 | [Owner : Jean-Marie | Parent : 1004(svchost.exe) | 131.94 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.15063.447) = C:\Windows\explorer.exe [11/07/2017 23:03:18] CPU Usage:0 % 4348 | [Owner : Jean-Marie | Parent : 1004(svchost.exe) | 13.62 Mo] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) - (10.0.15063.0) = C:\Windows\System32\rundll32.exe [18/03/2017 22:58:29] CPU Usage:0 % 4904 | [Owner : Système | Parent : 888(services.exe) | 7.96 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 1116 | [Owner : Jean-Marie | Parent : 2628() | 51.15 Mo] - (.IObit - UninstallerMonitor.) - (7.0.0.818) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe [07/07/2017 10:01:34] CPU Usage:4 % 7408 | [Owner : Jean-Marie | Parent : 2916(explorer.exe) | 38.74 Mo] - (. - .) - (0.0.0.0) = M:\lfs hyper-jobs janv2016-dtpro-rebit-p2go11\ajustages lfsu100%sf-juin2017-anniv barrow 2-vexe-widen-amine\lfsu100%sf pz z sigma++ (sfce)\silent installer 4 lfsu100%sf ptzs++sfce apps\sih.3.1.0.0 (2).exe [09/07/2017 19:24:41] CPU Usage:0 % 7372 | [Owner : Jean-Marie | Parent : 2916(explorer.exe) | 38.48 Mo] - (. - .) - (0.0.0.0) = M:\lfs hyper-jobs janv2016-dtpro-rebit-p2go11\ajustages lfsu100%sf-juin2017-anniv barrow 2-vexe-widen-amine\lfsu100%sf pz z sigma++ (sfce)\silent installer 4 lfsu100%sf ptzs++sfce apps\sih.3.1.0.0.exe [21/07/2017 11:31:58] CPU Usage:4 % 9628 | [Owner : Jean-Marie | Parent : 10008() | 122.37 Mo] - (.Easeware - DriverEasy.) - (5.5.2.0) = C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [22/07/2017 15:12:17] CPU Usage:5 % 10012 | [Owner : Jean-Marie | Parent : 9292() | 18.84 Mo] - (. - .) - (0.0.0.0) = C:\Users\Jean-Marie\Documents\VideoMeetingPlus_1.0.1711.0_Beta_VMX160226-03.exe [14/11/2016 11:04:51] CPU Usage:0 % 9348 | [Owner : Jean-Marie | Parent : 10012(VideoMeetingPlus_1.0.1711.0_Beta_VMX160226-03.exe) | 41.67 Mo] - (.CyberLink Corp. - .) - (1.0.0.0) = C:\Users\JEAN-M~1\AppData\Local\Temp\RarSFX2\Setup.exe [22/07/2017 15:12:58] CPU Usage:0 % 10924 | [Owner : Système | Parent : 888(services.exe) | 5.75 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 22:58:21] CPU Usage:0 % 10756 | [Owner : Jean-Marie | Parent : 9348(Setup.exe) | 75.27 Mo] - (.Igor Pavlov - 7-Zip Console.) - (9.25.0.0) = C:\Users\JEAN-M~1\AppData\Local\Temp\RarSFX2\7z.exe [22/07/2017 15:12:54] CPU Usage:0 % 12252 | [Owner : Jean-Marie | Parent : 10756(7z.exe) | 10.26 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.15063.0) = C:\Windows\System32\conhost.exe [18/03/2017 22:57:35] CPU Usage:0 % 9988 | [Owner : Jean-Marie | Parent : 1004(svchost.exe) | 13.22 Mo] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) - (10.0.15063.0) = C:\Windows\System32\rundll32.exe [18/03/2017 22:58:29] CPU Usage:0 % 3276 | [Owner : Jean-Marie | Parent : 2392() | 37.19 Mo] - (.Microsoft Corporation - Gestionnaire des tâches.) - (10.0.15063.0) = C:\Windows\System32\Taskmgr.exe [18/03/2017 22:57:08] CPU Usage:11 % 15712 | [Owner : Jean-Marie | Parent : 3276(Taskmgr.exe) | 137.74 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.15063.447) = C:\Windows\explorer.exe [11/07/2017 23:03:18] CPU Usage:0 % 12276 | [Owner : Système | Parent : 888(services.exe) | 52.75 Mo] - (.NordNet - Service Contrôle Parental.) - (6.5.2.2) = C:\Program Files (x86)\Contrôle Parental Orange\ocsvc.exe [22/07/2017 15:34:41] CPU Usage:0 % 17348 | [Owner : Système | Parent : 1004(svchost.exe) | 8.95 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.0) = C:\Windows\System32\wbem\WmiPrvSE.exe [18/03/2017 22:58:01] CPU Usage:0 % 15640 | [Owner : Jean-Marie | Parent : 15712(explorer.exe) | 40.9 Mo] - (.SosVirus - QuickDiag.) - (1.7.17.1) = C:\Users\Jean-Marie\Desktop\quickdiag_3_01.07.17.1.exe [17/07/2017 15:52:29] CPU Usage:0 % 17760 | [Owner : Jean-Marie | Parent : 15712(explorer.exe) | 56.08 Mo] - (.Microsoft Corporation - Bloc-notes.) - (10.0.15063.0) = C:\Windows\System32\notepad.exe [18/03/2017 22:58:29] CPU Usage:0 % 17812 | [Owner : Jean-Marie | Parent : 17760(notepad.exe) | 15.59 Mo] - (.Disc Soft Ltd - DAEMON Tools Shell Extensions Helper.) - (8.0.0.634) = C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe [25/10/2016 18:46:18] CPU Usage:0 % 3860 | [Owner : SERVICE RÉSEAU | Parent : 1004(svchost.exe) | 9.82 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.0) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [18/03/2017 22:58:50] CPU Usage:0 % ---------- | MD5 [MD5.CA3BF0F15BA4F24D511BFEE725CC89BD] - [11/07/2017 23:03:18] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4733.81 Ko] - (10.0.15063.447) : C:\WINDOWS\Explorer.exe [MD5.94912C1D73ADE68F2486ED4D8EA82DE6] - [18/03/2017 22:57:50] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [265.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\cmd.exe [MD5.31E45CAA8E7035ECD47E96A7377BE975] - [18/03/2017 22:57:38] - (.© Microsoft Corporation. Tous droits réservés. - Processus d’exécution client-serveur.) - [17.28 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\csrss.exe [MD5.2D29C0AFCC8225AFF6637F7362C22960] - [18/03/2017 22:58:21] - (.© Microsoft Corporation. All rights reserved. - COM Surrogate.) - [20.91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\dllhost.exe [MD5.90224339656D3CFEC43150209B4CD38E] - [12/05/2017 04:32:09] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [692.1 Ko] - (10.0.15063.296) : C:\WINDOWS\System32\Kernel32.dll [MD5.9936F9E94C6E3F47A158D7BFF020575A] - [11/07/2017 23:03:30] - (.© Microsoft Corporation. All rights reserved. - Local Security Authority Process.) - [57.12 Ko] - (10.0.15063.483) : C:\WINDOWS\System32\lsass.exe [MD5.0E79A4C76CAAA0CFE9CA42C13E5AA086] - [12/05/2017 04:32:10] - (.© Microsoft Corporation. All rights reserved. - Distributed COM Services.) - [1060 Ko] - (10.0.15063.296) : C:\WINDOWS\System32\rpcss.dll [MD5.ECB702B8C5650381C0784F1EEABB97BC] - [18/03/2017 22:58:29] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [67 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\rundll32.exe [MD5.800D00D1A7ADA9E341CACDF287347584] - [18/03/2017 22:57:39] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [515.6 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\services.exe [MD5.3120B24060924F9B94182A1432B2D7F9] - [18/03/2017 22:58:21] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [46.55 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\svchost.exe [MD5.9F67071B597A3CCC8C11CE761CE88B04] - [18/03/2017 22:57:35] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de l’API uilisateur de Windows multi-utilisateurs.) - [1313.56 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\user32.dll [MD5.46B72E05D0B9F489CA60DBD7361039B0] - [18/03/2017 22:58:21] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Userinit.) - [31.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\userinit.exe [MD5.B2DB5876B6F68D32E470F691C7088F3F] - [11/07/2017 23:02:57] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [310.77 Ko] - (10.0.15063.483) : C:\WINDOWS\System32\Wininit.exe [MD5.31E3287EF6D97C5864A301CEA75BBBA1] - [11/07/2017 23:03:22] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Windows.) - [690 Ko] - (10.0.15063.483) : C:\WINDOWS\System32\Winlogon.exe [MD5.AC1928C2F7505BD556C552F153B062AB] - [18/03/2017 22:57:36] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de fonction connexe pour WinSock.) - [596.4 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\afd.sys [MD5.01733BEEE02E51F712330D5909BD701C] - [18/03/2017 22:56:26] - (.© Microsoft Corporation. All rights reserved. - ATAPI IDE Miniport Driver.) - [28.41 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\atapi.sys [MD5.71CCAFFF7D5E64E3D07BD96F2B2898EF] - [18/03/2017 22:56:26] - (.© Microsoft Corporation. All rights reserved. - ATAPI Driver Extension.) - [189.91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\ataport.sys [MD5.B6E5AD7C83A5254DEE9D86023C0E5A81] - [18/03/2017 22:57:39] - (.© Microsoft Corporation. All rights reserved. - CD-ROM File System Driver.) - [91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\cdfs.sys [MD5.ABE77AD954BC3D72F559CF0C381E50BC] - [18/03/2017 22:56:25] - (.© Microsoft Corporation. All rights reserved. - SCSI CD-ROM Driver.) - [156.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\cdrom.sys [MD5.185A4519B7764F4DEF714D890A7A9FD2] - [18/03/2017 22:57:47] - (.© Microsoft Corporation. All rights reserved. - DFS Namespace Client Driver.) - [147 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\dfsc.sys [MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - [11/07/2017 23:05:18] - (.© Microsoft Corporation. All rights reserved. - High Definition Audio Bus Driver.) - [84.5 Ko] - (10.0.15063.447) : C:\WINDOWS\System32\Drivers\hdaudbus.sys [MD5.C6C8315E3262FAE460529C6DA2951682] - [18/03/2017 22:56:35] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [112.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\i8042prt.sys [MD5.DCC05E5EAA580C97F13B434FAFACED85] - [18/03/2017 22:58:21] - (.© Microsoft Corporation. All rights reserved. - IP Network Address Translator.) - [209.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\ipnat.sys [MD5.F2AD1B72C5A6475FB5FF332E1980DF88] - [18/03/2017 22:57:54] - (.© Microsoft Corporation. Tous droits réservés. - Minirdr SMB Windows NT.) - [456.4 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\mrxsmb.sys [MD5.59F3D5FEF4A24871C07C279762DA8624] - [11/07/2017 23:03:31] - (.© Microsoft Corporation. Tous droits réservés. - NDIS (Network Driver Interface Specification).) - [1213.41 Ko] - (10.0.15063.447) : C:\WINDOWS\System32\Drivers\ndis.sys [MD5.30C2F67EC84EB11B22011620107E0325] - [18/03/2017 22:57:35] - (.© Microsoft Corporation. All rights reserved. - MBT Transport driver.) - [298 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\netbt.sys [MD5.8D72D5038C5F91AFEF1B160FE524C2D9] - [11/07/2017 23:03:02] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [2272.91 Ko] - (10.0.15063.447) : C:\WINDOWS\System32\Drivers\ntfs.sys [MD5.2CC6C325B271C7CA60F374F8F868CB45] - [18/03/2017 22:56:26] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [95.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\parport.sys [MD5.5279EC98F6218D29EADDFECCC0D80E9A] - [18/03/2017 22:58:07] - (.© Microsoft Corporation. All rights reserved. - RAS L2TP mini-port/call-manager driver.) - [104.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\rasl2tp.sys [MD5.53A01D3FDB701AC5D9DDE4140227E3D9] - [18/03/2017 22:59:55] - (.© Microsoft Corporation. Tous droits réservés. - Redirecteur de périphérique de Microsoft RDP.) - [179 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\rdpdr.sys [MD5.DC0D1B5284152315F81894DAABBB2AF3] - [11/07/2017 23:04:46] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [2618.91 Ko] - (10.0.15063.447) : C:\WINDOWS\System32\Drivers\tcpip.sys [MD5.892AB2637603A5E9507C39E61101C3C3] - [06/07/2017 18:34:34] - (.© Microsoft Corporation. All rights reserved. - TDI Translation Driver.) - [116.91 Ko] - (10.0.15063.413) : C:\WINDOWS\System32\Drivers\tdx.sys [MD5.E3429DBBEA3965BB96E24B16EF4A2551] - [18/03/2017 22:57:39] - (.© Microsoft Corporation. All rights reserved. - Volume Shadow Copy driver.) - [387.91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\volsnap.sys ---------- | Locked Applications [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9e93b39-49d1-4179-9848-a5a2896955ea}] - () - (%systemroot%\system32\mrt.exe) ---------- | Explorer.exe component call (Microsoft Files Whitelisted) (.www.startisback.com.-.OldNewExplorer shell enhancements.) - (1.1.8.2) -- C:\skinpack\OldNewExplorer64.dll (.Rebit, Inc..-.Rebit Pro Namespace Extension.) - (5.1.3001.14505) -- C:\PROGRA~1\Rebit\REBITP~1\REBIT-~1.DLL (..-..) - (4.7.3.0) -- C:\PROGRA~1\Rebit\REBITP~1\QtCore4.dll (..-..) - (4.7.3.0) -- C:\PROGRA~1\Rebit\REBITP~1\QtNetwork4.dll (..-..) - (4.7.3.0) -- C:\PROGRA~1\Rebit\REBITP~1\QtSql4.dll (.Rebit, Inc..-.Rebit Pro Translations.) - (5.1.3001.14505) -- C:\PROGRA~1\Rebit\REBITP~1\cqt.dll (..-..) - (0.0.0.0) -- C:\PROGRA~1\Rebit\REBITP~1\LIBEAY32.dll (..-..) - (0.0.0.0) -- C:\PROGRA~1\Rebit\REBITP~1\SSLEAY32.dll (.TODO: .-.TODO: .) - (1.0.0.1) -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlayX64.dll (.Acronis.-.Acronis True Image Shell Extensions.) - (17.0.0.3100) -- C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (..-.Roxio Burn Plug in.) - (1.60.52.0) -- C:\Program Files\Roxio\Roxio Burn\RBVirtualFolder64.dll (..-..) - (0.0.0.0) -- C:\Program Files\DAEMON Tools Pro\DTShl64.dll differs from file image: (..-..) - (0.0.0.0) -- : Tue Oct 25 18:46:22 2016 (..-..) - (0.0.0.0) -- : Wed May 17 10:27:47 2017 (.Disc Soft Ltd.-.DAEMON Tools Pro.) - (8.0.0.634) -- C:\Program Files\DAEMON Tools Pro\DTShl64.dll (.Rebit, Inc..-.Rebit Pro Shell Extension.) - (5.1.3001.14505) -- C:\PROGRA~1\Rebit\REBITP~1\REBIT-~2.DLL (. .-.Copy Handler Shell Extension.) - (1.44.917.0) -- C:\Program Files\Copy Handler\chext64.dll (. .-.Async Logger Library.) - (1.44.917.0) -- C:\Program Files\Copy Handler\liblogger64u.dll (. .-.Copy Handler Core.) - (1.44.917.0) -- C:\Program Files\Copy Handler\libchcore64u.dll (.SQLite.-.SQLite.) - (3.15.1.0) -- C:\Program Files\Copy Handler\sqlite3_64.dll (.WinZip Computing, S.L..-.WinZip Shell Extension DLL.) - (4.1.0.0) -- C:\Program Files\WinZip\wzshls64.dll (.www.startisback.com.-.StartIsBack++ brains and soul.) - (5.0.0.2201) -- C:\Program Files (x86)\StartIsBack\StartIsBack64.dll (.Remo Software.-.Remo File Eraser.) - (2.0.0.49) -- C:\Program Files (x86)\Remo File Eraser 2.0\64\rsh64.dll (.Perigee Software.-.PerigeeCopy shell extension DLL.) - (1.6.0.0) -- C:\Program Files\PerigeeCopy\PerigeeCopy.dll (..-.DLLReg Module.) - (1.0.0.1) -- C:\Program Files (x86)\Batch Picture Resizer\DLLReg-x64.dll (..-..) - (12.0.649.11190) -- C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareShellExtension.dll (.Alexander Roshal.-.WinRAR shell extension.) - (5.40.0.0) -- C:\Program Files\WinRAR\rarext.dll (..-..) - (0.0.0.0) -- C:\Program Files\Unlocker\UnlockerCOM.dll (.IObit.-.IObit Smart Defrag Extension.) - (1.0.0.25) -- C:\WINDOWS\System32\IObitSmartDefragExtension.dll (.Rovi Corporation.-.Roxio Disc Copier Shell Extension (AMD64).) - (13.3.5.81) -- C:\Program Files\Roxio 2012\Virtual Drive 10\DC_ShellExt64.dll (.Malwarebytes.-.Malwarebytes Anti-Malware.) - (3.1.1.0) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll (.Killer{R}.-.KillCopy Shell Extension DLL.) - (1.0.0.1) -- C:\Program Files (x86)\KillSoft\KillCopy\killcopy_amd64.dll (.Glarysoft Ltd.-.MHContextHandler.dll.) - (1.0.0.5) -- C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\MHContextHandlerx64.dll (.Glarysoft Ltd.-.Context Menu Handler.) - (5.0.0.15) -- C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll (.Foxit Software Inc..-.ConvertToPDFShellExtension.) - (8.3.1.522) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll (.Foxit Software Inc..-.ConvertToPDFShellExtension.) - (8.3.0.331) -- C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll (.TeoreX.-..) - (4.0.0.1) -- C:\Program Files\FolderIco\FolderIco.dll (.Piriform Ltd.-.DefragglerShell.) - (2.21.0.993) -- C:\Program Files\Defraggler\DefragglerShell64.dll (.COMODO.-.COMODO Internet Security.) - (10.0.1.6258) -- C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll (.COMODO.-.COMODO Internet Security.) - (10.0.1.6258) -- C:\Program Files\COMODO\COMODO Internet Security\cmdres.DLL (..-..) - (1.0.0.0) -- C:\Program Files (x86)\Zemana AntiLogger\ZAMShellExt64.dll (.Nero AG.-.Nero Burning ROM Shell Extension.) - (17.0.8.0) -- C:\Program Files (x86)\Common Files\Nero\NeroShellExt\x64\NeroShellExt.dll (.Nero AG.-.Nero Solution Explorer Dynamic Link Library.) - (17.0.0.3) -- C:\Program Files (x86)\Common Files\Nero\NeroShellExt\x64\SolutionExplorer.dll (.IObit.-.IObitUnlockerExtension.) - (1.2.0.2) -- C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll (..-..) - (0.0.0.0) -- C:\PROGRA~1\TeraCopy\TERACO~2.DLL (.CHENGDU YIWO Tech Development Co.,Ltd.-.EaseUS Todo Backup Application.) - (3.0.0.1) -- C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll (..-.360 Total Security.) - (9.2.0.1000) -- C:\Program Files (x86)\360\Total Security\MenuEx64.dll (.SafeIT Security Sweden AB.-.SafeIT Shell Extension library.) - (7.6.2.0) -- C:\Program Files\Common Files\Lavasoft\Dlls\SITShellExLibrary.dll (.SafeIT Security Sweden AB.-.SafeIT Language Support.) - (7.7.2.0) -- C:\Program Files\Common Files\Lavasoft\Dlls\SITLanguageShellExt.dll (.Piriform Ltd.-.Recuva shell extensions.) - (1.53.0.1087) -- C:\Program Files\Recuva\RecuvaShell64.dll (.IObit.-.Protected Folder Shell Extension.) - (4.2.0.0) -- C:\Program Files (x86)\IObit\Protected Folder\PfShellExtension.dll (.IObit.-.IObitUnlockerExtension.) - (1.2.0.2) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll (.IObit.-.IMFShellExt Module.) - (5.0.0.2166) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll (.IObit.-.IObitUnlockerExtension.) - (1.2.0.2) -- C:\Program Files (x86)\IObit\Classic Start\IObitStartMenuExtension.dll (.LopeSoft.-.FileMenu Tools DLL.) - (7.3.3.0) -- C:\Program Files\LopeSoft\FileMenu Tools\FileMenuTools64.dll (.CHENGDU Yiwo Tech Development Co., Ltd..-.EverySync.) - (1.0.0.1) -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EUSyncExtMenux64.dll (..-..) - (0.0.0.0) -- C:\Program Files\TeraCopy\TeraCopy64.dll (.IObit.-.StartMenu8 StartMenuDll.) - (2.0.0.34) -- C:\Program Files (x86)\IObit\Classic Start\StartMenuDll.dll (..-..) - (0.0.0.0) -- : 15712 (.IObit.-.StartMenu8 StartMenuDll.) - (2.0.0.34) -- C:\Program Files (x86)\IObit\Classic Start\StartMenuDll.dll (.www.startisback.com.-.OldNewExplorer shell enhancements.) - (1.1.8.2) -- C:\skinpack\OldNewExplorer64.dll (.www.startisback.com.-.StartIsBack++ brains and soul.) - (5.0.0.2201) -- C:\Program Files (x86)\StartIsBack\StartIsBack64.dll (.TODO: .-.TODO: .) - (1.0.0.1) -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlayX64.dll (.Acronis.-.Acronis True Image Shell Extensions.) - (17.0.0.3100) -- C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (.Rebit, Inc..-.Rebit Pro Namespace Extension.) - (5.1.3001.14505) -- C:\PROGRA~1\Rebit\REBITP~1\REBIT-~1.DLL (..-..) - (4.7.3.0) -- C:\PROGRA~1\Rebit\REBITP~1\QtCore4.dll (..-..) - (4.7.3.0) -- C:\PROGRA~1\Rebit\REBITP~1\QtNetwork4.dll (..-..) - (4.7.3.0) -- C:\PROGRA~1\Rebit\REBITP~1\QtSql4.dll (.Rebit, Inc..-.Rebit Pro Translations.) - (5.1.3001.14505) -- C:\PROGRA~1\Rebit\REBITP~1\cqt.dll (..-..) - (0.0.0.0) -- C:\PROGRA~1\Rebit\REBITP~1\LIBEAY32.dll (..-..) - (0.0.0.0) -- C:\PROGRA~1\Rebit\REBITP~1\SSLEAY32.dll (.Rebit, Inc..-.Rebit Pro Shell Extension.) - (5.1.3001.14505) -- C:\PROGRA~1\Rebit\REBITP~1\REBIT-~2.DLL (. .-.Copy Handler Shell Extension.) - (1.44.917.0) -- C:\Program Files\Copy Handler\chext64.dll (. .-.Copy Handler Core.) - (1.44.917.0) -- C:\Program Files\Copy Handler\libchcore64u.dll (. .-.Async Logger Library.) - (1.44.917.0) -- C:\Program Files\Copy Handler\liblogger64u.dll (.SQLite.-.SQLite.) - (3.15.1.0) -- C:\Program Files\Copy Handler\sqlite3_64.dll (.Alexander Roshal.-.WinRAR shell extension.) - (5.40.0.0) -- C:\Program Files\WinRAR\rarext.dll (.Killer{R}.-.KillCopy Shell Extension DLL.) - (1.0.0.1) -- C:\Program Files (x86)\KillSoft\KillCopy\killcopy_amd64.dll (.WinZip Computing, S.L..-.WinZip Shell Extension DLL.) - (4.1.0.0) -- C:\Program Files\WinZip\wzshls64.dll (..-..) - (0.0.0.0) -- C:\Program Files\TeraCopy\TeraCopy64.dll (.Perigee Software.-.PerigeeCopy shell extension DLL.) - (1.6.0.0) -- C:\Program Files\PerigeeCopy\PerigeeCopy.dll ---------- | Svchost.exe component call (Microsoft Files Whitelisted) ---------- | ZeroAccess Check [HKLM64\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM64\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM64\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM64\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM64\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up EPLTarget\P0000000000000000 - (C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILPE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-710 Series" [HKU\S-1-5-18\SOFTWARE\...\Run]) - User: AUTORITE NT\Système EPLTarget\P0000000000000001 - (C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILPE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-710 Series" [HKU\S-1-5-18\SOFTWARE\...\Run]) - User: AUTORITE NT\Système OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE LOCAL OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE RÉSEAU DriverMax_RESTART - ( [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\...\Run]) - User: LFSULTRA-WIDEN\Jean-Marie Dashlane - ("C:\Users\Jean-Marie\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\...\Run]) - User: LFSULTRA-WIDEN\Jean-Marie DashlanePlugin - ("C:\Users\Jean-Marie\AppData\Roaming\Dashlane\DashlanePlugin.exe" ws [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\...\Run]) - User: LFSULTRA-WIDEN\Jean-Marie Advanced SystemCare Ultimate - ("C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /Auto [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\...\Run]) - User: LFSULTRA-WIDEN\Jean-Marie DAEMON Tools Pro Agent - ("C:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\...\Run]) - User: LFSULTRA-WIDEN\Jean-Marie EPLTarget\P0000000000000000 - (C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILPE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-710 Series" [HKU\.DEFAULT\SOFTWARE\...\Run]) - User: .DEFAULT EPLTarget\P0000000000000001 - (C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILPE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-710 Series" [HKU\.DEFAULT\SOFTWARE\...\Run]) - User: .DEFAULT errorlog - ( [Common Startup]) - User: Public RocketDock - (C:\SkinPack\ROCKET~1\ROCKET~1.EXE [Common Startup]) - User: Public SecurityHealth - (%ProgramFiles%\Windows Defender\MSASCuiL.exe [HKLM\SOFTWARE\...\Run]) - User: Public COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} - (C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [HKLM\SOFTWARE\...\Run]) - User: Public rfagent - ("C:\Program Files\RFA 11\rfagent64.exe" [HKLM\SOFTWARE\...\Run]) - User: Public Zoolz Tray - ("C:\Program Files\Genie9\Zoolz2\ZoolzLauncher.exe" "C:\Program Files\Genie9\Zoolz2\Zoolz.exe" "-Delay" [HKLM\SOFTWARE\...\Run]) - User: Public RTHDVCPL - ("C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [HKLM\SOFTWARE\...\Run]) - User: Public UMonit - (C:\WINDOWS\SysWOW64\UMonit64.exe [HKLM\SOFTWARE\...\Run]) - User: Public [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Run] "DriverMax_RESTART"= "Dashlane"="C:\Users\Jean-Marie\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup "DashlanePlugin"="C:\Users\Jean-Marie\AppData\Roaming\Dashlane\DashlanePlugin.exe" ws "Advanced SystemCare Ultimate"="C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /Auto "DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "CCleaner Monitoring"=0x03000000C0FC5C7C04C3D201 "CyberGhost"=0x03000000F0715D7C04C3D201 "DAEMON Tools Lite Automount"=0x0300000000995D7C04C3D201 "DriverMax_RESTART"=0x0300000010C05D7C04C3D201 "FileHippo.com"=0x03000000300E5E7C04C3D201 "GUDelayStartup"=0x03000000300E5E7C04C3D201 "ultracopier"=0x03000000505C5E7C04C3D201 "GoogleChromeAutoLaunch_E9AFBAF478AF4722057287C56E730AF4"=0x03000000FDDCFD9160F9D201 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU] "a"=C:\Users\Public\Desktop\RogueKiller.lnk\1 "MRUList"=ihegfdcba "b"=C:\Users\Jean-Marie\Desktop\quickdiag_3_01.07.17.1.exe\1 "c"=C:\Users\Jean-Marie\Desktop\Rem-VBSworm.exe\1 "d"=C:\Users\Jean-Marie\Desktop\OTL.exe\1 "e"=wordpad\1 "f"=C:\Users\Jean-Marie\Desktop\adsfix_4_21.07.17.1.exe\1 "g"=C:\Users\Jean-Marie\Desktop\pre-scan_7_13.07.17.1.exe\1 "h"="M:\lfs hyper-jobs janv2016-dtpro-rebit-p2go11\ajustages lfsu100%sf-juin2017-anniv barrow 2-vexe-widen-amine\lfsu100%sf pz z sigma++ (sfce)\silent installer 4 lfsu100%sf ptzs++sfce apps\sih.3.1.0.0.exe"\1 "i"=explorer.exe\1 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "Device"=VivPDF Printer,winspool,Ne00: "IsMRUEstablished"=1 "LegacyDefaultPrinterMode"=0 [HKLM64\Software\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Run] "SecurityHealth"=%ProgramFiles%\Windows Defender\MSASCuiL.exe "COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [08/06/2017 04:38:18] "rfagent"="C:\Program Files\RFA 11\rfagent64.exe" "Zoolz Tray"="C:\Program Files\Genie9\Zoolz2\ZoolzLauncher.exe" "C:\Program Files\Genie9\Zoolz2\Zoolz.exe" "-Delay" "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "UMonit"=C:\WINDOWS\SysWOW64\UMonit64.exe [HKLM64\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Wrapper"=runonce "GrpConv"=grpconv -o [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "SecurityHealth"=0x060000000000000000000000 "WindowsDefender"=0x040000000000000000000000 "AvastUI.exe"=0x03000000B8E5D88D60F9D201 "Malwarebytes TrayApp"=0x030000006A9F6EAD60F9D201 [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32] "StartCCC"=0x060000000000000000000000 "BingDesktop"=0x03000000A0D91C8204C3D201 "InstantBurn"=0x0300000010EB1D8204C3D201 "LWS"=0x0300000060AE1E8204C3D201 "MalTray"=0x03000000A04A1F8204C3D201 "Malwarebytes TrayApp"=0x03000000D0BF1F8204C3D201 "SecurityHealth"=0x030000000035208204C3D201 "Advanced System Optimizer"=0x030000000777828B60F9D201 "ClamWin"=0x030000008858999760F9D201 "CPMonitor"=0x020000000000000000000000 "DivXMediaServer"=0x030000000A9047A660F9D201 "ISUSPM"=0x03000000994F6EA860F9D201 "IObit Malware Fighter"=0x030000001D21E09E60F9D201 "Desktop Disc Tool"=0x03000000ADFC92AF60F9D201 "RoxWatchTray"=0x03000000009B36B160F9D201 "Syncios device service"=0x03000000DBDEA9F861F9D201 [HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"=C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL [22/04/2017 17:57:34] "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "EnableMitInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=1 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D2A02A4539A47C [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "BingDesktop"=C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey "LWS"=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide "Syncios device service"=C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [21/03/2017 08:19:20] ""= "ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe -scheduler "CPMonitor"="C:\Program Files (x86)\Roxio 2012\5.0\CPMonitor.exe" "Desktop Disc Tool"="C:\Program Files (x86)\Roxio 2012\Roxio Burn\RoxioBurnLauncher.exe" "IseUI"=C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe [11/07/2017 11:02:04] "IObit Malware Fighter"="C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart "Simple Malware Protector_startup"="C:\Program Files (x86)\Simple Malware Protector\SimpleMalwareProtector.exe" autolaunch "VMXPLXService"="C:\Program Files (x86)\CyberLink\Shared files\VMXPLXShare\Service\VMXPLXService.exe" /s "Contrôle Parental Orange"="C:\Program Files (x86)\Contrôle Parental Orange\ControleParental.exe" [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "cpinstall.exe"=C:\Program Files (x86)\Contrôle Parental Orange\cpinstall.exe -s -data gAAAAACAAAAAAAAAYwBlAHcAYgBlADEAMwB1AHMAaAB1AGEAaQBhAAAAUQB1AGUA bAAgAGUAcwB0ACAAbABlACAAcAByAOkAbgBvAG0AIABkAGUAIAB2AG8AdAByAGUA IABmAGkAbABzACAAPwAAAEoAbwBuAGEAdABoAGEAbgAAAA== [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "EnableMitInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=1 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Wininit.ini : ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List AdapterUpdaterAdvanced-PC-Care_LogonApplication Starter - f1375f225883e83d52e8db9690775c3cB3A986DC-C2DD-40A0-8C0C-FEF66B783511ByteFence ScanCreateExplorerShellUnelevatedTaskDriver Booster Beta SchedulerDriver Booster Beta SkipUAC (Jean-Marie)Driver Easy Scheduled ScanDriverMaxWelcomeEPSON XP-710 Series Invitation {68953606-62A7-4B6A-87A7-1CF73FEC7E9A}EPSON XP-710 Series Invitation {69791235-D3B3-45B7-A134-218554EE5C76}EPSON XP-710 Series Invitation {AE5780A0-0AF2-4E57-8021-42C010C39E40}EPSON XP-710 Series Invitation {FC6094E7-B8B4-44EE-9D76-76624B51979F}EPSON XP-710 Series Update {68953606-62A7-4B6A-87A7-1CF73FEC7E9A}EPSON XP-710 Series Update {69791235-D3B3-45B7-A134-218554EE5C76}EPSON XP-710 Series Update {AE5780A0-0AF2-4E57-8021-42C010C39E40}EPSON XP-710 Series Update {FC6094E7-B8B4-44EE-9D76-76624B51979F}GlaryInitialize 5GU5SkipUACMakeupDirector2.exe_20170711_085147_0871Opera scheduled Autoupdate 1499584801PC TuneUp Maestro Disk Defrag AnalysisPC TuneUp Maestro Scan FirstTimePC TuneUp Maestro Scan SecondTimePC TuneUp Maestro ScanPresenterLinkPlus.exe_20170711_101040_0036PresenterLinkPlus.exe_20170722_123500_0103Simple Disk OptimizerStart Simple Driver Updater for LFSULTRA-WIDEN@Jean-Marie(logon)Start Simple Driver Updater ScheduleStart Simple Driver Updater UpdateStart Simple PC Optimizer for LFSULTRA-WIDEN@Jean-Marie(logon)Start Simple PC Optimizer ScheduleStart Simple PC Optimizer UpdateStart Simple Registry Cleaner for LFSULTRA-WIDEN@Jean-Marie(logon)Start Simple Registry Cleaner ScheduleStart Simple Registry Cleaner UpdateStartMenu8_StartSupersonicPCTaskLogic ZN-165CUninstaller_SkipUac_Jean-MarieUSO-USOAutoCheckUpdate7DaysUSO-USOOneClickCareUTILILAB SystemOPTIMIZERWarThunder0WarThunder1WarThunder2WarThunder3Wise Hotkey ---------- | Startings up registry ¦ Folder ---------- | Other keys [HKLM\System\CurrentControlSet\Control\SecurityProviders]"SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Terminal Server]"AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "InstanceID"=2c9ea470-e5b6-4136-a354-1525320 "GlassSessionId"=1 "fDenyChildConnections"=0 [HKLM\System\CurrentControlSet\Control\Session Manager]"BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "ResourceTimeoutCount"=648000 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "AutoChkSkipSystemPartition"=0 "AutoChkTimeout"=5 "PendingFileRenameOperations"=\??\C:\Users\JEAN-M~1\AppData\Local\Temp\~nsu.tmp\Au_.exe \??\C:\Users\JEAN-M~1\AppData\Local\Temp\~nsu.tmp \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nsoC80F.tmp\DTShl64.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nsoC80F.tmp\ \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nsoC80F.tmp\Lang\ENU.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nsoC80F.tmp\Lang\FRA.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nsoC80F.tmp\DTShl64.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nsoC80F.tmp\ \??\C:\Users\Jean-Marie\AppData\Roaming\Orange\OrangeInside\ \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Contrôle Parental Orange\Désinstallation du Contrôle Parental.lnk \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Contrôle Parental Orange\Désinstallation du Contrôle Parental.lnk \??\C:\Program Files (x86)\Contrôle Parental Orange\~freebl328ffffd7.dll !\??\C:\Program Files (x86)\Contrôle Parental Orange\freebl3.dll \??\C:\Program Files (x86)\Contrôle Parental Orange\~libnspr422ffb7dd.dll !\??\C:\Program Files (x86)\Contrôle Parental Orange\libnspr4.dll \??\C:\Program Files (x86)\Contrôle Parental Orange\~libplc4bdffe742.dll !\??\C:\Program Files (x86)\Contrôle Parental Orange\libplc4.dll \??\C:\Program Files (x86)\Contrôle Parental Orange\~libplds483ff987c.dll !\??\C:\Program Files (x86)\Contrôle Parental Orange\libplds4.dll \??\C:\Program Files (x86)\Contrôle Parental Orange\~nss3e0ffb51f.dll !\??\C:\Program Files (x86)\Contrôle Parental Orange\nss3.dll \??\C:\Program Files (x86)\Contrôle Parental Orange\~ocpinet646bffc294.dll !\??\C:\Program Files (x86)\Contrôle Parental Orange\ocpinet64.dll \??\C:\Program Files (x86)\Contrôle Parental Orange\~ocsvcd5ffd32a.exe !\??\C:\Program Files (x86)\Contrôle Parental Orange\ocsvc.exe \??\C:\Users\JEAN-M~1\AppData\Local\Temp\~nsu.tmp\Au_.exe \??\C:\Users\JEAN-M~1\AppData\Local\Temp\~nsu.tmp \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nseF3CD.tmp\ \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nseF3CD.tmp\Lang\ENU.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nseF3CD.tmp\Lang\FRA.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\~nsu.tmp\Au_.exe \??\C:\Users\JEAN-M~1\AppData\Local\Temp\~nsu.tmp \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nse2C8F.tmp\ \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nse2C8F.tmp\Lang\ENU.dll \??\C:\Users\JEAN-M~1\AppData\Local\Temp\nse2C8F.tmp\Lang\FRA.dll \??\C:\Users\Jean-Marie\AppData\Roaming\Orange\OrangeInside\ \??\C:\Users\Jean-Marie\AppData\Roaming\Orange\OrangeInside\ \??\C:\Users\Jean-Marie\AppData\Roaming\Orange\OrangeInside\ \??\C:\WINDOWS\system32\SET8413.tmp \??\C:\WINDOWS\system32\DRIVERS\SET7E5A.tmp \??\C:\WINDOWS\system32\SET8311.tmp "AllowProtectedRenames"=1 [HKLM\System\CurrentControlSet\Control]"BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=AcrSch2Svc UsoSvc DeviceInstall gpsvc trustedinstaller "SvcHostSplitThresholdInKB"=3670016 "SystemStartOptions"= NOEXECUTE=OPTIN SAFEBOOT:NETWORK NOGUIBOOT BOOTLOGO "SystemBootDevice"=multi(0)disk(0)rdisk(4)partition(3) "FirmwareBootDevice"=multi(0)disk(0)rdisk(4)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=21 "WaitToKillServiceTimeout"=200 [HKLM\System\CurrentControlSet\Control\lsa]"auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Security Packages"="" [10/11/2016 15:52:04]"Notification Packages"=scecli "Authentication Packages"=msv1_0 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "LsaPid"=904 "ProductType"=3 "restrictanonymous"=0 "restrictanonymoussam"=1 "SamConnectedAccountsExist"=1 "SecureBoot"=1 ---------- | .LNK with Arguments c:\programdata\microsoft\windows\start menu\programs\google chrome.lnk - Encrypted: False - Target: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - Args: (hxxp://r.orange.fr/r/Oodc_CHshortcut_oi_v2?ref=O_OI_defaultPage_CH_odc_shortcut) - Hidden: False - Status: OKc:\programdata\microsoft\windows\start menu\programs\mozilla firefox.lnk - Encrypted: False - Target: C:\Program Files (x86)\Mozilla Firefox\firefox.exe - Args: (hxxp://r.orange.fr/r/Oodc_FFshortcut_oi_v2?ref=O_OI_defaultPage_FF_odc_shortcut) - Hidden: False - Status: OKc:\programdata\microsoft\windows\start menu\programs\navigateur opera.lnk - Encrypted: False - Target: C:\Program Files (x86)\Opera\launcher.exe - Args: (hxxp://r.orange.fr/r/Oodc_OPshortcut_oi_v2?ref=O_OI_defaultPage_OP_odc_shortcut) - Hidden: False - Status: OKc:\programdata\microsoft\windows\start menu\programs\srware iron\srware iron.lnk - Encrypted: False - Target: C:\Program Files (x86)\SRWare Iron\chrome.exe - Args: (hxxp://r.orange.fr/r/Oodc_SRshortcut_oi_v2?ref=O_OI_defaultPage_SR_odc_shortcut) - Hidden: False - Status: OKc:\users\jean-marie\appdata\roaming\microsoft\internet explorer\quick launch\navigateur opera.lnk - Encrypted: False - Target: C:\Program Files (x86)\Opera\launcher.exe - Args: (hxxp://r.orange.fr/r/Oodc_OPshortcut_oi_v2?ref=O_OI_defaultPage_OP_odc_shortcut) - Hidden: False - Status: OKc:\users\jean-marie\appdata\roaming\microsoft\internet explorer\quick launch\srware iron.lnk - Encrypted: False - Target: C:\Program Files (x86)\SRWare Iron\chrome.exe - Args: (hxxp://r.orange.fr/r/Oodc_SRshortcut_oi_v2?ref=O_OI_defaultPage_SR_odc_shortcut) - Hidden: False - Status: OKc:\users\jean-marie\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\navigateur opera.lnk - Encrypted: False - Target: C:\Program Files (x86)\Opera\launcher.exe - Args: (hxxp://r.orange.fr/r/Oodc_OPshortcut_oi_v2?ref=O_OI_defaultPage_OP_odc_shortcut) - Hidden: False - Status: OKc:\users\jean-marie\appdata\roaming\microsoft\windows\start menu\programs\warthunder\warthunder.lnk - Encrypted: False - Target: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - Args: ( --app=hxxp://go.playmmogames.com/aff_c?offer_id=698&aff_id=1034&source=1&click_id=4a9dc59841fef8c0ab9d0b7d013c8a8d9e3d51ca --start-fullscreen) - Hidden: False - Status: OKc:\users\jean-marie\desktop\barrow 2 à 4-widen-lfsu100%sf part 1 to z sigma apps\adsfix_donate.lnk - Encrypted: False - Target: C:\Program Files (x86)\Internet Explorer\iexplore.exe - Args: (hxxps://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=S3AQ8V3XRWWYN) - Hidden: False - Status: OKc:\users\jean-marie\desktop\barrow 2 à 4-widen-lfsu100%sf part 1 to z sigma apps\pre_scan_donate.lnk - Encrypted: False - Target: C:\Program Files (x86)\Internet Explorer\iexplore.exe - Args: (hxxps://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=S3AQ8V3XRWWYN) - Hidden: False - Status: OKc:\users\jean-marie\desktop\pre_scan_donate.lnk - Encrypted: False - Target: C:\Program Files (x86)\Internet Explorer\iexplore.exe - Args: (hxxp://r.orange.fr/r/Oodc_IEshortcut_oi_v2?ref=O_OI_defaultPage_IE_odc_shortcut) - Hidden: False - Status: OKc:\users\jean-marie\desktop\souvenir seule dernier version findykill et backup dextop 1er septem 2016\adsfix_donate.lnk - Encrypted: False - Target: C:\Program Files (x86)\Internet Explorer\iexplore.exe - Args: (hxxps://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=S3AQ8V3XRWWYN) - Hidden: False - Status: OK ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hostsC:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Control Panel\Desktop]"ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "LeftOverlapChars"=3 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "RightOverlapChars"=3 "ScreenSaveActive"=1 "SnapSizing"=1 "TileWallpaper"=0 "WallPaper"=C:\Users\Jean-Marie\AppData\Local\Microsoft\BingDesktop\themes\2017-07-21.jpg [21/07/2017 09:20:31]"WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "UserPreferencesMask"=0x9E1E078012000000 "AutoColorization"=0 "MaxVirtualDesktopDimension"=1280 "MaxMonitorDimension"=1280 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC3010098BE0F0080070000B004000004BBF9DAF101D30143003A005C00550073006500720073005C004A00650061006E002D004D0061007200690065005C0041007000700044006100740061005C004C006F00630061006C005C004D006900630072006F0073006F00660074005C00420069006E0067004400650073006B0074006F0070005C007400680065006D00650073005C0032003000310037002D00300037002D00320031002E006A007000670000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ImageColor"=2952058953 "Win8DpiScaling"=0 "DpiScalingVer"=4096 "ScreenSaverIsSecure"=1 "ForegroundLockTimeout"=0 "MenuShowDelay"=0 "AutoEndTasks"=1 "HungAppTimeout"=4000 "WaitToKillAppTimeout"=200 "Pattern Upgrade"=TRUE [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]"NoSimpleNetIDList"=1 "NolowDiskSpaceChecks"=1 "NoDriveTypeAutoRun"=255 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]"{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=0 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 "{871C5380-42A0-1069-A2EA-08002B30301D}"=0 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]"{871C5380-42A0-1069-A2EA-08002B30301D}"=0 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer]"ShellState"=0x240000003328000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SlowContextMenuEntries"=0x6024B221EA3A6910A2DC08002B30309DD4240200274A7A16EA2861488173963F9900D44C8CD50E005AA139C5F93A924CB77150CB78F5C751F00203000114020000000000C000000000000046E148030097679640FE8FC8469EF87003F33CCF0F4B891900 "GlobalAssocChangedCounter"=944 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "TelemetrySalt"=4 "FirstRunTelemetryComplete"=1 "AppReadinessLogonComplete"=1 "Browse For Folder Width"=347 "Browse For Folder Height"=328 "link"=0x00000000 "DesktopProcess"=1 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]"Start_SearchFiles"=2 "StoreAppsOnTaskbar"=1 "ServerAdminUI"=0 "Hidden"=2 "ShowCompColor"=0 "HideFileExt"=1 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=0 "SeparateProcess"=1 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "ListviewShadow"=1 "StartMenuInit"=13 "TaskbarStateLastRun"=0x897F705900000000 "ReindexedProfile"=1 "DisablePreviewDesktop"=0 "TaskbarSmallIcons"=0 "VirtualDesktopTaskbarFilter"=0 "VirtualDesktopAltTabFilter"=0 "Start_SearchPrograms"=1 "Start_PowerButtonAction"=2 "Start_ShowRecentDocs"=1 "Start_ShowMyDocs"=1 "ShellViewReentered"=1 "nonetcrawling"=1 "ListviewAlphaSelect"=0 "TaskbarAnimations"=0 "ShowTaskViewButton"=1 "TaskbarGlomLevel"=0 "TypeAhead"=1 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery]"MRUListEx"=0x0100000000000000FFFFFFFF "0"=0x42000000 "1"=0x44000000 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Policies\System]"ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "EnableLinkedConnections"=1 "UacDisableNotify"=0 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]"ForceActiveDesktopOn"=0 "NoActiveDesktop"=0 "NoActiveDesktopChanges"=0 "NoRecentDocsHistory"=0 "NoDriveTypeAutoRun"=255 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]"NoAddingComponents"=1 "NoComponents"=1 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]"{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=0 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=0 "{871C5380-42A0-1069-A2EA-08002B30309D}"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=0 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=0 "{2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9}"=1 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]"{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9}"=1 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]"CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM64\Software\Microsoft\Windows\CurrentVersion\Explorer]"ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "SmartScreenEnabled"=Off "GlobalAssocChangedCounter"=431 "Max Cached Icons"=2000 [HKLM64\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]"Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]"Application"=http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System]"ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "EnableLinkedConnections"=1 "UacDisableNotify"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer]"ForceActiveDesktopOn"=0 "NoActiveDesktop"=0 "NoActiveDesktopChanges"=0 "NoRecentDocsHistory"=0 "NoDriveTypeAutoRun"=255 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]"NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]"{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=0 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=0 "{871C5380-42A0-1069-A2EA-08002B30309D}"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=0 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=0 "{2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]"{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]"CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer]"ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=710 "Max Cached Icons"=2000 "SmartScreenEnabled"=Off [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced]"Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations]"Application"=http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s ---------- | Winlogon [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]"ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=15063 "FirstLogon"=0 "PUUActive"=0x3A3934BC010015003400C600BAF10400E0D305006CF80A00D100000002004600CCE714452D091D002D091D0016A00100276B0100393E000000000000A5670B00AE9000008C030000DC3D4C79F102D301BAF10400000000000100000000000000 "DP"=0xCE00580047001500330000003A3934BC000000000000000093A38D08F602D30193A38D08F602D301000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ParseAutoexec"=1 "AutoRestartShell"=0 [HKLM64\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]"Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DefaultDomainName"= "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=Explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "Userinit"=C:\WINDOWS\system32\userinit.exe, "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "LastLogOffEndTimePerfCounter"=18290953598 "ShutdownFlags"=2147484711 "AutoAdminLogon"=0 "DefaultUserName"=MicrosoftAccount\jean-marie.carribon@wanadoo.fr "ShutdownWithoutLogon"=0 "AutoRestartShell"=0 "DisableCad"=1 "EnableFirstLogonAnimation"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon]"DefaultDomainName"= "DefaultUserName"= "EnableSIHostIntegration"=1 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "userinit"=userinit.exe, "AutoRestartShell"=0 ---------- | Associations [HKLM64\Software\Classes\.exe]""=exefile "Content Type"=application/x-msdownload [HKLM64\Software\Classes\exefile\Shell\Open\Command]""="%1" %* "IsolatedCommand"="%1" %* [HKLM64\Software\Classes\.com]""=comfile [HKLM64\Software\Classes\comfile\Shell\Open\Command]""="%1" %* [HKLM64\Software\Classes\.reg]""=regfile [HKLM64\Software\Classes\regfile\Shell\Open\Command]""=regedit.exe "%1" [HKLM64\Software\Classes\.scr]""=scrfile [HKLM64\Software\Classes\scrfile\Shell\Open\Command]""="%1" /S [HKLM64\Software\Classes\.bat]""=batfile [HKLM64\Software\Classes\batfile\Shell\Open\Command]""="%1" %* [HKLM64\Software\Classes\.cmd]""=cmdfile [HKLM64\Software\Classes\cmdfile\Shell\Open\Command]""="%1" %* [HKLM64\Software\Classes\.pif]""=piffile [HKLM64\Software\Classes\piffile\Shell\Open\Command]""="%1" %* [HKLM64\Software\Classes\.inf]""=inffile [HKLM64\Software\Classes\inffile\Shell\Open\Command]""="%SystemRoot%\system32\NOTEPAD.EXE" %1 [HKLM64\Software\Classes\.url]""=InternetShortcut [HKLM64\Software\Classes\.lnk]""=lnkfile [HKLM64\Software\Classes\.hta]""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM64\Software\Classes\htafile\Shell\Open\Command]""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM64\Software\Classes\InternetShortcut]"EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM64\Software\Classes\Application.Manifest]""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM64\Software\Classes\Application.Reference]""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM64\Software\Classes\Folder]""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe]""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command]""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com]""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command]""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg]""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command]""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr]""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command]""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat]""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command]""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd]""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command]""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif]""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command]""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf]""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command]""="%SystemRoot%\system32\NOTEPAD.EXE" %1 [HKLM\Software\WOW6432Node\Classes\.url]""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk]""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta]""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command]""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut]"EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest]""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference]""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder]""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command]""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients\StartMenuInternet\PALEMOON.EXE\Shell\open\Command]""="C:\Program Files\Pale Moon\palemoon.exe" [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo]"ReinstallCommand"="C:\Program Files\Pale Moon\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients\StartMenuInternet\Torch.GDN6ZTIOQTOJMYEEE4OGX2YXRU\Shell\open\Command]""="C:\Users\Jean-Marie\AppData\Local\Torch\Application\torch.exe" [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients\StartMenuInternet\Torch.GDN6ZTIOQTOJMYEEE4OGX2YXRU\InstallInfo]"ReinstallCommand"="C:\Users\Jean-Marie\AppData\Local\Torch\Application\torch.exe" --make-default-browser [HKLM64\Software\Clients\StartMenuInternet\Avant.Browser\Shell\open\Command]""=C:\Program Files (x86)\Avant Browser\avant.exe [29/06/2017 04:35:00][HKLM64\Software\Clients\StartMenuInternet\Avant.Browser\InstallInfo]"ReinstallCommand"= [HKLM64\Software\Clients\StartMenuInternet\Dragon\Shell\open\Command]""="C:\Program Files (x86)\Comodo\Dragon\dragon.exe" [HKLM64\Software\Clients\StartMenuInternet\Dragon\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --make-default-browser [HKLM64\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command]""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM64\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM64\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command]""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM64\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM64\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command]""="C:\Program Files (x86)\Internet Explorer\iexplore.exe" [HKLM64\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo]"ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM64\Software\Clients\StartMenuInternet\Iron\Shell\open\Command]""="C:\Program Files (x86)\SRWare Iron\chrome.exe" [HKLM64\Software\Clients\StartMenuInternet\Iron\InstallInfo]"ReinstallCommand"= [HKLM64\Software\Clients\StartMenuInternet\OperaStable\Shell\open\Command]""="C:\Program Files (x86)\Opera\Launcher.exe" [HKLM64\Software\Clients\StartMenuInternet\OperaStable\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Opera\Launcher.exe" --makedefaultbrowser [HKLM64\Software\Clients\StartMenuInternet\PALEMOON.EXE\Shell\open\Command]""="C:\Program Files\Pale Moon\palemoon.exe" [HKLM64\Software\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo]"ReinstallCommand"="C:\Program Files\Pale Moon\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Avant.Browser\Shell\open\Command]""=C:\Program Files (x86)\Avant Browser\avant.exe [29/06/2017 04:35:00][HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Avant.Browser\InstallInfo]"ReinstallCommand"= [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Dragon\Shell\open\Command]""="C:\Program Files (x86)\Comodo\Dragon\dragon.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Dragon\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command]""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command]""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command]""="C:\Program Files (x86)\Internet Explorer\iexplore.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo]"ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Iron\Shell\open\Command]""="C:\Program Files (x86)\SRWare Iron\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Iron\InstallInfo]"ReinstallCommand"= [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\OperaStable\Shell\open\Command]""="C:\Program Files (x86)\Opera\Launcher.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\OperaStable\InstallInfo]"ReinstallCommand"="C:\Program Files (x86)\Opera\Launcher.exe" --makedefaultbrowser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\PALEMOON.EXE\Shell\open\Command]""="C:\Program Files\Pale Moon\palemoon.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo]"ReinstallCommand"="C:\Program Files\Pale Moon\uninstall\helper.exe" /SetAsDefaultAppGlobal ---------- | AppcompatFlags [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"SIGN.MEDIA=3EFFE utils\win64\syslinux64.exe"=0x534143500100000000000000070000002800000000CC03005617040001000000000000000000030673000000D5B3B31A57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000DB000000000000000100000001000000"SIGN.MEDIA=2F4BF31 Download\winzip210fr.exe"=0x534143500100000000000000070000002800000060EA9D0996C69E090100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000008000000000000000000000000000000000000000A7EFFA0E000000000200000002000000"SIGN.MEDIA=2F4BF31 Download\adksetup.exe"=0x5341435001000000000000000700000028000000E87A1A0095901A0001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000061AC5800000000000100000001000000"C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.12.945.9202\AdAwareDesktop.exe"=0x5341435001000000000000000700000028000000E8C62601C886270101000000000000000000000A00210000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000572B880E000000000600000006000000"SIGN.MEDIA=E6B61694 mort du porc - otlpe and pc mover pro 10 michel\pcmover_fr_10.exe"=0x5341435001000000000000000700000028000000F0819804DD2C99040100000000000000000000067102000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000EEA70200000000000100000001000000"SIGN.MEDIA=2F4BF31 Download\autoit-v3-setup.exe"=0x53414350010000000000000007000000280000003047BB0047F8BB000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000045C51A00000000000100000001000000"C:\Program Files (x86)\EPSON Software\Download Navigator\EPSDNAVI.EXE"=0x534143500100000000000000070000002800000018DE2900D53E2A000100000000000000000003060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000003E15508000000000300000003000000"C:\Program Files (x86)\Ashampoo\Ashampoo Privacy Protector\PrivacyProtector.exe"=0x5341435001000000000000000700000028000000701322005572220001000000000000000000000AF122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000007CE50700000000000100000001000000"C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe"=0x5341435001000000000000000700000028000000F018D400805ED4000100000000000000000003060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000FC2C0000000000000100000001000000"C:\Program Files (x86)\EPSON Software\Print CD\PrintCD.exe"=0x5341435001000000000000000700000028000000D0EC4800A1A0490001000000000000000000000A7122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000009CF31600000000000100000001000000"C:\Program Files (x86)\CyberLink\AppManager\AppManager.exe"=0x534143500100000000000000070000002800000018E103002636040001000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000054E82103000000000200000002000000"C:\Program Files\WinZip\WINZIP64.EXE"=0x53414350010000000000000007000000280000006068BD04446BBD0401000000000000000000000A00210000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000160A8600000000000100000001000000"C:\Users\Jean-Marie\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe"=0x534143500100000000000000070000002800000010A61400A6A9140001000000000000000000010671220000E63F486B2AA0D20100000080000000000200000028000000000000000000000000000000000000000000000000000000763D0000000000000F0000000F000000"C:\Users\Jean-Marie\AppData\Roaming\UsbFix\UsbFix.exe"=0x534143500100000000000000070000002800000000D41B004B0A1C0001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000095BE8200000000000100000001000000"C:\Program Files (x86)\CyberLink\Media Suite\PS.exe"=0x534143500100000000000000070000002800000018DF0800A839090001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000067940200000000000100000001000000"C:\Users\Jean-Marie\Documents\tuxboot-0.8.2.exe"=0x534143500100000000000000070000002800000000004E000000000001000000000000000000000A7122000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000003EC51500000000000100000001000000"C:\Program Files (x86)\ISO to USB\isotousb.exe"=0x5341435001000000000000000700000028000000003A1E00000000000100000000000000000003067122000033504C2B57DFD101000000000000000002000000280000000000000000000040000002000000000000000000000000004C2CC600000000000100000001000000"C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000D87E3801682C390101000000000000000000000A0021000033504C2B57DFD1010000000100000000"C:\Users\Jean-Marie\Documents\fondamentaux 1er semestre 2014 + lfsu100%sf part F\Cameyo.exe"=0x5341435001000000000000000700000028000000A90DE7009A991B0001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000C4EB0400000000000200000002000000"C:\Users\Jean-Marie\Documents\fondamentaux 1er semestre 2014 + lfsu100%sf part F\everysync_trial.exe"=0x5341435001000000000000000700000028000000A87F91014209920101000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000002FD90200000000000100000001000000"C:\Program Files (x86)\Glary Utilities 5\SoftwareUpdate.exe"=0x5341435001000000000000000700000028000000D07508007C88080001000000000000000000000A71220000E63F486B2AA0D20100000080000000000200000028000000000000000000000000000000000000000000000000000000D1963800000000000400000004000000"C:\Program Files (x86)\Kastor Tube To Mp3\TubeToMp3.exe"=0x534143500100000000000000070000002800000020B71400BFA5150001000000000000000000000AF122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000005ACA3700000000000100000001000000"C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe"=0x5341435001000000000000000700000028000000C0342400BB67240001000000000000000000030671020000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000D2441206000000001100000011000000"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"=0x5341435001000000000000000700000028000000982C53027375530201000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000009148B200000000000100000001000000"C:\Program Files (x86)\Amazing-Share\Free Partition Manager\Free Partition Manager.exe"=0x534143500100000000000000070000002800000000AA4F00866B500001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000D09A8002000000000900000009000000"C:\Program Files\FreeFileSync\FreeFileSync.exe"=0x5341435001000000000000000700000028000000A81407002600080001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000A0E58E02000000001800000018000000"C:\Program Files\Unlocker\Unlocker.exe"=0x534143500100000000000000070000002800000000E801000000000001000000000000000000020673220000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000002A690000000000000500000005000000"C:\Program Files\JAM Software\TreeSize\TreeSize.exe"=0x5341435001000000000000000700000028000000F0C35302DB6E540201000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000500000000000000000000040000000000000000000000000000000007AE50100000000000100000001000000000000000000000000000000000000000000000000000000591D0400000000000300000000000000"C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD.exe"=0x534143500100000000000000070000002800000028040800FAD6080001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000044022700000000000100000001000000"C:\Program Files (x86)\ArcSoft\VideoImpression 1.6\videoimp.exe"=0x534143500100000000000000070000002800000000A00B00000000000100000000000000000001057120000033504C2B57DFD101000000000000000002000000280000000000000000000000000400000000000000000000000000005CBB0100000000000100000001000000"C:\Program Files\CCleaner\CCleaner.exe"=0x5341435001000000000000000700000028000000D8C871003A24720001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000F2040000000000000100000001000000"C:\Pre_Scan\Pre_Scan_Restore.exe"=0x534143500100000000000000070000002800000010D613009C80140001000000000000000000000A0021000033504C2B57DFD1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000050460000000000000100000001000000"C:\Users\Jean-Marie\AppData\Roaming\ZHP\ZHPCleaner.exe"=0x534143500100000000000000070000002800000000262A0022722A000100000000000000000003060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000006EF05500000000000100000001000000"C:\Windows10Upgrade\Windows10UpgraderApp.exe"=0x5341435001000000000000000700000028000000C8DE1200E6C9130001000000000000000000000A7122000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000043147D00000000000100000001000000"C:\Program Files\CyberGhost 6\CyberGhost.exe"=0x5341435001000000000000000700000028000000302E1200179D120001000000000000000000000A80210000E78E163C2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000090450100000000000100000001000000"C:\Users\Jean-Marie\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000787C03003765040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000"C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareTray.exe"=0x5341435001000000000000000700000028000000D8114400F1B9440001000000000000000000000A00210000E78E163C2AA0D2010000000000000000"C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareDesktop.exe"=0x5341435001000000000000000700000028000000D807B6007252B60001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000019107502000000000400000004000000"C:\Program Files (x86)\Silent Install Builder 5\Sib.exe"=0x5341435001000000000000000700000028000000008A0B000000000001000000000000000000000A80210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000754A2B00000000000100000001000000"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe"=0x5341435001000000000000000700000028000000C07E3B00881C3C0001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000025B13A00000000000100000001000000"C:\Program Files (x86)\TechSmith\Jing\Jing.exe"=0x5341435001000000000000000700000028000000F86B2C00FA272D0001000000000000000000000AF1220000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001F02AD02000000000100000001000000"C:\Program Files (x86)\Eyes Relaxing And Focusing 3.0\Eyes.exe"=0x5341435001000000000000000700000028000000008814000000000001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000B2190000000000000100000001000000"C:\Users\Jean-Marie\Desktop\adsfix_4_29.04.17.1.exe"=0x5341435001000000000000000700000028000000A87D6300E23A640001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000096C10100000000000100000001000000"C:\Users\Jean-Marie\AppData\Local\Vision\vision-dynamic.exe"=0x5341435001000000000000000700000028000000C08404001846050001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000020A0000000000000100000001000000"C:\Users\Jean-Marie\Desktop\LFS Ultra - 100 % Sécurisé - Cewbé Suite v5.0\interface_utilisateur_ecb_v5\CaisseEpargne.exe"=0x534143500100000000000000070000002800000020D822003BF0220001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000BF8C0000000000000100000001000000"C:\Program Files (x86)\SecurityXploded\DailymotionVideoAdBlocker\DailymotionVideoAdBlocker.exe"=0x5341435001000000000000000700000028000000001426000000000001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000383D0000000000000100000001000000"C:\Program Files (x86)\SecurityXploded\SX Blocker Suite\GoogleAdBlocker.exe"=0x5341435001000000000000000700000028000000009A35000000000001000000000000000000000A00210000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000000F700000000000000100000001000000"C:\Program Files (x86)\SecurityXploded\SX Network Suite\WiFiHotspotScanner.exe"=0x534143500100000000000000070000002800000000F026000000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000E76F0200000000000100000001000000"C:\Program Files (x86)\SecurityXploded\SX System Suite\EnableAdmin.exe"=0x534143500100000000000000070000002800000000DE02000000000001000000000000000000020671020000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000DC340000000000000100000001000000"C:\Program Files (x86)\SecurityXploded\SX System Suite\Exe64bitDetector.exe"=0x5341435001000000000000000700000028000000003E06000000000001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000002B250000000000000100000001000000"C:\Program Files (x86)\SecurityXploded\SX System Suite\WindowsUACManager.exe"=0x534143500100000000000000070000002800000000DC02000000000001000000000000000000020671220000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000E2520000000000000100000001000000"C:\Program Files (x86)\SecurityXploded\SX WiFi Security Suite\WiFiPasswordDecryptor.exe"=0x5341435001000000000000000700000028000000009628000000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E66E0000000000000100000001000000"C:\Program Files (x86)\Trojan Remover\Rmvtrjan.exe"=0x5341435001000000000000000700000028000000184C56007D55560001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000F000000000000000000000000000000000620A0300000000000100000001000000"C:\Users\Jean-Marie\Documents\Mes téléchargements Filehippo\ReflectDL.exe"=0x5341435001000000000000000700000028000000D01936008FE3360001000000000000000000020600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000025B10601000000000100000001000000"C:\Program Files (x86)\Internet Explorer\iexplore.exe"=0x5341435001000000000000000700000028000000408D0C004F450D0001000000010000000000000A00210000E63F486B2AA0D2010000000000000000"C:\Program Files (x86)\Online Video Recorder\OnlineVideoRecorder.exe"=0x5341435001000000000000000700000028000000006C2900390B270001000000000000000000020671220000E63F486B2AA0D2010000000000000000"C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 2017\burningstudio2017.exe"=0x5341435001000000000000000700000028000000B8FD9401F73B950101000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000AD9B2601000000000500000005000000"C:\Users\Jean-Marie\Documents\Mes téléchargements Filehippo\gu5setup.exe"=0x5341435001000000000000000700000028000000E034000156C7000101000000000000000000010600010000E63F486B2AA0D2010000000000000000"C:\Program Files\Pale Moon\palemoon.exe"=0x5341435001000000000000000700000028000000682C06002434060001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000075742609000000001100000011000000"C:\Program Files\AVAST Software\Avast\AvastUI.exe"=0x5341435001000000000000000700000028000000A8D08B0011B48C0001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000036260000000000000100000001000000"C:\Program Files (x86)\Glary Utilities 5\Integrator.exe"=0x534143500100000000000000070000002800000000BC0D00CEEB0D0001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000028870200000000000300000003000000"C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe"=0x5341435001000000000000000700000028000000F87F2300A760240001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000A4380000000000000200000002000000"C:\Program Files\Greenshot\Greenshot.exe"=0x5341435001000000000000000700000028000000B00D08001737080001000000000000000000000A80210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000D24D0000000000000100000001000000"C:\Program Files (x86)\Amazing-Share\Free Screen Recorder\Free Screen Recorder.exe"=0x5341435001000000000000000700000028000000005615008C7B150001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000003D282D00000000000100000001000000"SIGN.MEDIA=3F58288 Setup file of CyberLink Power2Go 11 Essentials\CyberLink_Power2Go_11 stub install.exe"=0x534143500100000000000000070000002800000018CF1100AFAB120001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000046AD1E00000000000100000001000000"C:\Program Files (x86)\CyberLink\Power2Go11\Trial\TrialMgr.exe"=0x5341435001000000000000000700000028000000181F02009834020001000000000000000000000A71200000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001C680100000000000A0000000A000000"C:\Program Files (x86)\CyberLink\Power2Go11\Power2Go.exe"=0x534143500100000000000000070000002800000018216300C6F9630001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000E1330000000000000100000001000000"C:\Users\Jean-Marie\Documents\Windows 10 Transformation Pack 7.0\Windows 10 Transformation Pack 7.0.exe"=0x53414350010000000000000007000000280000001FDE78080802060001000000000000000000010671020000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000006E010200000000000100000001000000"C:\Users\Jean-Marie\Documents\Windows 10 UX Pack 7.0\Windows 10 UX Pack 7.0.exe"=0x5341435001000000000000000700000028000000E42823060802060001000000000000000000010671020000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000000E310100000000000100000001000000"C:\Program Files (x86)\XYplorerFree\XYplorerFree.exe"=0x5341435001000000000000000700000028000000A0316A009D076B0001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000002E42F900000000000600000006000000"C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe"=0x5341435001000000000000000700000028000000008C540031C3540001000000000000000000010600210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000100000000000000000000000000000D1FDF500000000000300000003000000"C:\UsbFix\UsbFix.exe"=0x5341435001000000000000000700000028000000E0AD1B0095BE1B0001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000005000000000000000000000400000000000000000000000000000000003722B00000000000100000001000000000000000000000000000000000000000000000000000000DD2B0100000000000100000000000000"C:\Program Files\UCheck\UCheck64.exe"=0x534143500100000000000000070000002800000048529D01B07A9D0101000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000074CE1C00000000000100000001000000"C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe"=0x5341435001000000000000000700000028000000C8524B031DDA4B0301000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000010000000000000000000000000000000007D8A0000000000000100000001000000"C:\Program Files\Malwarebytes\Anti-Malware\assistant.exe"=0x5341435001000000000000000700000028000000D0030600738C060001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000029640000000000000200000002000000"C:\Program Files (x86)\Anvsoft\Syncios\adb.exe"=0x534143500100000000000000070000002800000000AA15002AE3150001000000000000000000010571000000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000003D564104000000001600000016000000"C:\Program Files (x86)\CyberLink\Shared files\EffectExtractor.exe"=0x534143500100000000000000070000002800000018AD4800431D490001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000517C0400000000000D0000000D000000"C:\Users\Jean-Marie\Desktop\winrar-x64-540fr.exe"=0x5341435001000000000000000700000028000000A0C322000A67230001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000098690000000000000100000001000000"C:\Program Files\WinRAR\WinRAR.exe"=0x534143500100000000000000070000002800000090AB170059E6170001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000C9652C00000000001800000018000000"C:\Users\Jean-Marie\Desktop\ATI2016WD_build33\AcronisTrueImageWDEdition_33.exe"=0x5341435001000000000000000700000028000000809D9B16D0F99B1601000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000053955700000000000100000001000000"C:\Program Files\Internet Explorer\iexplore.exe"=0x534143500100000000000000070000002800000040930C00D5A10C0001000000010000000000000A00210000E78E163C2AA0D2010000000000000000"C:\Users\Jean-Marie\Desktop\processclose_2_08.01.17.1.exe"=0x5341435001000000000000000700000028000000A8270F003B5B0F0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000BABB0100000000000100000001000000"C:\Program Files\Fast HTML Checker\fasthtmlchecker.exe"=0x534143500100000000000000070000002800000038AF4900E6E4490001000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001CC30100000000000100000001000000"C:\Program Files (x86)\Ashampoo\Ashampoo StartUp Tuner 2\ASST.exe"=0x534143500100000000000000070000002800000060CF1B00DC2C1C0001000000000000000000000661220000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001A5C0000000000000100000001000000"C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageLauncher.exe"=0x5341435001000000000000000700000028000000B04B03000D24040001000000000000000000000A00210000E63F486B2AA0D2010000000000000000"C:\Program Files (x86)\StartIsBack\StartIsBackCfg.exe"=0x534143500100000000000000070000002800000060952100FDA1210001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000005000000000000000000000100000000000000000000000000000000098AF14000000000008000000080000000000000000000000000000000000000000000000000000000B1A0100000000001500000000000000"C:\Program Files (x86)\Paragon Software\ExtFS for Windows\Paragon ExtFS for Windows.exe"=0x534143500100000000000000070000002800000050BB4B0085604C0001000000000000000000000A71220000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000092B96800000000000300000003000000"C:\Users\Jean-Marie\Desktop\quickdiag_3_01.07.17.1(2).exe"=0x5341435001000000000000000700000028000000A83547001933480001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000312B8800000000000200000002000000"SIGN.MEDIA=81C87578 Data\Documents\Download\asetup.exe"=0x5341435001000000000000000700000028000000389815054DD5150501000000000000000000000671000000E63F486B2AA0D2010000000000000000"C:\Program Files (x86)\Avanquest\Fix-It\Fix-It.exe"=0x53414350010000000000000007000000280000001855100064A6100001000000000000000000000671020000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000071461A00000000000200000002000000"C:\Program Files (x86)\Avanquest\Fix-It\fcs.exe"=0x53414350010000000000000007000000280000009AAE00000000000001000000000000000000010571000000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000F9080000000000000100000001000000"C:\ProgramData\IObit\ASCDownloader\IU6\IObit Malware Fighter.exe"=0x5341435001000000000000000700000028000000B8AA6D02D8606E0201000000000000000000030600010000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000B0312400000000000100000001000000"C:\ProgramData\c38a54086e05480b80afe510b168cdcc\qx8Ynf8GelY.exe"=0x534143500100000000000000070000002800000000F00A000000000001000000000000000000000AF5220000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001A130A00000000000200000002000000"C:\Program Files (x86)\VivPDF Editor\VivPDF Editor.exe"=0x5341435001000000000000000700000028000000B8845501CA7B560101000000000000000000010600010000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000000F040500000000000100000001000000"C:\Program Files\LopeSoft\FileMenu Tools\FileMenuTools64.exe"=0x534143500100000000000000070000002800000000B448000000000001000000000000000000000A73220000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000066B50000000000000100000001000000"C:\ProgramData\8b65273228e94e319fb363944a28e77d\2Fm96RZBybG.exe"=0x534143500100000000000000070000002800000000F00A000000000001000000000000000000000AF5220000E78E163C2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000323E0000000000000100000001000000"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe"=0x5341435001000000000000000700000028000000C85043003D52430001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000592E0C00000000000200000002000000"C:\Program Files (x86)\Wise\Wise Driver Care\wisedrivercare.exe"=0x5341435001000000000000000700000028000000A87A1400CA53150001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000A9C5E800000000000100000001000000000000000000004000000000000000000000000000000000C7F43000000000000100000000000000"C:\Program Files (x86)\Wise\Wise Driver Care\7z.exe"=0x5341435001000000000000000700000028000000A8480400870A050001000000000000000000000A71200000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000003F4E0000000000000100000001000000"C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe"=0x5341435001000000000000000700000028000000D0390B0088680B0001000000000000000000000A71220000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000022AA0500000000000600000006000000"M:\lfs hyper-jobs janv2016-dtpro-rebit-p2go11\ajustages lfsu100%sf-juin2017-anniv barrow 2-vexe-widen-amine\lfsu100%sf pt Z sigma\Ou apesanlic 6\SharewareOnSale_Giveaway_Windows_Boot_Genius_hub.exe"=0x534143500100000000000000070000002800000048612500E806260001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001D981D00000000000300000003000000"M:\lfs hyper-jobs janv2016-dtpro-rebit-p2go11\ajustages lfsu100%sf-juin2017-anniv barrow 2-vexe-widen-amine\lfsu100%sf pt Z sigma\1ers giveaways après lfsu100%sf\UnWrapper_GOTD_v2.04\UnWrapper_GOTD_v2.04.exe"=0x534143500100000000000000070000002800000000F200000000000001000000000000000000000A61220000E63F486B2AA0D2010000000000000000"C:\Users\Jean-Marie\AppData\Local\Temp\RarSFX2\installer.exe"=0x5341435001000000000000000700000028000000B8520B00858D0B0001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000ADC60300000000000100000001000000"C:\Program Files (x86)\Opera\launcher.exe"=0x5341435001000000000000000700000028000000582013007495130001000000000000000000000A00210000E78E163C2AA0D2010000000000000000"C:\Users\Jean-Marie\Desktop\quickdiag_3_01.07.17.1.exe"=0x5341435001000000000000000700000028000000A83547001933480001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000050000000000000000000004000000000000000000000000000000000236A2A0400000000070000000200000000000000000000000000000000000000000000000000000083283601000000000200000000000000"C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe"=0x5341435001000000000000000700000028000000202903006B55030001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000048580200000000000100000001000000"C:\Users\Jean-Marie\Desktop\Rem-VBSworm\Rem-VBSworm.exe"=0x534143500100000000000000070000002800000000BE01000000000001000000000000000000010671020000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000008000000002000000280000000000000080000040000000000000000000000000000000000D099300000000000100000001000000"C:\Users\Jean-Marie\AppData\Local\Temp\tmpCC63.exe"=0x534143500100000000000000070000002800000078F10F203A88102001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000002F5B7D00000000000100000001000000"C:\Users\Jean-Marie\AppData\Local\Temp\7ZipSfx.001\bin\ise_installer\isestart.exe"=0x5341435001000000000000000700000028000000D0503A00EF273B0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000A49B0000000000000100000001000000"C:\Program Files\COMODO\PC TuneUP\CPCTuneUp.exe"=0x5341435001000000000000000700000028000000C8509600FB6D960001000000000000000000020673220000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000007B90C40A000000000500000005000000"C:\Program Files (x86)\Comodo\IceDragon\icedragon.exe"=0x5341435001000000000000000700000028000000B89E05003A24060001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000007808D000000000000100000001000000"C:\Program Files\Windows NT\Accessories\wordpad.exe"=0x534143500100000000000000070000002800000000864400D0C0440001000000010000000000000A63220000E78E163C2AA0D2010000000000000000"C:\Users\Jean-Marie\Desktop\look-my-hardware_2_26.04.17.1.exe"=0x5341435001000000000000000700000028000000A8E9120042D7130001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000A2630200000000000200000002000000"C:\Users\Jean-Marie\Desktop\Rem-VBSworm.exe"=0x534143500100000000000000070000002800000000BE01000000000001000000000000000000010671020000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000008000000002000000500000000000000080000040000000000000000000000000000000006D8393000000000002000000020000000000000080000000000000000000000000000000000000002A3F2F01000000000100000000000000"C:\Users\Jean-Marie\Desktop\OTL.exe"=0x534143500100000000000000070000002800000000300900870F0A0001000000000000000000000A41220000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000D12D0B00000000000200000002000000000000000000000000000000000000000000000000000000CCEF0400000000000100000000000000"C:\Program Files\MultiCommander (x64)\MultiCommander.exe"=0x534143500100000000000000070000002800000000E074000000000001000000000000000000000A00210000E78E163C2AA0D2010000000000000000"C:\Program Files\BCUninstaller\BCUninstaller.exe"=0x534143500100000000000000070000002800000080B1170046D9170001000000000000000000010680010000E78E163C2AA0D2010000000000000000020000002800000000000000000000400410000000000000000000000000000027794200000000000100000001000000"SIGN.MEDIA=4A90710 espace rapports otl rem vbs sosvirus win10 & autres apps lfsu100%sfpzs++sfce\SharewareOnSale_Giveaway_PodSilo_hub.exe"=0x5341435001000000000000000700000028000000409224007BEF240001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000CA0F0100000000000100000001000000"C:\Program Files (x86)\CyberLink\VideoMeetingPlus\VideoMeetingPlus.exe"=0x534143500100000000000000070000002800000018FF04007074050001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000749E4A09000000000100000001000000"C:\Program Files (x86)\IMSIDesign\Turbo View & Convert\tvc.exe"=0x534143500100000000000000070000002800000000E5BD01A6D4BE0101000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000B89C0100000000000200000002000000"C:\Program Files (x86)\Ashampoo\Ashampoo Snap 10\ashsnap.exe"=0x5341435001000000000000000700000028000000A0AB5D0045685E0001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000006301AC00000000000100000001000000"SIGN.MEDIA=14ABA9C Data\Documents\SoftOrbitsPhotoRetoucher40-i1sy2s\SORetoucher_pt1.exe"=0x534143500100000000000000070000002800000088BD4A01942D4B0101000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000CAE70B00000000000100000001000000"C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe"=0x534143500100000000000000070000002800000020756B0093EC6B0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000FB93D100000000000100000001000000"C:\Users\Jean-Marie\AppData\Roaming\Dashlane\Dashlane.exe"=0x5341435001000000000000000700000028000000804D0700FFED070001000000000000000000030600010000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000323F7F00000000000100000001000000"C:\Users\Jean-Marie\Desktop\OTM.exe"=0x534143500100000000000000070000002800000000F807000E4C080001000000000000000000000A41220000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000006BF00000000000000100000001000000 [HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]"C:\Program Files (x86)\Opera\Launcher.exe"=32 [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]"C:\Program Files (x86)\Opera\Launcher.exe"=32 ---------- | IFEO ---------- | Mountpoints2 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{a47efbdd-6369-11e7-bcc7-4c72b9f956a2}] : "D:\mblaunchpad.exe" (AutoRun) ---------- | Windows [HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]"APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]"windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM64\SOFTWARE\Microsoft\Security Center]"cval"=0 [HKLM64\SOFTWARE\Microsoft\Security Center\svc]"VistaSp1"=131377042204672739 [HKLM64\SOFTWARE\Microsoft\Windows Defender]"ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender"ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100"ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000"RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe"DisableAntiSpyware"=0"ProductType"=2"InstallTime"=0xB08DE3ECB83CD201"InstallLocation"=C:\Program Files\Windows Defender\"ProductStatus"=0"ManagedDefenderProductType"=0"OOBEInstallTime"=0x8815AF61BDBED201"DisableAntiVirus"=0"LastEnabledTime"=0x2F7ED2823EF6D201"OneTimeSqmDataSent"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]"EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]"EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ASCAntivirusSrv][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\cpwfpnd][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ocsvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMService][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{0CBD4F48-3751-475D-BE88-4F271385B672}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}][HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts # 127.0.0.1 localhost# ::1 localhost ---------- | Ping Envoi d'une requˆte 'ping' sur google.com [216.58.208.206] avec 32 octets de donn‚esÿ: R‚ponse de 216.58.208.206ÿ: octets=32 temps=986 ms TTL=54 R‚ponse de 216.58.208.206ÿ: octets=32 temps=1027 ms TTL=54 R‚ponse de 216.58.208.206ÿ: octets=32 temps=1146 ms TTL=54 R‚ponse de 216.58.208.206ÿ: octets=32 temps=1071 ms TTL=54 Statistiques Ping pour 216.58.208.206: Paquetsÿ: envoy‚s = 4, re‡us = 4, perdus = 0 (perte 0%), Dur‚e approximative des boucles en millisecondes : Minimum = 986ms, Maximum = 1146ms, Moyenne = 1057ms ---------- | @ [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Internet Explorer\Main]"Anchor Underline"=yes"Cache_Update_Frequency"=yes"Disable Script Debugger"=yes"DisableScriptDebuggerIE"=yes"Display Inline Images"=yes"Do404Search"=0x01000000"Local Page"=%11%\blank.htm"Save_Session_History_On_Exit"=no"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896"Show_FullURL"=no"Show_StatusBar"=yes"Show_ToolBar"=yes"Show_URLinStatusBar"=yes"Show_URLToolBar"=yes"Use_DlgBox_Colors"=yes"UseClearType"=no"XMLHTTP"=1"Enable Browser Extensions"=no"Play_Background_Sounds"=yes"Play_Animations"=yes"Start Page"=http://r.orange.fr/r/Oodc_IE_oi_v2?ref=O_OI_defaultPage_IE_odc"OperationalData"=13"CompatibilityFlags"=0"FullScreen"=no"Window_Placement"=0x2C00000002000000030000000083FFFF0083FFFFFFFFFFFFFFFFFFFF240000002400000044030000A4020000"ImageStoreRandomFolder"=81c6u2j"Start Page Redirect Cache_TIMESTAMP"=0xC2855094BE3CD201"Start Page Redirect Cache AcceptLangs"=fr-FR"IE10RunOncePerInstallCompleted"=1"IE10RunOnceCompletionTime"=0x57E6DD1D9FBED201"IE10TourShown"=1"IE10TourShownTime"=0x57E6DD1D9FBED201"Start Page_TIMESTAMP"=0xE9913E33A000D301"SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"=0x0100000076000000246C04973F9E4ADC84D48217E60D58B14BEAFD8C24102594814812F87B588BDE02AE64F13397996E0F1B68FFC02F7E5EC27196BA803371D9AE1839F33461EA698CC71FC892A2589AFB073E297FD03FDFFC411310DA4ECB34C1836EB0DC9103AAC825E761E20B7E1E109079A0F307A021C4636B54756D02000000100000007663585725326233636639496F253364"DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF12010000D600000092030000B6020000"NotifyDownloadComplete"=yes"TabShutdownDelay"=0"IE11EdgeNotifyTime"=0xBEDFC6D274C2D201"EdgeReminderRemainingCount"=5"Use FormSuggest"=no"Default Download Directory"=C:\Users\Jean-Marie\Desktop"Check_Associations"=no"Isolation"=PMIL"TabProcGrowth"=0"DisableFirstRunCustomize"=1"RunOnceHasShown"=1"RunOnceComplete"=1"NoUpdateCheck"=1"FormSuggest PW Ask"=no"FormSuggest Passwords"=no"Secondary Start Pages"=https://search.yahoo.com/?fr=vmn&type=auslog_yaapp30_hp http://www.google.com/cse/home?cx=006195091930824655782:f6rbuy9j0s8 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings]"DisableCachingOfSSLPages"=0"IE5_UA_Backup_Flag"=5.0"PrivacyAdvanced"=1"SecureProtocols"=2688"CertificateRevocation"=1"User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32)"ZonesSecurityUpgrade"=0x57E6DD1D9FBED201"WarnonZoneCrossing"=0"EnableNegotiate"=1"MigrateProxy"=1"GlobalUserOffline"=0"MaxConnectionsPerServer"=10"MaxConnectionsPer1_0Server"=10"ProxyEnable"=0 [HKLM64\Software\Microsoft\Internet Explorer\Main]"ApplicationTileImmersiveActivation"=1"AssociationActivationMode"=0"AutoHide"=yes"Anchor_Visitation_Horizon"=0x01000000"Cache_Percent_of_Disk"=0x0A000000"Default_Secondary_Page_URL"="Delete_Temp_Files_On_Exit"=yes"Enable_Disk_Cache"=yes"Extensions Off Page"=about:NoAdd-ons"Local Page"=C:\Windows\System32\blank.htm"Placeholder_Height"=0x1A000000"Placeholder_Width"=0x1A000000"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896"Security Risk Page"=about:SecurityRisk"Use_Async_DNS"=yes"x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE"Start Page"=about:blank"DoNotTrack"=1 [HKLM64\Software\Microsoft\Internet Explorer\AboutURLs]"blank"=res://mshtml.dll/blank.htm"DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm"Home"=270"InPrivate"=res://ieframe.dll/inprivate.htm"NavigationCanceled"=res://ieframe.dll/navcancl.htm"NavigationFailure"=res://ieframe.dll/navcancl.htm"NoAdd-ons"=res://ieframe.dll/noaddon.htm"NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm"PostNotCached"=res://ieframe.dll/repost.htm"SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM64\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]""=http:// [HKLM64\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]"ftp"=ftp://"home"=http://"mosaic"=http://"www"=http:// [HKLM64\Software\Microsoft\Windows\CurrentVersion\Internet settings]"ActiveXCache"=C:\Windows\Downloaded Program Files"CodeBaseSearchPath"=CODEBASE"EnablePunycode"=1"MinorVersion"=0"WarnOnIntranet"=1"GlobalUserOffline"=0"ProxyEnable"=0 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main]"ApplicationTileImmersiveActivation"=1"AssociationActivationMode"=0"AutoHide"=yes"Start Page"=about:blank"Anchor_Visitation_Horizon"=0x01000000"Cache_Percent_of_Disk"=0x0A000000"Default_Secondary_Page_URL"="Delete_Temp_Files_On_Exit"=yes"Enable_Disk_Cache"=yes"Extensions Off Page"=about:NoAdd-ons"Local Page"=C:\Windows\SysWOW64\blank.htm"Placeholder_Height"=0x1A000000"Placeholder_Width"=0x1A000000"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896"Security Risk Page"=about:SecurityRisk"Use_Async_DNS"=yes"x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE"FormSuggest PW Ask"=no"FormSuggest Passwords"=no"FormSuggest Use FormSuggest"=no [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs]"blank"=res://mshtml.dll/blank.htm"DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm"Home"=270"InPrivate"=res://ieframe.dll/inprivate.htm"NavigationCanceled"=res://ieframe.dll/navcancl.htm"NavigationFailure"=res://ieframe.dll/navcancl.htm"NoAdd-ons"=res://ieframe.dll/noaddon.htm"NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm"PostNotCached"=res://ieframe.dll/repost.htm"SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes]"ftp"=ftp://"home"=http://"mosaic"=http://"www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings]"ActiveXCache"=C:\Windows\Downloaded Program Files"CodeBaseSearchPath"=CODEBASE"EnablePunycode"=1"MinorVersion"=0"WarnOnIntranet"=1"GlobalUserOffline"=0"ProxyEnable"=0 ---------- | Proxy [HKLM\System\CurrentControlSet\Services\NLASVC\Parameters\Internet\Manualproxies][HKLM\System\CurrentControlSet\Services\NLASVC\Parameters\Internet\Manualproxies]"ProxyEnable"=0"GlobalUserOffline"=0 ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | Execution FileExts [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi]"Application"=wmplayer.exe"DivX.AAR.backup"=Media Player Classic"Progid"=divx_avi_file[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bdmv]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.clpprj]"Application"=ClPhpEd.Files[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.div]"DivX.AAR.backup"=Media Player Classic"Progid"=divx_div_file[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx]"Application"=wmplayer.exe"DivX.AAR.backup"=Media Player Classic"Progid"=divx_divx_file[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dv]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.evo]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdmov]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ifo]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M1V]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv]"Application"=wmplayer.exe"DivX.AAR.backup"=Media Player Classic"Progid"=divx_mkv_file[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2V]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPE]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpls]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv4]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mxf]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogv]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rec]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snapdoc]"ProgID"=SNAP.DOC[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tix]"DivX.AAR.backup"=Media Player Classic"Progid"=divx_tix_file[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tps]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.trp]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm]"Application"=wmplayer.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xvid]"DivX.AAR.backup"=Media Player Classic"Progid"=divx_xvid_file ---------- | SIOI | SEH | URLSH [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ EaseUSEverySyncedOverlay] - {52103F52-9856-43F7-B5C4-A026FD84288C} -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlayX64.dll [23/04/2017 13:47:33][HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ EaseUSEverySyncFailedOverlay] - {A6D755FC-42D6-46BF-8A5D-1F810C3FCEA6} -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlayX64.dll [23/04/2017 13:47:33][HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ EaseUSEverySyncingOverlay] - {0F45C9C8-E236-4CEC-A858-BFEB47D8CD3C} -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlayX64.dll [23/04/2017 13:47:33][HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw] - {472083B0-C522-11CF-8763-00608CC02F24} -- [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\AcronisSyncError] - {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} -- C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [11/11/2015 12:02:44][HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\AcronisSyncInProgress] - {00F848DC-B1D4-4892-9C25-CAADC86A215D} -- C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [11/11/2015 12:02:44][HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\AcronisSyncOk] - {71573297-552E-46fc-BE3D-3DFAF88D47B7} -- C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [11/11/2015 12:02:44][HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [18/03/2017 22:57:23][HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ EaseUSEverySyncedOverlay] - {52103F52-9856-43F7-B5C4-A026FD84288C} -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlay.dll [23/04/2017 13:47:33][HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ EaseUSEverySyncFailedOverlay] - {A6D755FC-42D6-46BF-8A5D-1F810C3FCEA6} -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlay.dll [23/04/2017 13:47:33][HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ EaseUSEverySyncingOverlay] - {0F45C9C8-E236-4CEC-A858-BFEB47D8CD3C} -- C:\Program Files (x86)\EaseUS\EaseUS EverySync\bin\EverySyncExplorerOverlay.dll [23/04/2017 13:47:33][HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= ---------- | Toolbar [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar]"Locked"=1 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser]"ITBar7Height64"=0 [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]"KnownProvidersUpgradeTime"=0x57E6DD1D9FBED201 "Version"=5 "UpgradeTime"=0x57E6DD1D9FBED201 "DefaultScope"={96BBC430-9900-4299-9F5D-7951AB36EFDF} [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Toolbar]"{9421DD08-935F-4701-A9CA-22DF90AC4EA6}"=EPTBL [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Toolbar]"{669695BC-A811-4A9D-8CDF-BA8C795F261C}"=Dashlane Toolbar ---------- | Extensions ---------- | SearchScopes [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{96BBC430-9900-4299-9F5D-7951AB36EFDF}] - (Google) - http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{981B3BDE-F9A8-4786-8ADA-4271DE3882D2}] - (Yahoo) - https://search.yahoo.com/search/?toggle=1&cop=mss&ei=UTF-8&fr=vmn&type=auslog_yaapp30_ch&p={searchTerms} : ---------- | ElevationPolicy [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\E6ADCBB4-97D5-4891-9955-026A20E2A3A7] - (C:\Users\Jean-Marie\AppData\Roaming\get2Clouds\bin\) - get2Clouds.exe : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5B236E3E-80B2-4322-B6A2-529D751B7FB1}] - (C:\Users\Jean-Marie\AppData\Roaming\Dashlane) - Dashlane.exe : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A9F603B-51A8-4630-AE99-4BBF01675575}] - (C:\Program Files (x86)\Foxit Software\Foxit Reader\) - FoxitReader.exe : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\FoxitReaderBrowserAx.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9d7b25eb-a156-456e-baf1-1801f1751a52}] - (C:\Users\Jean-Marie\AppData\Local\Amazon Music) - Amazon Music.exe : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD41E1A5-99E5-41BA-8703-6BE974416118}] - (C:\Program Files (x86)\Nero\Nero 2016\Nero Burning ROM\) - nero.exe : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F05E0524-ED06-43A7-BB08-04FEF67C7D11}] - (C:\Program Files (x86)\Dashlane) - Dashlane_launcher.exe : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDD14F6-78DA-49E7-A868-85EC771148EE}] - (C:\Program Files (x86)\MediaSerchIE) - m8i8Rxaq.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{003B91A6-61E3-4591-891D-01E94C8CB11E}] - (C:\Program Files\Microsoft Silverlight\5.1.50907.0\) - Silverlight.Configuration.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] - (C:\Program Files\Common Files\Microsoft Shared\Ink) - tabtip.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] - (C:\Windows\System32) - wpcer.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] - (C:\Windows\System32) - wuapp.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework64\v2.0.50727) - dfsvc.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0935-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework64\v2.0.50727) - dfsvc.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1ec76a37-1762-46ff-9b14-765b3e6793be}] - (C:\Program Files\Microsoft Silverlight\5.1.50907.0\) - agcp.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2391d819-9d17-44ec-9ac1-f6aa07549469}] - (%systemroot%\system32) - wermgr.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] - (C:\Program Files\Internet Explorer) - ieinstal.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29907af0-44fd-4598-9b66-c21a735d1a53}] - (C:\WINDOWS\system32\spool\DRIVERS\x64\3) - E_IPRELPE.EXE : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2dec4925-1312-4d7f-a6f5-89272d848dcf}] - (%WINDIR%\system32\IME\IMEJP\) - IMJPUEX.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{357FBE87-6C8E-490D-A059-4746C864AE6F}] - (C:\Program Files\Common Files\Microsoft Shared\Ink) - InputPersonalization.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38f2c092-34df-4c12-9d9e-c9679bf0ab31}] - (C:\Windows\SysWOW64) - presentationhost.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3ab87659-1d5b-47cc-83a1-6e1e3df9007a}] - (C:\WINDOWS\system32\spool\DRIVERS\x64\3) - E_IARNLPE.EXE : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B477573-B0C2-4C66-AA40-2890F74B2408}] - (C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\) - NativeMessagingEXE.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49E561B1-1091-4E65-98A0-AFCA4996CD1D}] - (C:\Windows\System32) - RuntimeBroker.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4D256DB0-6C34-4EC1-9704-02182D6503A6}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8381C-2705-4DC2-ADF3-347D4D619350}] - (%WINDIR%\system32\IME\shared) - imecfmui.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61bd7005-d55e-4693-a191-0caa33601426}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{681f008a-b1c3-412d-9d95-e7a68837a6ce}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] - (%ProgramFiles%\Windows Media Player) - wmplayer.exe : %SystemRoot%\system32\wmp.dll[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] - (%ProgramFiles(x86)%\Windows Media Player) - wmplayer.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] - (C:\Program Files\Internet Explorer) - iedw.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{734A9EB3-A34D-4fb7-9DB4-549C28F7EF97}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] - (C:\Windows\System32\) - CertEnrollCtrl.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] - (C:\Windows\System32) - verclsid.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f7bd411-f034-4ac0-9424-224bd7ab4e4e}] - (%WINDIR%\system32\IME\SHARED\) - IMEPADSV.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{812954F9-FAA2-4aee-A9E7-3C4FDE2166A6}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] - (C:\Windows\System32) - ctfmon.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{877467C0-F9E4-4561-84F0-65AA7539833C}] - (C:\Windows\System32) - CredentialUIBroker.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] - (C:\Windows) - helppane.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{989F13EE-B25B-4FAB-9AED-C4336C8CCF0C}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98E3C2D3-E92F-469F-87EB-76054F640517}] - (C:\Windows\System32\IME\SHARED\) - imesearch.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99555a39-07ca-4d86-97a4-749be42f4d1b}] - (C:\WINDOWS\system32\spool\DRIVERS\x64\3) - E_IPRELPE.EXE : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a1ad1bbb-3b33-4260-a74c-5fd8bc1479fc}] - (C:\Windows) - splwow64.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a4fbcbc6-4be5-4c3d-8ab5-8b873357a23e}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5054EC7-B9CB-4ad5-9F95-D8171A6D6BFA}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] - (C:\Windows\SysWOW64\xpsviewer) - xpsviewer.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8E307D0-1522-495E-A8A7-BA1441ECF670}] - (C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\) - FXC_ProxyProcess.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC155DD0-14EE-4F26-86AA-F974045CFE55}] - (C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\Creator) - FXC_ProxyProcess.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{afe26134-8a16-4149-b798-242574f3f4a9}] - (%SystemRoot%\system32\IME\IMETC\) - IMTCPROP.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] - (C:\Windows\System32) - cmd.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] - (%systemroot%\system32) - TSWbPrxy.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ce8abfb5-ed46-41ab-81e1-61b0b4903c0f}] - (C:\WINDOWS\system32\spool\DRIVERS\x64\3) - E_IARNLPE.EXE : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC6F}] - (c:\Program Files (x86)\McAfee\SiteAdvisor) - saUI.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] - (C:\Windows\System32) - notepad.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E62A7A31-6025-408E-87F6-81AEB0DC9347}] - (C:\WINDOWS\system32\) - vsjitdebugger.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea109b0c-6a97-45f0-9eb4-5907dd99b995}] - (%WINDIR%\system32\IME\SHARED\) - imedictupdateui.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] - (C:\Windows\System32) - presentationhost.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f5d04f46-b4b2-4202-a191-f780421b4200}] - (%WINDIR%\system32\IME\IMEJP\) - imjpdct.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa6f0991-f729-4899-b095-d3fbca253cf6}] - () - : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] - (C:\Windows\System32\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] - (C:\Windows\System32\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\E6ADCBB4-97D5-4891-9955-026A20E2A3A7] - (C:\Users\Jean-Marie\AppData\Roaming\get2Clouds\bin\) - get2Clouds.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{003B91A6-61E3-4591-891D-01E94C8CB11E}] - (C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\) - Silverlight.Configuration.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] - (C:\Program Files (x86)\Common Files\Microsoft Shared\Ink) - tabtip.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] - (C:\Windows\SysWOW64) - wpcer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}] - (C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat Elements) - Acrobat Elements.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] - (C:\Windows\SysWOW64) - wuapp.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] - (C:\Windows\microsoft.net\framework\v2.0.50727) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1ec76a37-1762-46ff-9b14-765b3e6793be}] - (C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\) - agcp.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] - (C:\Program Files (x86)\Internet Explorer) - ieinstal.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2dec4925-1312-4d7f-a6f5-89272d848dcf}] - (%WINDIR%\system32\IME\IMEJP\) - IMJPUEX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{357FBE87-6C8E-490D-A059-4746C864AE6F}] - (C:\Program Files (x86)\Common Files\Microsoft Shared\Ink) - InputPersonalization.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B477573-B0C2-4C66-AA40-2890F74B2408}] - (C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\) - NativeMessagingEXE.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49E561B1-1091-4E65-98A0-AFCA4996CD1D}] - (C:\Windows\SysWOW64) - RuntimeBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}] - (C:\Program Files (x86)\adobe\acrobat 7.0\reader) - acrord32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4D256DB0-6C34-4EC1-9704-02182D6503A6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8381C-2705-4DC2-ADF3-347D4D619350}] - (%WINDIR%\system32\IME\shared) - imecfmui.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F17E524-3447-4c7d-8E5F-4EFF31CDE3B7}] - (C:\Program Files (x86)\Common Files\DivX Shared\DesktopService) - DDMService.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61bd7005-d55e-4693-a191-0caa33601426}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{64903E32-AE0B-408D-909C-09A08791F28D}] - (C:\Program Files (x86)\DivX\DivX Web Player) - dwpBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{681f008a-b1c3-412d-9d95-e7a68837a6ce}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] - (%ProgramFiles%\Windows Media Player) - wmplayer.exe : %SystemRoot%\system32\wmp.dll[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] - (%ProgramFiles(x86)%\Windows Media Player) - wmplayer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] - (C:\Program Files (x86)\Internet Explorer) - iedw.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{734A9EB3-A34D-4fb7-9DB4-549C28F7EF97}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] - (C:\Windows\SysWOW64\) - CertEnrollCtrl.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] - (C:\Windows\SysWOW64) - verclsid.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f7bd411-f034-4ac0-9424-224bd7ab4e4e}] - (%WINDIR%\sysnative\IME\SHARED\) - IMEPADSV.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{812954F9-FAA2-4aee-A9E7-3C4FDE2166A6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] - (C:\Windows\SysWOW64) - ctfmon.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{877467C0-F9E4-4561-84F0-65AA7539833C}] - (C:\Windows\SysWOW64) - CredentialUIBroker.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] - (C:\Windows) - helppane.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}] - (C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat) - acrobat.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{989F13EE-B25B-4FAB-9AED-C4336C8CCF0C}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98E3C2D3-E92F-469F-87EB-76054F640517}] - (C:\Windows\SysWOW64\IME\SHARED\) - imesearch.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}] - (C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements) - Acrobat Elements.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a1ad1bbb-3b33-4260-a74c-5fd8bc1479fc}] - (C:\Windows) - splwow64.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a4fbcbc6-4be5-4c3d-8ab5-8b873357a23e}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5054EC7-B9CB-4ad5-9F95-D8171A6D6BFA}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] - (C:\Windows\SysWOW64\xpsviewer) - xpsviewer.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8E307D0-1522-495E-A8A7-BA1441ECF670}] - (C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\) - FXC_ProxyProcess.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC155DD0-14EE-4F26-86AA-F974045CFE55}] - (C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\Creator) - FXC_ProxyProcess.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{afe26134-8a16-4149-b798-242574f3f4a9}] - (%SystemRoot%\system32\IME\IMETC\) - IMTCPROP.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] - (C:\Windows\SysWOW64) - cmd.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] - (%systemroot%\system32) - TSWbPrxy.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8999AED-AECE-4E27-9BCB-5358B13F9FF9}] - (C:\Windows\Microsoft.NET\Framework64\v4.0.30319\) - dfsvc.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC6F}] - (c:\Program Files (x86)\McAfee\SiteAdvisor) - saUI.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] - (C:\Windows\SysWOW64) - notepad.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD41E1A5-99E5-41BA-8703-6BE974416118}] - (C:\Program Files (x86)\Nero\Nero 2016\Nero Burning ROM\) - nero.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e5f90a07-7db7-4dcb-bd6d-d3fecd376ca3}] - (C:\Program Files (x86)\adobe\acrobat 6.0\reader) - acrord32.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E62A7A31-6025-408E-87F6-81AEB0DC9347}] - (C:\WINDOWS\system32\) - vsjitdebugger.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea109b0c-6a97-45f0-9eb4-5907dd99b995}] - (%WINDIR%\sysnative\IME\SHARED\) - imedictupdateui.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] - (C:\Windows\SysWOW64) - presentationhost.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f5d04f46-b4b2-4202-a191-f780421b4200}] - (%WINDIR%\system32\IME\IMEJP\) - imjpdct.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa6f0991-f729-4899-b095-d3fbca253cf6}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] - (C:\Windows\SysWOW64\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] - (C:\Windows\SysWOW64\Macromed\Flash) - FlashUtil_ActiveX.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}] - (C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat) - acrobat.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFCB3198-32F3-4E8B-9539-4324694ED664}] - (C:\Program Files\Adblock Plus for IE) - Adblock.exe : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDD14F6-78DA-49E7-A868-85EC771148EE}] - (C:\Program Files (x86)\MediaSerchIE) - m8i8Rxaq.exe : ---------- | Ext\Settings [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2781761E-28E0-4109-99FE-B9D127C57AFE}] : : %ProgramFiles%\Windows Defender\MpOav.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] : : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{333C7BC4-460F-11D0-BC04-0080C7055A83}] : : C:\Windows\SysWOW64\tdc.ocx[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{40354A83-504E-4611-ACAE-3D137F6F595E}] : : C:\Users\Jean-Marie\AppData\Roaming\Dashlane\ie\Dashlanei.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}] : : C:\Users\Jean-Marie\AppData\Roaming\Dashlane\ie\Dashlanei.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1}] : : C:\Windows\SysWOW64\ieframe.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{669695BC-A811-4A9D-8CDF-BA8C795F261C}] : : C:\Users\Jean-Marie\AppData\Roaming\Dashlane\ie\KWIEBar.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6BF52A52-394A-11D3-B153-00C04F79FAA6}] : : %SystemRoot%\system32\wmp.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A}] : : C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] : : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{BFD9D8A8-57FF-488A-B919-065EC77CF82F}] : : C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] : : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000}] : : C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEAF541-F3E1-4C24-ACAC-99C30715084A}] : : C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FFCB3198-32F3-4E8B-9539-4324694ED664}] : : ---------- | Ext\Stats [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25336920-03F9-11CF-8FD0-00AA00686F13}] : : C:\Windows\SysWOW64\mshtml.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5}] : : C:\skinpack\OldNewExplorer32.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2933BF90-7B36-11D2-B20E-00C04F983E60}] : : %SystemRoot%\System32\msxml3.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{333C7BC4-460F-11D0-BC04-0080C7055A83}] : : C:\Windows\SysWOW64\tdc.ocx[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1}] : : C:\Windows\SysWOW64\ieframe.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{669695BC-A811-4A9D-8CDF-BA8C795F261C}] : : C:\Users\Jean-Marie\AppData\Roaming\Dashlane\ie\KWIEBar.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6BF52A52-394A-11D3-B153-00C04F79FAA6}] : : %SystemRoot%\system32\wmp.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8856F961-340A-11D0-A96B-00C04FD705A2}] : : C:\Windows\SysWOW64\ieframe.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}] : : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}] : : C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEAF541-F3E1-4C24-ACAC-99C30715084A}] : : C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6ADCBB4-97D5-4891-9955-026A20E2A3A7}] : : [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ED8C108E-4349-11D2-91A4-00C04F7969E8}] : : %SystemRoot%\System32\msxml3.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE09B103-97E0-11CF-978F-00A02463E06F}] : : C:\Windows\SysWOW64\scrrun.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}] : : %SystemRoot%\System32\msxml3.dll[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}] : : %SystemRoot%\System32\msxml3.dll ---------- | Browser Helper Objects [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}] -> (Dashlane BHO) : C:\Users\Jean-Marie\AppData\Roaming\Dashlane\ie\Dashlanei.dll ---------- | Chrome [HKLM64\Software\Google\Chrome\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci][HKLM\Software\WOW6432Node\Google\Chrome\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci] ---------- | Opera ---------- | Firefox [HKLM64\Software\mozilla\Firefox\Extensions]"FFExtnHTML2PDF@foxitsoftware.com"=C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi[HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions]"FFExtnHTML2PDF@foxitsoftware.com"=C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi[HKLM64\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0] - (DivX Web Player) : C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf] - () : C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf] - () : C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp] - () : C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf] - () : C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll[HKLM\Software\WOW6432Node\MozillaPlugins\@Nero.com/KM] - () : C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL C:\Users\Jean-Marie\AppData\Roaming\Mozilla\Firefox\Profiles\dco13h36.default\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20170628075643");user_pref("browser.startup.homepage_override.mstone", "54.0.1");user_pref("extensions.blocklist.pingCountVersion", 0);user_pref("extensions.bootstrappedAddons", "{\"aushelper@mozilla.org\":{\"version\":\"2.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\aushelper@mozilla.org.xpi\",\"multiprocessCompatible\":true,\"runInSafeMode\":true,\"dependencies\":[],\"hasEmbeddedWebExtension\":false},\"e10srollout@mozilla.org\":{\"version\":\"1.50\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\e10srollout@mozilla.org.xpi\",\"multiprocessCompatible\":true,\"runInSafeMode\":true,\"dependencies\":[],\"hasEmbeddedWebExtension\":false},\"firefox@getpocket.com\":{\"version\":\"1.0.5\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\firefox@getpocket.com.xpi\",\"multiprocessCompatible\":true,\"runInSafeMode\":true,\"dependencies\":[],\"hasEmbeddedWebExtension\":false},\"screenshots@mozilla.org\":{\"version\":\"6.6.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\screenshots@mozilla.org.xpi\",\"multiprocessCompatible\":true,\"runInSafeMode\":true,\"dependencies\":[],\"hasEmbeddedWebExtension\":false},\"webcompat@mozilla.org\":{\"version\":\"1.1\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\webcompat@mozilla.org.xpi\",\"multiprocessCompatible\":true,\"runInSafeMode\":true,\"dependencies\":[],\"hasEmbeddedWebExtension\":false}}");user_pref("extensions.databaseSchema", 19);user_pref("extensions.e10s.rollout.blocklist", "");user_pref("extensions.e10s.rollout.hasAddon", false);user_pref("extensions.e10s.rollout.policy", "50allmpc");user_pref("extensions.e10sBlockedByAddons", false);user_pref("extensions.e10sMultiBlockedByAddons", false);user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:54.0.1");user_pref("extensions.getAddons.databaseSchema", 5);user_pref("extensions.lastAppVersion", "54.0.1");user_pref("extensions.lastPlatformVersion", "54.0.1");user_pref("extensions.pendingOperations", false);user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}");user_pref("extensions.xpiState", "{\"app-system-defaults\":{\"aushelper@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\aushelper@mozilla.org.xpi\",\"e\":true,\"v\":\"2.0\",\"st\":1498672059317},\"e10srollout@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\e10srollout@mozilla.org.xpi\",\"e\":true,\"v\":\"1.50\",\"st\":1498672059320},\"firefox@getpocket.com\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\firefox@getpocket.com.xpi\",\"e\":true,\"v\":\"1.0.5\",\"st\":1498672060077},\"screenshots@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\screenshots@mozilla.org.xpi\",\"e\":true,\"v\":\"6.6.0\",\"st\":1498672060537},\"webcompat@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\webcompat@mozilla.org.xpi\",\"e\":true,\"v\":\"1.1\",\"st\":1498672059376}},\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi\",\"e\":true,\"v\":\"54.0.1\",\"st\":1498672059357}},\"winreg-app-global\":{\"FFExtnHTML2PDF@foxitsoftware.com\":{\"d\":\"C:\\\\Program Files (x86)\\\\Foxit Software\\\\Foxit PhantomPDF\\\\plugins\\\\Creator\\\\FirefoxAddin\\\\FFExtnHTML2PDF.xpi\",\"e\":false,\"v\":\"8.1.80\",\"st\":1490113814000}}}"); [Profile0] - Name=default -> Profiles/dco13h36.default ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters]"DhcpNameServer"=192.168.1.1 192.168.1.1[HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{f082584a-8909-4bb8-81f4-a55b0715a133}]"DhcpNameServer"=192.168.1.1 192.168.1.1[HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{f082584a-8909-4bb8-81f4-a55b0715a133}]"DhcpNameServer"=192.168.1.1 192.168.1.1 ---------- | ActiveX [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] - () - -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - () - -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - () - -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] - () - -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - () - -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] - () - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player) - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\inf\unregmp2.exe /ShowWMP[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player 12.0) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] - (Offline Browsing Pack) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - (Microsoft Windows) - -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] - (DirectDrawEx) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] - (Internet Explorer Help) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] - (Microsoft Windows Script 5.6) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] - (Internet Explorer Setup Tools) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] - (Browsing Enhancements) - -> %SystemRoot%\system32\msieftp.dll[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - (Microsoft Windows Media Player) - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /FirstLogon[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] - (MSN Site Access) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] - (Address Book 7) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] - () - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - (Web Platform Customizations) - @C:\Windows\System32\ie4uinit.exe,-2000 -> C:\Windows\System32\ie4uinit.exe -UserConfig[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] - (Google Chrome) - -> "C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level[HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] - (Dynamic HTML Data Binding) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] - (Internet Explorer Core Fonts) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] - (HTML Help) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{E087BCD1-F9A5-32C2-811C-5811D0694333}] - (.NET Framework) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] - (Active Directory Service Interface) - -> [HKLM64\SOFTWARE\Microsoft\Active Setup\Installed Components\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}] - (.NET Framework) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player) - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /ShowWMP[HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] - (Microsoft Windows Media Player 12.0) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] - (Offline Browsing Pack) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] - (Microsoft Windows) - -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE[HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] - (DirectDrawEx) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] - (Internet Explorer Help) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] - (Microsoft Windows Script 5.6) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] - (Internet Explorer Setup Tools) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] - (Browsing Enhancements) - -> %SystemRoot%\system32\msieftp.dll[HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] - (Microsoft Windows Media Player) - @%SystemRoot%\system32\wmploc.dll,-128 -> %SystemRoot%\system32\unregmp2.exe /FirstLogon[HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] - (MSN Site Access) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] - (Address Book 7) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}] - (.NET Framework) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] - () - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] - () - -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install[HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] - (Dynamic HTML Data Binding) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}] - (.NET Framework) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] - (Internet Explorer Core Fonts) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{CA8D3B25-8CCF-32BC-BDF5-3C8E3AB24681}] - (.NET Framework) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] - (HTML Help) - -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] - (Active Directory Service Interface) - -> ---------- | Applications [HKLM64\SOFTWARE\Classes\Applications\devenv.exe] : "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe" "%1"[HKLM64\SOFTWARE\Classes\Applications\firefox.exe] : "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1"[HKLM64\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1[HKLM64\SOFTWARE\Classes\Applications\MovieCreator.exe] : C:\Program Files (x86)\Avanquest\Video Explosion Ultimate\MovieCreator.exe "%1"[HKLM64\SOFTWARE\Classes\Applications\mpc-hc.exe] : "C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe" "%1"[HKLM64\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1[HKLM64\SOFTWARE\Classes\Applications\opera.exe] : "C:\Program Files (x86)\Opera\Launcher.exe" "%1"[HKLM64\SOFTWARE\Classes\Applications\palemoon.exe] : "C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"[HKLM64\SOFTWARE\Classes\Applications\PhotoEditor.exe] : C:\Program Files (x86)\InPixio\InPixio Photo Editor\PhotoEditor.exe "%1"[HKLM64\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen[HKLM64\SOFTWARE\Classes\Applications\VSLauncher.exe] : "C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\VSLauncher.exe" "%1"[HKLM64\SOFTWARE\Classes\Applications\WinRAR.exe] : "C:\Program Files\WinRAR\WinRAR.exe" "%1"[HKLM64\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L"[HKLM64\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\devenv.exe] : "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe" "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\firefox.exe] : "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieCreator.exe] : C:\Program Files (x86)\Avanquest\Video Explosion Ultimate\MovieCreator.exe "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\mpc-hc.exe] : "C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe" "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\opera.exe] : "C:\Program Files (x86)\Opera\Launcher.exe" "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\palemoon.exe] : "C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\PhotoEditor.exe] : C:\Program Files (x86)\InPixio\InPixio Photo Editor\PhotoEditor.exe "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\VSLauncher.exe] : "C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\VSLauncher.exe" "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WinRAR.exe] : "C:\Program Files\WinRAR\WinRAR.exe" "%1"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L"[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | DCOMApplications Name: VUISceneDetectDialog - AppID: {00107395-9173-4F52-9258-0A45A1100EC1}Name: User Notification - AppID: {0010890e-8789-413c-adbc-48f5b511b3af}Name: Local Service Credential UI Broker - AppID: {00944ad3-b2ad-4bcf-9202-59bf4662d521}Name: PhotoAcquire - AppID: {00f22b16-589e-4982-a172-a51d9dcceb68}Name: PhotoAcqHWEventHandler - AppID: {00f2b433-44e4-4d88-b2b0-2698a0a91dba}Name: TabTip - AppID: {01419581-4d63-4d43-ac26-6e2fc976c1f3}Name: RoxVideo3DTagManager - AppID: {01CD2ACF-A51D-48D3-BEDF-DF6BA451C157}Name: lfsvc - AppID: {020FB939-2C8B-4DB7-9E90-9527966E38E5}Name: PLA - AppID: {03837503-098b-11d8-9414-505054503030}Name: VUIAudioVideoMMPlugIn - AppID: {03DBB128-2447-4DC6-A0E9-254A9B5922A6}Name: CTapiLuaLib Class - AppID: {03e15b2e-cca6-451c-8fb0-1e2ee37a27dd}Name: Microsoft SQL Server Replication Remote Merge Agent 11.0 - AppID: {042A4340-A4D7-44DD-A22E-93278FB52475}Name: DevicesFlowExperienceFlow - AppID: {046AEAD9-5A27-4D3C-8A67-F82552E0A91B}Name: CELERITASWMSecureShell - AppID: {0545D0D4-6CF7-4088-B65A-65F1EA53A70F}Name: GSService - AppID: {0547389D-9569-41f6-B844-4829FC8001BB}Name: COpenControlPanel - AppID: {06622D85-6856-4460-8DE1-A81921B41C4B}Name: SMLUA - AppID: {0671E064-7C24-4AC0-AF10-0F3055707C32}Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {06C792F8-6212-4F39-BF70-E8C0AC965C23}Name: VCPTextOverlay - AppID: {072408AA-911D-4848-9C0E-12F4FD223281}Name: OOBE Bio Enrollment - AppID: {0771f7af-8de6-4bce-9528-2d4a12cb8168}Name: DVDWelcomeDialog - AppID: {07A4CD3F-C94E-4BC0-9168-197C9614A02E}Name: sppui - AppID: {0868DC9B-D9A2-4f64-9362-133CEA201299}Name: Retail Demo User COM Agent - AppID: {0886dae5-13ba-49d6-a6ef-d0922e502d96}Name: RtkApoApi - AppID: {08B039CA-84AA-40EA-8E9C-1D9537DC415B}Name: WIA Extension Host for 64 bit extensions - AppID: {08F646B3-5E7F-4B7A-A5CB-F95445F9F67A}Name: Proximity Sharing - AppID: {08FC06E4-C6B5-40BE-97B0-B80F943C615B}Name: PersistentZoneIdentifier - AppID: {0968e258-16c7-4dba-aa86-462dd61e31a3}Name: Windows Media Player Rich Preview Handler - AppID: {09C5C2B5-1D32-4598-B87E-203F32BB08E3}Name: SEAPO - AppID: {0A21D954-674A-4C09-806E-DB4FBE8F199C}Name: AxInstSv - AppID: {0B15AFD8-3A99-4A6E-9975-30D66F70BD94}Name: NotificationController App ID - AppID: {0B789C73-D8DA-416D-B665-C1603676CEB1}Name: RASDLGLUA - AppID: {0C3B05FB-3498-40C3-9C03-4B22D735550C}Name: %SystemRoot%\system32\appwiz.cpl - AppID: {0da7bfdf-c0a0-44eb-be82-b7a82c4721de}Name: NeroShellExt - AppID: {10EBE05D-77B3-4C15-9080-6002AFD08B48}Name: MACustomSource - AppID: {11F92289-DFDF-4DA5-83FA-DE8F66E79060}Name: Sync Center Client - AppID: {1202DB60-1DAC-42C5-AED5-1ABDD432248E}Name: Virtual Factory for DiagCpl - AppID: {12C21EA7-2EB8-4B55-9249-AC243DA8C666}Name: Shell Create Object Task Server - AppID: {133eac4f-5891-4d04-bada-d84870380a80}Name: Shell Create Object Handler - AppID: {135fd325-45b7-4c30-89f8-4386961669f0}Name: ShareAPI - AppID: {13C9FC73-0581-4C59-B45D-8968266E31B7}Name: TPM Virtual Smart Card VCard Module Manager - AppID: {150F28F1-49A5-4C28-BE1A-CFA854A1D04B}Name: Remote TPM Virtual Smart Card Manager - AppID: {152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}Name: VssMgr - AppID: {15B49E67-122E-4D57-9EE2-199A0026DA76}Name: RuntimeBroker - AppID: {15c20b67-12e7-4bb6-92bb-7aff07997402}Name: TPM Virtual Smart Card Manager - AppID: {16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}Name: Speech Runtime COM - AppID: {1725704B-A716-4E04-8EF6-87ED4F0A180A}Name: AutorunsScannerPlugin - AppID: {185582CD-AAEE-499E-848D-242C032B440A}Name: WsDrvInst - AppID: {1909e113-997e-4759-baa3-bcb780797176}Name: Immersive TPM Virtual Smart Card Manager - AppID: {19833350-BF9B-42A1-BDF0-BD1FCBE1FD31}Name: Sync Center Control - AppID: {1A1F4206-0688-4E7F-BE03-D82EC69DF9A5}Name: GIDS Smart Card Simulator Manager - AppID: {1AC32B1A-E379-4CAD-B655-F978A30856EC}Name: NAUpdate - AppID: {1AC9CDC0-9D87-4371-9DE7-65C3F39AE5E6}Name: %systemroot%\system32\lpksetup.exe - AppID: {1C749B87-568C-4865-8E73-6413F8372CE6}Name: Disc soft DT Lite bus service - AppID: {1CA3841D-15B5-4C70-9751-7A87730A1BE9}Name: dataStream - AppID: {1CB37889-925E-435C-9E52-962EAB3B03CC}Name: RUExt - AppID: {1D928D64-60D3-4FAC-B810-C4D9D8A680CF}Name: Office Licensing COM Server 16 - AppID: {1E886174-DC88-4B83-8BC5-66409EC75F16}Name: Disc soft DT Pro bus service - AppID: {1E9D16CB-FF03-481F-ABE2-F406C2808FE2}Name: MyEpson Portal Service - AppID: {1EA8AE6B-3E49-4C56-B4F6-91BC83604BEB}Name: TIManagersProxy Class Application - AppID: {1EF75F33-893B-4E8F-9655-C3D602BA4897}Name: rshx32.dll - AppID: {1f2e5c40-9550-11ce-99d2-00aa006e086c}Name: ThirdPartyEapDispatcherPeerConfig - AppID: {1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}Name: Microsoft WMI Provider Subsystem Secured Host - AppID: {1F87137D-0E7C-44d5-8C73-4EFFB68962F2}Name: UACObject - AppID: {1F9BF350-B68F-4DCA-8B87-707E26DC7390}Name: DetectionAndSharing - AppID: {1fda955b-61ff-11da-978c-0008744faab7}Name: Microsoft Software Protection Platform Admin Object (Inner) - AppID: {205609B7-5E08-443E-B0A7-A7AED3F3A717}Name: Microsoft Windows WSMan Provider Host With User Settings - AppID: {209444d2-2540-495e-962c-a61ad3243526}Name: Provisioning Core - AppID: {217700E0-0000-11DF-ADB9-F4CE462D9137}Name: MSDAINITIALIZE - AppID: {2206CDB0-19C1-11D1-89E0-00C04FD7A829}Name: Dispatch - AppID: {224FC5DE-26AD-4A47-A2C3-5A50885F314C}Name: VUIMakeMovie - AppID: {242437CB-9DC1-43E2-A8F3-1D03300C16F0}Name: CortanaExperienceFlow - AppID: {24AC8F2B-4D4A-4C17-9607-6A4B14068F97}Name: Experimentation Broker - AppID: {2568BFC5-CDBE-4585-B8AE-C403A2A5B84A}Name: VCPEffects - AppID: {25C0D16E-F584-4181-965F-2E2D8E1D816D}Name: InstallAgent - AppID: {260eb9de-5cbe-4bff-a99a-3710af55bf1e}Name: Microsoft WBEM Active Scripting Event Consumer Provider - AppID: {266C72E7-62E8-11D1-AD89-00C04FD8FDFF}Name: IMAPI2 - AppID: {273541FF-7F64-5B0F-8F00-5D77AFBE261E}Name: WInRTDesktopBroker - AppID: {27550CA0-E9DE-4186-A566-37A59BB6CA69}Name: Cloud Change Wnf Monitor - AppID: {276D4FD3-C41D-465F-8CA9-A82A7762DF32}Name: netman - AppID: {27AF75ED-20D9-11D1-B1CE-00805FC1270E}Name: WalletService - AppID: {27D6B72D-094D-445A-9ACE-8298CBA0611A}Name: AERTACap - AppID: {288E7ECC-EB53-45df-8EBD-72EAF9AFCB00}Name: InstallAgentUserBroker - AppID: {28d08f70-46eb-4f26-a6cb-54b75132e100}Name: ImageHost - AppID: {2903EDD7-545F-4156-977A-5E730E57F253}Name: RasMobilityManager - AppID: {292bed96-e9ce-40f8-b71b-c313defa3a78}Name: SITInstallWrapperEXECOM - AppID: {2A1E68FB-F00A-4C05-8871-EA37BA583FF4}Name: ReviverSoft Smart Monitor Service - AppID: {2A2423AE-1AD9-4B60-A021-BBD75766C2FD}Name: UACObject - AppID: {2A39E11E-7FDE-45b1-99C6-B9E557D3ABA1}Name: DSThemeViewCtl - AppID: {2B399D9D-9A9B-4498-A36D-E68B2945D0E9}Name: TeamViewer Service - AppID: {2B433F44-5456-42FF-8CBD-54E8176ECD01}Name: player - AppID: {2B67B4B3-A0E4-4839-83FD-1C2B4ACF32A1}Name: faultrep.dll - AppID: {2C256447-3F0D-4CBB-9D12-575BB20CDA0A}Name: FileSystemImage - AppID: {2C941FD1-975B-59BE-A960-9A2A262853A5}Name: WinZip Smart Monitor Service - AppID: {2CA75AD3-A844-4DF9-999D-CB82069C55C3}Name: DTS Package Host (32-bit) - AppID: {2CB1C2AA-A8EA-41CD-B439-25F4F4C846A9}Name: RegistrySettingsScannerPlugin - AppID: {2E26FE83-4468-428F-8D99-62434EEA9105}Name: CreateProjectWizard - AppID: {2E9B628E-73CA-4EAB-933B-2F1751D9527E}Name: WalletService - AppID: {2EA38040-0B9C-4379-87FD-4D38BB892F37}Name: ConvertToPDFShellExtension - AppID: {2EAE6086-084B-4C42-B2CA-B30549B3D047}Name: Windows Security Health Service - AppID: {2EB6D15C-5239-41CF-82FB-353D20B816CF}Name: DevicesFlow - AppID: {2F93C02D-77F9-46B4-95FB-8CBB81EEB62C}Name: Immersive Shell Broker - AppID: {2FD08A73-D1F1-43EB-B888-24C2496F95FD}Name: ShellServiceHostBrokerProvider - AppID: {30AD8C8E-AE85-42FA-B9E8-7E99E3DFBFC5}Name: Identity Store - AppID: {30d49246-d217-465f-b00b-ac9ddd652eb7}Name: AuthHost - AppID: {31337EC7-5767-11CF-BEAB-00AA006C3606}Name: Immersive Shell - AppID: {316CDED5-E4AE-4B15-9113-7055D84DCC97}Name: MediaSelector - AppID: {328A6B63-78E2-432A-BA33-0CFA92F7DB63}Name: StitchWizard - AppID: {3290FC65-907E-4F06-A418-796309C319AC}Name: Delivery Optimization Mgmt - AppID: {338B40F9-9D68-4B53-A793-6B9AA0C5F63B}Name: Language Components Installer Com Handler - AppID: {33ADC7D5-BAF1-4661-9822-1FD23E63B39F}Name: RstLogon - AppID: {34D4FBDB-CC26-4C51-84A0-32CFD4C886BF}Name: wpnservice - AppID: {34E76A18-223B-4E23-BEAD-F59358CC0A90}Name: CoreDpusSvr - AppID: {36234D6F-D9B8-404B-91C9-736BD2EE3040}Name: Windows Push Notification Platform - AppID: {362cc086-4d81-4824-bbb5-666d34b3197d}Name: Microsoft SQL Server Replication Logreader Agent 11.0 - AppID: {368C2E48-7E89-4970-94C9-6757E96C49AF}Name: TabTip - AppID: {36938566-B1AA-4E77-9B3F-730CF4E996AB}Name: Security Health Agent Activate As Activator Host - AppID: {37096FBE-2F09-4FF6-8507-C6E4E1179893}Name: Delivery Optimization - AppID: {379001DE-7108-4A45-8A74-6CD0A9FBEF2C}Name: Microsoft Portable Workspace Launcher - AppID: {37B73D7B-A976-43AE-97E4-BD4977B241F2}Name: RstCatNotifications - AppID: {3A59FBF1-C30E-41CE-8A46-2EB302468ED2}Name: CortanaMapiHelper - AppID: {3BFADDE5-09ED-42AE-8190-2E68B650CFE6}Name: WorkspacePolicyProcessor - AppID: {3C3F40BC-60EB-4567-B90C-480C87C21AC1}Name: EEL64A - AppID: {3D5781D9-B2FF-4396-8478-395412020995}Name: Microsoft.VisualStudio.ProductKeyDialog - AppID: {3DC42F2C-AD30-461E-B877-11C917E8FE20}Name: StarBurnXLib - AppID: {3DD7EA49-B5E1-4493-895D-C73562138FC0}Name: SITDiskShredCom - AppID: {3DDE8484-00B3-410A-85D8-B222EACE8D02}Name: CMLUAUTIL - AppID: {3E000D72-A845-4CD9-BD83-80C07C3B881F}Name: Microsoft Windows Remote Shell Host - AppID: {3e5ca495-8d6a-4d1f-ad99-177b426c8b8e}Name: CMSTPLUA - AppID: {3E5FC7F9-9A51-4367-9063-A120244FBEC7}Name: WinInetCacheServer - AppID: {3eb3c877-1f16-487c-9050-104dbcd66683}Name: VideoShower - AppID: {3EEAD8BF-4B43-454B-A047-300EE661CAEB}Name: Out Of Proc Mapi Handler - AppID: {3F5E4B87-C907-4f76-82E4-6FDF0CE90E25}Name: PhotoCapture - AppID: {3F85617F-070D-42D0-9B20-ED66E925BB98}Name: Microsoft Windows WSMan Provider Host - AppID: {3feb2f63-0eec-4b96-84ab-da1307e0117c}Name: HTML Application - AppID: {40AEEAB6-8FDA-41e3-9A5F-8350D4CFCA91}Name: Connected User Store - AppID: {40AFA0B6-3B2F-4654-8C3F-161DE85CF80E}Name: NaturalAuthentication - AppID: {412E0F20-6C5B-43EC-879F-DA444A416EAC}Name: AERTARen - AppID: {41C98373-FE7F-4a42-B694-34CC4F979E61}Name: EntAppSvc - AppID: {42C21DF5-FB58-4102-90E9-96A213DC7CE8}Name: VSPerfControl - AppID: {42F36251-2EB6-4026-88A0-3A4A0B508046}Name: RxAET - AppID: {43203B03-872B-4990-8AF6-689B126BB7B1}Name: AccessibilityCplAdmin - AppID: {434A6274-C539-4E99-88FC-44206D942775}Name: RegistryDefrag - AppID: {435AC3EC-C213-4700-9FE2-C417AC8E813B}Name: SPP External COM Object - AppID: {44831FEC-DC51-4716-A7E1-E898FDF83C85}Name: Thumbnail Extraction Host Class - AppID: {4545dea0-2dfc-4906-a728-6d986ba399a9}Name: Add to Windows Media Player list - AppID: {45597c98-80f6-4549-84ff-752cf55e2d29}Name: Application Activation Manager - AppID: {45BA127D-10A8-46EA-8AB7-56EA9078943C}Name: PIFUAC - AppID: {45CB30B1-B453-488a-9E8F-CE3C2ABFAAA7}Name: Set Network Location Elevated Virtual Factory - AppID: {46B988E8-BEC2-401F-A1C5-16C694F26D3E}Name: RXAVCHDCapture13 - AppID: {47307934-52AF-4292-803C-EBEDE9A7A4FD}Name: Radio Management Service - AppID: {478B41E6-3257-4519-BDA8-E971F9843849}Name: EEG64A - AppID: {47EC1E17-F30B-430b-B9C4-DF60ED501A4B}Name: EmailWizard - AppID: {4809C73B-1E36-4710-9912-E994FB2E3422}Name: ShellServiceHost - AppID: {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}Name: IASDataStoreComServer - AppID: {48da6741-1bf0-4a44-8325-293086c79077}Name: RMFMediaObjects - AppID: {494F3102-AFCE-4A56-85D0-16C90B70AA28}Name: COM_SRS_HP360 - AppID: {49611624-F1A3-4AA7-8A06-0209D7D6BA92}Name: Microsoft WBEM Unsecured Apartment - AppID: {49BD2028-1523-11D1-AD79-00C04FD8FDFF}Name: Telephony App Launcher - AppID: {49EBD8BE-1A92-4A86-A651-70AC565E0FEB}Name: UIAutomationCrossBitnessHook64 Class - AppID: {49f171dd-b51a-40d3-9a6c-52d674cc729d}Name: IndexedDbCacheServer - AppID: {49f6e667-6658-4bd1-9de9-6af87f9faf85}Name: Virtual Factory for Languages Configuration - AppID: {4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}Name: VCGRenderingServices - AppID: {4A4264D7-1F2F-4ED8-B2E6-487679F5E614}Name: RASGCWLUA - AppID: {4A6B8BAD-9872-4525-A812-71A52367DC17}Name: wercplsupport.dll - AppID: {4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}Name: MAFilters - AppID: {4BC72581-DE6E-4554-99E1-71D12ACABED7}Name: hippoedit - AppID: {4CACFC77-FAFA-4852-AF35-4C270AC2403B}Name: CategoryFactory - AppID: {4CD538D9-D9D3-4EA1-BB24-BEA3661AFF07}Name: AszBrowseHelper - AppID: {4D0EF64C-71D3-4A05-93B1-8EC58AE8D6D9}Name: Shell Security Editor - AppID: {4D111E08-CBF7-4f12-A926-2C7920AF52FC}Name: DTS Task Host (32-bit) - AppID: {4D3E4495-4A1C-4AB6-BFCB-E4056EB546D0}Name: Dispatch - AppID: {4D5F23BB-D55A-4961-9BC0-3FE728E15D9D}Name: Microsoft Volume Shadow Copy Service software provider - AppID: {4db9c793-c48d-449c-9754-46027ee45c94}Name: COM+ Event System - AppID: {4E14FBA2-2E22-11D1-9964-00C04FBBB345}Name: upnpcont.exe - AppID: {4F0AC159-5804-4aa7-AE91-117D6E67BB9B}Name: MalwareScannerPlugin - AppID: {4F18DDDC-31BF-4567-9BE6-4A36E0BB3897}Name: Shell Computer Accounts - AppID: {4f6bcd94-c2a5-42ce-8dbc-31e794be4630}Name: WkspRT.exe - AppID: {4FCDA643-B15B-41C6-84F8-5E447F6F6D25}Name: DiskDuplicates - AppID: {4FF73765-6547-49E9-9B24-67AEE8F943EE}Name: HomeGroup CPL Advanced Settings Writer - AppID: {50a9ab2a-20f8-4d71-9f32-9fd305b49601}Name: Microsoft Windows Font Folder - AppID: {50d69d24-961d-4828-9d1c-5f4717f226d1}Name: wuapihost - AppID: {50E1C3FD-EC35-490E-9CCF-C68F9AE91919}Name: acppage.dll - AppID: {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}Name: %systemroot%\system32\intl.cpl - AppID: {514B5E31-5596-422F-BE58-D804464683B5}Name: RemoteProxyFactory32 Class - AppID: {53362C32-A296-4F2D-A2F8-FD984D08340B}Name: RemoteProxyFactory32 Class - AppID: {53362C64-A296-4F2D-A2F8-FD984D08340B}Name: 32-bit Preview Handler Surrogate Host - AppID: {534A1E02-D58F-44f0-B58B-36CBED287C7C}Name: Visual Studio Just-In-Time Debugger (Internal) - AppID: {534E4CF4-3249-4842-8D65-A9BEAE0BBEAC}Name: Virtual Disk Service Loader - AppID: {5364ED0E-493F-4B16-9DBF-AE486CF22660}Name: LockScreenContentServer Out of Proc Helper for LockScreenContent Clients - AppID: {536AACFB-5238-4314-B4D4-5B0A2E8B968E}Name: iPodProtocolHandler - AppID: {5450FF76-BDC1-4DB3-98F1-D2E179322BED}Name: ShareFlow - AppID: {549e57e9-b362-49d1-b679-b64d510efe4b}Name: SRS_APO_Universal - AppID: {553C48B2-BA6B-412B-9F8D-2B62B1B912AA}Name: SonicHTTPClient - AppID: {5597311B-73FE-4A0C-971A-8D9D9F9C8FD5}Name: RstMod - AppID: {562EBFF0-A9BF-4764-B901-B7BA6DC86519}Name: DiskScannerPlugin - AppID: {562F845B-A532-470D-9888-3A0C62525973}Name: DSMediaDetEx - AppID: {5652BD67-DFA5-412E-B693-4AF2FB3E7886}Name: ShapeCollector - AppID: {56676660-4A4D-45B0-B24E-9CF6B35E9ABF}Name: Volume Shadow Copy Service - AppID: {56BE716B-2F76-4dfa-8702-67AE10044F0B}Name: Elevated System Settings COM Host - AppID: {57360832-5F9B-4190-8467-000D2D510212}Name: PSActivityPanes - AppID: {57F3CA01-D88B-47E5-B20B-B1177886420D}Name: PrintNotify - AppID: {588E10FA-0618-48A1-BE2F-0AD93E899FCC}Name: FaxCommon Class - AppID: {59347292-B72D-41F2-98C5-E9ACA1B247A2}Name: PfShellExtension - AppID: {59A55EF0-525F-4276-AB62-8F7E5F230399}Name: Authentication UI Terminal Services Bump Dialog - AppID: {59c7f6ec-7d18-412f-a68e-877982768e61}Name: Docking.VirtualInput Create Object Server - AppID: {5A4ED3BD-2F40-44B4-93DA-2B5ECC197B26}Name: videoDownloader - AppID: {5AAF474D-1853-47BD-BFED-05252719B7BB}Name: VideosCapture - AppID: {5B5197F9-B334-417E-B387-9BB22C9BDC8B}Name: WalletService - AppID: {5BC7A3A1-E905-414B-9790-E511346F5CA6}Name: Microsoft Maps Background Transfer Service - AppID: {5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}Name: EED64A - AppID: {5C73574D-FC7B-4747-8352-143F011923A0}Name: GraphBuilder - AppID: {5DFD3C39-15B1-40A6-8774-21663E70F0BE}Name: WiaWow64 - AppID: {5E1395B2-B685-44e3-8AED-E2304D85ACD1}Name: Splash screen - AppID: {5EAD00DC-0E8B-497C-BDE8-B9153058CBEF}Name: User OOBE Create User Object Server - AppID: {5f7f3f7b-1177-4d4b-b1db-bc6f671b8f25}Name: UIAutomationCrossBitnessHook32 Class - AppID: {60a90a2f-858d-42af-8929-82be9d99e8a1}Name: wlidcli - AppID: {623D5F5E-2F09-427d-8BD7-64495CD9835D}Name: DSChapterDetectDialog - AppID: {6245273A-0E14-4B7B-AFDA-90FB86C86AF2}Name: LCPrintCalibration11 - AppID: {6260B456-D67E-4DBC-BC0D-6ED94ED18A8B}Name: Sync Center (Private) - AppID: {6295DF2D-35EE-11D1-8707-00C04FD93327}Name: Boot - AppID: {6307AC72-C9EB-4512-A817-79EF64EA182B}Name: PenIMC2 - AppID: {63CE6D27-426A-41F9-8E51-549C1132DAE2}Name: Windows Update Agent - AppID: {653C5148-4DCE-4905-9CFD-1B23662D3D9E}Name: FwCplLUA - AppID: {6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}Name: VWaveCapture12 - AppID: {659AB6F0-3FC0-48CD-90A3-BCA71DFCE422}Name: VUIProdDataMMPlugIn - AppID: {65C55B27-E210-44A1-9DB6-C5596FA07675}Name: ForceDelete - AppID: {65CC603B-3DBF-4CE2-8FDC-D6B0B52BEF52}Name: tiledatamodelsvc - AppID: {65E2E13A-7110-4912-9F03-9A42E253D8F6}Name: AvAScr - AppID: {66A841F2-956C-4631-BFE7-C90225F417D6}Name: Microsoft Visual Studio 2015 - AppID: {67E88D46-FF81-4E57-8C5E-F270A4F9EA1A}Name: GDIShapeObject - AppID: {684E9AA9-1914-4B55-9DC3-CED5A89D3C94}Name: Background Intelligent Transfer Service - AppID: {69AD4AEE-51BE-439b-A92C-86AE490E8B30}Name: Sync Center Isolation Collection (Private) - AppID: {69F9CB25-25E2-4BE1-AB8F-07AA7CB535E8}Name: CPluginService - AppID: {6AD2BEF6-C03C-4C6F-B6AB-EDCB617FB8CB}Name: RoxShellView - AppID: {6AD7E2F9-DACC-4B07-A085-8F6BCD7D756F}Name: PDFPreviewHandlerHost - AppID: {6B127CFD-C642-4338-BC8C-472DF61E5A14}Name: MsRdpSessionManager - AppID: {6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F}Name: PSEditDocument - AppID: {6BB520C3-6C7B-4CDB-B211-05119D6621D3}Name: Preview Handler Surrogate Host - AppID: {6d2b5079-2f0b-48dd-ab7f-97cec514d30b}Name: UPnPContainer - AppID: {6d8ff8e0-730d-11d4-bf42-00b0d0118b56}Name: UPnPContainer64 - AppID: {6d8ff8e8-730d-11d4-bf42-00b0d0118b56}Name: SPPComApi - AppID: {6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}Name: TieringEngineService - AppID: {6DF5BCF4-22E9-446D-8763-A2C7677ECF7D}Name: AutoItX3 - AppID: {6E8109C4-F369-415D-AF9A-2AEEFF313234}Name: HomeGroup UI Status - AppID: {6f33340d-8a01-473a-b75f-ded88c8360ce}Name: SEMgrSvc - AppID: {6F4B8D94-91FE-4665-B1E7-A34AE3F299F6}Name: IEWindows - AppID: {6f5bad87-9d5e-459f-bd03-3957407051ca}Name: EditionUpgradeHelper - AppID: {6F65B602-F798-4094-8A41-A2A61961E5E8}Name: HomeGroup Provider Object - AppID: {6F7C8E8F-DC69-4e3f-BC05-439962A05FD5}Name: Windows Insider Service - AppID: {7006698d-2974-4091-a424-85dd0b909e23}Name: DILElevationProxy12 - AppID: {70C4A096-96BC-4A5E-9D24-22A47F58C243}Name: VUIDVDProjectMMPlugin - AppID: {70F32D5D-6782-4059-8032-A9BE635C53ED}Name: workfolderssvc - AppID: {712cedb9-16a4-4f79-801d-7de24d8c706e}Name: WebUploadProtocolHandler - AppID: {725527F1-1D09-4539-869E-40EBFB7AAECC}Name: Sharing Elevated Virtual Factory - AppID: {72A7994A-3092-4054-B6BE-08FF81AEEFFC}Name: User Profile Service DCOM server - AppID: {72E3272B-4EEA-4104-B358-1A282E4FC1AD}Name: Microsoft WMI Provider Subsystem Host - AppID: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}Name: Trusted Installer Service - AppID: {752073A2-23F2-4396-85F0-8FDB879ED0ED}Name: BOTService - AppID: {7562D8CD-775B-4FCF-B877-923A00541B39}Name: PenIMC4 - AppID: {7568952A-571E-4C70-BEA9-7F9004393436}Name: PrintFilterPipelineSvc - AppID: {76db1bf3-e820-4765-a1b2-0b16a86b1950}Name: ChilkatAx - AppID: {77317069-C4A6-4489-BEB9-757AA9525B31}Name: XWizard Virtual Factory - AppID: {777BA81A-2498-4875-933A-3067DE883070}Name: SITPVC - AppID: {786401D2-A2F7-4A1E-B0C4-247015D28B3C}Name: CGActivator - AppID: {78798E4D-7202-453C-9970-06F15B3AEADC}Name: CLMLSvc_P2G11 - AppID: {79454E97-52CD-4517-B6A1-43A1D3C5FDAC}Name: SITShellExLibrary - AppID: {79512DE8-3A0D-4DCA-801F-EE8B75A48487}Name: Dispatch - AppID: {7953C53B-4031-43ca-9AE7-033F565EFD5F}Name: WebPlatStorageBrokerServer - AppID: {7966b4d8-4fdc-4126-a10b-39a3209ad251}Name: Network and Sharing Center Cpl Elevated Virtual Factory - AppID: {7A076CE1-4B31-452a-A4F1-0304C8738100}Name: Shell FMIFS Wrapper - AppID: {7aa7790d-75d7-484b-98a1-3913d022091d}Name: EapThirdPartyDllHost - AppID: {7B130458-E09C-4823-A8AF-2583DCD9AEC7}Name: Internet Explorer Add-on Installer - AppID: {7B29F495-0F55-49F7-8885-9E8A22CE3829}Name: Shell Create Object Local Server - AppID: {7B6EA1D5-03C2-4AE4-B21C-8D0515CC91B7}Name: AppFramework.Services.ProductionManagerOutProc - AppID: {7c1b0cb3-32c3-4af9-85de-109385acb27d}Name: WlanPrefLUA - AppID: {7C8AB6D9-8764-4033-8F62-2FE896E54B32}Name: Microsoft Windows Remote Shell Host With User Settings - AppID: {7d378de6-ed8d-426d-91df-0273d07cd7f6}Name: HomeGroup Printing Device Class - AppID: {7DF8EF76-D449-485f-B4EB-58DC96B31EDB}Name: MMC Application Class - AppID: {7e0423cd-1119-0928-900c-e6d4a52a0715}Name: Security Health Agent Interactive User Host - AppID: {7E55A26D-EF95-4A45-9F55-21E52ADF9887}Name: Battery Notification Manager - AppID: {7EAD5C10-8B3F-11E6-AE22-56B6B6499611}Name: Dispatch - AppID: {7EB545FB-872B-4286-B4E2-96B3A64EEC57}Name: wisptis - AppID: {7F429620-16D1-471E-A81A-114992148034}Name: Authentication UI CredUI Out of Proc Helper for AppContainer Clients - AppID: {7FC12E96-4CB7-4ABD-ADAA-EF7845B10629}Name: SonicLicenseManager - AppID: {7FD05526-51A1-48F3-AD6D-1CEAF766CC73}Name: RecuvaShell - AppID: {80109467-DE5A-42A1-9445-7E3952C80B6E}Name: AdAwareShellExtension - AppID: {815E3070-A914-4A36-BC40-2F35AAD1C91E}Name: RoxAlbumView - AppID: {81DCFE66-2452-41FB-8DC7-36212F7E8C67}Name: CFmIfsEngine host - AppID: {82D94FB3-7FE6-4797-BB72-9A886C66073B}Name: Wondershare.AppFrame.Client - AppID: {83045d03-658e-471c-ac48-edf4cb87f1a7}Name: MVSNClientDownloadManager61Lib - AppID: {830DB37A-B286-4092-9758-9934982F2004}Name: AdminUtils - AppID: {83435DBB-C4A6-4678-98DA-EF1AA2C6570E}Name: CatCtx - AppID: {83B7BC6F-EE9B-40C3-99AB-5DCDCE0BA8CE}Name: CustReg Class - AppID: {84D586C4-A423-11D2-B943-00C04F79D22F}Name: TeamViewer Application - AppID: {850A928D-5456-4865-BBE5-42635F1EBCA1}Name: BOTRPdch - AppID: {86780D98-7991-4AE9-A899-32FB59C7664C}Name: AnaglyphMaker - AppID: {86CE6DC7-623C-4CF8-9FDF-7A9ADCB6983D}Name: Virtual Factory for Usercpl - AppID: {86d5eb8a-859f-4c7b-a76b-2bd819b7a850}Name: CElevateWlanUi - AppID: {86F80216-5DD6-4F43-953B-35EF40A35AEE}Name: ThirdPartyEapDispatcherPeerRuntime - AppID: {87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}Name: AppReadiness Service - AppID: {88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}Name: ASPSPrevControls12 - AppID: {888CD72E-5641-4F09-AEF1-63D18420960B}Name: PSSourcePanes - AppID: {88F11398-86EC-44EC-9BF0-E6843596C09F}Name: CavWp - AppID: {895A8A5F-FE77-4089-AF43-354D81EF1099}Name: EventsScannerPlugin - AppID: {89A5984F-7B05-4725-9FF8-038CD897F77D}Name: Activation Manager Shim - AppID: {8A9AE632-CB07-4A11-8872-358A2A271A24}Name: Desktop Wallpaper Factory - AppID: {8B30085D-A3E3-44e3-AE7F-B03A1340EBED}Name: Windows Management and Instrumentation - AppID: {8BC3F05E-D86B-11D0-A075-00C04FB68820}Name: TSTheme - AppID: {8be0366c-8522-40be-8b08-cb26557f2854}Name: ObexDevice - AppID: {8C075C55-F8D2-4DFA-AFFF-145EE350D319}Name: IASExtensionHost - AppID: {8C334A55-DDB9-491C-817E-35A6B85D2ECB}Name: RoxSKUAboutDlg - AppID: {8C6A8155-79C9-4EE1-8CDF-8984B3278F4E}Name: Microsoft Visual Studio - AppID: {8CD2DD97-4EC1-4bc4-9359-89A3EEDD57A6}Name: AP Client HxHelpPaneServer Class - AppID: {8cec58ae-07a1-11d9-b15e-000d56bfe6ee}Name: TiWorker - AppID: {8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}Name: Sync Center Schedule Wizard - AppID: {8D8B8E30-C451-421B-8553-D2976AFA648C}Name: WalletService - AppID: {8E44A57C-5638-44D3-9B83-34DF70EB57F2}Name: ScrRecX - AppID: {8E568865-5A19-4822-B682-41762E732560}Name: RdpSa - AppID: {8e7fae4d-cff0-41d3-a326-5a80470264bb}Name: MAAudioEffects - AppID: {8ED23FB9-F922-4036-8CA3-7A9A8DC3B712}Name: Shell Computer Groups - AppID: {8f3080a6-af99-4f2e-a806-f3d5702a0444}Name: SDRSVC service - AppID: {9037e3cf-1794-4af6-9c8d-92838d7a23db}Name: ErrorStack - AppID: {906277F7-4361-4D27-9ECA-70D8C4448FA9}Name: Microsoft.Windows.Simulator.UtilitiesElevated AppID - AppID: {907FF85D-B346-40F6-94D8-10D908817647}Name: UACObject - AppID: {90B553F3-415D-44D8-8665-C2F78763F8F1}Name: SQLTaskConnections - AppID: {91A708A7-D12F-4B03-B8D0-DDE814119454}Name: WindowsSimulatorServiceFactory - AppID: {91F0793A-CD98-4304-BCA2-654A2786F328}Name: Virtual Factory for Recovery - AppID: {9200689A-F979-4eea-8830-0E1D6B74821F}Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients - AppID: {924DC564-16A6-42EB-929A-9A61FA7DA06F}Name: RtkPgExt - AppID: {92842063-1ECC-4a1a-9343-9A8E1C972E60}Name: HtmlLocalFileResolver - AppID: {93AAD2A0-036A-4B11-A078-DA8776B38139}Name: OnLineShareWizard - AppID: {94A1E5CB-4CEB-49A1-AA99-AE5209A8ABD7}Name: UiaManager - AppID: {94a38670-983b-459c-87c8-bb6ad617fd74}Name: SchedulerTaskMgr - AppID: {9586847C-2EF1-4F2A-A8C3-F57B960E62FA}Name: CommonWizards - AppID: {968E2A07-60AD-47AA-8E0C-24129DAEC557}Name: RBVirtualFolder - AppID: {9694EBD9-8ED1-423E-BD1C-2A1DB6A40CC1}Name: WebPlatformStorageServer - AppID: {973d20d7-562d-44b9-b70b-5a0f49ccdf3f}Name: RHAnalysisServices - AppID: {975A6164-891B-47DD-9AA9-0F9E032C0B1B}Name: PrintIsolationHost - AppID: {98a89e0c-1fde-4c2a-a373-b04831e6aa60}Name: Telephony Incoming Call Toast - AppID: {990F07C7-78DC-4BD2-B145-5F791410BDDE}Name: Microsoft SQL Server Replication Remote Dist Agent 11.0 - AppID: {99434DAB-0F08-4F30-8CCF-B3E80296C907}Name: Shell Hardware Mixed Content Handler - AppID: {995C996E-D918-4a8c-A302-45719A6F4EA7}Name: ShellWindows - AppID: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}Name: VUITemplateUser - AppID: {9C0D0317-AF6A-4D1D-9265-C5020F667C8A}Name: ProjectImporter - AppID: {9C3D9531-43A5-4046-A769-35B083B133B8}Name: SonicMediaClient - AppID: {9C6D491B-C314-4996-BF0F-EFFD1D147E21}Name: RuntimeBroker - AppID: {9CA88EE3-ACB7-47c8-AFC4-AB702511C276}Name: PSNavigationPanes - AppID: {9D41EA68-5920-4726-A2F0-7C8085F7713D}Name: VCGCapture - AppID: {9D4285BF-0F1D-4BB2-842D-00DB6969D3E7}Name: chext - AppID: {9D4C4C5F-EE90-4a6b-9245-244C369E4FAE}Name: MalwareHunterContextHandler - AppID: {9D8C0710-8D32-4A42-84E5-210927BC6CB0}Name: PCProxy - AppID: {9DC8FA51-B596-4f77-802C-5B295919C205}Name: timedate.cpl - AppID: {9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}Name: WSearch - AppID: {9E175B9C-F52A-11D8-B9A5-505054503030}Name: WMLSS - AppID: {9E88EF3C-E2BB-4E5E-AFBA-565B81069D7D}Name: Dashlane - AppID: {9F384869-F6AD-41E9-8BD2-CF54BE338D1E}Name: RtkCfg - AppID: {A11009A7-DC01-48F8-B6AA-C4613FC5CB15}Name: WIA Device Manager - AppID: {A1F4E726-8CF1-11D1-BF92-0060081ED811}Name: TrayNotify - AppID: {a2b77517-6d12-4c60-b0c6-725e971ec8fe}Name: rundll32.exe - AppID: {a2d9ca22-a492-400c-b875-78ac25c0a6f3}Name: Virtual Factory for Windows Firewall Cpl - AppID: {A4B07E49-6567-4FB8-8D39-01920E3B2357}Name: Shell ChkdskEx Dialog - AppID: {a4c31131-ff70-4984-afd6-0609ced53ad6}Name: DsmAdminApi - AppID: {A5065670-136D-4FD6-A45F-00C85B90359C}Name: WPDShextAutoplay - AppID: {A55803CC-4D53-404c-8557-FD63DBA95D24}Name: WLIDSvc - AppID: {A6721677-BA21-44E9-9E2A-76466D24D121}Name: Virtual Factory for MaintenanceUI - AppID: {A6BFEA43-501F-456F-A845-983D3AD7B8F0}Name: RCEngine - AppID: {A6E8B488-D0A2-4F26-A9EF-02E2EB533063}Name: Microsoft Windows Defender - AppID: {A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}Name: %SystemRoot%\System32\fveui.dll - AppID: {A7A63E5C-3877-4840-8727-C1EA9D7A4D50}Name: SysFxUi - AppID: {A7D2EC8B-B70F-434C-A0CE-0DF324805F7D}Name: ContextHandler - AppID: {A805009D-B902-439A-8E64-26EE3507A12E}Name: PacketX - AppID: {A80AAEA4-1CDD-422D-AC45-E97FC805FA61}Name: SimpleStar Smart Monitor Service - AppID: {A85EF924-D5E3-4C9F-90A8-524ED861385F}Name: SwapAPODll - AppID: {A85F41D6-156B-470D-B505-110388968D5A}Name: Delivery Optimization Mgmt - AppID: {AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}Name: F12AppFrameClient Class - AppID: {AABAA6AA-5398-4C08-AE60-6321A7F05E9C}Name: DEFRAGSVC service - AppID: {ab7c873b-eb14-49a6-be60-a602f80e6d22}Name: Thumbnail Cache Out of Proc Server - AppID: {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}Name: BDEUILauncher Class - AppID: {AB93B6F1-BE76-4185-A488-A9001B105B94}Name: PaymentsSvc - AppID: {AC05815A-A8D5-434B-B9A8-2FFD162F2B7D}Name: RxPathsResolver - AppID: {AC5295FD-35FA-4EBA-B153-D695D1CF8A1D}Name: RetailDemo Service - AppID: {ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}Name: WPN Srumon Server - AppID: {ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}Name: BOTRstSrv - AppID: {ADF87D33-83C7-4489-A958-38F56156FDC5}Name: RXDVDCapture12 - AppID: {AF2C2162-2C07-44E5-8720-DA0E8B8D11AB}Name: TrayToastActivator - AppID: {AFC732E2-BA57-4B3E-A70A-71371F99B871}Name: WorkspaceBroker Class - AppID: {B06FF84E-0A77-4DD2-A919-0EABD8979DC1}Name: MADynamicEffects - AppID: {B0A32428-4974-44F5-87C8-D90893F4B0BF}Name: TabIps - AppID: {B1445657-5A98-11d9-A4E5-00301BB132BA}Name: DockInterface COM server - AppID: {b21858c6-9711-4257-99c8-5c0084bebce1}Name: Windows Update Agent - Remote Access - AppID: {B366DEBE-645B-43A5-B865-DDD82C345492}Name: AppActivationFailedHandler - AppID: {B3AADFEA-8404-4CBE-A62E-B0B715412C9E}Name: WsAppService - AppID: {b3ce22d7-739b-4dd3-ba38-b67cb26c3ed1}Name: UACObject - AppID: {B49FBDA8-D846-43c4-ACAA-06D7794374C8}Name: RichVideo64 - AppID: {B58B304A-D419-4c50-BE1F-6F6CD234B7EF}Name: RContextMenu - AppID: {B5B6E648-E9F7-4CE3-987C-53FEDA97C1FA}Name: VCGProxyFileManager - AppID: {B6104B07-72DC-49a8-8D2A-BA41C6CBA2A0}Name: BOTCtxMenu - AppID: {B657A9FE-5731-4516-9989-F731A2DAFBB5}Name: EASendMailObj - AppID: {B68B03DD-C8C4-49A6-9ACD-D427E9325754}Name: Found New Hardware Wizard - AppID: {B6A32FE6-E29D-AEAE-A608-D273E40CA34C}Name: WIA Device Manager 2 - AppID: {B6C292BC-7C88-41EE-8B54-8EC92617E599}Name: Com_SRS_TruSurroundHD - AppID: {B6D5C1B8-6F68-4A82-8E20-2D0F3A52BD6A}Name: Sync Center (Private) - AppID: {B8558612-DF5E-4F95-BB81-8E910B327FB2}Name: VCGOutput - AppID: {B8B8DFB0-4D66-4A75-BC1A-6BDC852CB19C}Name: Windows Media Player - AppID: {B8C54A54-355E-11D3-83EB-00A0C92A2F2D}Name: InstalledApplication - AppID: {B91AAE6E-3ACC-4980-95E7-BEFCE65ECBB9}Name: ApplicationActivationImpl - AppID: {B9305506-D05B-4C36-81C5-0E50886C1755}Name: SyncIt - AppID: {B9AD4383-E2FF-4D2E-A032-196BE4566B4E}Name: Application Frame Host - AppID: {B9B05098-3E30-483F-87F7-027CA78DA287}Name: VideoFileToIPOD - AppID: {BA3B76C9-61F7-4419-9F79-A9E3717EFE22}Name: RoxMediaDB - AppID: {BA94BBA5-9AAB-4ACC-80CF-EDD2128EBC70}Name: CloudSer - AppID: {BABD83F8-E723-4D8F-B5D1-B03E1F1108F5}Name: VCUSelect - AppID: {BAE26D5D-CC05-4736-A9EA-CEE4DB6BF296}Name: Event Object Change 2 - AppID: {BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4}Name: DShowEncodeManager11 - AppID: {BBB6CB64-1681-4764-AEC2-64108AB68A8F}Name: SyncHost - AppID: {BBC4356A-F004-4628-A27A-E13D70412B70}Name: Virtual Factory for Power Options Control Panel - AppID: {BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}Name: Setting Sync Task Factory - AppID: {bcbb3f8c-2889-474f-8fb7-904d4a416145}Name: DfsShlEx.dll - AppID: {BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}Name: EditionUpgradeManagerObj - AppID: {BD54C901-076B-434E-B6C7-17C531F4AB41}Name: FoxitPrevHndlr - AppID: {BD5BDF7D-9849-4FEF-AC02-28EE2E7C7C46}Name: RstEvents - AppID: {BD8C1FFE-D556-4CA4-9FB8-2DE221E88F2C}Name: VM IC Heartbeat Service - AppID: {be0fc7f0-f248-4091-a123-34ca29a6901b}Name: Shell AutoPlay Direct - AppID: {BF8841C9-378A-4CAD-B4FC-5091366CBC0D}Name: ShellBrowserWindow - AppID: {c08afd90-f2a1-11d1-8455-00a0c91f3880}Name: LockAppHost Out of Proc Helper for Lock Apps - AppID: {C08B030B-E91C-479D-BEFD-02DDA7FF1BCF}Name: Spectrum - AppID: {C0E1CE99-C981-44A2-AC4C-41036FAC6593}Name: VCPEffects - AppID: {C1DB7C4F-3C5A-4B96-9D33-4FC868D9B0C1}Name: provsvc.dll - AppID: {c2a71820-3463-498f-bab7-4798795a2ff6}Name: DataExchangeHost - AppID: {C2E9756F-8155-4EAC-9ED5-0B690169D412}Name: RetailCoreSystemAgent Service - AppID: {C2EA2356-994C-45AF-BDAE-10796F73BC47}Name: cttunesvr - AppID: {C3A34354-660F-41EE-B072-2AEA5E3A80AF}Name: Microsoft Block Level Backup Service - AppID: {C3B65D83-FB15-4e3f-BA04-097D1E2B5AC1}Name: SecureShell - AppID: {C42CB13B-CA97-468D-9F93-AD1220004E62}Name: APSPluginDialogs12 - AppID: {C43F4675-7821-4993-A65A-396DE2315369}Name: Microsoft IMAPI - AppID: {C49F2185-50A7-11D3-9144-00104BA11C5E}Name: BdeUISrv - AppID: {C4AB7CB7-E735-48FF-AADD-39D09668F444}Name: HomeGroup Listener Service - AppID: {C4CDC408-581C-4480-9FFE-3B1C78D5C20D}Name: Acronis True Image Shell Extension Backend - AppID: {C4E69DB9-E094-483e-B922-E7ADE65FB497}Name: RoxWatch - AppID: {C51172D2-C2FF-43A1-B955-564072C36EB1}Name: LCTaskAssistant - AppID: {C5318BE7-60F1-435C-9EA9-61332696B0E7}Name: Xbox Live Game Saves - AppID: {C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}Name: RstMgr - AppID: {C6169DCF-51E4-4D6B-A38B-2BDBC33626C3}Name: VCPOverlays - AppID: {C627EB41-4FE6-41D1-989E-F8E2E0A072B2}Name: EntAppSvc - AppID: {C63261E4-6052-41FF-B919-496FECF4C4E5}Name: EmailClient Class - AppID: {C6E0A4C8-A933-411E-8068-406C2391665F}Name: FamilySafetyRefreshTask - AppID: {C844C79D-AED8-4DCE-AB25-4D359BED84F8}Name: ConvertToPDFShellExtension_RD - AppID: {C88D8F9A-04DA-4008-B535-375F38366DDA}Name: DVDButtonStyleLibraryDlg - AppID: {C8E8E8B7-619D-4A87-BEB1-D197BF249E3E}Name: TSWbPrxy.exe - AppID: {C92A9617-0EAE-4235-BD2B-84540EF1FFA9}Name: DictationHost Class - AppID: {C945AD06-534F-460C-8CB4-17C33099AF81}Name: Sync Infrastructure - AppID: {C947D50F-378E-4FF6-8835-FCB50305244D}Name: netprofm - AppID: {C96887DA-A652-4426-905E-4A37546F847C}Name: SlideShowWizard - AppID: {C97376FB-0945-4D12-B72A-0D4AF46A060D}Name: editionupgradebroker - AppID: {C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}Name: NavigationControl - AppID: {C97ED374-D06B-4ED7-9AA3-93F8CC79968F}Name: RCM - AppID: {C9F65BA8-1F8F-4382-AE27-C91FFB29275F}Name: RMFDRMObject - AppID: {CA105E5D-E87C-4B48-A625-31512065573E}Name: User OOBE Create Elevated Object Server - AppID: {ca8c87c1-929d-45ba-94db-ef8e6cb346ad}Name: EPTBL - AppID: {CACC252F-95A7-4741-BBE8-FB1F18C2826F}Name: OpenSearch Description Create Search Connector Verb Handler - AppID: {CB1DFE3A-EDFF-4d1f-867D-8ADB02926F4B}Name: PrintIsolationSessionHost - AppID: {CB363445-F453-4C1E-8EE4-BD123C5E394F}Name: UACObject - AppID: {CB43451C-E132-4866-B714-435253C98BBA}Name: EnhancedStorageShell - AppID: {CC70FEAD-94B9-4F76-88CC-004BB068ACDF}Name: sppui - AppID: {CCFDD24D-CEAB-458B-A4F1-F884973395DF}Name: Windows Media Player Burn Audio CD Handler - AppID: {cdc32574-7521-4124-90c3-8d5605a34933}Name: Elevated-Unelevated Explorer Factory - AppID: {CDCBCFCA-3CDC-436f-A4E2-0E02075250C2}Name: EmailObject - AppID: {CDFBD7BA-82CB-4380-B68D-0A404F9C1534}Name: BingDesktopUpdater - AppID: {CE41EBCF-17C0-4307-971E-03FEBCBB7D39}Name: PNPXAssoc.dll - AppID: {cee8ccc9-4f6b-4469-a235-5a22869eef03}Name: sdchange - AppID: {CF254B00-1986-4b24-A92D-463D01F7E395}Name: SmartAlertsService - AppID: {CFD5784E-242E-400E-8357-9DA458F8D51D}Name: Event Object Change - AppID: {D0565000-9DF4-11D1-A281-00C04FCA0AA7}Name: WebShareTranscoder - AppID: {D1C80882-4DF0-4681-90F2-7BDDF0DC4026}Name: Winmgmt MOF Compiler OOP - AppID: {D215781D-019E-4FA0-903D-0CDCDE13A4F5}Name: Color Management - AppID: {D2E7041B-2927-42fb-8E9F-7CE93B6DC937}Name: Bitmap Image - AppID: {D3E34B21-9D75-101A-8C3D-00AA001A1652}Name: Microsoft SQL Server Replication Distribution Agent 11.0 - AppID: {D41192E9-AB13-4A23-AB3B-A5FED98306DB}Name: URLReqService - AppID: {D4859CE9-3B25-4235-8973-A74F5D9A04F2}Name: DVSiTunes - AppID: {D5FEAED3-3444-4CEA-9940-A972FB6726F1}Name: CaptureApp - AppID: {D6199E93-1EE1-47F3-A23D-074C5153142D}Name: Sync Center User Profile Notification Handler - AppID: {D63AA156-D534-4BAC-9BF1-55359CF5EC30}Name: sfFTPLib - AppID: {D6625767-E42E-491C-A919-9A71641572A4}Name: PlugNBurnWizard - AppID: {D69F6A31-1D81-4715-8CBE-218D0BCEFEA4}Name: UACObject - AppID: {D8239E84-D6EC-41dc-B7EA-98CDBF472200}Name: BOTPath - AppID: {D86EA132-5044-4C18-879D-1175F396464C}Name: CloudStorageWizard - AppID: {D8775A07-C529-4EA7-B307-BA7C8CBBDA03}Name: Microsoft Software Protection Platform Admin Object (outer) - AppID: {D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}Name: RegistryScannerPlugin - AppID: {DC064D87-7C2D-4FCE-A6B5-932723747396}Name: IndexedDbBrokerServer - AppID: {dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}Name: Microsoft Volumetric Audio Compositor - AppID: {DD7B2C49-A779-4055-BBD5-7C96F502F97F}Name: BrowserBrokerServer - AppID: {DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}Name: Srumon Server - AppID: {ddcfd26b-feed-44cd-b71d-79487d2e5e5a}Name: EverySyncExplorerOverlay - AppID: {DE4CE140-5838-468B-86C0-A422AC75B092}Name: rundll32.exe - AppID: {de5d803e-5d2a-4b5f-9c63-af25a465cc44}Name: AccStore Class - AppID: {DE5DBCDC-104A-4cbc-A4D5-0C2104A142C5}Name: VCGCaptureFO - AppID: {DE6A6DF4-1D42-4D1C-BB5D-F6E433ED49C2}Name: EAGetMailObj - AppID: {DE73C9C2-1C57-4306-99B9-CBFF7A423DA6}Name: LockScreen Call Broker - AppID: {DE7D3D65-5454-4EF5-9518-776739DAB39F}Name: FoxitThumbnailHndlr - AppID: {E1084781-9CA9-42EF-AC67-140D37CCD97E}Name: Profile Notification Host - AppID: {E10F6C3A-F1AE-4adc-AA9D-2FE65525666E}Name: CavShell - AppID: {E11C8519-5595-4397-B515-AB036DEC467A}Name: Immersive Print Dialog Surrogate - AppID: {E15FBAC2-C276-4523-92CA-561456EBCF3E}Name: RtkAPODll - AppID: {E1D2965E-D32B-4e1c-B9F1-159ACB984258}Name: DefinitionsCategory - AppID: {E1DF0971-80AA-4473-931D-529FD4AABBF8}Name: Windows Update Agent User Interface for Published Applications - AppID: {e30984f1-b02b-4c27-a40f-23d11b8c1212}Name: Scan - AppID: {E32549C4-C2B8-4BCC-90D7-0FC3511092BB}Name: VssProc - AppID: {E39EE780-5E3C-4C02-B801-40F918B51F63}Name: SmartSoundASPlugin - AppID: {E4039489-1EBB-4707-9916-B217F158365A}Name: Execute Unknown - AppID: {e44e9428-bdbc-4987-a099-40dc8fd255e7}Name: Authentication UI CredUI Out of Proc Helper for Non-AppContainer Clients (Failed Mouse In Pointer) - AppID: {E45A56CE-399C-45F0-9E6F-BFAACD3C711F}Name: COM_SRS_WOWHD2 - AppID: {E46D2660-D86E-4B0A-BB61-F0FFE9BBDEB5}Name: upnphost - AppID: {E495081B-BBA5-4b89-BA3C-3B86A686B87A}Name: BatchWizard - AppID: {E5F8F2F3-3D03-4E18-AF45-3F2972C3AFA2}Name: Visual Studio Just-In-Time Debugger - AppID: {E62A7A31-6025-408E-87F6-81AEB0DC9347}Name: TrayDesktopBand - AppID: {E6442437-6C68-4f52-94DD-2CFED267EFB9}Name: Orchestrator Service - AppID: {E7299E79-75E5-47BB-A03D-6D319FB7F886}Name: LeResourceLoader12 - AppID: {E7E9FC71-7389-41E9-A3E4-FFC5EC0D9FC8}Name: UICOM - AppID: {E8054D20-497D-4E16-BF41-6E69FCD381A5}Name: QuickTimeVideoDecoder - AppID: {E8E074E8-B100-4F7A-B145-A971BD8C68E6}Name: wscui.cpl - AppID: {E9495B87-D950-4ab5-87A5-FF6D70BF3E90}Name: Remove Device elevation surrogate - AppID: {E95186C7-7D80-4311-843D-0702CBC8B1E4}Name: File Prop Sheet Page Helper - AppID: {E96767E0-7EAA-45E1-8E7D-64414AFF281A}Name: PanZoomDialog - AppID: {E9D797DA-B835-4B44-8A4B-5421EFCE9532}Name: Exchange Active Sync Policy Manager Broker - AppID: {E9DD849F-B3CF-4614-94BB-CB2696BD34FB}Name: PfShellExtension - AppID: {E9F269D7-7652-41a7-9C53-008CF3B0A943}Name: HomeGroup Provider Service - AppID: {EA022610-0748-4c24-B229-6C507EBDFDBB}Name: %systemroot%\System32\UserAccountControlSettings.dll - AppID: {EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}Name: TextEditorAgent - AppID: {EAE2B659-6043-406C-A3A0-83870EEF71E3}Name: VCPTransitions - AppID: {EB172713-88CA-45AD-A277-1E530C375270}Name: LeResourceIDGenerator12 - AppID: {EB1E4953-BC0C-4C32-A529-B57DF98FE851}Name: Immersive Print Dialog Surrogate - AppID: {EB28E902-728E-42C4-97DC-DA89E144C744}Name: Remote Desktop Services Message Server - AppID: {EB521D7D-4095-4E61-88FB-BF25700F142A}Name: MassDownloader - AppID: {EC44F4D7-22E1-45EB-913A-3AB67DA2C5C6}Name: ComEvents.ComServiceEvents - AppID: {ECABB0C3-7F19-11D2-978E-0000F8757E2A}Name: ComEvents.ComSystemAppEventData - AppID: {ECABB0C6-7F19-11D2-978E-0000F8757E2A}Name: PrintWizard - AppID: {ECD70704-1826-4C4E-8ECA-417542E45BEA}Name: Play with Windows Media Player - AppID: {ed1d0fdf-4414-470a-a56d-cfb68623fc58}Name: WPDProtocolHandler - AppID: {ED2CECE7-11A5-4590-A99C-B76A333E8C19}Name: ImagXpr7 - AppID: {ED512BE6-6629-4FB4-953D-D0C353847163}Name: Windows Media Player Launch - AppID: {ED6BB178-B06A-47ad-98B3-6066E0CF0147}Name: VUISettings - AppID: {ED9A4553-A39F-40A6-A66E-1E2FF415AB27}Name: Share Manager - AppID: {edb5f444-cb8d-445a-a523-ec5ab6ea33c7}Name: MixedRealityCapture - AppID: {EE3C7093-A852-49BA-8AC8-7DFBEC469F72}Name: RichVideo - AppID: {EEDE56D6-82E5-4B98-B99E-D4339825E216}Name: usum - AppID: {EFCAD731-949C-497d-9623-20F3514966F9}Name: CloudExperienceHost Broker AppID - AppID: {efe2d6d8-a81b-41e7-ae77-e5244ab80522}Name: Microsoft Audio Device Graph Server - AppID: {F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC}Name: AvailableNetworksExperienceFlow - AppID: {F2506CD7-82C2-43D9-A1D3-F85F5EFE7D09}Name: Acronis VSS Requestor - AppID: {F282135C-65A6-4A99-80F1-F315BAC76BF4}Name: Virtual Disk Service - AppID: {F290BFB2-1864-45B1-8804-2654194A87E7}Name: FodHelper - AppID: {F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}Name: SPPSurrogate - AppID: {f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}Name: VCU3DCheck - AppID: {F390D210-670E-4CA3-A590-787DB00F8300}Name: notificationui - AppID: {F3A0A2BE-B815-4934-938C-628A9956B7CE}Name: MyPrivilegedObject - AppID: {F3D3A6E1-385A-4A4D-A9D3-071FA9FE5500}Name: NDFAPI - AppID: {F3D3AA8D-EF96-4470-848E-BD70B803047A}Name: PerfCenter Enabler - AppID: {f4be747e-45c4-4701-90f1-d49d9ac30248}Name: sdclt - AppID: {f56b7b2a-5b5a-46d8-b6f9-d927ce34b717}Name: Pen Workspace Discover Broker - AppID: {F5A6ACF4-FFE0-4934-AE1D-5F960EA0AAD9}Name: PeakMeterAx - AppID: {F697C1C9-4074-4985-8CC9-D7DD60DBAC68}Name: WMPNSSCI - AppID: {F74BCE98-9EB4-4022-8317-11C723E5CCF8}Name: CloudExperienceHost Create System Object Server - AppID: {f7fa3149-91e7-43b7-8040-b707688ced1a}Name: logagent - AppID: {F808DF63-6049-11D1-BA20-006097D2898E}Name: WLIDFDP - AppID: {F828BB1A-2FAE-4AC4-AE6F-CAC9B529F996}Name: RAServer - AppID: {F8FD03A6-DDD9-4C1B-84EE-58159476A0D7}Name: WinInetBrokerServer - AppID: {F9717507-6651-4EDB-BFF7-AE615179BCCF}Name: DaemonShellExtImage - AppID: {F9B84490-4C45-4737-82E5-0EA0B1CF5307}Name: NCLUA - AppID: {FA1456D3-4B97-4f9c-8511-2786161DC333}Name: VssEvent - AppID: {FAF53CC4-BD73-4E36-83F1-2B23F46E513E}Name: Shell Hardware Mixed Content Handler Cancelled - AppID: {fb479c02-9ec4-4fed-8599-debe037452cb}Name: RegisterControl - AppID: {FC38B7C8-9E50-497d-A387-7DEBDAD14160}Name: Hotspot Auth Module - AppID: {FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}Name: ESLoadSevice - AppID: {FCA6F20F-92E5-4E74-AC19-D14B59CB1C15}Name: appwiz.cpl - AppID: {FCC74B77-EC3E-4dd8-A80B-008A702075A9}Name: GenericIPE - AppID: {FCD097F6-D45B-47F8-9B9C-F9863AE8D032}Name: Wordpad - AppID: {fd6c8b29-e936-4a61-8da6-b0c12ad3ba00}Name: Microsoft SQL Server Replication Queuereader Agent 11.0 - AppID: {FD737704-43CB-4791-B4DB-EE8CDBC64450}Name: Proximity UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10C}Name: MP UX Host - AppID: {FDA74D11-C4A6-4577-9F73-D7CA8586E10D}Name: HippoEDIT - AppID: {FDE4C27F-D753-41FE-8051-BEC3094B3054}Name: Microsoft SQL Server Replication Merge Agent 11.0 - AppID: {FDF7E044-456E-46C5-A396-807479AAFB4D}Name: PSEditView - AppID: {FEDC7493-555C-4E73-BBCC-230B1E866CAF}Name: SpaceIndicator - AppID: {FF6DF140-AB03-4A0E-80EF-9C233033B34D}Name: Shell Execute Hardware Event Handler - AppID: {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}Name: EntAppSvc - AppID: {FFE1E5FE-F1F0-48C8-953E-72BA272F2744} Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{00021401-0000-0000-C000-000000000046}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{00944ad3-b2ad-4bcf-9202-59bf4662d521}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{00944ad3-b2ad-4bcf-9202-59bf4662d521}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{00944ad3-b2ad-4bcf-9202-59bf4662d521}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{00944ad3-b2ad-4bcf-9202-59bf4662d521}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-15-3-3215430884-1339816292-89257616-1145831019"Win32_DCOMApplication.AppID="{020FB939-2C8B-4DB7-9E90-9527966E38E5}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{03837503-098b-11d8-9414-505054503030}" - Win32_SID.SID="S-1-5-32-559"Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0671E064-7C24-4AC0-AF10-0F3055707C32}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{0771f7af-8de6-4bce-9528-2d4a12cb8168}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{0771f7af-8de6-4bce-9528-2d4a12cb8168}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{0868DC9B-D9A2-4f64-9362-133CEA201299}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0868DC9B-D9A2-4f64-9362-133CEA201299}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0C3B05FB-3498-40C3-9C03-4B22D735550C}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0da7bfdf-c0a0-44eb-be82-b7a82c4721de}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{0EA3EECE-6ABF-467A-9040-11AA728B7B0B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{0EA3EECE-6ABF-467A-9040-11AA728B7B0B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{0EA3EECE-6ABF-467A-9040-11AA728B7B0B}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{12C21EA7-2EB8-4B55-9249-AC243DA8C666}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{133eac4f-5891-4d04-bada-d84870380a80}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{135fd325-45b7-4c30-89f8-4386961669f0}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{136A0DC7-DF5C-4271-A2AC-15DF1A1323F2}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{136A0DC7-DF5C-4271-A2AC-15DF1A1323F2}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{150F28F1-49A5-4C28-BE1A-CFA854A1D04B}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{152EA2A8-70DC-4C59-8B2A-32AA3CA0DCAC}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{16A18E86-7F6E-4C20-AD89-4FFC0DB7A96A}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{1725704B-A716-4E04-8EF6-87ED4F0A180A}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-547"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{19BCA967-D266-436f-B2D4-CBE4D4B42F96}" - Win32_SID.SID="S-1-5-32-556"Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{1AC32B1A-E379-4CAD-B655-F978A30856EC}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1BA783C1-2A30-4ad3-B928-A9A46C604C28}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1C749B87-568C-4865-8E73-6413F8372CE6}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F16}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F16}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F16}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{1E886174-DC88-4B83-8BC5-66409EC75F16}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1f2e5c40-9550-11ce-99d2-00aa006e086c}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1F9BF350-B68F-4DCA-8B87-707E26DC7390}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{1F9BF350-B68F-4DCA-8B87-707E26DC7390}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1fb2a002-4c6c-4de7-85c2-cb8db9a4f728}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{1fda955b-61ff-11da-978c-0008744faab7}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{205609B7-5E08-443E-B0A7-A7AED3F3A717}" - Win32_SID.SID="S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628"Win32_DCOMApplication.AppID="{205609B7-5E08-443E-B0A7-A7AED3F3A717}" - Win32_SID.SID="S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464"Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{217700E0-0000-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-556"Win32_DCOMApplication.AppID="{224FC5DE-26AD-4A47-A2C3-5A50885F314C}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{224FC5DE-26AD-4A47-A2C3-5A50885F314C}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-15-3-1024-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-32-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-15-3-1024-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937"Win32_DCOMApplication.AppID="{260eb9de-5cbe-4bff-a99a-3710af55bf1e}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-2781"Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{27170d71-7a40-4c8b-a3d1-64f7cbe81c66}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{27550CA0-E9DE-4186-A566-37A59BB6CA69}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-32-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-15-3-1024-4267310653-3012624349-32869343-335676702-674013981-1531007892-2777328540-762217067"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-5-32-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937"Win32_DCOMApplication.AppID="{28d08f70-46eb-4f26-a6cb-54b75132e100}" - Win32_SID.SID="S-1-15-3-1024-2558976728-3115931106-1512009022-3208506203-2008579624-341828572-3950653509-2339491937"Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{292bed96-e9ce-40f8-b71b-c313defa3a78}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{2A39E11E-7FDE-45b1-99C6-B9E557D3ABA1}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{2A39E11E-7FDE-45b1-99C6-B9E557D3ABA1}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{2A947841-0594-48CF-9C53-A08C95C22B55}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{2A947841-0594-48CF-9C53-A08C95C22B55}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{2B433F44-5456-42FF-8CBD-54E8176ECD01}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-15-3-1024-1314380931-3989923313-3249193833-1963115619-3940350845-1282913705-2904921893-3519892189"Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030"Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1212"Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{2EA38040-0B9C-4379-87FD-4D38BB892F37}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{304CE942-6E39-40D8-943A-B913C40C9CD4}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{34E76A18-223B-4E23-BEAD-F59358CC0A90}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{34E76A18-223B-4E23-BEAD-F59358CC0A90}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{34E76A18-223B-4E23-BEAD-F59358CC0A90}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{36234D6F-D9B8-404B-91C9-736BD2EE3040}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{36234D6F-D9B8-404B-91C9-736BD2EE3040}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{37096FBE-2F09-4FF6-8507-C6E4E1179893}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{37096FBE-2F09-4FF6-8507-C6E4E1179893}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{37096FBE-2F09-4FF6-8507-C6E4E1179893}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{37096FBE-2F09-4FF6-8507-C6E4E1179893}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{379001DE-7108-4A45-8A74-6CD0A9FBEF2C}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{37B73D7B-A976-43AE-97E4-BD4977B241F2}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{3ad05575-8857-4850-9277-11b85bdb8e09}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{3DC42F2C-AD30-461E-B877-11C917E8FE20}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{3DC42F2C-AD30-461E-B877-11C917E8FE20}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{3E000D72-A845-4CD9-BD83-80C07C3B881F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{3eb3c877-1f16-487c-9050-104dbcd66683}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{3eb3c877-1f16-487c-9050-104dbcd66683}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{3eb3c877-1f16-487c-9050-104dbcd66683}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{3eb3c877-1f16-487c-9050-104dbcd66683}" - Win32_SID.SID="S-1-15-3-1"Win32_DCOMApplication.AppID="{3eb3c877-1f16-487c-9050-104dbcd66683}" - Win32_SID.SID="S-1-15-3-2"Win32_DCOMApplication.AppID="{3eb3c877-1f16-487c-9050-104dbcd66683}" - Win32_SID.SID="S-1-15-3-3"Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{3F4D7BB8-4F38-4526-8CD3-C44D68689C5F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{412E0F20-6C5B-43EC-879F-DA444A416EAC}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{412E0F20-6C5B-43EC-879F-DA444A416EAC}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{42C21DF5-FB58-4102-90E9-96A213DC7CE8}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-15-3-1024-3153509613-960666767-3724611135-2725662640-12138253-543910227-1950414635-4190290187"Win32_DCOMApplication.AppID="{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{434A6274-C539-4E99-88FC-44206D942775}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{46B988E8-BEC2-401F-A1C5-16C694F26D3E}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{46C166AA-3108-11D4-9348-00C04F8EEB71}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{48da6741-1bf0-4a44-8325-293086c79077}" - Win32_SID.SID="S-1-5-80-611605672-2879557022-2206624263-4029342278-3129212340"Win32_DCOMApplication.AppID="{4963f89b-261e-4ffa-ac2e-71a7d5a17071}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{4963f89b-261e-4ffa-ac2e-71a7d5a17071}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{4963f89b-261e-4ffa-ac2e-71a7d5a17071}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{4963f89b-261e-4ffa-ac2e-71a7d5a17071}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{4963f89b-261e-4ffa-ac2e-71a7d5a17071}" - Win32_SID.SID="S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622"Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{49EBD8BE-1A92-4A86-A651-70AC565E0FEB}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{4A3F2F56-454A-4CC5-9734-BB7D8141AC0A}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{4A6B8BAD-9872-4525-A812-71A52367DC17}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{4D111E08-CBF7-4f12-A926-2C7920AF52FC}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{4D5F23BB-D55A-4961-9BC0-3FE728E15D9D}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{4D5F23BB-D55A-4961-9BC0-3FE728E15D9D}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{4FCDA643-B15B-41C6-84F8-5E447F6F6D25}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{50a9ab2a-20f8-4d71-9f32-9fd305b49601}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{50d69d24-961d-4828-9d1c-5f4717f226d1}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-5-32-2707581722-3970398075-3301609242-3412871183-2565310287-2959982868-2531230773-2372594412"Win32_DCOMApplication.AppID="{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}" - Win32_SID.SID="S-1-15-3-1024-2707581722-3970398075-3301609242-3412871183-2565310287-2959982868-2531230773-2372594412"Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{514B5E31-5596-422F-BE58-D804464683B5}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{51a1467f-96a2-4b1c-9632-4b4d950fe216}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{534E4CF4-3249-4842-8D65-A9BEAE0BBEAC}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{534E4CF4-3249-4842-8D65-A9BEAE0BBEAC}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{57360832-5F9B-4190-8467-000D2D510212}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{588E10FA-0618-48A1-BE2F-0AD93E899FCC}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{59347292-B72D-41F2-98C5-E9ACA1B247A2}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{59347292-B72D-41F2-98C5-E9ACA1B247A2}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{59c7f6ec-7d18-412f-a68e-877982768e61}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{5A4ED3BD-2F40-44B4-93DA-2B5ECC197B26}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{5A4ED3BD-2F40-44B4-93DA-2B5ECC197B26}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{5A4ED3BD-2F40-44B4-93DA-2B5ECC197B26}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{5A4ED3BD-2F40-44B4-93DA-2B5ECC197B26}" - Win32_SID.SID="S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-15-3-1024-3625662137-2682091254-856171984-2868379045-3001028726-1009205972-4175949866-684286152"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1031"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{5BC7A3A1-E905-414B-9790-E511346F5CA6}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{5C03E1B1-EB13-4DF1-8943-2FE8E7D5F309}" - Win32_SID.SID="S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376"Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{5E1395B2-B685-44e3-8AED-E2304D85ACD1}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{5E176815-9A63-4A69-810F-62E90D36612A}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{5E176815-9A63-4A69-810F-62E90D36612A}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{60173D16-A550-47f0-A14B-C6F9E4DA0831}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{642ef9d6-48a5-476b-919a-a507cfd02c0f}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{64bb4bed-73f6-4d74-a048-035b4f63ec98}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{64bb4bed-73f6-4d74-a048-035b4f63ec98}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{64bb4bed-73f6-4d74-a048-035b4f63ec98}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{64bb4bed-73f6-4d74-a048-035b4f63ec98}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{64bb4bed-73f6-4d74-a048-035b4f63ec98}" - Win32_SID.SID="S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991"Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{653C5148-4DCE-4905-9CFD-1B23662D3D9E}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{6571503D-D0FB-4D98-BBC3-1FBB2B3F344E}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{65E2E13A-7110-4912-9F03-9A42E253D8F6}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{65E2E13A-7110-4912-9F03-9A42E253D8F6}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{67E88D46-FF81-4E57-8C5E-F270A4F9EA1A}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{67E88D46-FF81-4E57-8C5E-F270A4F9EA1A}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{6B1DE8B3-DFB1-4C0E-9D9A-89CA730DE93F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{6D9A7A40-DDCA-414E-B48E-DFB032C03C1B}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{6F65B602-F798-4094-8A41-A2A61961E5E8}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7007ACC5-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7007ACD1-3202-11D1-AAD2-00805FC1270E}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{70C4A096-96BC-4A5E-9D24-22A47F58C243}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{70C4A096-96BC-4A5E-9D24-22A47F58C243}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{72A7994A-3092-4054-B6BE-08FF81AEEFFC}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{730BFCEC-E4BF-4D3A-9FBB-01DD132467A4}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{752073A2-23F2-4396-85F0-8FDB879ED0ED}" - Win32_SID.SID="S-1-5-6"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-15-3-1024-4044835139-2658482041-3127973164-329287231-3865880861-1938685643-461067658-1087000422"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{7578dea3-a321-4d03-8b60-fc6749ae7385}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-32-546"Win32_DCOMApplication.AppID="{76db1bf3-e820-4765-a1b2-0b16a86b1950}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{777BA81A-2498-4875-933A-3067DE883070}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7953C53B-4031-43ca-9AE7-033F565EFD5F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7953C53B-4031-43ca-9AE7-033F565EFD5F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7966b4d8-4fdc-4126-a10b-39a3209ad251}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7966b4d8-4fdc-4126-a10b-39a3209ad251}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7966b4d8-4fdc-4126-a10b-39a3209ad251}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{7966b4d8-4fdc-4126-a10b-39a3209ad251}" - Win32_SID.SID="S-1-15-3-1024-3623855041-1826999956-3747069818-3525260223-3747374510-1746272624-950601168-56556331"Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7A076CE1-4B31-452a-A4F1-0304C8738100}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7aa7790d-75d7-484b-98a1-3913d022091d}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7C8AB6D9-8764-4033-8F62-2FE896E54B32}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7DF8EF76-D449-485f-B4EB-58DC96B31EDB}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7E55A26D-EF95-4A45-9F55-21E52ADF9887}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7E55A26D-EF95-4A45-9F55-21E52ADF9887}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{7E55A26D-EF95-4A45-9F55-21E52ADF9887}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7E55A26D-EF95-4A45-9F55-21E52ADF9887}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{7EAD5C10-8B3F-11E6-AE22-56B6B6499611}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{7EAD5C10-8B3F-11E6-AE22-56B6B6499611}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{7EAD5C10-8B3F-11E6-AE22-56B6B6499611}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{7EB545FB-872B-4286-B4E2-96B3A64EEC57}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{7EB545FB-872B-4286-B4E2-96B3A64EEC57}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{82D94FB3-7FE6-4797-BB72-9A886C66073B}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{84D586C4-A423-11D2-B943-00C04F79D22F}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{86d5eb8a-859f-4c7b-a76b-2bd819b7a850}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{86F80216-5DD6-4F43-953B-35EF40A35AEE}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{874E03B4-29BD-4628-A0F6-78B8B011ADA9}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{874E03B4-29BD-4628-A0F6-78B8B011ADA9}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{874E03B4-29BD-4628-A0F6-78B8B011ADA9}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{874E03B4-29BD-4628-A0F6-78B8B011ADA9}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{87df41c9-cb91-4709-849c-f8f3c7058b50}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{87df41c9-cb91-4709-849c-f8f3c7058b50}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{87df41c9-cb91-4709-849c-f8f3c7058b50}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{87df41c9-cb91-4709-849c-f8f3c7058b50}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{87df41c9-cb91-4709-849c-f8f3c7058b50}" - Win32_SID.SID="S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622"Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-6"Win32_DCOMApplication.AppID="{88283d7c-46f4-47d5-8fc2-db0b5cf0cb54}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{8be0366c-8522-40be-8b08-cb26557f2854}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{8C334A55-DDB9-491C-817E-35A6B85D2ECB}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8C482DCE-2644-4419-AEFF-189219F916B9}" - Win32_SID.SID="S-1-5-80-4155767994-3874329934-3800885181-2130851812-726865888"Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{8D15A4F3-1BE5-4120-8A4D-2EF92A5DD58D}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{8DF61FB6-3223-4E2D-8A92-D937DDB0DF4C}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-15-3-1024-1701033769-137094913-3738083205-577272984-1204217555-1180762924-3352773070-2589626690"Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1030"Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-21-2702878673-795188819-444038987-1210"Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{8E44A57C-5638-44D3-9B83-34DF70EB57F2}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{8e7fae4d-cff0-41d3-a326-5a80470264bb}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{90B553F3-415D-44D8-8665-C2F78763F8F1}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{90B553F3-415D-44D8-8665-C2F78763F8F1}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{9200689A-F979-4eea-8830-0E1D6B74821F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-5-6"Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{924DC564-16A6-42EB-929A-9A61FA7DA06F}" - Win32_SID.SID="S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622"Win32_DCOMApplication.AppID="{92940059-57cc-41bc-a042-80a6247ffce6}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{92940059-57cc-41bc-a042-80a6247ffce6}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{92940059-57cc-41bc-a042-80a6247ffce6}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{92940059-57cc-41bc-a042-80a6247ffce6}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{92940059-57cc-41bc-a042-80a6247ffce6}" - Win32_SID.SID="S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194-3859068477-1314311106-1651661491-1685393560"Win32_DCOMApplication.AppID="{973d20d7-562d-44b9-b70b-5a0f49ccdf3f}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{973d20d7-562d-44b9-b70b-5a0f49ccdf3f}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{973d20d7-562d-44b9-b70b-5a0f49ccdf3f}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{973d20d7-562d-44b9-b70b-5a0f49ccdf3f}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{973d20d7-562d-44b9-b70b-5a0f49ccdf3f}" - Win32_SID.SID="S-1-15-3-1024-3623855041-1826999956-3747069818-3525260223-3747374510-1746272624-950601168-56556331"Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{98a89e0c-1fde-4c2a-a373-b04831e6aa60}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{990F07C7-78DC-4BD2-B145-5F791410BDDE}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{9D73451F-6BFC-47C7-95FB-46598431BC19}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{9D73451F-6BFC-47C7-95FB-46598431BC19}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{9D73451F-6BFC-47C7-95FB-46598431BC19}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{9D73451F-6BFC-47C7-95FB-46598431BC19}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{9D73451F-6BFC-47C7-95FB-46598431BC19}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{9df523b0-a6c0-4ea9-b5f1-f4565c3ac8b8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{A1F4E726-8CF1-11D1-BF92-0060081ED811}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{a2d9ca22-a492-400c-b875-78ac25c0a6f3}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}" - Win32_SID.SID="S-1-15-3-1024-3623855041-1826999956-3747069818-3525260223-3747374510-1746272624-950601168-56556331"Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{A4B07E49-6567-4FB8-8D39-01920E3B2357}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{a4c31131-ff70-4984-afd6-0609ced53ad6}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{A6BFEA43-501F-456F-A845-983D3AD7B8F0}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{A79DB36D-6218-48e6-9EC9-DCBA9A39BF0F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{A7A63E5C-3877-4840-8727-C1EA9D7A4D50}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-15-3-1024-4044835139-2658482041-3127973164-329287231-3865880861-1938685643-461067658-1087000422"Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{AA0B85DA-FDDF-4272-8D1D-FF9B966D75B0}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{AC05815A-A8D5-434B-B9A8-2FFD162F2B7D}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{AC05815A-A8D5-434B-B9A8-2FFD162F2B7D}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{AC05815A-A8D5-434B-B9A8-2FFD162F2B7D}" - Win32_SID.SID="S-1-15-3-1024-2922296261-1647482768-2017091146-3858667068-4135663662-2931985894-1627820925-818366431"Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-6"Win32_DCOMApplication.AppID="{ac793c1d-eb2f-4ffd-b1ec-7af1aaaf3325}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{ada41b3c-c6fd-4a08-8cc1-d6efde67be7d}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{b0316d0c-da2f-40e0-9f91-f600caf042dc}" - Win32_SID.SID="S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622"Win32_DCOMApplication.AppID="{B06FF84E-0A77-4DD2-A919-0EABD8979DC1}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{B06FF84E-0A77-4DD2-A919-0EABD8979DC1}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{b21858c6-9711-4257-99c8-5c0084bebce1}" - Win32_SID.SID="S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708"Win32_DCOMApplication.AppID="{B366DEBE-645B-43A5-B865-DDD82C345492}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{B49FBDA8-D846-43c4-ACAA-06D7794374C8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{B49FBDA8-D846-43c4-ACAA-06D7794374C8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{B6C292BC-7C88-41EE-8B54-8EC92617E599}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{B8C54A54-355E-11D3-83EB-00A0C92A2F2D}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{B8C54A54-355E-11D3-83EB-00A0C92A2F2D}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{BA126F01-2166-11D1-B1D0-00805FC1270E}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{BA94BBA5-9AAB-4ACC-80CF-EDD2128EBC70}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{BA94BBA5-9AAB-4ACC-80CF-EDD2128EBC70}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{BBD8C065-5E6C-4e88-BFD7-BE3E6D1C063B}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{BCEA735B-4DAC-4B71-9C47-1D560AFD2A9B}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{BD54C901-076B-434E-B6C7-17C531F4AB41}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-5-80-2731152606-4244467407-1946816704-3721569673-479255522"Win32_DCOMApplication.AppID="{C0E1CE99-C981-44A2-AC4C-41036FAC6593}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C100BEBB-D33A-4a4b-BF23-BBEF4663D017}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{c2a71820-3463-498f-bab7-4798795a2ff6}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{C2E9756F-8155-4EAC-9ED5-0B690169D412}" - Win32_SID.SID="S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622"Win32_DCOMApplication.AppID="{C2EA2356-994C-45AF-BDAE-10796F73BC47}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C2EA2356-994C-45AF-BDAE-10796F73BC47}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{C2EA2356-994C-45AF-BDAE-10796F73BC47}" - Win32_SID.SID="S-1-5-6"Win32_DCOMApplication.AppID="{C2EA2356-994C-45AF-BDAE-10796F73BC47}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C3A34354-660F-41EE-B072-2AEA5E3A80AF}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{C51172D2-C2FF-43A1-B955-564072C36EB1}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{C51172D2-C2FF-43A1-B955-564072C36EB1}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{C5D3C0E1-DC41-4F83-8BA8-CC0D46BCCDE3}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{C6169DCF-51E4-4D6B-A38B-2BDBC33626C3}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{C6169DCF-51E4-4D6B-A38B-2BDBC33626C3}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C6169DCF-51E4-4D6B-A38B-2BDBC33626C3}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C6169DCF-51E4-4D6B-A38B-2BDBC33626C3}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C63261E4-6052-41FF-B919-496FECF4C4E5}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-11"Win32_DCOMApplication.AppID="{C844C79D-AED8-4DCE-AB25-4D359BED84F8}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{C92A9617-0EAE-4235-BD2B-84540EF1FFA9}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{C945AD06-534F-460C-8CB4-17C33099AF81}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991"Win32_DCOMApplication.AppID="{C97E2AEF-AB0E-4FA6-BA29-1A1A7CCBA125}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{ca8c87c1-929d-45ba-94db-ef8e6cb346ad}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{CB363445-F453-4C1E-8EE4-BD123C5E394F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{CB43451C-E132-4866-B714-435253C98BBA}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{CB43451C-E132-4866-B714-435253C98BBA}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{CCFDD24D-CEAB-458B-A4F1-F884973395DF}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{CCFDD24D-CEAB-458B-A4F1-F884973395DF}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{CE0E0BE8-CF56-4577-9577-34CC96AC087C}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{cee8ccc9-4f6b-4469-a235-5a22869eef03}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{CF254B00-1986-4b24-A92D-463D01F7E395}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{CF254B00-1986-4b24-A92D-463D01F7E395}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{D215781D-019E-4FA0-903D-0CDCDE13A4F5}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{D8239E84-D6EC-41dc-B7EA-98CDBF472200}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{D8239E84-D6EC-41dc-B7EA-98CDBF472200}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}" - Win32_SID.SID="S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628"Win32_DCOMApplication.AppID="{D8D4249F-A8FB-44A7-8AA0-564E8C385BD6}" - Win32_SID.SID="S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464"Win32_DCOMApplication.AppID="{dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{dc4537c3-ca73-4ac7-9e1d-b2ce27c3a7a6}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{DD7B2C49-A779-4055-BBD5-7C96F502F97F}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{DD7B2C49-A779-4055-BBD5-7C96F502F97F}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{DD7B2C49-A779-4055-BBD5-7C96F502F97F}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{DD9C53BC-8441-4B94-BD0E-36E6E02A6D61}" - Win32_SID.SID="S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194"Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{ddcfd26b-feed-44cd-b71d-79487d2e5e5a}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{de5d803e-5d2a-4b5f-9c63-af25a465cc44}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{e30984f1-b02b-4c27-a40f-23d11b8c1212}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{e53cd6ee-5c5c-4701-9ff2-c204bfed819d}" - Win32_SID.SID="S-1-15-3-1024-2819154332-3691255550-2499738133-2646149002-4290075130-3069449926-721213713-3168903538"Win32_DCOMApplication.AppID="{E62A7A31-6025-408E-87F6-81AEB0DC9347}" - Win32_SID.SID="S-1-2-0"Win32_DCOMApplication.AppID="{E62A7A31-6025-408E-87F6-81AEB0DC9347}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{E62A7A31-6025-408E-87F6-81AEB0DC9347}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{E62A7A31-6025-408E-87F6-81AEB0DC9347}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{E62A7A31-6025-408E-87F6-81AEB0DC9347}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{E7299E79-75E5-47BB-A03D-6D319FB7F886}" - Win32_SID.SID="S-1-5-32-545"Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{E8054D20-497D-4E16-BF41-6E69FCD381A5}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{E9495B87-D950-4ab5-87A5-FF6D70BF3E90}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{E95186C7-7D80-4311-843D-0702CBC8B1E4}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{EA022610-0748-4c24-B229-6C507EBDFDBB}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{EB521D7D-4095-4E61-88FB-BF25700F142A}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{EC9846B3-2762-4A6B-A214-6ACB603462D2}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{EE3C7093-A852-49BA-8AC8-7DFBEC469F72}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{EE3C7093-A852-49BA-8AC8-7DFBEC469F72}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{efe2d6d8-a81b-41e7-ae77-e5244ab80522}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC}" - Win32_SID.SID="S-1-5-7"Win32_DCOMApplication.AppID="{F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{F135BE18-BF34-4CBD-B1D5-55D49F0DEDCC}" - Win32_SID.SID="S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991"Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{F1425A67-1545-44A2-AB59-8DF1020452D9}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-32-551"Win32_DCOMApplication.AppID="{F290BFB2-1864-45B1-8804-2654194A87E7}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{F2F94BB3-595C-4509-B7EE-243FA2BDEA5B}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{f32d97df-e3e5-4cb9-9e3e-0eb5b4e49801}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{F3D3A6E1-385A-4A4D-A9D3-071FA9FE5500}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{F3D3A6E1-385A-4A4D-A9D3-071FA9FE5500}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{F3D3AA8D-EF96-4470-848E-BD70B803047A}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{f4be747e-45c4-4701-90f1-d49d9ac30248}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-3433512109-503559027-1389316256-1766580070-2256751264"Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-1260278928-804197538-2066346633-4268302704-2216462912"Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-345135819-4012009209-3062012967-1747265747-3674605950"Win32_DCOMApplication.AppID="{F72671A9-012C-4725-9D2F-2A4D32D65169}" - Win32_SID.SID="S-1-5-80-951620777-1059631183-2804607755-3010024351-809615488"Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-80-364023826-931424190-487969545-1024119571-74567675"Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{f735e733-d681-4aef-83c1-7ec82cac5ecc}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{f8842f8e-dafe-4b37-9d38-4e0714a61149}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{F8FD03A6-DDD9-4C1B-84EE-58159476A0D7}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-15-2-1"Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-15-3-1"Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-15-3-2"Win32_DCOMApplication.AppID="{F9717507-6651-4EDB-BFF7-AE615179BCCF}" - Win32_SID.SID="S-1-15-3-3"Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{FA1456D3-4B97-4f9c-8511-2786161DC333}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{FBF23B40-E3F0-101B-8488-00AA003E56F8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-544"Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-19"Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-20"Win32_DCOMApplication.AppID="{FC5EEAF6-0002-11DF-ADB9-F4CE462D9137}" - Win32_SID.SID="S-1-5-32-556"Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{FCC74B77-EC3E-4dd8-A80B-008A702075A9}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-4"Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{ff9e6131-a8c1-4188-aa03-82e9f10a05a8}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-1-0"Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-10"Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-18"Win32_DCOMApplication.AppID="{FFE1E5FE-F1F0-48C8-953E-72BA272F2744}" - Win32_SID.SID="S-1-5-32-544" ---------- | SvcHost (Whitelist) [HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]"DcomLaunch"=Power LSM BrokerInfrastructure PlugPlay DcomLaunch DeviceInstall SystemEventsBroker"rdxgroup"=RetailDemo"Camera"=FrameS"DevicesFlow"=DevicesFlowUserSvc"smbsvcs"=lanmanserver browser [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost]"DcomLaunch"=PlugPlay DcomLaunch DeviceInstall"smbsvcs"=lanmanserver ---------- | SvcHost - Netsvcs (Whitelist) TokenBroker - %SystemRoot%\System32\TokenBroker.dll : %SystemRoot%\system32\svchost.exe -k netsvcs ---------- | Software [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\2BrightSparks][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\7-Zip][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\A-PDF][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Acronis][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Adlice Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Admin Arsenal][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Aiseesoft Studio][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Alexander Avdonin][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Amazing-Share][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Amazon][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Amazon Services LLC][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\AnyMedia Player][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\AnyMP4 Studio][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\AppDataLow][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Ashampoo][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ASProtect][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ATI][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\AutoIt v3][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Avanquest][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Avant Browser][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Azureus][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Belarc][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Bitdefender Home Scanner][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\BugSplat][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\CamStudioOpenSource for Nick][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Caphyon][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ChemTable Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Chromium-BackupByVivaldiPortable][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\CineForm][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Clients][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ClPhpEd][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Code Sector][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Comodo][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ComodoGroup][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\CompuClever][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\concept/design][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Corel][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\CyberGhost][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\CyberLink][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Dashlane_profiles][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Datastead][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Disc Soft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\DivX][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\DivXNetworks][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\DMGR1.25][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\DTLSoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\EaseUS][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ej-technologies][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Encrypt4allSoftware][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\EPSON][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\EPSON Software Updater][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\FileHippo.com][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\FLEXnet][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\FlipBuilder][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Foxit Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\g3n-h@ckm@n][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Gabest][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\giveawayoftheday.com][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\GlarySoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\GNU][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Google][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Grabilla][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Haali][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\HippoEDIT][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\HissenITMasterdata][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\IMSIDesign][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Informer Technologies, Inc.][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Innovative Solutions][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Intelligent Converters][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\IObit][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\IrisTech][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\iSkysoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\iZotope][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\JavaSoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\KillSoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Lake][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Laplink][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\LAV][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Leadertech][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Licenses][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\LiteManager][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\LogiShrd][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Logitech][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\LogMeInRescueCallingCard][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\LopeSoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\macrium][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Macromedia][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Macrovision][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\madFlac][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Magnet][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\MainConcept][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Malwarebytes][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Marmiton][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\MediaInfo][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Mirage][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\MONOGRAM][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Mozilla][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\MPC-HC][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\MRU-Blaster][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Multi Commander][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\MultiCommander][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Netscape][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\NetVoyage][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\NewBlue][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Nico Mak Computing][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\NOS][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Obsidium][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\OCS][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Online Video Recorder][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Opera Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Orange][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\OrangeInside][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Ordinarysoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\OSTotoSoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Panda Security][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Paragon][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Paragon Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Paramount Software (UK) Ltd.][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\PCurVersion][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\pdfforge][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\PDFTXTEXT][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\PEiD][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Perigee Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Piriform][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Policies][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\proDAD][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\QtProject][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Rebit][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Recover Keys][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\RegisteredApplications][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Remo Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Resplendence Sp][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Roxio][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SafeIT Security][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SafelyRemove][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Safer Networking Limited][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SEIKO EPSON CORPORATION][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SGSolution][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SharewareOnSale][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Siber Systems][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SimpleStar][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Simply Super Software][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\softorbits][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Softvoile][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Space Sciences Laboratory, U.C. Berkeley][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\StackDocklet][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\StartIsBack][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Steganos][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\SyncEngines][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Syncios][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\sysinternals][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\TAdvCheckList][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\TeamViewer][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\techPowerUp][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\TechSmith][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Tihiy][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\TiushkovNikolay][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Trolltech][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\UCT][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Ultracopier][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\undefined][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\UsbFix][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\UsbFix Standard][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\utililab][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Viv][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Vivaldi][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\VOS][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\VS Revo Group][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Windows 10 - Codec Pack][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Windows 7 - Codec Pack][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Windscribe][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\WinRAR][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\WinRAR SFX][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\WixSharp][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Wondershare][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Wow6432Node][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\WSVCUPlugin][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Xilisoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\xplorer2l][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ZabaraKatranemia Plc][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ZebHelpProcess Helper][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Zemana][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\ZHP][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\{88048F60-BFF3-40E0-98BA-3FAE9872BA6A}][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\{98132F81-18BE-4722-8B1D-0A25D9AE3DA0}][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\AppDataLow\Software\Microsoft][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\CurrentVersion][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\DWM][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\PrivacySettingsBeforeCreatorsUpdate][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\Roaming][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\Shell][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\ShellNoRoam][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\TabletPC][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\Windows Error Reporting][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows\Winlogon][HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\Software\Microsoft\Windows NT\CurrentVersion][HKLM64\Software\Acronis][HKLM64\Software\AdAware][HKLM64\Software\Admin Arsenal][HKLM64\Software\AdsFix][HKLM64\Software\AMD][HKLM64\Software\Ashampoo][HKLM64\Software\ATI][HKLM64\Software\ATI Technologies][HKLM64\Software\AVC3][HKLM64\Software\Azureus][HKLM64\Software\Bitdefender][HKLM64\Software\Bitdefender Home Scanner][HKLM64\Software\Clean_Dns][HKLM64\Software\Clients][HKLM64\Software\Code Sector][HKLM64\Software\CodeGear][HKLM64\Software\COMODO][HKLM64\Software\Contrôle Parental Orange][HKLM64\Software\Corel Corporation][HKLM64\Software\CyberGhost][HKLM64\Software\CyberLink][HKLM64\Software\Disc Soft][HKLM64\Software\DivX][HKLM64\Software\Eassos][HKLM64\Software\ej-technologies][HKLM64\Software\EPSON][HKLM64\Software\Fortemedia][HKLM64\Software\Foxit Software][HKLM64\Software\g3n-h@ckm@n][HKLM64\Software\Genie9][HKLM64\Software\Google][HKLM64\Software\GridinSoft][HKLM64\Software\HaaliMkx][HKLM64\Software\Ignis][HKLM64\Software\INextUUID][HKLM64\Software\Intel][HKLM64\Software\Interwoven][HKLM64\Software\jam software][HKLM64\Software\JavaSoft][HKLM64\Software\KeyCryptSDK][HKLM64\Software\Khronos][HKLM64\Software\KHT][HKLM64\Software\Lavasoft][HKLM64\Software\Logitech][HKLM64\Software\Macrium][HKLM64\Software\Macromedia][HKLM64\Software\Microsoft][HKLM64\Software\Mozilla][HKLM64\Software\mozilla.org][HKLM64\Software\MozillaPlugins][HKLM64\Software\MozillaPlugins-BackupByVivaldiPortable][HKLM64\Software\MSNSett][HKLM64\Software\NewBlue][HKLM64\Software\Nico Mak Computing][HKLM64\Software\Notepad++][HKLM64\Software\NSIS.Library.RegTool.v3][HKLM64\Software\Nuance][HKLM64\Software\ODBC][HKLM64\Software\OEM][HKLM64\Software\Ordinarysoft][HKLM64\Software\Paragon Software][HKLM64\Software\Patch My PC][HKLM64\Software\pdfforge][HKLM64\Software\Piriform][HKLM64\Software\Policies][HKLM64\Software\Printers][HKLM64\Software\proDAD][HKLM64\Software\QEMU][HKLM64\Software\Qiling][HKLM64\Software\QWR2YW5jZWRwY2NhcmUubmV0][HKLM64\Software\Realtek][HKLM64\Software\Reason][HKLM64\Software\RegisteredApplications][HKLM64\Software\Remo Software][HKLM64\Software\SafeIT Security][HKLM64\Software\Seed4.Me VPN][HKLM64\Software\Siber Systems][HKLM64\Software\Simple PC Optimizer][HKLM64\Software\SRS Labs][HKLM64\Software\sysinternals][HKLM64\Software\TAP-Windows][HKLM64\Software\WinRAR][HKLM64\Software\Wondershare][HKLM64\Software\WOW6432Node][HKLM64\Software\xplorer2p64_u][HKLM64\Software\zabkat][HKLM64\Software\Zemana][HKLM64\Software\ZmnGlobalSDK][HKLM64\Software\Microsoft\Windows\ClickNote][HKLM64\Software\Microsoft\Windows\CurrentVersion][HKLM64\Software\Microsoft\Windows\Dwm][HKLM64\Software\Microsoft\Windows\DynamicManagement][HKLM64\Software\Microsoft\Windows\EnterpriseResourceManager][HKLM64\Software\Microsoft\Windows\Heat][HKLM64\Software\Microsoft\Windows\HTML Help][HKLM64\Software\Microsoft\Windows\ITStorage][HKLM64\Software\Microsoft\Windows\PrivacySettingsBeforeCreatorsUpdate][HKLM64\Software\Microsoft\Windows\ScheduledDiagnostics][HKLM64\Software\Microsoft\Windows\ScriptedDiagnosticsProvider][HKLM64\Software\Microsoft\Windows\Shell][HKLM64\Software\Microsoft\Windows\Tablet PC][HKLM64\Software\Microsoft\Windows\TabletPC][HKLM64\Software\Microsoft\Windows\Windows Error Reporting][HKLM64\Software\Microsoft\Windows\Windows Search][HKLM64\Software\Microsoft\Windows NT\CurrentVersion][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DevicesFlow][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\rdxgroup][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport][HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx][HKLM\Software\WOW6432Node\2BrightSparks][HKLM\Software\WOW6432Node\360Safe][HKLM\Software\WOW6432Node\7-Zip][HKLM\Software\WOW6432Node\Acronis][HKLM\Software\WOW6432Node\adaware][HKLM\Software\WOW6432Node\Admin Arsenal][HKLM\Software\WOW6432Node\Alexander Avdonin][HKLM\Software\WOW6432Node\Amazing-Share][HKLM\Software\WOW6432Node\AMD][HKLM\Software\WOW6432Node\AnyMedia Player][HKLM\Software\WOW6432Node\Apple Inc.][HKLM\Software\WOW6432Node\ArcSoft][HKLM\Software\WOW6432Node\ASDMA][HKLM\Software\WOW6432Node\Ashampoo][HKLM\Software\WOW6432Node\ATI][HKLM\Software\WOW6432Node\ATI Technologies][HKLM\Software\WOW6432Node\Auslogics][HKLM\Software\WOW6432Node\AutoIt v3][HKLM\Software\WOW6432Node\Avanquest][HKLM\Software\WOW6432Node\AVAST Software][HKLM\Software\WOW6432Node\Avid][HKLM\Software\WOW6432Node\Belarc][HKLM\Software\WOW6432Node\ByteFence][HKLM\Software\WOW6432Node\calibre][HKLM\Software\WOW6432Node\Caphyon][HKLM\Software\WOW6432Node\Codec Tweak Tool][HKLM\Software\WOW6432Node\Comodo][HKLM\Software\WOW6432Node\ComodoGroup][HKLM\Software\WOW6432Node\CyberGhost][HKLM\Software\WOW6432Node\CyberLink][HKLM\Software\WOW6432Node\Cygnus Solutions][HKLM\Software\WOW6432Node\Debug][HKLM\Software\WOW6432Node\DebugMode][HKLM\Software\WOW6432Node\DigitalWave][HKLM\Software\WOW6432Node\DivX][HKLM\Software\WOW6432Node\DivXNetworks][HKLM\Software\WOW6432Node\DoYourData][HKLM\Software\WOW6432Node\Dragon][HKLM\Software\WOW6432Node\DTLSoft][HKLM\Software\WOW6432Node\EaseUS][HKLM\Software\WOW6432Node\EaseUS Todo Backup][HKLM\Software\WOW6432Node\EPSON][HKLM\Software\WOW6432Node\Flip HTML5][HKLM\Software\WOW6432Node\Foxit Software][HKLM\Software\WOW6432Node\FreeFileSync][HKLM\Software\WOW6432Node\g3n-h@ckm@n][HKLM\Software\WOW6432Node\Gabest][HKLM\Software\WOW6432Node\Genie9][HKLM\Software\WOW6432Node\GiliSoft][HKLM\Software\WOW6432Node\GlarySoft][HKLM\Software\WOW6432Node\GNU][HKLM\Software\WOW6432Node\Google][HKLM\Software\WOW6432Node\GuidGuid13][HKLM\Software\WOW6432Node\HaaliMkx][HKLM\Software\WOW6432Node\Hummingbird][HKLM\Software\WOW6432Node\iFunSoft][HKLM\Software\WOW6432Node\illiminable][HKLM\Software\WOW6432Node\Innovative Solutions][HKLM\Software\WOW6432Node\Intel][HKLM\Software\WOW6432Node\InterVideo][HKLM\Software\WOW6432Node\IObit][HKLM\Software\WOW6432Node\iSkysoft][HKLM\Software\WOW6432Node\iSkysoftSysMenuDATA][HKLM\Software\WOW6432Node\JavaSoft][HKLM\Software\WOW6432Node\JreMetrics][HKLM\Software\WOW6432Node\Khronos][HKLM\Software\WOW6432Node\KillSoft][HKLM\Software\WOW6432Node\KLCodecPack][HKLM\Software\WOW6432Node\Lake][HKLM\Software\WOW6432Node\Laplink][HKLM\Software\WOW6432Node\Lavasoft][HKLM\Software\WOW6432Node\Licenses][HKLM\Software\WOW6432Node\LiteManagerTeam][HKLM\Software\WOW6432Node\logishrd][HKLM\Software\WOW6432Node\Logitech][HKLM\Software\WOW6432Node\LogMeInRescueCallingCard][HKLM\Software\WOW6432Node\macrium][HKLM\Software\WOW6432Node\Macromedia][HKLM\Software\WOW6432Node\Media Player - Codec Pack][HKLM\Software\WOW6432Node\Microsoft][HKLM\Software\WOW6432Node\Microsoft Corporation][HKLM\Software\WOW6432Node\MimarSinan][HKLM\Software\WOW6432Node\Mozilla][HKLM\Software\WOW6432Node\mozilla.org][HKLM\Software\WOW6432Node\MozillaPlugins][HKLM\Software\WOW6432Node\muCommander][HKLM\Software\WOW6432Node\MyDrivers][HKLM\Software\WOW6432Node\Nero][HKLM\Software\WOW6432Node\NewBlue][HKLM\Software\WOW6432Node\Nico Mak Computing][HKLM\Software\WOW6432Node\Npcap][HKLM\Software\WOW6432Node\Nuance][HKLM\Software\WOW6432Node\NuGet][HKLM\Software\WOW6432Node\ODBC][HKLM\Software\WOW6432Node\OldTimer Tools][HKLM\Software\WOW6432Node\Online Video Recorder][HKLM\Software\WOW6432Node\OpenAL][HKLM\Software\WOW6432Node\OpenVPN][HKLM\Software\WOW6432Node\Opera Software][HKLM\Software\WOW6432Node\OSTotoSoft][HKLM\Software\WOW6432Node\O_CP_V6][HKLM\Software\WOW6432Node\Panda Security][HKLM\Software\WOW6432Node\Paragon Software][HKLM\Software\WOW6432Node\PeaZip][HKLM\Software\WOW6432Node\PeaZip_additional][HKLM\Software\WOW6432Node\Piriform][HKLM\Software\WOW6432Node\PreEmptive Solutions][HKLM\Software\WOW6432Node\proDAD][HKLM\Software\WOW6432Node\Realtek][HKLM\Software\WOW6432Node\Rebit][HKLM\Software\WOW6432Node\Remo Software][HKLM\Software\WOW6432Node\Roxio][HKLM\Software\WOW6432Node\Runtime Software][HKLM\Software\WOW6432Node\S3R521][HKLM\Software\WOW6432Node\SafeIT Security][HKLM\Software\WOW6432Node\Seiko Epson Corporation][HKLM\Software\WOW6432Node\Siber Systems][HKLM\Software\WOW6432Node\SimpleStar][HKLM\Software\WOW6432Node\Simply Super Software][HKLM\Software\WOW6432Node\SmartSound Software][HKLM\Software\WOW6432Node\Sonic][HKLM\Software\WOW6432Node\SOSVirus][HKLM\Software\WOW6432Node\Space Sciences Laboratory, U.C. Berkeley][HKLM\Software\WOW6432Node\Spearit][HKLM\Software\WOW6432Node\Speed Install][HKLM\Software\WOW6432Node\Steganos][HKLM\Software\WOW6432Node\SuperBoost][HKLM\Software\WOW6432Node\Syncios][HKLM\Software\WOW6432Node\sysinternals][HKLM\Software\WOW6432Node\TeamViewer][HKLM\Software\WOW6432Node\TechSmith][HKLM\Software\WOW6432Node\tenoras][HKLM\Software\WOW6432Node\trolCommander][HKLM\Software\WOW6432Node\Turbo View & Convert][HKLM\Software\WOW6432Node\UCT][HKLM\Software\WOW6432Node\Ultra eBook Reader][HKLM\Software\WOW6432Node\Ultra File Opener][HKLM\Software\WOW6432Node\utililab][HKLM\Software\WOW6432Node\Viv][HKLM\Software\WOW6432Node\Volatile][HKLM\Software\WOW6432Node\WafCX][HKLM\Software\WOW6432Node\WinPcap][HKLM\Software\WOW6432Node\wise][HKLM\Software\WOW6432Node\WiseCleaner][HKLM\Software\WOW6432Node\WiseDriverCare][HKLM\Software\WOW6432Node\Wondershare][HKLM\Software\WOW6432Node\WOW6432Node][HKLM\Software\WOW6432Node\WUW][HKLM\Software\WOW6432Node\Xilisoft][HKLM\Software\WOW6432Node\Zemana][HKLM\Software\WOW6432Node\Clients][HKLM\Software\WOW6432Node\Policies][HKLM\Software\WOW6432Node\RegisteredApplications][HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote][HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion][HKLM\Software\WOW6432Node\Microsoft\Windows\Dwm][HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager][HKLM\Software\WOW6432Node\Microsoft\Windows\Heat][HKLM\Software\WOW6432Node\Microsoft\Windows\Help][HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help][HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage][HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider][HKLM\Software\WOW6432Node\Microsoft\Windows\Security Center][HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC][HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting][HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing][HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] ---------- | FeatureControl [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]"CyberGhost.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]"CyberGhost.exe"="0""ybrowser.exe"="0""xbrowser.exe"="0""zbrowser.exe"="0"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]"burningstudio2017.exe"="11001""softinfo.exe"="11000""CyberGhost.exe"="0""Trial.exe"="8888""Azureus.exe"="11001""ybrowser.exe"="11001""xbrowser.exe"="7000""m8i8Rxaq.exe"="9999""OkayFreedomClient.exe"="11001""Notifier.exe"="11001""utorrentie.exe"="11000""ashsnap.exe"="11001""MirrorGo.exe"="10001""onlineTV.exe"="11000"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CrossDomain_Fix_KB867801]"ashsnap.exe"="1""burningstudio2017.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation]"ashsnap.exe"="1""burningstudio2017.exe"="1""utorrentie.exe"="0"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS]"CyberGhost.exe"="1""onlineTV.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION]"CyberGhost.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]"ybrowser.exe"="0""xbrowser.exe"="0""zbrowser.exe"="0"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING]"CyberGhost.exe"="1""ashsnap.exe"="1""burningstudio2017.exe"="1""softinfo.exe"="0""ybrowser.exe"="1""xbrowser.exe"="1""zbrowser.exe"="1""MirrorGo.exe"="1""onlineTV.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]"CyberGhost.exe"="0""ybrowser.exe"="0""xbrowser.exe"="0""zbrowser.exe"="0"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]"ashsnap.exe"="10""burningstudio2017.exe"="10""ybrowser.exe"="16""xbrowser.exe"="16""zbrowser.exe"="16"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]"ashsnap.exe"="10""burningstudio2017.exe"="10""ybrowser.exe"="16""xbrowser.exe"="16""zbrowser.exe"="16"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE]"CyberGhost.exe"="0"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION]"ashsnap.exe"="1""burningstudio2017.exe"="1""ybrowser.exe"="1""xbrowser.exe"="1""zbrowser.exe"="1""utorrentie.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]"ybrowser.exe"="1""xbrowser.exe"="1""zbrowser.exe"="1"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING]"ybrowser.exe"="1""xbrowser.exe"="1""zbrowser.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]"PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]"HelpPane.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]"*"="1""explorer.exe"="1""iexplore.exe"="1""infopath.exe"="0""wmplayer.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]"HelpPane.exe"="1""prevhost.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]"HelpPane.exe"="1""PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]"HelpPane.exe"="1""PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]"HelpPane.exe"="1""PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]"HelpPane.exe"="10000""prevhost.exe"="8000""winzip64.exe"="8000""sllauncher.exe"="8000""Filmora.exe"="9999""ColorDirector.exe"="9000""AudioDirector.exe"="9000""PDR.exe"="8000""softinfo.exe"="11000""CCleaner64.exe"="11001""hippoedit.exe"="9999""WiseHotkey.exe"="11000""advlauncher.exe"="11000"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]"PresentationHost.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]"*"="1""explorer.exe"="1""iexplore.exe"="1""SAPfewgsrv.exe"="0""SAPGUI.exe"="0""SAPGuiIT.exe"="0""SAPLgPad.exe"="0""SAPLOGON.exe"="0""Scale_for_R3.exe"="0""wmplayer.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]"ieuser.exe"="1""iexplore.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]"HelpPane.exe"="1""PresentationHost.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]"YahooMusicEngine.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]"HelpPane.exe"="100000"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]"devenv.exe"="1""dexplore.exe"="1""helppane.exe"="1""PresentationHost.exe"="0""sllauncher.exe"="0"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]"msfeedssync.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]"PresentationHost.exe"="1""prevhost.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING]"softinfo.exe"="0"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]"HelpPane.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]""="""msiexec.exe"="0"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]"cs.exe"="1""waol.exe"="1""wm.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]"iexplore.exe"="0"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]"helppane.exe"="0"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]"wlmail.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]"explorer.exe"="1""HelpPane.exe"="1""iexplore.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""sllauncher.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]"explorer.exe"="4""sllauncher.exe"="6""iexplore.exe"="10"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]"explorer.exe"="2""sllauncher.exe"="6""iexplore.exe"="10"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]"explorer.exe"="1""HelpPane.exe"="1""iexplore.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]"mshta.exe"="1""outlook.exe"="1""sidebar.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]"explorer.exe"="0""iexplore.exe"="0""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]"communicator.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]"HelpPane.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]"HelpPane.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]"msimn.exe"="1""prevhost.exe"="1""winmail.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]"PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]"HelpPane.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]"explorer.exe"="1""HelpPane.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]"prevhost.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]"HelpPane.exe"="0""prevhost.exe"="0"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]"PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]"PresentationHost.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]"msimn.exe"="1""outlook.exe"="1""winmail.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]"HelpPane.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]"excel.exe"="1""infopath.exe"="1""powerpnt.exe"="1""winword.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]"HelpPane.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]"HelpPane.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]"msn.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]"iexplore.exe"="1""prevhost.exe"="1"[HKLM64\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]"explorer.exe"="1""iexplore.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""OSE.EXE"="1""VSTOInstaller.exe"="1""OSPPREARM.EXE"="1""LICLUA.EXE"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]"PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]"HelpPane.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]"*"="1""explorer.exe"="1""iexplore.exe"="1""infopath.exe"="0""wmplayer.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BFCACHE]"iexplore.exe"="0"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]"devenv.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]"HelpPane.exe"="1""prevhost.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]"HelpPane.exe"="1""PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]"HelpPane.exe"="1""PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]"HelpPane.exe"="1""PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]"HelpPane.exe"="10000""prevhost.exe"="8000""Power2Go.exe"="8000""WebAuthBroker.exe"="10000""sllauncher.exe"="8000""MediaShow6.exe"="11000""PowerDVD.exe"="8000""AcqWeb.exe"="11001""FoxitPhantomPDF.exe"="11000""Syncios.exe"="10001""hippoedit.exe"="9999""WiseDuplicateFinder.exe"="11000""ClPhpEd.exe"="11000""WiseFolderHider.exe"="11000""FoxitReader.exe"="11000""wisedrivercare.exe"="11000""ProductAgentUI.exe"="11000""onlineTV.exe"="11000"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]"PresentationHost.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]"*"="1""explorer.exe"="1""iexplore.exe"="1""SAPfewgsrv.exe"="0""SAPGUI.exe"="0""SAPGuiIT.exe"="0""SAPLgPad.exe"="0""SAPLOGON.exe"="0""Scale_for_R3.exe"="0""wmplayer.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS]"onlineTV.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]"ieuser.exe"="1""iexplore.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]"HelpPane.exe"="1""PresentationHost.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]"YahooMusicEngine.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]"HelpPane.exe"="100000"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]"dexplore.exe"="1""helppane.exe"="1""PresentationHost.exe"="0""devenv.exe"="0""sllauncher.exe"="0"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]"msfeedssync.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]"PresentationHost.exe"="1""prevhost.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING]"onlineTV.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]"HelpPane.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IFRAME_MAILTO_THRESHOLD]"devenv.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]""="""msiexec.exe"="0"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]"cs.exe"="1""waol.exe"="1""wm.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]"iexplore.exe"="0"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]"helppane.exe"="0"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]"wlmail.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]"explorer.exe"="1""HelpPane.exe"="1""iexplore.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""devenv.exe"="1""sllauncher.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]"explorer.exe"="4""sllauncher.exe"="6""iexplore.exe"="10"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]"explorer.exe"="2""sllauncher.exe"="6""iexplore.exe"="10"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]"explorer.exe"="1""HelpPane.exe"="1""iexplore.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]"mshta.exe"="1""outlook.exe"="1""sidebar.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]"explorer.exe"="0""iexplore.exe"="0""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]"communicator.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]"HelpPane.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""devenv.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]"HelpPane.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]"msimn.exe"="1""prevhost.exe"="1""winmail.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]"PresentationHost.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]"HelpPane.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]"explorer.exe"="1""HelpPane.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION]"devenv.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]"prevhost.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]"HelpPane.exe"="0""prevhost.exe"="0"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]"PresentationHost.exe"="1""devenv.exe"="1""sllauncher.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]"PresentationHost.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]"msimn.exe"="1""outlook.exe"="1""winmail.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]"HelpPane.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]"excel.exe"="1""infopath.exe"="1""powerpnt.exe"="1""winword.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]"HelpPane.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]"HelpPane.exe"="1""devenv.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]"msn.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]"explorer.exe"="1""iexplore.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]"iexplore.exe"="1""prevhost.exe"="1"[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]"explorer.exe"="1""iexplore.exe"="1""PresentationHost.exe"="1""prevhost.exe"="1""wmplayer.exe"="1""VSTOInstaller.exe"="1" ---------- | The Created last ones ¦ Modified [MD5.00000000000000000000000000000000] - [09/07/2017 08:49:36] - |AD| - [3622824] - C:\Program Files (x86)\7-Zip[MD5.00000000000000000000000000000000] - [06/07/2017 15:16:49] - |AD| - [23488557] - C:\Program Files (x86)\A-PDF to Video[MD5.00000000000000000000000000000000] - [11/07/2017 08:13:54] - |D| - [100843310] - C:\Program Files (x86)\Ad-Aware Browser[MD5.00000000000000000000000000000000] - [11/07/2017 07:53:55] - |D| - [914894562] - C:\Program Files (x86)\Amazing Studio[MD5.00000000000000000000000000000000] - [11/07/2017 08:13:38] - |D| - [44559946] - C:\Program Files (x86)\Android Data Recovery[MD5.00000000000000000000000000000000] - [11/07/2017 08:14:33] - |D| - [20841628] - C:\Program Files (x86)\Any Data Recovery Pro[MD5.00000000000000000000000000000000] - [21/07/2017 19:48:24] - |D| - [220633593] - C:\Program Files (x86)\AnyMP4 Studio[MD5.00000000000000000000000000000000] - [22/07/2017 15:13:10] - |D| - [75712097] - C:\Program Files (x86)\AoaoPhoto Digital Studio[MD5.00000000000000000000000000000000] - [09/07/2017 20:26:26] - |AD| - [106367910] - C:\Program Files (x86)\ATI Technologies[MD5.00000000000000000000000000000000] - [22/07/2017 12:07:44] - |D| - [18242564] - C:\Program Files (x86)\Auslogics[MD5.00000000000000000000000000000000] - [07/07/2017 09:57:06] - |AD| - [902835198] - C:\Program Files (x86)\Avanquest[MD5.00000000000000000000000000000000] - [06/07/2017 15:22:22] - |AD| - [17019810] - C:\Program Files (x86)\Avant Browser[MD5.00000000000000000000000000000000] - [09/07/2017 09:15:01] - |D| - [5864575] - C:\Program Files (x86)\Belarc[MD5.00000000000000000000000000000000] - [11/07/2017 10:00:25] - |AD| - [15428702] - C:\Program Files (x86)\BOINC[MD5.00000000000000000000000000000000] - [09/07/2017 09:01:54] - |AD| - [172197537] - C:\Program Files (x86)\Calibre2[MD5.00000000000000000000000000000000] - [11/07/2017 08:15:02] - |D| - [17466465] - C:\Program Files (x86)\Card Data Recovery[MD5.00000000000000000000000000000000] - [07/07/2017 09:38:04] - |D| - [146113898] - C:\Program Files (x86)\Codelobster Software[MD5.00000000000000000000000000000000] - [11/07/2017 08:46:33] - |D| - [287600924] - C:\Program Files (x86)\Comodo[MD5.00000000000000000000000000000000] - [21/07/2017 18:34:03] - |D| - [5920516] - C:\Program Files (x86)\concept design[MD5.00000000000000000000000000000000] - [22/07/2017 15:34:35] - |D| - [11164666] - C:\Program Files (x86)\Contrôle Parental Orange[MD5.00000000000000000000000000000000] - [21/07/2017 10:22:49] - |D| - [0] - C:\Program Files (x86)\Dashlane[MD5.00000000000000000000000000000000] - [11/07/2017 08:15:25] - |D| - [2820738] - C:\Program Files (x86)\Data Wipe[MD5.00000000000000000000000000000000] - [21/07/2017 18:36:05] - |D| - [108300976] - C:\Program Files (x86)\Deskshare[MD5.00000000000000000000000000000000] - [21/07/2017 17:27:21] - |D| - [113965483] - C:\Program Files (x86)\Digiarty[MD5.00000000000000000000000000000000] - [22/07/2017 15:18:04] - |D| - [21884969] - C:\Program Files (x86)\DoYourData[MD5.00000000000000000000000000000000] - [06/07/2017 15:16:17] - |D| - [74852168] - C:\Program Files (x86)\DsNET Corp[MD5.00000000000000000000000000000000] - [21/07/2017 18:24:03] - |D| - [26594453] - C:\Program Files (x86)\DTLSoft[MD5.00000000000000000000000000000000] - [21/07/2017 18:14:33] - |D| - [53192328] - C:\Program Files (x86)\EZ-Agile Project Management [Community][MD5.00000000000000000000000000000000] - [21/07/2017 18:04:56] - |D| - [9234501] - C:\Program Files (x86)\File Arranger[MD5.00000000000000000000000000000000] - [07/07/2017 11:57:39] - |AD| - [1775875] - C:\Program Files (x86)\File Identifier[MD5.00000000000000000000000000000000] - [07/07/2017 09:49:37] - |AD| - [5939143] - C:\Program Files (x86)\Folder Size[MD5.00000000000000000000000000000000] - [11/07/2017 08:21:18] - |AD| - [5024997] - C:\Program Files (x86)\Free Any Data Encryption[MD5.00000000000000000000000000000000] - [10/07/2017 23:04:45] - |AD| - [24908441] - C:\Program Files (x86)\Free Any Data Recovery[MD5.00000000000000000000000000000000] - [11/07/2017 08:51:04] - |AD| - [13812287] - C:\Program Files (x86)\Free Any Photo Recovery[MD5.00000000000000000000000000000000] - [21/07/2017 11:15:37] - |D| - [0] - C:\Program Files (x86)\Genesys Logic[MD5.00000000000000000000000000000000] - [21/07/2017 17:19:05] - |D| - [330514010] - C:\Program Files (x86)\GiliSoft[MD5.00000000000000000000000000000000] - [06/07/2017 15:23:41] - |D| - [79556408] - C:\Program Files (x86)\iFunSoft[MD5.00000000000000000000000000000000] - [07/07/2017 11:49:16] - |D| - [149018801] - C:\Program Files (x86)\IMSIDesign[MD5.00000000000000000000000000000000] - [07/07/2017 10:51:16] - |AD| - [38774426] - C:\Program Files (x86)\Kastor All Video Downloader[MD5.00000000000000000000000000000000] - [21/07/2017 18:58:34] - |D| - [0] - C:\Program Files (x86)\LimeWire[MD5.00000000000000000000000000000000] - [11/07/2017 07:38:40] - |AD| - [21194263] - C:\Program Files (x86)\LiteManager Pro - Server[MD5.00000000000000000000000000000000] - [11/07/2017 07:39:57] - |AD| - [35574977] - C:\Program Files (x86)\LiteManager Pro - Viewer[MD5.00000000000000000000000000000000] - [11/07/2017 09:07:00] - |AD| - [59499560] - C:\Program Files (x86)\Malwarebytes Anti-Malware[MD5.00000000000000000000000000000000] - [11/07/2017 09:06:12] - |D| - [921100] - C:\Program Files (x86)\marmiton-install.exe 0.0.0.0[MD5.00000000000000000000000000000000] - [22/07/2017 17:44:55] - |D| - [94045922] - C:\Program Files (x86)\Mozilla Firefox[MD5.00000000000000000000000000000000] - [09/07/2017 09:34:51] - |D| - [442253] - C:\Program Files (x86)\Mozilla Maintenance Service[MD5.00000000000000000000000000000000] - [09/07/2017 09:48:28] - |AD| - [88483823] - C:\Program Files (x86)\Mozilla Thunderbird[MD5.00000000000000000000000000000000] - [10/07/2017 20:53:23] - |AD| - [1981739] - C:\Program Files (x86)\MRU-Blaster[MD5.00000000000000000000000000000000] - [21/07/2017 16:52:00] - |D| - [16159124] - C:\Program Files (x86)\MultiCommander[MD5.00000000000000000000000000000000] - [11/07/2017 07:46:52] - |AD| - [2313046120] - C:\Program Files (x86)\Nero[MD5.00000000000000000000000000000000] - [11/07/2017 08:22:49] - |AD| - [46550478] - C:\Program Files (x86)\OkayFreedom[MD5.00000000000000000000000000000000] - [09/07/2017 09:01:45] - |D| - [809496] - C:\Program Files (x86)\OpenAL[MD5.00000000000000000000000000000000] - [09/07/2017 09:19:50] - |AD| - [315569257] - C:\Program Files (x86)\Opera[MD5.00000000000000000000000000000000] - [06/07/2017 12:00:32] - |D| - [133854619] - C:\Program Files (x86)\Paragon Software[MD5.00000000000000000000000000000000] - [11/07/2017 07:37:56] - |AD| - [1331793] - C:\Program Files (x86)\PasswordConfidential[MD5.00000000000000000000000000000000] - [06/07/2017 15:29:17] - |D| - [1269883] - C:\Program Files (x86)\PDF Files Text Extractor v2.0[MD5.00000000000000000000000000000000] - [21/07/2017 18:37:38] - |D| - [29041407] - C:\Program Files (x86)\PeaZip[MD5.00000000000000000000000000000000] - [21/07/2017 18:38:25] - |D| - [22314723] - C:\Program Files (x86)\Photopus[MD5.00000000000000000000000000000000] - [10/07/2017 20:41:31] - |AD| - [22886767] - C:\Program Files (x86)\Photopus Pro[MD5.00000000000000000000000000000000] - [08/07/2017 14:40:46] - |D| - [519080824] - C:\Program Files (x86)\Realtek[MD5.00000000000000000000000000000000] - [09/07/2017 09:14:47] - |AD| - [24697864] - C:\Program Files (x86)\Recover Keys[MD5.00000000000000000000000000000000] - [07/07/2017 12:07:46] - |AD| - [25547914] - C:\Program Files (x86)\Remo Recover Outlook Express[MD5.00000000000000000000000000000000] - [07/07/2017 10:38:51] - |AD| - [21350931] - C:\Program Files (x86)\Remo Repair Word 2.0[MD5.00000000000000000000000000000000] - [07/07/2017 19:22:32] - |D| - [525850646] - C:\Program Files (x86)\Roxio[MD5.00000000000000000000000000000000] - [07/07/2017 12:21:43] - |AD| - [2273384605] - C:\Program Files (x86)\Roxio 2012[MD5.00000000000000000000000000000000] - [11/07/2017 08:19:07] - |D| - [44263902] - C:\Program Files (x86)\Samsung Data Recovery[MD5.00000000000000000000000000000000] - [22/07/2017 12:22:34] - |D| - [34958266] - C:\Program Files (x86)\Simple Disk Optimizer[MD5.00000000000000000000000000000000] - [22/07/2017 12:18:32] - |D| - [31223366] - C:\Program Files (x86)\Simple Malware Protector[MD5.00000000000000000000000000000000] - [21/07/2017 09:49:09] - |D| - [83053707] - C:\Program Files (x86)\SoftOrbits Photo Retoucher[MD5.00000000000000000000000000000000] - [06/07/2017 15:20:11] - |AD| - [174160344] - C:\Program Files (x86)\SRWare Iron[MD5.00000000000000000000000000000000] - [22/07/2017 06:58:53] - |D| - [707214282] - C:\Program Files (x86)\Studio V5[MD5.00000000000000000000000000000000] - [21/07/2017 16:57:19] - |D| - [4206814] - C:\Program Files (x86)\Super Password[MD5.00000000000000000000000000000000] - [21/07/2017 10:56:02] - |D| - [32677236] - C:\Program Files (x86)\SuperBoost[MD5.00000000000000000000000000000000] - [22/07/2017 07:01:57] - |D| - [61001395] - C:\Program Files (x86)\SupersonicPC[MD5.00000000000000000000000000000000] - [08/07/2017 14:01:23] - |HD| - [0] - C:\Program Files (x86)\Temp[MD5.00000000000000000000000000000000] - [11/07/2017 08:18:52] - |D| - [4385602] - C:\Program Files (x86)\Tenorshare Partition Manager[MD5.00000000000000000000000000000000] - [11/07/2017 08:15:54] - |D| - [64598071] - C:\Program Files (x86)\Tenorshare Video Converter Standard[MD5.00000000000000000000000000000000] - [09/07/2017 09:15:21] - |AD| - [2023813] - C:\Program Files (x86)\Top Password[MD5.00000000000000000000000000000000] - [21/07/2017 16:57:05] - |D| - [2038393] - C:\Program Files (x86)\TSS[MD5.00000000000000000000000000000000] - [22/07/2017 16:56:21] - |D| - [48558537] - C:\Program Files (x86)\Tweaking.com[MD5.00000000000000000000000000000000] - [06/07/2017 15:21:46] - |AD| - [16914250] - C:\Program Files (x86)\USB Safely Remove[MD5.00000000000000000000000000000000] - [22/07/2017 12:00:30] - |D| - [64030152] - C:\Program Files (x86)\UTILILAB[MD5.00000000000000000000000000000000] - [09/07/2017 08:34:30] - |D| - [285030907] - C:\Program Files (x86)\Windows Boot Genius[MD5.00000000000000000000000000000000] - [22/07/2017 15:14:24] - |D| - [49585269] - C:\Program Files (x86)\Windscribe[MD5.00000000000000000000000000000000] - [22/07/2017 15:17:09] - |D| - [36545075] - C:\Program Files (x86)\WonderFox Soft[MD5.00000000000000000000000000000000] - [21/07/2017 19:53:35] - |D| - [770769] - C:\Program Files (x86)\Xvid[MD5.D41D8CD98F00B204E9800998ECF8427E] - [21/07/2017 19:10:32] - |A| - [0] - C:\WINDOWS\1[MD5.293283CF350E00AF8C4A2770BDBF4D50] - [06/07/2017 18:33:58] - |AC| - [64512] - C:\WINDOWS\bfsvc.exe[MD5.A2D3EB8406C58E919AE3A92A38F197E5] - [22/07/2017 07:12:32] - |A| - [17627] - C:\WINDOWS\DirectX.log[MD5.CA3BF0F15BA4F24D511BFEE725CC89BD] - [11/07/2017 23:03:18] - |A| - [4847424] - C:\WINDOWS\explorer.exe[MD5.E064A38A807C83ADC8AD9E1B54C85CF9] - [06/07/2017 18:34:10] - |A| - [975360] - C:\WINDOWS\HelpPane.exe[MD5.00000000000000000000000000000000] - [22/07/2017 16:11:49] - |D| - [133328152] - C:\WINDOWS\LastGood[MD5.00000000000000000000000000000000] - [21/07/2017 11:15:36] - |D| - [53029553] - C:\WINDOWS\LastGood.Tmp[MD5.04B0D40C4FA88E6FAB7EACD5D9CD64B9] - [19/07/2017 13:21:07] - |A| - [480644444] - C:\WINDOWS\MEMORY.DMP[MD5.D442530453C42CBD1D8874C8E5A5869B] - [17/07/2017 08:28:47] - |A| - [335664] - C:\WINDOWS\PFRO.log[MD5.0DD3698CBEE8CB6ACEC3379A813F62C1] - [21/07/2017 11:24:13] - |A| - [4332032] - C:\WINDOWS\RtCRU64.exe[MD5.A095B3E67C8EB8F2137EAC63687F2F5B] - [09/07/2017 07:32:27] - |A| - [2839520] - C:\WINDOWS\RtlExUpd.dll[MD5.114B5AAEF0C4CF3734C7973A7C642673] - [17/07/2017 12:27:44] - |A| - [9950] - C:\WINDOWS\setupact.log[MD5.D41D8CD98F00B204E9800998ECF8427E] - [17/07/2017 12:27:44] - |A| - [0] - C:\WINDOWS\setuperr.log[MD5.00000000000000000000000000000000] - [09/07/2017 09:02:17] - |D| - [4110280] - C:\WINDOWS\SmartFix[MD5.ADFD9CF83AD65D38F107909521159EFD] - [22/07/2017 16:55:53] - |A| - [190806] - C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt[MD5.4C364F600CC7370E0ED056B86E373556] - [05/07/2017 12:15:00] - |A| - [51621] - C:\WINDOWS\uninstaller.dat[MD5.321E59EE3B05221A53AC7041C7160FFA] - [21/07/2017 19:10:38] - |A| - [2434] - C:\WINDOWS\W7Patcher_x64_Uninstall.log[MD5.038356387332650843BCB352BB89A101] - [17/07/2017 08:29:55] - |A| - [275] - C:\WINDOWS\WindowsUpdate.log[MD5.E7633AA6A479BBBE82DBE794126BBECA] - [07/07/2017 12:47:35] - |A| - [132] - C:\WINDOWS\wininit.ini[MD5.9A2DB1C46E2093A7FD23A9B850D17013] - [15/07/2017 16:24:27] - |A| - [52038142] - C:\WINDOWS\WinSxS_NTFS.acl[MD5.F1D3FF8443297732862DF21DC4E57262] - [07/07/2017 09:57:06] - |ASH| - [4] - C:\WINDOWS\wisefs.dat[MD5.0F4092E1E0DC29C0D790830964490522] - [07/07/2017 09:57:06] - |A| - [55712] - C:\WINDOWS\WiseFs64.sys[MD5.72F2D357120F95C1E725C22915FE95E1] - [07/07/2017 10:36:03] - |A| - [193] - C:\WINDOWS\WORDPAD.INI[MD5.7A207B6C9BC806F2156C66B9A21F5611] - [07/07/2017 13:07:22] - |A| - [25824] - C:\WINDOWS\ZAM.krnl.trace[MD5.983E0FBBE45EFC38FA95FD591BF7EC16] - [07/07/2017 13:07:22] - |A| - [2148] - C:\WINDOWS\ZAM_Guard.krnl.trace[MD5.81082E9E753FBEB85F23F9B2CC179C56] - [11/07/2017 07:26:12] - |AC| - [35158016] - C:\WINDOWS\Installer\1affa1.msi[MD5.A94AB35BA3BEF7F94E163FC964E44675] - [11/07/2017 07:30:41] - |AC| - [2140672] - C:\WINDOWS\Installer\1affa7.msi[MD5.E41BF30257495A6FF15BC30FDE08E08C] - [11/07/2017 07:30:34] - |AC| - [5588992] - C:\WINDOWS\Installer\1affae.msi[MD5.E4A68C523300D19EFAC25B0455A86201] - [11/07/2017 07:27:46] - |AC| - [1199104] - C:\WINDOWS\Installer\1affb5.msi[MD5.C398032386D565AA9DEEF9B4CBE68690] - [11/07/2017 07:27:39] - |AC| - [1216000] - C:\WINDOWS\Installer\1affbc.msi[MD5.979F1F98EA72C0B18F9C3A7ED4A928C2] - [11/07/2017 07:30:45] - |AC| - [3156992] - C:\WINDOWS\Installer\1affc3.msi[MD5.241116FACDD2275530D2AB31D942EB93] - [11/07/2017 07:29:33] - |AC| - [1216000] - C:\WINDOWS\Installer\1affca.msi[MD5.A21C9CB38F4A56EB2E0DDDD92911E5B4] - [11/07/2017 07:27:37] - |AC| - [1217536] - C:\WINDOWS\Installer\1affd1.msi[MD5.0CE3DB6358B90E9CC1A53D59A13E5E32] - [11/07/2017 07:27:36] - |AC| - [3817472] - C:\WINDOWS\Installer\1affd8.msi[MD5.CCD1A3FF06A8338BFD9E5F760754B7B5] - [11/07/2017 07:27:12] - |AC| - [867328] - C:\WINDOWS\Installer\1affdf.msi[MD5.E53A82728A820134CA9E5820FE329254] - [11/07/2017 07:29:53] - |AC| - [1812480] - C:\WINDOWS\Installer\1affe6.msi[MD5.C04CB61ECD7207150E960D23017734B1] - [11/07/2017 07:29:31] - |AC| - [3005440] - C:\WINDOWS\Installer\1affed.msi[MD5.6C3D5D17E37BFCCC6ED2924EE222ACFF] - [11/07/2017 07:27:56] - |AC| - [2101248] - C:\WINDOWS\Installer\1afff4.msi[MD5.88F348EAD95E84FC203EB578EDC58B29] - [11/07/2017 07:27:22] - |AC| - [5206528] - C:\WINDOWS\Installer\1afffb.msi[MD5.87B42C89EDAC6D0B7E8057EEE5B134E5] - [11/07/2017 07:27:24] - |AC| - [4472320] - C:\WINDOWS\Installer\1b0002.msi[MD5.73AAC6E63825CF6EAED974AF9F312398] - [11/07/2017 07:26:31] - |AC| - [5762560] - C:\WINDOWS\Installer\1b0009.msi[MD5.4EE74D0ED3F3B8049F55A2501D7BEEA0] - [11/07/2017 07:27:20] - |AC| - [1181696] - C:\WINDOWS\Installer\1b0010.msi[MD5.FA46E4D23737B0B7377AF6F06E825A0F] - [11/07/2017 07:27:10] - |AC| - [1373696] - C:\WINDOWS\Installer\1b0016.msi[MD5.63115A5698215F6D1A388A7E3CF5B8FC] - [11/07/2017 07:27:49] - |AC| - [4322304] - C:\WINDOWS\Installer\1b001c.msi[MD5.E0732E2D2725DAE49CC4D343D0DEBB16] - [11/07/2017 07:29:37] - |AC| - [3717632] - C:\WINDOWS\Installer\1b0023.msi[MD5.CA70C605C7423D3BD80BAA96527BAC6B] - [11/07/2017 07:30:47] - |AC| - [2830336] - C:\WINDOWS\Installer\1b002a.msi[MD5.83D2E5BDBB119F6BA08AE5EC9DA44769] - [11/07/2017 07:29:28] - |AC| - [1168896] - C:\WINDOWS\Installer\1b0031.msi[MD5.51B34393B44FE1EF6976D8C841421F21] - [11/07/2017 07:29:50] - |AC| - [866816] - C:\WINDOWS\Installer\1b0038.msi[MD5.7730C7CB6213D019A9ED600B6F336FEB] - [11/07/2017 07:27:11] - |AC| - [2380288] - C:\WINDOWS\Installer\1b003f.msi[MD5.08132257EF664AA0ABB4CE98427FE73E] - [11/07/2017 07:41:05] - |AC| - [5780992] - C:\WINDOWS\Installer\1b0044.msi[MD5.72C6757046F50341BEC71B0E0F4C8670] - [11/07/2017 07:41:14] - |AC| - [1183744] - C:\WINDOWS\Installer\1b004a.msi[MD5.F9651F199BEF3A36F25CE49ECDD99950] - [11/07/2017 07:42:15] - |AC| - [1357824] - C:\WINDOWS\Installer\1b0051.msi[MD5.5C429B2E031B1FB6C3139BE4C20B7DF4] - [11/07/2017 07:41:58] - |AC| - [1306112] - C:\WINDOWS\Installer\1b0058.msi[MD5.8F496261809F0034D99FD6135F00F86D] - [11/07/2017 07:41:34] - |AC| - [1369600] - C:\WINDOWS\Installer\1b005f.msi[MD5.EAB06DCA869C39A4F5950FA07468F8EF] - [11/07/2017 07:41:20] - |AC| - [1255424] - C:\WINDOWS\Installer\1b0066.msi[MD5.AB22AF8618E3649A971C4D40C75D0239] - [11/07/2017 07:41:17] - |AC| - [1231872] - C:\WINDOWS\Installer\1b006d.msi[MD5.3D6EFEF0BDD46F566F972DAAA9F698B0] - [11/07/2017 07:41:12] - |AC| - [1195520] - C:\WINDOWS\Installer\1b0074.msi[MD5.1C180E3110B50E9B72C0D7BE63C8C6D3] - [11/07/2017 07:44:50] - |AC| - [1228288] - C:\WINDOWS\Installer\1b007c.msi[MD5.F53C829E593395923E376B1881201EE3] - [11/07/2017 07:44:41] - |AC| - [1216512] - C:\WINDOWS\Installer\1b0083.msi[MD5.CADC161C76F43C9B2311584DB697AAC2] - [11/07/2017 07:44:05] - |AC| - [1485824] - C:\WINDOWS\Installer\1b008a.msi[MD5.76A1754E69C7B3D0ED7BC7E012009525] - [11/07/2017 07:43:39] - |AC| - [1241088] - C:\WINDOWS\Installer\1b0091.msi[MD5.5EEF9703364D15DFF4464B3FD7A715F0] - [11/07/2017 07:43:21] - |AC| - [1201152] - C:\WINDOWS\Installer\1b0098.msi[MD5.63407A91C80A0BEB3771B283EDDD362B] - [11/07/2017 07:42:58] - |AC| - [1291264] - C:\WINDOWS\Installer\1b009f.msi[MD5.6D2599A79F991A00A1FA875255CB4ADC] - [07/07/2017 04:24:52] - |AC| - [11223040] - C:\WINDOWS\Installer\27fd6ab.msi[MD5.B8BF0984DEF73DC22A418B3432CBD06E] - [07/07/2017 04:26:18] - |AC| - [14274560] - C:\WINDOWS\Installer\27fd6c6.msi[MD5.CF4BD0F8A5D1CFC63EC5759D4DFC4811] - [06/07/2017 15:21:45] - |RAC| - [53350400] - C:\WINDOWS\Installer\298b4e.msp[MD5.BBA7C93A9FCAAF334448E2D018D79D5D] - [07/07/2017 07:13:20] - |AC| - [294912] - C:\WINDOWS\Installer\39e5938.msi[MD5.ED13D8E8C471940489059744C948233D] - [06/07/2017 08:08:17] - |AC| - [45056] - C:\WINDOWS\Installer\41cc4a.msi[MD5.E60D71A0EB4FD335B33650D3F32A3F4D] - [09/07/2017 09:01:43] - |AC| - [63705088] - C:\WINDOWS\Installer\4251bf.msi[MD5.C2561306DCABF17384439A25DFA1CE14] - [11/07/2017 09:01:51] - |AC| - [1160704] - C:\WINDOWS\Installer\679227.msi[MD5.7F5312B605CC0B4278411E7E8085652D] - [02/07/2017 14:26:59] - |AC| - [43397120] - C:\WINDOWS\Installer\8a13b9.msi[MD5.03C0024F948C5EEE4D64827FBF2C8E0B] - [11/07/2017 09:58:57] - |AC| - [8488960] - C:\WINDOWS\Installer\9be001.msi[MD5.E6466983CB50D0C5F3549FC4C2018BE6] - [07/07/2017 13:42:23] - |AC| - [184676352] - C:\WINDOWS\Installer\b488e.msi[MD5.5DB162CAE8C83C4CC09C4DEDBD3B9211] - [11/07/2017 08:21:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}[MD5.1AF3F9CCDFFC5B423391195EC12A14B2] - [07/07/2017 19:26:32] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{0517F875-BBB2-4812-A63E-733B33CEF215}[MD5.B115323487B46BBB4E4361CC21C1DE5D] - [07/07/2017 13:22:25] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{05C61A04-0BDA-4BAC-B4E3-3809FB768EFA}[MD5.866896DF906F5DB5B111F1A49FDF3FAE] - [11/07/2017 08:10:57] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{05C6B128-1B40-4495-9CB9-090B368BFA0A}[MD5.09C76C4E14EAB197361D37AF4BB6924C] - [09/07/2017 20:29:30] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{063E67F0-C298-8A2A-0FA6-84C15322A4E0}[MD5.2CD1FFC16A470AD3134CF1F64FB7F1E9] - [07/07/2017 19:55:53] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{071c9b48-7c32-4621-a0ac-3f809523288f}[MD5.4EAB992E93417D33EBC5EEF53E223E2F] - [09/07/2017 20:28:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{07326A3E-02B3-1078-25D7-B8666BA8FE15}[MD5.333C1B93F347C7E6B41A72B4677CE34D] - [09/07/2017 20:27:48] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}[MD5.C76EDFD3E1B0FEE359B72F584619B3E6] - [09/07/2017 09:01:49] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{0B456D24-DD76-4163-8175-4F720E6F3C92}[MD5.D3F7A56F24ABCA92A140B6CD9AF59995] - [09/07/2017 20:26:32] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{11087D24-567D-7D88-69C6-D7A08B5F4C47}[MD5.D92CE2BBE149E0BECE4FB8754C17B17F] - [11/07/2017 08:44:43] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{150D88F1-40AF-4678-A39D-BCE2332F34E5}[MD5.5E95A0E1E8DF0B12DC5B8C2F77228524] - [09/07/2017 20:26:43] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{1AD99E77-37CC-744E-39CA-67F6FD34565A}[MD5.55F8DE9FFE26D8690A627FBFFB9D103D] - [11/07/2017 07:49:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{1B6F5E51-575E-4693-BCA2-7543570D076D}[MD5.BDBE1160CE8E87EF25E5CEEDCDE7B397] - [09/07/2017 20:27:38] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}[MD5.E6DF87CF74923F3AC2DAECE14B48A55E] - [11/07/2017 08:17:29] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{1C63279A-BF36-4852-9924-B1978D6585A6}[MD5.B45DAB766908B6553838BB1DB77726C0] - [07/07/2017 19:45:11] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{1D273D91-D7D5-4036-8B84-EB4615FF5F81}[MD5.BBFF42F59CDA81A42BACCC7AA219DA5C] - [09/07/2017 20:27:53] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}[MD5.D052F96CB6ACEF98284D3B99221C8CA7] - [11/07/2017 08:31:51] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}[MD5.AC1346C5210B8C43876B5B00B9627644] - [11/07/2017 07:55:50] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{2432E589-6256-4513-B0BF-EFA8E325D5F0}[MD5.9F26C486C10D53F0F7A6BC1AB74DF7AA] - [09/07/2017 20:28:50] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}[MD5.0ACD4B80989E98E0527D0C56C0BBDA44] - [11/07/2017 08:34:48] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}[MD5.998AF96B5606E9260CE1E5B18950BAE7] - [11/07/2017 07:50:36] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{29F67D84-3A70-456E-806A-52301B02070B}[MD5.1A2A67AEAE9C02D50A4D6FE62E55AC32] - [07/07/2017 19:24:32] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{2B682751-E749-441C-A4B3-1F538E26E56E}[MD5.1F6440665DB62E45FDE30A5E456BC524] - [09/07/2017 20:27:58] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{2D07E15C-A9A4-D8D6-D371-92EC8779E587}[MD5.4C5D33A8AEC5C1B6C39F3D4BD4F1DD43] - [07/07/2017 20:02:23] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{2DDBB2E7-CB4E-4E65-A6B9-B9C95ED77D42}[MD5.A5DF2111E6F16C4522B03AB73E7B22C0] - [07/07/2017 19:27:12] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}[MD5.C150AD945C6DAEC92772D9788101E84A] - [07/07/2017 19:19:00] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{302763FD-5CEA-4DFF-80C8-9B41414C4822}[MD5.DB7004D18141708C188304B660C1446D] - [09/07/2017 20:27:43] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}[MD5.23395FAC863D3B0009D473F55ED4F980] - [09/07/2017 20:29:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{35A71DED-DA81-1313-352A-EC8A0B27DF3B}[MD5.E29E1658F5B3F28EDFF57A7012411283] - [07/07/2017 10:41:07] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{3A9527CF-4E91-4683-A03F-F1AD022126E5}[MD5.FBC1A37758FC1EDBEE07A8DE36A1C601] - [11/07/2017 08:27:56] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{4D25D881-7183-462F-95C8-990CA1944E0B}[MD5.97358ACC2A17426BB2FC729FC12432F3] - [11/07/2017 08:45:16] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}[MD5.9D856B008469544B6DEE1D941C85F965] - [11/07/2017 07:39:46] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{5686E484-7136-4674-A4B2-508C7B26DCA4}[MD5.458D44E87F2EA8046314E26A3DD247F5] - [07/07/2017 13:46:00] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{56EECD69-F428-41C4-ADF6-6CDEE14DDF3F}[MD5.75A2AC97DE251DEFE3543BCAF60AC3FD] - [21/07/2017 12:06:51] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{582EA838-9199-3518-A05C-DB09462F68EC}[MD5.B10511753918AF9B8092ED3CE138DB79] - [11/07/2017 07:54:58] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}[MD5.C878F4D6085410595E707477AC1CB9BF] - [11/07/2017 08:00:52] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{60251665-84B4-41D6-84BF-6D50CE68DD08}[MD5.7BD281B8F1BB99C2F22F3B45F42C334C] - [11/07/2017 08:11:23] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}[MD5.0CC1AC4655B5444F50256D98EFC559C0] - [21/07/2017 12:07:19] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{68306422-7C57-373F-8860-D26CE4BA2A15}[MD5.F9C644CB7552CDBD55F4432B107F7FBB] - [11/07/2017 08:08:16] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{6861C1AD-9829-4DE4-8647-4785ECEA421A}[MD5.4CA6512980B196A55CA5680261AD91CA] - [09/07/2017 20:27:20] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}[MD5.00E670834D2117588787DA613108287D] - [11/07/2017 07:38:35] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{71FFA475-24D5-44FB-A51F-39B699E3D82C}[MD5.6963589324D61405FA022CE53257145B] - [07/07/2017 19:21:13] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{729B89D0-946A-407E-A121-343BD3320C40}[MD5.932A5477E52E417948A4B40DDE16DFF0] - [11/07/2017 09:59:36] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{7309D717-F38D-436D-9537-066AA0AC7639}[MD5.A130A370F5145231D82DB9810AB07C9E] - [07/07/2017 21:35:12] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{75D563F2-A567-4815-A2E2-080D3503E209}[MD5.75B8654EB4A31C540D9D4EA81C671BF5] - [07/07/2017 18:10:42] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{77CDA026-3860-4C95-8233-34F3CEF121FB}[MD5.285DD964EFE26CE11C747E02064C8633] - [09/07/2017 20:29:24] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{79D22166-78C1-2AD4-04E7-BD22BD58FD46}[MD5.EEA7D46509F66E1B527DBBC876AD1EB1] - [11/07/2017 08:24:11] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}[MD5.5A21C33B7BD6412F65CB0E25F7796FD7] - [11/07/2017 08:01:48] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}[MD5.736BD39A0E71950F83A3ED8FB0891392] - [11/07/2017 08:05:57] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{7F22DD97-256D-491D-9090-743FADC79BBE}[MD5.83A34B576A25FAEEDA4E781228BB955A] - [09/07/2017 20:28:04] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{82CA1714-13EA-F419-91FE-12834424745E}[MD5.1E65D4CAAD09716D74BBF28A3F6CB7ED] - [11/07/2017 08:25:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}[MD5.55A26D69FDC74DE0471C30A77A529C8B] - [07/07/2017 12:21:21] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}[MD5.147443134D7161D82AE74497D0E49589] - [11/07/2017 08:29:14] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}[MD5.CDAD4534B98D5ACC1AD74E80B11EEDDA] - [09/07/2017 20:29:11] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}[MD5.2670DA4DC232B5CD13E4CEDF5B2D4AA6] - [21/07/2017 11:51:36] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{8D4F7A6D-6B81-3DC8-9C21-6008E4866727}[MD5.165E7DCAF2E3EF7BDDD5A103BF048C3A] - [07/07/2017 13:44:06] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{8EFB7927-48AD-4E6D-91B7-6B2BD6C3F380}[MD5.3922EFD028C0BDB6DC281777B7124BE5] - [09/07/2017 20:28:57] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}[MD5.29612ED80F239FABFD33316ABDA72484] - [06/07/2017 10:43:31] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{90160000-007E-0000-1000-0000000FF1CE}[MD5.AC2EAE1643E11C2E91AF77CF0D0DE21C] - [06/07/2017 10:41:22] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{90160000-008C-0000-1000-0000000FF1CE}[MD5.1AA152B0D12EF735C3E42040ED57FE1C] - [06/07/2017 10:43:27] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{90160000-008C-0409-1000-0000000FF1CE}[MD5.AD05DF9A7A1BDC71B4EAE884A539052A] - [22/07/2017 07:10:28] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{9074000C-5331-4686-92D8-6C3066E99C63}[MD5.1641FA026175B740D15F3CDB3C1913B4] - [11/07/2017 08:17:52] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{910B539D-F257-46C8-9CB8-6C95EFF9CF22}[MD5.FFACC72E5CC8F5C93626DF6609AF2518] - [08/07/2017 06:49:59] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{929FBD26-9020-399B-9A7A-751D61F0B942}[MD5.6DE6870596A1B7C564038A681D9D01D3] - [11/07/2017 07:57:28] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{92EBE575-0C6E-4713-B095-34BB927E5AC6}[MD5.9AD84947721DB4E4194988FE54A4E106] - [11/07/2017 08:22:09] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{955BF340-C379-4375-AA2F-F3BCB2A498AB}[MD5.8A6024EE40070CDD8AAEC5A202E31C64] - [07/07/2017 19:25:03] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{9569E6BC-326A-432F-97AB-35263A327BF1}[MD5.CF40BB75A37C783192266A72BAA0BCAB] - [11/07/2017 07:44:29] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{9C637A56-4287-487F-95BF-1422FC1AA879}[MD5.A104D367D558709E108AB5990F9535C8] - [07/07/2017 18:13:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}[MD5.E076D072272A7F12EB4BB80E6A9C5228] - [11/07/2017 08:14:54] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{A163159C-B476-4501-B163-3F77809AC833}[MD5.4A48D5CF966DD5E0D2B3C7EA6264D4A1] - [11/07/2017 11:02:48] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{A1E718A7-BB83-41B8-BA96-BC219C322B8E}[MD5.AF78823E6E39AC82890D6AB8B68B6346] - [09/07/2017 20:28:31] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{A5A6A4D0-2005-2A05-2E21-495808CF95ED}[MD5.6AF951B65AD78E3E688D171D9CB0FA60] - [08/07/2017 06:49:37] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}[MD5.AF6EC0F069B95BCA9F73967DA55951AC] - [09/07/2017 20:29:04] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{A760847A-C4D9-E7EF-716F-07C6CBF6B147}[MD5.46A0ACFEFBD28072D2C0E04B6BE0514F] - [11/07/2017 07:46:19] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{ABC88553-8770-4B97-B43E-5A90647A5B63}[MD5.11F2BCB03A931429CE033625A2D5CC6A] - [11/07/2017 07:51:56] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{ACE49D50-19CD-44A6-B192-46F985283B26}[MD5.434D15901D8B9453AB13CB917E7E033A] - [09/07/2017 11:39:08] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}[MD5.9941B0B82629EDBF7911E1004F662666] - [09/07/2017 20:29:57] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}[MD5.99C9CC029B16CDCC4A4F7C8A0F737A30] - [07/07/2017 14:09:47] - |AC| - [24576] - C:\WINDOWS\Installer\SourceHash{B07BBB6E-6753-41B0-B4B9-1E9FE4AF5C18}[MD5.ECD84D62827010E914DA4C57DE328C49] - [11/07/2017 08:06:47] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}[MD5.6BA6308B042C48A9999B775F306B3957] - [09/07/2017 20:28:44] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{B839153C-D4D2-F89C-5033-0A160C62706B}[MD5.A7836FE93980C04D2147A22CB93B1B83] - [07/07/2017 18:10:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}[MD5.667D596CBB78506508755DB5692F6FB7] - [07/07/2017 19:24:08] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{BD3EAE4D-862D-4D41-8BB5-F5C2CFFE6022}[MD5.C064E921ABA7938FDBC5095CB10521AA] - [11/07/2017 08:12:34] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}[MD5.D04DDA8E81183F52D62A06881B0BAFC3] - [11/07/2017 07:47:26] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}[MD5.6624DC6B75D2C343519C6412AF3669B3] - [09/07/2017 20:28:11] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{C1EA3764-1138-AE27-AD63-549BAD99BA15}[MD5.2AB1A2B9BC29E1FFB949F616C000905E] - [09/07/2017 20:27:03] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}[MD5.D77DB141909D02283CD8DFB795CE0076] - [11/07/2017 08:21:58] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}[MD5.831E6F144511735DEEF25F34BE8C7601] - [09/07/2017 20:28:24] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}[MD5.2A1548E5130C4957EDB7F75965009EE5] - [07/07/2017 19:45:54] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{CDE9C04A-7F8B-40A8-A4A5-875E228254A6}[MD5.0D2D5D0F1492FE0C0E4CB5816127D5F6] - [11/07/2017 08:43:59] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{CE675FBD-75C3-45F1-B6AF-8D250861D536}[MD5.52DB05CA0937064E37CA262663934A99] - [07/07/2017 18:13:46] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{CE86D656-C887-4EF1-B2D7-2A1075435964}[MD5.F3885080999F0E2981B2FC7780586B21] - [11/07/2017 07:49:54] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}[MD5.0DDD284D26A6C0B930F892656B9FD04D] - [13/07/2017 14:12:06] - |AC| - [49152] - C:\WINDOWS\Installer\SourceHash{D15DF9B0-3A98-4BEF-B7D5-FC3AEA421657}[MD5.6F0EB435921F3B50B98DF16B7C2E41D9] - [22/07/2017 03:28:02] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{D7EACFE3-BC6A-48bb-B28C-4DBF318225E3}[MD5.63F04583805D530D4ABF2895B1ED9162] - [07/07/2017 12:19:39] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}[MD5.609A2B6D94C0482F89F6D637690199F6] - [11/07/2017 07:48:26] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}[MD5.A769B03E81A524EEFE03A7CBF36D5217] - [21/07/2017 11:52:22] - |A| - [20480] - C:\WINDOWS\Installer\SourceHash{E512788E-C50B-3858-A4B9-73AD5F3F9E93}[MD5.7AFB27349FACACD9BB6B8F2860411BF5] - [09/07/2017 20:29:39] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{E7366CA8-7179-77AE-E712-BA18D70A0A07}[MD5.35225F5A47A8E42C23295DAE7EA99690] - [09/07/2017 20:28:37] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{E817E580-6318-AFC8-2102-322C73117EC4}[MD5.FA58647D2D444E1CBA7A1D6ADF728128] - [11/07/2017 08:36:49] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{EEBF1676-AF87-4266-93D8-0C14A34C4217}[MD5.709FA6DFE0050E0413A692EA2EB5B4A4] - [11/07/2017 08:11:50] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{EF0BA418-AF37-471E-9594-EAE5913F4681}[MD5.97CA1B19E34489FE64D5C1E14FEA3039] - [11/07/2017 08:17:14] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{F030BFE8-8476-4C08-A553-233DE80A2BE1}[MD5.E7D4F2B611B85CFF89E8287FFC1202A4] - [06/07/2017 12:00:27] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{F0CF025B-D6F3-4F7C-939B-23291F52875C}[MD5.C0D47EB210D48E7E373A467E8E812F2B] - [07/07/2017 09:50:18] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{F24FF688-7138-4CCF-A83F-71E9FB01170E}[MD5.2C11BADCCF675A912BE2E944EBE7D9EE] - [07/07/2017 18:15:16] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{F53529E7-07B1-409A-ACE0-3910D2338D12}[MD5.121286E9F78333F17B386C1399A7B0F2] - [09/07/2017 20:27:28] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{F77474EE-EB6C-C87B-88AF-3310C848E068}[MD5.C0454FC3A5046DECEF37E8310D3E15FD] - [09/07/2017 20:27:14] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{F8DDBE95-DCBE-03B5-5359-DE3601146E21}[MD5.12D4F2371F54AA990E3D1161C90CF89B] - [07/07/2017 13:45:46] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{FA02F344-8F3D-4EDC-97DA-A7B4469EC72E}[MD5.76746922CA4F8DC245C70BC07D862D5A] - [11/07/2017 08:38:34] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}[MD5.237D5D2B3D22926658271582DB84FD64] - [07/07/2017 19:18:03] - |AC| - [20480] - C:\WINDOWS\Installer\SourceHash{FFAC39DA-CF79-434B-A6E0-4055689667D9}[MD5.00000000000000000000000000000000] - [11/07/2017 08:21:42] - |DC| - [454128] - C:\WINDOWS\Installer\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:47] - |DC| - [764030] - C:\WINDOWS\Installer\{04833277-EE61-4251-9273-0CF86C0FE710}[MD5.00000000000000000000000000000000] - [07/07/2017 19:26:42] - |DC| - [260592] - C:\WINDOWS\Installer\{0517F875-BBB2-4812-A63E-733B33CEF215}[MD5.00000000000000000000000000000000] - [11/07/2017 08:11:08] - |DC| - [436208] - C:\WINDOWS\Installer\{05C6B128-1B40-4495-9CB9-090B368BFA0A}[MD5.00000000000000000000000000000000] - [09/07/2017 20:29:33] - |DC| - [88102] - C:\WINDOWS\Installer\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:20] - |DC| - [88102] - C:\WINDOWS\Installer\{07326A3E-02B3-1078-25D7-B8666BA8FE15}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:49] - |DC| - [88102] - C:\WINDOWS\Installer\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}[MD5.00000000000000000000000000000000] - [09/07/2017 09:02:06] - |DC| - [46994] - C:\WINDOWS\Installer\{0B456D24-DD76-4163-8175-4F720E6F3C92}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:47] - |DC| - [764030] - C:\WINDOWS\Installer\{0BC63E80-F9DE-40B2-AE07-EFAD9C82E06E}[MD5.00000000000000000000000000000000] - [09/07/2017 20:26:34] - |DC| - [10134] - C:\WINDOWS\Installer\{11087D24-567D-7D88-69C6-D7A08B5F4C47}[MD5.00000000000000000000000000000000] - [11/07/2017 08:44:58] - |DC| - [436208] - C:\WINDOWS\Installer\{150D88F1-40AF-4678-A39D-BCE2332F34E5}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{18F14F4B-D8A9-4309-817E-3BC0B7664E53}[MD5.00000000000000000000000000000000] - [09/07/2017 20:26:54] - |DC| - [88102] - C:\WINDOWS\Installer\{1AD99E77-37CC-744E-39CA-67F6FD34565A}[MD5.00000000000000000000000000000000] - [11/07/2017 07:49:40] - |DC| - [436208] - C:\WINDOWS\Installer\{1B6F5E51-575E-4693-BCA2-7543570D076D}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:36] - |DC| - [764030] - C:\WINDOWS\Installer\{1B932032-73EB-4E1B-99F6-1541DEFD631A}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:39] - |DC| - [88102] - C:\WINDOWS\Installer\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}[MD5.00000000000000000000000000000000] - [11/07/2017 08:17:36] - |DC| - [122880] - C:\WINDOWS\Installer\{1C63279A-BF36-4852-9924-B1978D6585A6}[MD5.00000000000000000000000000000000] - [07/07/2017 19:45:16] - |DC| - [946992] - C:\WINDOWS\Installer\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:54] - |DC| - [88102] - C:\WINDOWS\Installer\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:41] - |DC| - [764030] - C:\WINDOWS\Installer\{1EBC6C6F-7D31-4897-B241-DC7052F3E7A5}[MD5.00000000000000000000000000000000] - [11/07/2017 08:33:42] - |DC| - [436208] - C:\WINDOWS\Installer\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}[MD5.00000000000000000000000000000000] - [11/07/2017 07:56:35] - |DC| - [122880] - C:\WINDOWS\Installer\{2432E589-6256-4513-B0BF-EFA8E325D5F0}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:52] - |DC| - [88102] - C:\WINDOWS\Installer\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{2736B6BD-31EC-4FC8-A48C-F0A5C914C0B6}[MD5.00000000000000000000000000000000] - [11/07/2017 08:36:13] - |DC| - [436208] - C:\WINDOWS\Installer\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}[MD5.00000000000000000000000000000000] - [11/07/2017 07:51:29] - |DC| - [436208] - C:\WINDOWS\Installer\{29F67D84-3A70-456E-806A-52301B02070B}[MD5.00000000000000000000000000000000] - [07/07/2017 19:24:45] - |DC| - [180736] - C:\WINDOWS\Installer\{2B682751-E749-441C-A4B3-1F538E26E56E}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:00] - |DC| - [88102] - C:\WINDOWS\Installer\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}[MD5.00000000000000000000000000000000] - [07/07/2017 20:02:40] - |DC| - [495104] - C:\WINDOWS\Installer\{2DDBB2E7-CB4E-4E65-A6B9-B9C95ED77D42}[MD5.00000000000000000000000000000000] - [07/07/2017 19:27:21] - |DC| - [229195] - C:\WINDOWS\Installer\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}[MD5.00000000000000000000000000000000] - [07/07/2017 19:19:49] - |DC| - [525296] - C:\WINDOWS\Installer\{302763FD-5CEA-4DFF-80C8-9B41414C4822}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:45] - |DC| - [88102] - C:\WINDOWS\Installer\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}[MD5.00000000000000000000000000000000] - [09/07/2017 20:29:19] - |DC| - [88102] - C:\WINDOWS\Installer\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:47] - |DC| - [764030] - C:\WINDOWS\Installer\{367D1EA4-24FD-402F-AFF0-08A678D2EE28}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:41] - |DC| - [764030] - C:\WINDOWS\Installer\{37AD632E-994D-4944-B57D-A80852BCB96D}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:47] - |DC| - [764030] - C:\WINDOWS\Installer\{38F898C8-272F-455F-9BD6-71FEBA3E4AF5}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{4C5D0B6A-944A-47A6-A2F3-BCB58E05CA5D}[MD5.00000000000000000000000000000000] - [11/07/2017 08:28:42] - |DC| - [436200] - C:\WINDOWS\Installer\{4D25D881-7183-462F-95C8-990CA1944E0B}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{4EAB2511-0135-48CA-A47B-CE1E6836793A}[MD5.00000000000000000000000000000000] - [11/07/2017 08:46:01] - |DC| - [436208] - C:\WINDOWS\Installer\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:09] - |DC| - [764030] - C:\WINDOWS\Installer\{51E5F3BE-F3D1-4F44-B49F-05BFA7E0D2D2}[MD5.00000000000000000000000000000000] - [11/07/2017 07:40:02] - |DC| - [366816] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}[MD5.00000000000000000000000000000000] - [11/07/2017 07:55:21] - |DC| - [424272] - C:\WINDOWS\Installer\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}[MD5.00000000000000000000000000000000] - [11/07/2017 08:01:13] - |DC| - [710640] - C:\WINDOWS\Installer\{60251665-84B4-41D6-84BF-6D50CE68DD08}[MD5.00000000000000000000000000000000] - [11/07/2017 08:11:37] - |DC| - [69632] - C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:23] - |DC| - [764030] - C:\WINDOWS\Installer\{67DA4459-33A8-4E69-9C7B-FB5CBADA60AB}[MD5.00000000000000000000000000000000] - [11/07/2017 08:10:21] - |DC| - [2138048] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{68BE8BAB-5375-4C99-9116-1808F5968D40}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:21] - |DC| - [88102] - C:\WINDOWS\Installer\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}[MD5.00000000000000000000000000000000] - [11/07/2017 07:38:43] - |DC| - [313872] - C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}[MD5.00000000000000000000000000000000] - [07/07/2017 19:22:44] - |DC| - [616960] - C:\WINDOWS\Installer\{729B89D0-946A-407E-A121-343BD3320C40}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{73830292-868E-4C82-9AF5-CCFE2047B6A3}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:36] - |DC| - [764030] - C:\WINDOWS\Installer\{73D4C081-72C2-4C3B-A8CC-BE86DC7A503D}[MD5.00000000000000000000000000000000] - [07/07/2017 18:11:59] - |DC| - [591872] - C:\WINDOWS\Installer\{77CDA026-3860-4C95-8233-34F3CEF121FB}[MD5.00000000000000000000000000000000] - [09/07/2017 20:29:26] - |DC| - [88102] - C:\WINDOWS\Installer\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{7B1A9CD1-B552-4FA7-BBC1-EDDEAB8855A7}[MD5.00000000000000000000000000000000] - [11/07/2017 08:24:59] - |DC| - [436208] - C:\WINDOWS\Installer\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}[MD5.00000000000000000000000000000000] - [11/07/2017 08:05:18] - |DC| - [888768] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}[MD5.00000000000000000000000000000000] - [11/07/2017 08:06:16] - |DC| - [1886152] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:06] - |DC| - [88102] - C:\WINDOWS\Installer\{82CA1714-13EA-F419-91FE-12834424745E}[MD5.00000000000000000000000000000000] - [11/07/2017 08:27:32] - |DC| - [436208] - C:\WINDOWS\Installer\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:45] - |DC| - [764030] - C:\WINDOWS\Installer\{84875F6F-2996-4469-BF1D-F59A85C5C702}[MD5.00000000000000000000000000000000] - [07/07/2017 12:21:52] - |DC| - [58736] - C:\WINDOWS\Installer\{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}[MD5.00000000000000000000000000000000] - [13/07/2017 12:59:31] - |DC| - [764030] - C:\WINDOWS\Installer\{897FA7E3-17BF-405F-BC91-FB72A669DCD3}[MD5.00000000000000000000000000000000] - [11/07/2017 08:30:56] - |DC| - [436208] - C:\WINDOWS\Installer\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}[MD5.00000000000000000000000000000000] - [09/07/2017 20:29:12] - |DC| - [88102] - C:\WINDOWS\Installer\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}[MD5.00000000000000000000000000000000] - [13/07/2017 12:59:31] - |DC| - [764030] - C:\WINDOWS\Installer\{8E048D96-59B5-4BD8-A5D0-8FFCFC161A5A}[MD5.00000000000000000000000000000000] - [07/07/2017 13:44:19] - |DC| - [287934] - C:\WINDOWS\Installer\{8EFB7927-48AD-4E6D-91B7-6B2BD6C3F380}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:59] - |DC| - [88102] - C:\WINDOWS\Installer\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}[MD5.00000000000000000000000000000000] - [11/07/2017 08:18:03] - |DC| - [122880] - C:\WINDOWS\Installer\{910B539D-F257-46C8-9CB8-6C95EFF9CF22}[MD5.00000000000000000000000000000000] - [11/07/2017 07:59:58] - |DC| - [710640] - C:\WINDOWS\Installer\{92EBE575-0C6E-4713-B095-34BB927E5AC6}[MD5.00000000000000000000000000000000] - [11/07/2017 08:23:56] - |DC| - [436208] - C:\WINDOWS\Installer\{955BF340-C379-4375-AA2F-F3BCB2A498AB}[MD5.00000000000000000000000000000000] - [07/07/2017 19:26:17] - |DC| - [218624] - C:\WINDOWS\Installer\{9569E6BC-326A-432F-97AB-35263A327BF1}[MD5.00000000000000000000000000000000] - [11/07/2017 07:45:34] - |DC| - [456688] - C:\WINDOWS\Installer\{9C637A56-4287-487F-95BF-1422FC1AA879}[MD5.00000000000000000000000000000000] - [07/07/2017 18:13:27] - |DC| - [53248] - C:\WINDOWS\Installer\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}[MD5.00000000000000000000000000000000] - [11/07/2017 08:16:53] - |DC| - [122880] - C:\WINDOWS\Installer\{A163159C-B476-4501-B163-3F77809AC833}[MD5.00000000000000000000000000000000] - [11/07/2017 11:05:39] - |DC| - [764030] - C:\WINDOWS\Installer\{A1E718A7-BB83-41B8-BA96-BC219C322B8E}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{A305217D-C8FC-46D3-B9E3-054B707B4E62}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:32] - |DC| - [88102] - C:\WINDOWS\Installer\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}[MD5.00000000000000000000000000000000] - [09/07/2017 20:29:06] - |DC| - [88102] - C:\WINDOWS\Installer\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}[MD5.00000000000000000000000000000000] - [11/07/2017 07:46:56] - |DC| - [1374144] - C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}[MD5.00000000000000000000000000000000] - [11/07/2017 07:53:54] - |DC| - [436208] - C:\WINDOWS\Installer\{ACE49D50-19CD-44A6-B192-46F985283B26}[MD5.00000000000000000000000000000000] - [09/07/2017 20:30:18] - |DC| - [88102] - C:\WINDOWS\Installer\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}[MD5.00000000000000000000000000000000] - [07/07/2017 14:10:41] - |DC| - [847768] - C:\WINDOWS\Installer\{B07BBB6E-6753-41B0-B4B9-1E9FE4AF5C18}[MD5.00000000000000000000000000000000] - [11/07/2017 08:07:58] - |DC| - [1026000] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:46] - |DC| - [88102] - C:\WINDOWS\Installer\{B839153C-D4D2-F89C-5033-0A160C62706B}[MD5.00000000000000000000000000000000] - [07/07/2017 18:10:22] - |DC| - [220856] - C:\WINDOWS\Installer\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{BCC0552D-76C0-4130-BFBD-49BE49ACC594}[MD5.00000000000000000000000000000000] - [11/07/2017 08:14:22] - |DC| - [329712] - C:\WINDOWS\Installer\{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}[MD5.00000000000000000000000000000000] - [11/07/2017 07:48:05] - |DC| - [122880] - C:\WINDOWS\Installer\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:13] - |DC| - [88102] - C:\WINDOWS\Installer\{C1EA3764-1138-AE27-AD63-549BAD99BA15}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:05] - |DC| - [88102] - C:\WINDOWS\Installer\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}[MD5.00000000000000000000000000000000] - [11/07/2017 08:22:02] - |DC| - [436208] - C:\WINDOWS\Installer\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:36] - |DC| - [764030] - C:\WINDOWS\Installer\{C7C71F0C-4CC1-4B17-943C-96E5196DDA74}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:26] - |DC| - [88102] - C:\WINDOWS\Installer\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:51] - |DC| - [764030] - C:\WINDOWS\Installer\{CC6B1BB4-4E06-4A5B-A166-B371B551324B}[MD5.00000000000000000000000000000000] - [07/07/2017 19:48:55] - |DC| - [495104] - C:\WINDOWS\Installer\{CDE9C04A-7F8B-40A8-A4A5-875E228254A6}[MD5.00000000000000000000000000000000] - [11/07/2017 08:44:31] - |DC| - [436208] - C:\WINDOWS\Installer\{CE675FBD-75C3-45F1-B6AF-8D250861D536}[MD5.00000000000000000000000000000000] - [07/07/2017 18:13:54] - |DC| - [1010688] - C:\WINDOWS\Installer\{CE86D656-C887-4EF1-B2D7-2A1075435964}[MD5.00000000000000000000000000000000] - [11/07/2017 07:50:04] - |DC| - [710640] - C:\WINDOWS\Installer\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{D6AB1F5B-FED6-49a9-9747-327BD28FB3C7}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:03] - |DC| - [764030] - C:\WINDOWS\Installer\{D931AD15-3DD2-484F-A803-73940E7EED25}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:09] - |DC| - [764030] - C:\WINDOWS\Installer\{DAC390BA-1387-4DF8-A9BC-683E81E77E86}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:36] - |DC| - [764030] - C:\WINDOWS\Installer\{DAE39927-6F98-4122-A3D2-AC16A5B0E52F}[MD5.00000000000000000000000000000000] - [07/07/2017 12:20:23] - |DC| - [53248] - C:\WINDOWS\Installer\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}[MD5.00000000000000000000000000000000] - [11/07/2017 07:48:53] - |DC| - [436208] - C:\WINDOWS\Installer\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}[MD5.00000000000000000000000000000000] - [09/07/2017 20:29:44] - |DC| - [4846] - C:\WINDOWS\Installer\{E7366CA8-7179-77AE-E712-BA18D70A0A07}[MD5.00000000000000000000000000000000] - [09/07/2017 20:28:39] - |DC| - [88102] - C:\WINDOWS\Installer\{E817E580-6318-AFC8-2102-322C73117EC4}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:41] - |DC| - [764030] - C:\WINDOWS\Installer\{EC925096-5689-4BE3-B675-D16D0394B4A0}[MD5.00000000000000000000000000000000] - [11/07/2017 08:38:02] - |DC| - [436208] - C:\WINDOWS\Installer\{EEBF1676-AF87-4266-93D8-0C14A34C4217}[MD5.00000000000000000000000000000000] - [11/07/2017 08:12:01] - |DC| - [1013712] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{EF478DD2-1CD0-412F-B006-06AC204385D3}[MD5.00000000000000000000000000000000] - [11/07/2017 08:17:19] - |DC| - [419824] - C:\WINDOWS\Installer\{F030BFE8-8476-4C08-A553-233DE80A2BE1}[MD5.00000000000000000000000000000000] - [06/07/2017 12:00:33] - |DC| - [5333222] - C:\WINDOWS\Installer\{F0CF025B-D6F3-4F7C-939B-23291F52875C}[MD5.00000000000000000000000000000000] - [07/07/2017 09:50:21] - |DC| - [25214] - C:\WINDOWS\Installer\{F24FF688-7138-4CCF-A83F-71E9FB01170E}[MD5.00000000000000000000000000000000] - [07/07/2017 19:00:18] - |DC| - [6105088] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:29] - |DC| - [88102] - C:\WINDOWS\Installer\{F77474EE-EB6C-C87B-88AF-3310C848E068}[MD5.00000000000000000000000000000000] - [09/07/2017 20:27:15] - |DC| - [88102] - C:\WINDOWS\Installer\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}[MD5.00000000000000000000000000000000] - [11/07/2017 21:04:50] - |DC| - [764030] - C:\WINDOWS\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}[MD5.00000000000000000000000000000000] - [11/07/2017 08:43:29] - |DC| - [436208] - C:\WINDOWS\Installer\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}[MD5.00000000000000000000000000000000] - [07/07/2017 19:18:18] - |DC| - [211968] - C:\WINDOWS\Installer\{FFAC39DA-CF79-434B-A6E0-4055689667D9}[MD5.3ED3209E5F4CDD776ED814DEB08DAA83] - [11/07/2017 23:02:13] - |AC| - [527360] - C:\WINDOWS\system32\aadcloudap.dll[MD5.2C36926EF11CDB8B063088DD0A089467] - [11/07/2017 23:02:13] - |AC| - [1293824] - C:\WINDOWS\system32\aadtb.dll[MD5.282127EB019CBBD9A2D1F6A6CC58CFED] - [11/07/2017 23:02:47] - |A| - [299520] - C:\WINDOWS\system32\AboveLockAppHost.dll[MD5.ECDE960BC5DED2110041D907C32513C8] - [11/07/2017 23:01:49] - |AC| - [136096] - C:\WINDOWS\system32\acmigration.dll[MD5.17EE01427708DB0E659FC15A9CA453FB] - [11/07/2017 23:03:23] - |A| - [411648] - C:\WINDOWS\system32\ActivationManager.dll[MD5.CEE0991074D7A0EF836F7A13BDBACADF] - [11/07/2017 23:01:45] - |AC| - [96256] - C:\WINDOWS\system32\ActiveSyncCsp.dll[MD5.9C191E3AE8FE73A636D23713510DAE66] - [11/07/2017 23:01:55] - |AC| - [1713664] - C:\WINDOWS\system32\ActiveSyncProvider.dll[MD5.4C6BE6AA9DD545B790099F9D1F22422F] - [11/07/2017 23:02:00] - |AC| - [1214880] - C:\WINDOWS\system32\aeinv.dll[MD5.4F0DB5BA15A828959AD26BAEDB46FB12] - [11/07/2017 23:02:58] - |AC| - [233376] - C:\WINDOWS\system32\aepic.dll[MD5.488A6353A529114DF839FE40019E48C2] - [11/07/2017 23:01:44] - |AC| - [1703424] - C:\WINDOWS\system32\aitstatic.exe[MD5.832C37BD4BE751D4323880F9641F2120] - [11/07/2017 23:02:04] - |AC| - [1564576] - C:\WINDOWS\system32\appraiser.dll[MD5.FFAE5D5B096BBF43A1E917331727FD17] - [11/07/2017 23:03:24] - |AC| - [585216] - C:\WINDOWS\system32\AppReadiness.dll[MD5.591C1BC89F9DF7F9493805B57A997798] - [11/07/2017 23:02:34] - |AC| - [255904] - C:\WINDOWS\system32\AppxAllUserStore.dll[MD5.DC5807EB7ED79AC65B6040344E56D81D] - [06/07/2017 18:33:54] - |A| - [654976] - C:\WINDOWS\system32\AppXDeploymentClient.dll[MD5.5CB188F2FB1F504853A14A02B9CCF70B] - [11/07/2017 23:02:44] - |AC| - [1468416] - C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll[MD5.D983AC34DF8D06185F4E94ACAC454ED3] - [11/07/2017 23:02:39] - |AC| - [1886208] - C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll[MD5.4C63CB8375AE0BD0BD6496850D8A14B5] - [11/07/2017 23:02:34] - |AC| - [2804736] - C:\WINDOWS\system32\AppXDeploymentServer.dll[MD5.8E55649F0C32694D4661F7D88F2CE1FB] - [06/07/2017 18:34:10] - |AC| - [382368] - C:\WINDOWS\system32\atmfd.dll[MD5.13B141B8DD62F1AA9E6633625DFD10BE] - [06/07/2017 18:34:10] - |AC| - [47104] - C:\WINDOWS\system32\atmlib.dll[MD5.E067CF5B2FB010673B942A57C0FBA618] - [11/07/2017 23:01:59] - |AC| - [583304] - C:\WINDOWS\system32\audiodg.exe[MD5.435DC20A3642BA5974FC30A6C8AAAB66] - [11/07/2017 23:02:10] - |AC| - [625152] - C:\WINDOWS\system32\AudioEndpointBuilder.dll[MD5.486B57B257A70A3B3873E3AFBE13EFB5] - [11/07/2017 23:02:01] - |AC| - [1337848] - C:\WINDOWS\system32\AudioEng.dll[MD5.09A2034BB3B0D56B710E6CCD509C7057] - [11/07/2017 23:02:02] - |AC| - [1054280] - C:\WINDOWS\system32\AudioSes.dll[MD5.132A5D82E9BC66F6B013AE28C4A182BC] - [11/07/2017 23:02:15] - |AC| - [1357824] - C:\WINDOWS\system32\audiosrv.dll[MD5.94108D4EF7B6BB99EC53B17493841458] - [11/07/2017 23:02:41] - |AC| - [1878016] - C:\WINDOWS\system32\AzureSettingSyncProvider.dll[MD5.9A4FBE86826A6357A5E33131C95369B7] - [11/07/2017 23:03:02] - |AC| - [204192] - C:\WINDOWS\system32\basecsp.dll[MD5.3A5C0F9E45018152D24B96D5867AA05A] - [11/07/2017 23:01:37] - |AC| - [916992] - C:\WINDOWS\system32\bcastdvr.exe[MD5.22DC955285840B5100C2B50539071644] - [06/07/2017 18:33:58] - |AC| - [197120] - C:\WINDOWS\system32\bcdboot.exe[MD5.5915E483D5D05D66F0F338B02B06BC2D] - [11/07/2017 23:04:01] - |AC| - [8331264] - C:\WINDOWS\system32\BingMaps.dll[MD5.29052CEB6E1DA5F58D20F7A28F392D5B] - [11/07/2017 23:03:24] - |A| - [847872] - C:\WINDOWS\system32\bisrv.dll[MD5.06473EB9B29F89CDC83CC0590D04A9F3] - [11/07/2017 23:01:50] - |AC| - [189440] - C:\WINDOWS\system32\BluetoothApis.dll[MD5.B45F2FFFBF486F3FF742CC57886B0B3E] - [06/07/2017 18:33:58] - |AC| - [211872] - C:\WINDOWS\system32\browserbroker.dll[MD5.09E6115D0B15BA914C005E8281223DFA] - [06/07/2017 18:33:51] - |A| - [321376] - C:\WINDOWS\system32\capauthz.dll[MD5.A0E5905465CBCCB63FE915F5B08752A8] - [06/07/2017 18:34:04] - |AC| - [970240] - C:\WINDOWS\system32\cdpsvc.dll[MD5.56C1E0FD604483E96DD5349FB11584E8] - [11/07/2017 23:01:37] - |AC| - [791040] - C:\WINDOWS\system32\certca.dll[MD5.096A25B08D6C26975A00DE69379DA168] - [11/07/2017 23:01:37] - |AC| - [455680] - C:\WINDOWS\system32\certcli.dll[MD5.7554042B3DE9AC5BE70E851B654DA937] - [11/07/2017 23:02:05] - |AC| - [3057664] - C:\WINDOWS\system32\CertEnroll.dll[MD5.62E13528B9F900A5662E243D4315F10B] - [11/07/2017 23:02:53] - |AC| - [189952] - C:\WINDOWS\system32\certprop.dll[MD5.2448718250C347C56C22DCD7652515C4] - [11/07/2017 23:02:55] - |AC| - [1425920] - C:\WINDOWS\system32\certutil.exe[MD5.C40DB719EE3E4DC8A2C887103593AC2F] - [11/07/2017 23:03:55] - |AC| - [8238080] - C:\WINDOWS\system32\Chakra.dll[MD5.188360E5796BCD195A860C7E3669894A] - [11/07/2017 23:03:27] - |AC| - [110592] - C:\WINDOWS\system32\Chakradiag.dll[MD5.3B4708C3848188E76C80CB4491C10E60] - [11/07/2017 23:02:09] - |AC| - [56832] - C:\WINDOWS\system32\cldapi.dll[MD5.456A4E125C6CEDBAAC46BEF0BB5866B3] - [11/07/2017 23:01:47] - |A| - [205312] - C:\WINDOWS\system32\ClipboardServer.dll[MD5.A30BAA8AF16E34E0715FA58B6A780817] - [11/07/2017 23:01:54] - |A| - [147800] - C:\WINDOWS\system32\Clipc.dll[MD5.4351225ABE115E9B81639CFC87B980BB] - [11/07/2017 23:02:30] - |AC| - [872472] - C:\WINDOWS\system32\ClipSVC.dll[MD5.7B38B27F09D5ADC3EA4F774020627A5F] - [11/07/2017 23:01:39] - |AC| - [81920] - C:\WINDOWS\system32\CloudDomainJoinAUG.dll[MD5.0AE1FE710B07A7F65CA33C0AF371FF01] - [11/07/2017 23:01:42] - |AC| - [335872] - C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll[MD5.C5A866AD8A612AEAF49BE2DD692D3767] - [11/07/2017 23:02:12] - |AC| - [372128] - C:\WINDOWS\system32\CloudExperienceHost.dll[MD5.A43068D1B52B4022270BD2D6340292D5] - [11/07/2017 23:01:47] - |AC| - [203168] - C:\WINDOWS\system32\CloudExperienceHostBroker.dll[MD5.92ED30D0624B6C3591719C484ACF4AD0] - [11/07/2017 23:01:47] - |AC| - [426912] - C:\WINDOWS\system32\CloudExperienceHostCommon.dll[MD5.CFE6F03F740814A7AE41CA6477EA8A5F] - [11/07/2017 23:01:46] - |AC| - [179608] - C:\WINDOWS\system32\CloudExperienceHostUser.dll[MD5.E47E1AC139CB38A4BF523A37991BEED0] - [06/07/2017 18:34:32] - |A| - [660384] - C:\WINDOWS\system32\comctl32.dll[MD5.EDF83CCD37E7AFE15D58F8D6BDD29AF2] - [06/07/2017 18:34:06] - |A| - [1046016] - C:\WINDOWS\system32\comdlg32.dll[MD5.7178448832AF6D4FE2568FE247462F09] - [11/07/2017 23:01:52] - |AC| - [96672] - C:\WINDOWS\system32\CompatTelRunner.exe[MD5.71FE8439182F423E4A93E3BFFF3525F8] - [22/07/2017 15:29:56] - |A| - [122312] - C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll[MD5.70F376918BCED2EC7B05CDC564C7D40A] - [11/07/2017 23:03:20] - |A| - [360960] - C:\WINDOWS\system32\ConhostV2.dll[MD5.D270EE296EDA16437812C04B4CD61561] - [11/07/2017 23:02:51] - |A| - [923040] - C:\WINDOWS\system32\CoreMessaging.dll[MD5.8728C47498C9AE064AA134E65FFE39EF] - [11/07/2017 23:03:22] - |A| - [2969880] - C:\WINDOWS\system32\CoreUIComponents.dll[MD5.952F5DB9AE62CA68B5D8B1BE648D01D3] - [11/07/2017 23:02:56] - |AC| - [102312] - C:\WINDOWS\system32\CredentialUIBroker.exe[MD5.93B704419CB7B64834C8325AD0385FC6] - [11/07/2017 23:02:53] - |A| - [58368] - C:\WINDOWS\system32\csrsrv.dll[MD5.67F9B8648E5433B0D9EC92F298B8C19E] - [11/07/2017 23:03:04] - |A| - [5892096] - C:\WINDOWS\system32\d2d1.dll[MD5.C6BC3579E16910752E798DCCCC95DD61] - [11/07/2017 23:02:53] - |AC| - [498176] - C:\WINDOWS\system32\d2d1debug3.dll[MD5.3EBF620536A13CA343E52ECA4F0DE7F8] - [07/07/2017 11:54:44] - |A| - [1400176] - C:\WINDOWS\system32\D3DCompiler_33.dll[MD5.9D9407F52B8E24E99358D9944B0D5FA3] - [07/07/2017 11:56:37] - |A| - [1401200] - C:\WINDOWS\system32\D3DCompiler_34.dll[MD5.B21427EDF0449E92000FF497DAAF89C9] - [07/07/2017 11:58:12] - |A| - [1985904] - C:\WINDOWS\system32\D3DCompiler_35.dll[MD5.7299DF5CF81135934740211D9A946737] - [07/07/2017 11:59:36] - |A| - [2006552] - C:\WINDOWS\system32\D3DCompiler_36.dll[MD5.31026CEA5AFA2798292179102C06FE40] - [07/07/2017 12:01:53] - |A| - [1860120] - C:\WINDOWS\system32\D3DCompiler_37.dll[MD5.A7E59BB6FAC119FABB83F18BD72AA1D7] - [07/07/2017 12:04:35] - |A| - [1941528] - C:\WINDOWS\system32\D3DCompiler_38.dll[MD5.7741A0A6CED6C441B97D625B730D6075] - [22/07/2017 07:15:55] - |A| - [1942552] - C:\WINDOWS\system32\D3DCompiler_39.dll[MD5.37309B833480DC69FDE7DB68F9B8BC20] - [07/07/2017 12:09:36] - |A| - [2605920] - C:\WINDOWS\system32\D3DCompiler_40.dll[MD5.A59A5BADE4AF200C720D99EAE6E04E0E] - [07/07/2017 12:12:12] - |A| - [2430312] - C:\WINDOWS\system32\D3DCompiler_41.dll[MD5.E92D2E4AFA43CD39A8C1C2C2DB59667E] - [07/07/2017 12:14:05] - |A| - [2582888] - C:\WINDOWS\system32\D3DCompiler_42.dll[MD5.78E67F44E6F880ECDF3F99A665C19DC8] - [11/07/2017 23:03:16] - |A| - [4396032] - C:\WINDOWS\system32\D3DCompiler_47.dll[MD5.F13B90F5090EBA9041558BC6AAED79B8] - [07/07/2017 12:13:32] - |A| - [5554512] - C:\WINDOWS\system32\d3dcsx_42.dll[MD5.8251826F04BA0822D08AD9B92C65A3D5] - [07/07/2017 11:53:01] - |A| - [469264] - C:\WINDOWS\system32\d3dx10.dll[MD5.839C3921005BB41D441E3752C74F2292] - [07/07/2017 11:54:45] - |A| - [506728] - C:\WINDOWS\system32\d3dx10_33.dll[MD5.1ED4E7A82BD5C7DEED082F00E63BB7A0] - [07/07/2017 11:56:37] - |A| - [506728] - C:\WINDOWS\system32\d3dx10_34.dll[MD5.84116AA94672D623B95217648AE5B5B9] - [07/07/2017 11:58:13] - |A| - [508264] - C:\WINDOWS\system32\d3dx10_35.dll[MD5.570FDAE7041775DE0C67747BB7081939] - [07/07/2017 11:59:37] - |A| - [508264] - C:\WINDOWS\system32\d3dx10_36.dll[MD5.A8C5688BBA00C1630550F26260AB5CAE] - [07/07/2017 12:01:52] - |A| - [529424] - C:\WINDOWS\system32\d3dx10_37.dll[MD5.72CB653CECF4EA670E7F5A8D74358423] - [07/07/2017 12:04:35] - |A| - [540688] - C:\WINDOWS\system32\d3dx10_38.dll[MD5.EAA692FDC990ED0407DF957316DA33C2] - [22/07/2017 07:15:55] - |A| - [540688] - C:\WINDOWS\system32\d3dx10_39.dll[MD5.862586AD4B1355F7DCDE111EE0AAF350] - [07/07/2017 12:09:35] - |A| - [519000] - C:\WINDOWS\system32\d3dx10_40.dll[MD5.E730967811E3702499446FFC8A432607] - [07/07/2017 12:12:10] - |A| - [520544] - C:\WINDOWS\system32\d3dx10_41.dll[MD5.B739C423276AE62D7AC91773226EC13B] - [07/07/2017 12:12:55] - |A| - [523088] - C:\WINDOWS\system32\d3dx10_42.dll[MD5.522749761B6CC69F8630F4B472DCA623] - [07/07/2017 12:13:09] - |A| - [285024] - C:\WINDOWS\system32\d3dx11_42.dll[MD5.B165DF72E13E6AF74D47013504319921] - [07/07/2017 11:31:53] - |A| - [3544272] - C:\WINDOWS\system32\d3dx9_24.dll[MD5.4C56E7C5B2A61353E534C7D15D05856D] - [07/07/2017 11:33:19] - |A| - [3823312] - C:\WINDOWS\system32\d3dx9_25.dll[MD5.44F5C5E27D6825E4E62420BC29B8B533] - [07/07/2017 11:34:24] - |A| - [3767504] - C:\WINDOWS\system32\d3dx9_26.dll[MD5.914C3237E4D145A18DCD1D0D4C8659E1] - [07/07/2017 11:35:44] - |A| - [3807440] - C:\WINDOWS\system32\d3dx9_27.dll[MD5.88BAC8306D4EC79A82B1FFA17DC8CF4A] - [07/07/2017 11:37:06] - |A| - [3815120] - C:\WINDOWS\system32\d3dx9_28.dll[MD5.68B35CBDB4A8CC424718BBCC894FEEEA] - [07/07/2017 11:38:36] - |A| - [3830992] - C:\WINDOWS\system32\d3dx9_29.dll[MD5.E09A9CF383ACF4A28038561E62277377] - [07/07/2017 11:43:21] - |A| - [3927248] - C:\WINDOWS\system32\d3dx9_30.dll[MD5.FAAA0BB9CD2905B25334132E5BA093EB] - [07/07/2017 11:50:49] - |A| - [3977496] - C:\WINDOWS\system32\d3dx9_31.dll[MD5.A4DDFE5DC4E73D1FED9B1B3A3D885612] - [07/07/2017 11:52:46] - |A| - [4398360] - C:\WINDOWS\system32\d3dx9_32.dll[MD5.3172C3CAC8EA7CA1B5D5AF6699C037D6] - [07/07/2017 11:54:21] - |A| - [4494184] - C:\WINDOWS\system32\d3dx9_33.dll[MD5.AE5D5439525B4A4CBF206058D493685D] - [07/07/2017 11:56:13] - |A| - [4496232] - C:\WINDOWS\system32\d3dx9_34.dll[MD5.1B3AF16A27D390096925576202A64037] - [07/07/2017 11:57:51] - |A| - [5073256] - C:\WINDOWS\system32\d3dx9_35.dll[MD5.BBB6C6833C30E323B41860D6DF61972D] - [07/07/2017 11:59:12] - |A| - [5081608] - C:\WINDOWS\system32\d3dx9_36.dll[MD5.8A10974DC6E1E42BDC635C2C2AFBD2CC] - [07/07/2017 12:01:11] - |A| - [4910088] - C:\WINDOWS\system32\D3DX9_37.dll[MD5.E5EC2AB7156A752F9614CDA4BE66EFE8] - [07/07/2017 12:04:15] - |A| - [4991496] - C:\WINDOWS\system32\D3DX9_38.dll[MD5.7505C133FC704B40CFDDFD38777BAAC3] - [22/07/2017 07:15:47] - |A| - [4992520] - C:\WINDOWS\system32\D3DX9_39.dll[MD5.29A79F0B607FAF5722D7BAF2485F632A] - [07/07/2017 12:09:16] - |A| - [5631312] - C:\WINDOWS\system32\D3DX9_40.dll[MD5.ECDDB13BC805B9F3EF3A855E6FD85C69] - [07/07/2017 12:11:35] - |A| - [5425496] - C:\WINDOWS\system32\D3DX9_41.dll[MD5.1AF7AE1FDE027A30B9097280819A0A86] - [07/07/2017 12:12:36] - |A| - [2475352] - C:\WINDOWS\system32\D3DX9_42.dll[MD5.0F1B85E33759BEC84D339B6221C20C46] - [11/07/2017 23:01:56] - |AC| - [62464] - C:\WINDOWS\system32\dataclen.dll[MD5.5DD706DE1A819C465264F96D7B9A1C3F] - [11/07/2017 23:02:15] - |A| - [520704] - C:\WINDOWS\system32\daxexec.dll[MD5.C2042892EF93FB65CB6AD9387A4E27D7] - [11/07/2017 23:03:17] - |AC| - [5557760] - C:\WINDOWS\system32\dbgeng.dll[MD5.CAE6FB8533C79DF0BA0D04AE1AD86EEE] - [11/07/2017 23:02:59] - |AC| - [335776] - C:\WINDOWS\system32\dcntel.dll[MD5.ABF6FBE381C9968851C05D1363C8FBFB] - [11/07/2017 23:01:57] - |A| - [1171032] - C:\WINDOWS\system32\dcomp.dll[MD5.83569B603BC56C0F16FBD0FF2B63C179] - [11/07/2017 23:02:55] - |AC| - [34720] - C:\WINDOWS\system32\DeviceCensus.exe[MD5.E8D874AFC7163E125538D96E32B1D284] - [06/07/2017 18:34:27] - |AC| - [76800] - C:\WINDOWS\system32\DeviceCredentialDeployment.exe[MD5.DDBE5B84103D8FB5B5CCF220EDBD04B6] - [06/07/2017 18:34:08] - |AC| - [2347520] - C:\WINDOWS\system32\DeviceFlows.DataModel.dll[MD5.BF79562C2C0829AEFA227503A17B5B9A] - [06/07/2017 18:34:27] - |AC| - [221184] - C:\WINDOWS\system32\devicengccredprov.dll[MD5.5DDC9F037946436FEA698199785B5432] - [11/07/2017 23:01:39] - |AC| - [563712] - C:\WINDOWS\system32\DevicePairing.dll[MD5.963D6BB3B2DE708394DDB40597B71329] - [11/07/2017 23:01:59] - |AC| - [544160] - C:\WINDOWS\system32\devinv.dll[MD5.3835D0DD7A932266CC0746FDC5EC5568] - [06/07/2017 18:34:35] - |AC| - [2516480] - C:\WINDOWS\system32\diagtrack.dll[MD5.6CB9CA68A6D6E8959C1EF79D6F3CF8A6] - [06/07/2017 18:33:51] - |AC| - [549888] - C:\WINDOWS\system32\DictationManager.dll[MD5.A4EFCF98966197BD738E6572091C569E] - [11/07/2017 23:02:56] - |AC| - [59392] - C:\WINDOWS\system32\DmApiSetExtImplDesktop.dll[MD5.14E29B4FED894572B29D33A5641B086D] - [11/07/2017 23:01:52] - |AC| - [119384] - C:\WINDOWS\system32\dmcmnutils.dll[MD5.79158D721EAD2D86DE6580CA4F99E633] - [11/07/2017 23:01:40] - |AC| - [138752] - C:\WINDOWS\system32\DMPushRouterCore.dll[MD5.FCCB8E68828E90379514E0047E725A73] - [11/07/2017 23:01:55] - |AC| - [778240] - C:\WINDOWS\system32\DolbyHrtfEnc.dll[MD5.8C64B2048FFB1F77ED97437C32C5BE97] - [11/07/2017 23:01:54] - |AC| - [231936] - C:\WINDOWS\system32\DolbyMATEnc.dll[MD5.B26E6E2A5E28ADB68D97A14DD85D8565] - [11/07/2017 23:02:44] - |AC| - [256000] - C:\WINDOWS\system32\domgmt.dll[MD5.4E4CB66E2C02AB9B636EC011A66C3720] - [11/07/2017 23:02:42] - |AC| - [1305088] - C:\WINDOWS\system32\dosvc.dll[MD5.20C69DBE1F602C31185CED73A555A3B5] - [11/07/2017 23:01:40] - |A| - [577024] - C:\WINDOWS\system32\duser.dll[MD5.CC735B002F732D9E748E7877FAE196A9] - [11/07/2017 23:02:35] - |A| - [2649600] - C:\WINDOWS\system32\dwmcore.dll[MD5.6C5EB938CF7560D8D045CDA6B9FCE2D5] - [06/07/2017 18:34:07] - |A| - [142848] - C:\WINDOWS\system32\dwmredir.dll[MD5.83520CB1CDD6BEE11E2CCE3045A10A9F] - [11/07/2017 23:03:08] - |A| - [2829824] - C:\WINDOWS\system32\DWrite.dll[MD5.68B43BA891E5FD23F353141B6733113E] - [11/07/2017 23:03:54] - |AC| - [274944] - C:\WINDOWS\system32\dxtrans.dll[MD5.C622399D9CB26AA9210158A3BF016F02] - [11/07/2017 23:01:36] - |A| - [29696] - C:\WINDOWS\system32\eapprovp.dll[MD5.17451B259AFF7861016D834B161ABF11] - [11/07/2017 23:03:53] - |AC| - [23677440] - C:\WINDOWS\system32\edgehtml.dll[MD5.B438E6C7A6C395E0C2B31E80112C3ACE] - [11/07/2017 23:03:03] - |AC| - [31932] - C:\WINDOWS\system32\edgehtmlpluginpolicy.bin[MD5.A0F45004DFBFCE962FF939178CFD5638] - [11/07/2017 23:02:55] - |AC| - [178176] - C:\WINDOWS\system32\EditionUpgradeHelper.dll[MD5.8955AD8B202C9C3398E9BCAD25AB562F] - [11/07/2017 23:02:57] - |AC| - [833160] - C:\WINDOWS\system32\EditionUpgradeManagerObj.dll[MD5.4F112BBAA4F73E5D15DE3B7BAF6465F5] - [11/07/2017 23:01:36] - |A| - [253440] - C:\WINDOWS\system32\edputil.dll[MD5.0DBD45D1CDAC2FE8759F30890AD75C9A] - [06/07/2017 18:34:09] - |AC| - [961952] - C:\WINDOWS\system32\efscore.dll[MD5.5E4AB60D50F368A09275F4055D621EDC] - [06/07/2017 18:33:51] - |AC| - [149504] - C:\WINDOWS\system32\embeddedmodesvc.dll[MD5.0BDDA21404956F1455A119F9FB1F8EC6] - [11/07/2017 23:02:37] - |A| - [4707840] - C:\WINDOWS\system32\ExplorerFrame.dll[MD5.C864A615CB48497666C66943C0632C2D] - [17/07/2017 08:29:01] - |A| - [411624] - C:\WINDOWS\system32\FNTCACHE.DAT[MD5.3020F526B7E94A178D3EBF958397F7BC] - [11/07/2017 23:03:09] - |AC| - [1888256] - C:\WINDOWS\system32\FntCache.dll[MD5.B7BFC0E302EFF9418CF0A6525D56864F] - [11/07/2017 23:02:39] - |A| - [750560] - C:\WINDOWS\system32\fontdrvhost.exe[MD5.2A2EB05E795BBDDAABE82639E9691502] - [11/07/2017 23:01:49] - |AC| - [600064] - C:\WINDOWS\system32\FrameServer.dll[MD5.45AFF399D293D01C8D9137A6C28302F0] - [11/07/2017 23:02:38] - |AC| - [840192] - C:\WINDOWS\system32\fveapi.dll[MD5.4D42F34D9CF662D494683BBD0297EFDB] - [11/07/2017 23:02:16] - |AC| - [1260544] - C:\WINDOWS\system32\GamePanel.exe[MD5.B359B03A592B5FED2C3578C5A681B906] - [06/07/2017 18:34:09] - |A| - [1596600] - C:\WINDOWS\system32\gdi32full.dll[MD5.EEC28B69CDD1FD605AF653792F8F2D73] - [11/07/2017 23:01:51] - |A| - [1640448] - C:\WINDOWS\system32\GdiPlus.dll[MD5.11A5AB0B1F9D8A9E6E1A71DB425F1715] - [22/07/2017 16:15:27] - |A| - [5636288] - C:\WINDOWS\system32\GeneIcon.dll[MD5.C7C8319FBAFD6D830F5ED61E60464CCC] - [11/07/2017 23:01:58] - |AC| - [629152] - C:\WINDOWS\system32\generaltel.dll[MD5.42BAF90B44A46A7B1DCB240947A4AAE9] - [21/07/2017 11:12:32] - |A| - [153760] - C:\WINDOWS\system32\GSCoinst.dll[MD5.67183D7DF04A5599DE7A4FE554AA662E] - [11/07/2017 23:03:41] - |AC| - [947712] - C:\WINDOWS\system32\HoloSI.PCShell.dll[MD5.61FB3675CFD0594D3E1C731AD8A7762C] - [11/07/2017 23:02:39] - |AC| - [1024928] - C:\WINDOWS\system32\hvax64.exe[MD5.BA46365DD4A2C20391F990FDB2D152B5] - [11/07/2017 23:02:32] - |AC| - [1147288] - C:\WINDOWS\system32\hvix64.exe[MD5.6885BF565DDEDDBFF393A9B5F4A0D934] - [11/07/2017 23:01:49] - |AC| - [965024] - C:\WINDOWS\system32\hvloader.efi[MD5.9D3FCD37933264DD69CD3490FBFB5052] - [11/07/2017 23:01:47] - |AC| - [821664] - C:\WINDOWS\system32\hvloader.exe[MD5.6CE22E3DD9CCB935ACF24D025DA51794] - [11/07/2017 23:04:12] - |AC| - [386560] - C:\WINDOWS\system32\iedkcs32.dll[MD5.6819975E03A5F3993F8C019D05A7007B] - [11/07/2017 23:03:51] - |A| - [12786176] - C:\WINDOWS\system32\ieframe.dll[MD5.80DB20302B6CB01B4CE73BEF52B094AC] - [11/07/2017 23:04:03] - |AC| - [140288] - C:\WINDOWS\system32\iepeers.dll[MD5.E9E439B358E02FC072CB457F21CB2B31] - [06/07/2017 18:34:14] - |A| - [805888] - C:\WINDOWS\system32\ieproxy.dll[MD5.2A007C96F0FC3A4819B4517BE8F6EC67] - [11/07/2017 23:02:42] - |A| - [2645688] - C:\WINDOWS\system32\iertutil.dll[MD5.F38DBCB3387DFFC15F008383ED7511E0] - [11/07/2017 23:03:27] - |AC| - [557568] - C:\WINDOWS\system32\ieui.dll[MD5.BB82F9A4A2333B4B98A1288A1C54B949] - [11/07/2017 23:03:59] - |AC| - [2077184] - C:\WINDOWS\system32\inetcpl.cpl[MD5.152A734EBC3F089FB2D93B699CA0BE3A] - [11/07/2017 23:04:00] - |A| - [2938880] - C:\WINDOWS\system32\InputService.dll[MD5.6AE425FBFA6AC9530C29517E64B243D4] - [11/07/2017 23:02:44] - |A| - [406528] - C:\WINDOWS\system32\InputSwitch.dll[MD5.7D4805F52F4F789658F9231F64591E94] - [11/07/2017 23:04:34] - |AC| - [374784] - C:\WINDOWS\system32\InstallAgent.exe[MD5.5240CD067F50BE2E5C21A27B7979223C] - [11/07/2017 23:04:34] - |AC| - [417792] - C:\WINDOWS\system32\InstallAgentUserBroker.exe[MD5.46DC2657D5A5473E624F7FEEE97D67DE] - [11/07/2017 23:01:56] - |AC| - [334240] - C:\WINDOWS\system32\invagent.dll[MD5.D506921989872994B9C5615D4761882C] - [22/07/2017 12:11:34] - |A| - [128288] - C:\WINDOWS\system32\IObitSmartDefragExtension.dll[MD5.BBD33293FB4F5C2461C1C399BE293717] - [11/07/2017 11:02:04] - |A| - [256040] - C:\WINDOWS\system32\iseguard64.dll[MD5.80F41EC5E595C8CA334D8FD6041530CC] - [06/07/2017 18:34:21] - |A| - [909824] - C:\WINDOWS\system32\ISM.dll[MD5.DABB9543B2E048734EC377EFAFB9BCCF] - [11/07/2017 23:04:07] - |AC| - [4730880] - C:\WINDOWS\system32\jscript9.dll[MD5.C0BF6E60EBC45A3C3820CF884FD7AA89] - [11/07/2017 23:03:27] - |AC| - [692736] - C:\WINDOWS\system32\jscript9diag.dll[MD5.1B9EA49FDE947BE1FB69099FA63DA4C4] - [11/07/2017 23:03:03] - |A| - [922112] - C:\WINDOWS\system32\kerberos.dll[MD5.801A485BB836C5C6FE3D25703BA3044A] - [11/07/2017 23:04:01] - |A| - [2399728] - C:\WINDOWS\system32\KernelBase.dll[MD5.8B08BCFF44BF4A26D12F1FC0D10BC630] - [11/07/2017 23:04:52] - |AC| - [1055648] - C:\WINDOWS\system32\LicenseManager.dll[MD5.CAD227D8739DC5B1E6A4C65EA802A9C7] - [11/07/2017 23:04:02] - |AC| - [1142272] - C:\WINDOWS\system32\localspl.dll[MD5.8E72B2724F5A455A52D583729B73252A] - [11/07/2017 23:03:23] - |AC| - [646656] - C:\WINDOWS\system32\LockHostingFramework.dll[MD5.38C80C906320E12997878F953BF883A9] - [11/07/2017 23:03:25] - |AC| - [687616] - C:\WINDOWS\system32\LogonController.dll[MD5.9936F9E94C6E3F47A158D7BFF020575A] - [11/07/2017 23:03:30] - |A| - [58488] - C:\WINDOWS\system32\lsass.exe[MD5.31285F42BAE4730D131B8BEF1B24A665] - [06/07/2017 18:34:16] - |AC| - [3135488] - C:\WINDOWS\system32\MapGeocoder.dll[MD5.B50AE1EEA548B0261F9B224293DC9CF4] - [11/07/2017 23:04:12] - |AC| - [3784704] - C:\WINDOWS\system32\MapRouter.dll[MD5.280A037CE700B378D487CE96EBE6E1BE] - [06/07/2017 18:34:17] - |AC| - [1141760] - C:\WINDOWS\system32\MapsStore.dll[MD5.BBD437FC9BE2D003F17EC025207DD27B] - [11/07/2017 23:03:41] - |AC| - [823296] - C:\WINDOWS\system32\MbaeApi.dll[MD5.E8B2CB14CA0238566BDB20BD2A06D733] - [06/07/2017 18:34:32] - |AC| - [778240] - C:\WINDOWS\system32\MBR2GPT.EXE[MD5.36DFAC142BB4F3F85ADEA0B67B082889] - [06/07/2017 18:33:52] - |AC| - [892416] - C:\WINDOWS\system32\MessagingDataModel2.dll[MD5.49C8354A662959620EDD05BAD7C104B3] - [11/07/2017 23:03:40] - |AC| - [467504] - C:\WINDOWS\system32\MFCaptureEngine.dll[MD5.17DF4DB6D00B529B33D1FC7D295C6F80] - [06/07/2017 18:34:17] - |AC| - [4709528] - C:\WINDOWS\system32\mfcore.dll[MD5.775C25D7712B40EDC2630A69A30BEAFA] - [11/07/2017 23:04:06] - |AC| - [4536320] - C:\WINDOWS\system32\MFMediaEngine.dll[MD5.ED241F1DD849F2B1EF764246B10D4F32] - [06/07/2017 18:34:17] - |AC| - [2604256] - C:\WINDOWS\system32\mfmp4srcsnk.dll[MD5.F3F797883E61B23824B252156DE0EC73] - [06/07/2017 18:34:17] - |A| - [1700408] - C:\WINDOWS\system32\mfplat.dll[MD5.FD9352FC219C0C1137B68DC5D0E31BFF] - [11/07/2017 23:04:16] - |AC| - [254168] - C:\WINDOWS\system32\mfps.dll[MD5.DBF49D209BD10869F37BC2DE5BCF46D0] - [11/07/2017 23:04:16] - |AC| - [1220072] - C:\WINDOWS\system32\mfsvr.dll[MD5.A5B8637F381285D8BAB2C208F0A1C6DA] - [11/07/2017 23:02:09] - |AC| - [3204096] - C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll[MD5.C310B746993E3C54F2B5A3DD05E30A9D] - [11/07/2017 23:01:43] - |AC| - [216064] - C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll[MD5.6D45871C33C019E3F35759FA0C707571] - [11/07/2017 23:02:08] - |A| - [406072] - C:\WINDOWS\system32\MMDevAPI.dll[MD5.684E8AA4A200B531C2C162D5E5A7007F] - [11/07/2017 23:01:39] - |AC| - [696320] - C:\WINDOWS\system32\mmsys.cpl[MD5.4E967C59A5867FF10B3FFFEFD5CA0EF2] - [06/07/2017 18:34:18] - |A| - [1028608] - C:\WINDOWS\system32\modernexecserver.dll[MD5.53DF42A16A3D4E7954338D2FD960C868] - [11/07/2017 23:03:43] - |AC| - [7149056] - C:\WINDOWS\system32\mos.dll[MD5.80B5C951FB61CEE0365516416ED510C1] - [11/07/2017 23:02:54] - |A| - [1057832] - C:\WINDOWS\system32\MrmCoreR.dll[MD5.0C152CCCBA1167A2D74C52697CC1AAB2] - [11/07/2017 23:03:42] - |AC| - [411992] - C:\WINDOWS\system32\MSAudDecMFT.dll[MD5.5A5710181A91D4CF5FD9B31A138C14D5] - [06/07/2017 18:34:34] - |A| - [1459728] - C:\WINDOWS\system32\msctf.dll[MD5.1A4D1CDCB85171BAB3B0AB6BC01D97E3] - [11/07/2017 23:01:41] - |AC| - [970752] - C:\WINDOWS\system32\msctfuimanager.dll[MD5.EB9971803D575D8AEA46A4414F3363B4] - [11/07/2017 23:03:59] - |AC| - [751104] - C:\WINDOWS\system32\msfeeds.dll[MD5.6148C8F5C63FE55B0EA0752E63860BA9] - [11/07/2017 23:01:58] - |A| - [3139584] - C:\WINDOWS\system32\msftedit.dll[MD5.B262D6844BA886FCFA45516FF977380A] - [11/07/2017 23:03:49] - |A| - [23681536] - C:\WINDOWS\system32\mshtml.dll[MD5.A9EB114C4B0DDBFE6E3EE7262CA4515F] - [11/07/2017 23:03:55] - |AC| - [84992] - C:\WINDOWS\system32\MshtmlDac.dll[MD5.F1F70EC7058CA787F9517177DD756ADB] - [11/07/2017 23:03:54] - |AC| - [96256] - C:\WINDOWS\system32\mshtmled.dll[MD5.02A32803544C5D74886D620C46FF0A68] - [11/07/2017 23:01:53] - |AC| - [370176] - C:\WINDOWS\system32\msinfo32.exe[MD5.469FC10EA715306455286DD34D6D621A] - [06/07/2017 18:34:18] - |AC| - [6726656] - C:\WINDOWS\system32\mspaint.exe[MD5.C83FAF2FBABC6A61AF4CA7AA17F0A252] - [06/07/2017 18:34:53] - |AC| - [128000] - C:\WINDOWS\system32\mssprxy.dll[MD5.66E1366B90BBCCBF7F2B10B1F1DC8BFB] - [11/07/2017 23:06:39] - |A| - [2597888] - C:\WINDOWS\system32\mssrch.dll[MD5.AF1156BE1893DA3FAED21714B632B2CD] - [11/07/2017 23:04:32] - |AC| - [8211968] - C:\WINDOWS\system32\mstscax.dll[MD5.52D45DCD3C9D13FE43ADA2E6BEFBC441] - [11/07/2017 23:03:06] - |A| - [411040] - C:\WINDOWS\system32\msv1_0.dll[MD5.929B6B629FCB805DA947FC714333B358] - [11/07/2017 23:03:29] - |AC| - [1812480] - C:\WINDOWS\system32\msxml3.dll[MD5.D7485DAF92988CE20B68BF84D3CECD51] - [06/07/2017 18:34:35] - |AC| - [52736] - C:\WINDOWS\system32\musdialoghandlers.dll[MD5.2BA500366E29E1A31864C13E5EA328D3] - [11/07/2017 23:04:35] - |AC| - [293376] - C:\WINDOWS\system32\MusNotification.exe[MD5.45F902F1C63B3AFE1F1F99E50FCB880F] - [06/07/2017 18:34:36] - |AC| - [102400] - C:\WINDOWS\system32\MusNotificationUx.exe[MD5.9DF65EE65073AC987E3711741C86C66D] - [06/07/2017 18:34:36] - |AC| - [259400] - C:\WINDOWS\system32\MusNotifyIcon.exe[MD5.49E0C5B292E90BF02A7927DBE467F65A] - [11/07/2017 23:04:34] - |AC| - [722432] - C:\WINDOWS\system32\MusUpdateHandlers.dll[MD5.4F745DA4303407A2304DC85E76BBFF59] - [11/07/2017 23:03:28] - |AC| - [357888] - C:\WINDOWS\system32\Narrator.exe[MD5.B96E40B872B0919523A62679B6FA33E4] - [11/07/2017 23:02:06] - |AC| - [3059200] - C:\WINDOWS\system32\NetworkMobileSettings.dll[MD5.9ECFD7DD594DBEAED3A2889045B2DCBD] - [06/07/2017 18:34:32] - |AC| - [1046016] - C:\WINDOWS\system32\ngcsvc.dll[MD5.00000000000000000000000000000000] - [08/07/2017 14:36:28] - |D| - [753472] - C:\WINDOWS\system32\Npcap[MD5.03F0EEE8EFB7D429B3C9CA7E6557EDA4] - [06/07/2017 18:34:19] - |A| - [159744] - C:\WINDOWS\system32\NPSM.dll[MD5.3AAB15D3C0BA383A00B9C147DE3AA01C] - [06/07/2017 18:34:19] - |AC| - [866816] - C:\WINDOWS\system32\NPSMDesktopProvider.dll[MD5.66041B27B2EFEC6D9D946F9CA33230D7] - [11/07/2017 23:03:01] - |A| - [1930320] - C:\WINDOWS\system32\ntdll.dll[MD5.227F6E3AC0735F75C798F764C3E600FA] - [11/07/2017 23:03:15] - |A| - [8318880] - C:\WINDOWS\system32\ntoskrnl.exe[MD5.50B0B2122AAABD76A64CDD52AFFF83C8] - [22/07/2017 15:35:37] - |A| - [4160] - C:\WINDOWS\system32\ocsvc.ini[MD5.26C812B50D31694461513EF308D30222] - [22/07/2017 15:34:38] - |A| - [12560] - C:\WINDOWS\system32\ocsvcOff.ini[MD5.BEED42981D98AC6712DD18C288C1B75E] - [06/07/2017 18:34:16] - |AC| - [29696] - C:\WINDOWS\system32\odbcconf.dll[MD5.D5EC698A61D2B5E7BBF115DB5E496A8B] - [11/07/2017 23:01:46] - |AC| - [114688] - C:\WINDOWS\system32\officecsp.dll[MD5.22852343D5A45BBFBD37F743E60128C5] - [11/07/2017 23:03:25] - |A| - [1325968] - C:\WINDOWS\system32\ole32.dll[MD5.5D455EDE64EA837F2070B3FB1CE4D125] - [11/07/2017 23:01:39] - |A| - [417280] - C:\WINDOWS\system32\oleacc.dll[MD5.70AD4B9AAE5AFE52C6B21DC3F768BA2E] - [06/07/2017 18:34:21] - |A| - [777400] - C:\WINDOWS\system32\oleaut32.dll[MD5.AAAD6AEDD2CD5D0B8E103C38CA9092D5] - [11/07/2017 23:01:51] - |AC| - [290816] - C:\WINDOWS\system32\omadmclient.exe[MD5.F58C4F61F099B4C134DCB4F03EADA8AF] - [11/07/2017 23:02:40] - |A| - [5477088] - C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll[MD5.69FABFEB036B4EFF687BF4AB5D4C05F1] - [06/07/2017 18:34:32] - |AC| - [586240] - C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll[MD5.4BC987B3C188A1602D2DA4B86160DD0E] - [11/07/2017 23:02:09] - |AC| - [2177024] - C:\WINDOWS\system32\OpcServices.dll[MD5.2AD7B4F3C8D2BB686D231EDFF404B7A4] - [09/07/2017 09:01:45] - |A| - [122904] - C:\WINDOWS\system32\OpenAL32.dll[MD5.7DCAE9B806146D0E46EAB64C573CE1DB] - [11/07/2017 23:02:07] - |AC| - [443392] - C:\WINDOWS\system32\PerceptionSimulationExtensions.dll[MD5.F3C40DDEAA4E822EC8D9BE3FBC63AE13] - [11/07/2017 23:03:30] - |AC| - [570880] - C:\WINDOWS\system32\PhotoScreensaver.scr[MD5.509B62E02ED147B12A7F389F3898201B] - [11/07/2017 23:01:41] - |AC| - [430080] - C:\WINDOWS\system32\PlayToDevice.dll[MD5.3F5122FB8F2F8CC45EB2CF665735B1E4] - [11/07/2017 23:04:28] - |AC| - [272896] - C:\WINDOWS\system32\PlayToReceiver.dll[MD5.974A1A964BE31F32844B7AD0257F4707] - [11/07/2017 23:01:58] - |A| - [472728] - C:\WINDOWS\system32\policymanager.dll[MD5.433B5896A3017E0CBCDCE226F3FEED10] - [11/07/2017 23:03:28] - |AC| - [175616] - C:\WINDOWS\system32\prntvpt.dll[MD5.A7249FC95F012A9A7827F95497978309] - [11/07/2017 23:02:06] - |AC| - [427008] - C:\WINDOWS\system32\provengine.dll[MD5.1F0DD560CBF97E2F354669AE80EB3F9D] - [11/07/2017 23:04:29] - |A| - [328704] - C:\WINDOWS\system32\PsmServiceExtHost.dll[MD5.98B20DB47872DC005D3863F01D710FB4] - [11/07/2017 23:02:55] - |A| - [208384] - C:\WINDOWS\system32\psmsrv.dll[MD5.28BC1FDB964C3237EBC05B94AED189F9] - [11/07/2017 23:01:44] - |A| - [809984] - C:\WINDOWS\system32\rasapi32.dll[MD5.069DEE6E15260E1F397E01574BA3E60F] - [11/07/2017 23:01:36] - |AC| - [137216] - C:\WINDOWS\system32\raschap.dll[MD5.253F7435C83011A6C3625BBE3C466F03] - [11/07/2017 23:01:40] - |AC| - [397312] - C:\WINDOWS\system32\rascustom.dll[MD5.D5E9823BC7CD1149917CC49AD4052D94] - [11/07/2017 23:01:52] - |AC| - [873472] - C:\WINDOWS\system32\rasmans.dll[MD5.47B71DD5406576348614D907379DE8EC] - [11/07/2017 23:01:37] - |AC| - [497152] - C:\WINDOWS\system32\rastls.dll[MD5.E5B576331E7875694B5F3E63C524B59D] - [22/07/2017 15:44:34] - |A| - [2210784] - C:\WINDOWS\system32\RCoInstII64.dll[MD5.635B87847C9A44869AD1B9C0A9E29FE0] - [22/07/2017 15:44:58] - |A| - [72520712] - C:\WINDOWS\system32\RCoRes64.dat[MD5.3A30DBAEB259F4EDB57FBFD7A065D9DF] - [06/07/2017 18:34:27] - |AC| - [641536] - C:\WINDOWS\system32\rdbui.dll[MD5.4537CDE4DFEFD47EAF89C0557093B3EF] - [11/07/2017 23:04:29] - |AC| - [94624] - C:\WINDOWS\system32\rdpudd.dll[MD5.FE7AEF48A5F905C9E12702213D2F8DB9] - [11/07/2017 23:02:55] - |AC| - [400896] - C:\WINDOWS\system32\RDXTaskFactory.dll[MD5.3E9ED366E91695D90923990309017F78] - [06/07/2017 18:34:34] - |AC| - [2438656] - C:\WINDOWS\system32\ResetEngine.dll[MD5.34AF5134384A41F3A3730A607375504B] - [22/07/2017 15:43:35] - |A| - [3515416] - C:\WINDOWS\system32\RltkAPO64.dll[MD5.42E1F830002907DFF7B869B150D5F5A8] - [22/07/2017 12:00:49] - |A| - [18096] - C:\WINDOWS\system32\roboot64.exe[MD5.F85C8899860241F78D7107C7581AA2F1] - [22/07/2017 16:00:39] - |A| - [321712] - C:\WINDOWS\system32\RP3DAA64.dll[MD5.BA3C19EF06BA9B0E316D702C31E6DBA6] - [22/07/2017 16:00:42] - |A| - [321712] - C:\WINDOWS\system32\RP3DHT64.dll[MD5.EC784045CFF557E9FA754317B1C86EB7] - [06/07/2017 18:34:23] - |AC| - [199680] - C:\WINDOWS\system32\RstrtMgr.dll[MD5.951A3A163A6D5146E3DF1A19AF173413] - [22/07/2017 16:00:10] - |A| - [1347136] - C:\WINDOWS\system32\RTCOM64.dll[MD5.D7CFCE6811519582690065C21088E9A5] - [21/07/2017 11:24:16] - |A| - [84480] - C:\WINDOWS\system32\RtCRX64.dll[MD5.83C9EC89F1C9228BF481CC51D15B446D] - [22/07/2017 16:06:41] - |A| - [691680] - C:\WINDOWS\system32\RtDataProc64.dll[MD5.8CF627BC89548ABC9DB4DE7912834DE7] - [22/07/2017 16:01:00] - |A| - [214824] - C:\WINDOWS\system32\RTEED64A.dll[MD5.92C9AF448C11908A907A7EF92B338000] - [22/07/2017 16:00:59] - |A| - [88344] - C:\WINDOWS\system32\RTEEG64A.dll[MD5.A3DFE60ECBBEDE0E2BAAE2444B881994] - [22/07/2017 16:00:58] - |A| - [110976] - C:\WINDOWS\system32\RTEEL64A.dll[MD5.97382543BC45FEF210414DAEABF2C040] - [22/07/2017 16:01:04] - |A| - [387312] - C:\WINDOWS\system32\RTEEP64A.dll[MD5.5AFB4E206DD0C3C0446F4AF7FB211FE5] - [22/07/2017 15:59:40] - |A| - [3509200] - C:\WINDOWS\system32\RtkApi64.dll[MD5.CA012683EA211F5CDD5929970E9B502B] - [22/07/2017 16:00:21] - |A| - [192976] - C:\WINDOWS\system32\RtkCfg64.dll[MD5.2EE48D8435EBC15BF235280A48573419] - [22/07/2017 16:00:28] - |A| - [343704] - C:\WINDOWS\system32\RtlCPAPI64.dll[MD5.495F7460DA206A7F8AFBE501469D562F] - [22/07/2017 15:44:05] - |A| - [3205120] - C:\WINDOWS\system32\RtPgEx64.dll[MD5.19E1C98F3F9C8AAA0DE5B6DD9BB24F16] - [22/07/2017 15:33:56] - |A| - [3677152] - C:\WINDOWS\system32\RTSnMg64.cpl[MD5.53F03A8A228D6C8016139A4B2583A2D8] - [11/07/2017 23:02:53] - |AC| - [250368] - C:\WINDOWS\system32\SCardSvr.dll[MD5.CBCC25CDF5D30ACB253CC92ADC7D569C] - [11/07/2017 23:02:54] - |AC| - [200192] - C:\WINDOWS\system32\ScDeviceEnum.dll[MD5.AEEBE7A2F6BC3FB9F43BAAC04AC0EFDE] - [11/07/2017 23:03:01] - |AC| - [251392] - C:\WINDOWS\system32\scksp.dll[MD5.B1A78C1D665048DC795E4156456E042E] - [22/07/2017 16:09:00] - |A| - [526280] - C:\WINDOWS\system32\SEAPO64.dll[MD5.5F661E5FC0B2D079C0BED4036D4DF5F3] - [06/07/2017 18:34:53] - |AC| - [933376] - C:\WINDOWS\system32\SearchIndexer.exe[MD5.96CB662846932E98D3B14CBCAFD3FE30] - [11/07/2017 23:05:37] - |AC| - [364032] - C:\WINDOWS\system32\SearchProtocolHost.exe[MD5.83B2B892EF06768E689081A14648BCC0] - [11/07/2017 23:01:50] - |AC| - [1017760] - C:\WINDOWS\system32\SecConfig.efi[MD5.7FFBEA7313A539DB9DDC79897E0EBA8B] - [22/07/2017 16:09:05] - |A| - [868176] - C:\WINDOWS\system32\SECOMN64.dll[MD5.51EDD6CD3D12E998AE1AB5890061C7F1] - [06/07/2017 18:33:51] - |AC| - [543648] - C:\WINDOWS\system32\securekernel.exe[MD5.1D4F5F50BEA1329FAEFA5D15F683F87F] - [11/07/2017 23:05:52] - |AC| - [336320] - C:\WINDOWS\system32\SecurityHealthService.exe[MD5.99DBC07D31FE6D8CFD7BF2ABB90E6CB6] - [06/07/2017 18:34:52] - |AC| - [809472] - C:\WINDOWS\system32\SecurityHealthSSO.dll[MD5.FD2ECC145AE622C3E9C09AE49A0EC392] - [22/07/2017 16:09:12] - |A| - [1016928] - C:\WINDOWS\system32\SEHDHF64.dll[MD5.87406B441CA845BC150BCEA1F2BC577B] - [22/07/2017 16:09:21] - |A| - [866640] - C:\WINDOWS\system32\SEHDRA64.dll[MD5.1FB82117A69A64A280D3C2A63029BA1B] - [11/07/2017 23:01:42] - |AC| - [135680] - C:\WINDOWS\system32\sendmail.dll[MD5.90D0A52297A9C10A1591C3AA3A90442A] - [11/07/2017 23:03:40] - |AC| - [412160] - C:\WINDOWS\system32\SensorsApi.dll[MD5.AA4BA5CCB3B01E23605ACE13F4A94ECE] - [11/07/2017 23:04:28] - |AC| - [548864] - C:\WINDOWS\system32\SensorService.dll[MD5.00897F867A525D2118DF98E2DCADA050] - [11/07/2017 23:03:30] - |AC| - [205824] - C:\WINDOWS\system32\sensrsvc.dll[MD5.697DBE44CB6516ECAE92552CBBCD8752] - [21/07/2017 11:12:32] - |A| - [132184] - C:\WINDOWS\system32\SET8311.tmp[MD5.9D7E5C98ABDF12D8D5238334628B1779] - [11/07/2017 23:03:05] - |AC| - [315392] - C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll[MD5.50A340289B73D2CA19D1D1A311676145] - [06/07/2017 18:34:29] - |AC| - [491520] - C:\WINDOWS\system32\SettingsHandlers_Display.dll[MD5.9774065DD75C7B284F8338569A615A0A] - [11/07/2017 23:01:56] - |AC| - [365056] - C:\WINDOWS\system32\SettingsHandlers_Notifications.dll[MD5.D2C4647633BD33D04272E6B9A204CFFB] - [11/07/2017 23:02:43] - |AC| - [4447744] - C:\WINDOWS\system32\SettingsHandlers_nt.dll[MD5.E67FA1CECA219CB1574CC4D9F4B255B7] - [06/07/2017 18:34:32] - |A| - [1102848] - C:\WINDOWS\system32\SettingSyncCore.dll[MD5.581A1DE0E7E8FFFD231FBDDAEA5C1F62] - [06/07/2017 18:33:51] - |A| - [1275904] - C:\WINDOWS\system32\ShareHost.dll[MD5.4C6C42DC04BD287882A1D855E9BB8055] - [11/07/2017 23:02:29] - |A| - [21353208] - C:\WINDOWS\system32\shell32.dll[MD5.4DA8F9EC96D639B4E6CA844D8A301E37] - [11/07/2017 23:01:53] - |AC| - [229888] - C:\WINDOWS\system32\SIHClient.exe[MD5.2354FCDB540A378A657866DF39D87573] - [22/07/2017 16:07:54] - |A| - [984912] - C:\WINDOWS\system32\sl3apo64.dll[MD5.D52E47DC28B44901CFC8ED3C5CF3BE14] - [22/07/2017 16:08:05] - |A| - [3410832] - C:\WINDOWS\system32\slcnt64.dll[MD5.649CBCA4755E2AD7EDC371D849447681] - [22/07/2017 16:08:02] - |A| - [258856] - C:\WINDOWS\system32\slprp64.dll[MD5.6C1A08D54D1E2E40C95641A2296F4540] - [22/07/2017 16:08:34] - |A| - [3122656] - C:\WINDOWS\system32\sltech64.dll[MD5.30A38A2FB46D2372393336169B12BB0D] - [11/07/2017 23:02:59] - |AC| - [899072] - C:\WINDOWS\system32\SmartcardCredentialProvider.dll[MD5.D57880A3F9F22D67974EF0EB8B67021C] - [22/07/2017 12:11:34] - |A| - [36824] - C:\WINDOWS\system32\SmartDefragBootTime.exe[MD5.5CFFCDC66C84D2E96098B0BE8AE44ACE] - [06/07/2017 18:34:33] - |AC| - [2730496] - C:\WINDOWS\system32\smartscreen.exe[MD5.EEE802F2BD574FDE09F1629664A074CE] - [06/07/2017 18:34:33] - |AC| - [209408] - C:\WINDOWS\system32\smartscreenps.dll[MD5.1E6AA5E069F56E4E2D9EFF5AFBC9231C] - [22/07/2017 12:18:26] - |A| - [20480] - C:\WINDOWS\system32\smpnative64.exe[MD5.8457DF5F351C36B385468609A8DB849D] - [11/07/2017 23:01:49] - |A| - [621056] - C:\WINDOWS\system32\SndVolSSO.dll[MD5.9977AFF389C0C32DE419226564886E09] - [06/07/2017 18:34:33] - |AC| - [15872] - C:\WINDOWS\system32\snmptrap.exe[MD5.2198474472474C48169F532553207419] - [22/07/2017 16:07:30] - |A| - [467152] - C:\WINDOWS\system32\SRAPO64.dll[MD5.826C0C7F0AA01D30809795A3B37FC338] - [22/07/2017 16:07:51] - |A| - [341144] - C:\WINDOWS\system32\SRCOM.dll[MD5.028CA8FC7B630E7E3A5696EAA7C07E4F] - [22/07/2017 16:07:34] - |A| - [381408] - C:\WINDOWS\system32\SRCOM64.dll[MD5.EF3B7E686F857B5C9D5EBB257F629F43] - [11/07/2017 23:02:19] - |AC| - [3332096] - C:\WINDOWS\system32\SRH.dll[MD5.F27491D59709E7E047FD9B51738A5738] - [22/07/2017 16:07:38] - |A| - [1435136] - C:\WINDOWS\system32\SRRPTR64.dll[MD5.284606226D06EF38393C8CFE4A7ACA96] - [22/07/2017 15:59:38] - |A| - [209528] - C:\WINDOWS\system32\SRSHP64.dll[MD5.A701A35E1492887D7FB220D18C9201F3] - [22/07/2017 15:59:36] - |A| - [221960] - C:\WINDOWS\system32\SRSTSH64.dll[MD5.636F6AE756E2E57426EBEEF517D83FF1] - [22/07/2017 15:59:30] - |A| - [532376] - C:\WINDOWS\system32\SRSTSX64.dll[MD5.177A57DA2987C03ED941376215B0DE4A] - [22/07/2017 15:59:34] - |A| - [166200] - C:\WINDOWS\system32\SRSWOW64.dll[MD5.A7010513641776D4F52703B38111F98F] - [06/07/2017 18:34:37] - |AC| - [1078272] - C:\WINDOWS\system32\StoreAgent.dll[MD5.D86308FD6F879CE1108161F2DFA8E337] - [11/07/2017 23:04:29] - |AC| - [165888] - C:\WINDOWS\system32\storewuauth.dll[MD5.7C29BBF63178BB6788AD1C2B231150A5] - [06/07/2017 18:34:31] - |AC| - [972800] - C:\WINDOWS\system32\sysmain.dll[MD5.696ECBCA7A87F0F672346447C94C2F2C] - [06/07/2017 18:34:28] - |AC| - [370928] - C:\WINDOWS\system32\SystemSettingsAdminFlows.exe[MD5.120CFA59CA05D2FBC1805F2D135F7E9B] - [11/07/2017 23:03:11] - |AC| - [3803136] - C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll[MD5.CA4CC9C28ECFB0513C2D2B6E321E188C] - [11/07/2017 23:04:33] - |AC| - [510976] - C:\WINDOWS\system32\TDLMigration.dll[MD5.B74E1010A8C24A30B1738B2A5716502D] - [11/07/2017 23:01:40] - |AC| - [2873344] - C:\WINDOWS\system32\themeui.dll[MD5.4F9A5CE9F3C75AF1EE4B00D5E69F7CF7] - [11/07/2017 23:04:31] - |A| - [632832] - C:\WINDOWS\system32\tileobjserver.dll[MD5.92C9606A41D2D8CD247D746AA116245E] - [11/07/2017 23:01:45] - |AC| - [45056] - C:\WINDOWS\system32\TokenBrokerUI.dll[MD5.B40A9FB7142C0564258945D1477F91F0] - [06/07/2017 18:34:35] - |AC| - [551936] - C:\WINDOWS\system32\TpmCoreProvisioning.dll[MD5.6E433C1678562F4976BDF8C44008CF8D] - [11/07/2017 23:06:35] - |A| - [3377664] - C:\WINDOWS\system32\tquery.dll[MD5.EC141242B7313AF43261931464A0836A] - [11/07/2017 23:04:37] - |AC| - [985600] - C:\WINDOWS\system32\TSWorkspace.dll[MD5.AD60622F6CFAC51E294F6431C5D2486B] - [06/07/2017 18:34:35] - |A| - [1506712] - C:\WINDOWS\system32\twinapi.appcore.dll[MD5.00B99B980A732A2A488B9B635CD2A034] - [11/07/2017 23:02:41] - |A| - [1076736] - C:\WINDOWS\system32\twinui.appcore.dll[MD5.226137B85BB04D83C5BFDAC8A72F232C] - [11/07/2017 23:02:37] - |A| - [7931392] - C:\WINDOWS\system32\twinui.dll[MD5.95912D363581ABD02D6EC441E13DB5B4] - [11/07/2017 23:03:10] - |A| - [2499584] - C:\WINDOWS\system32\twinui.pcshell.dll[MD5.1ACB1BBC69D1A95A8193B3704B4460F5] - [06/07/2017 18:34:10] - |AC| - [2560] - C:\WINDOWS\system32\tzres.dll[MD5.7E4E5D4AA0774F29E76D27256867A9DE] - [06/07/2017 18:34:36] - |A| - [1003624] - C:\WINDOWS\system32\ucrtbase.dll[MD5.E275A1AEAAB0227DD2CFD1772424F59D] - [11/07/2017 23:01:44] - |A| - [859136] - C:\WINDOWS\system32\uDWM.dll[MD5.45DE86C8A5C453EE5EC544F7B01CC50B] - [11/07/2017 23:02:48] - |A| - [1818624] - C:\WINDOWS\system32\UIAutomationCore.dll[MD5.F0962E66D31699634C52A43129E2E23E] - [06/07/2017 18:34:36] - |AC| - [584192] - C:\WINDOWS\system32\UIRibbonRes.dll[MD5.F6A0B848F75CF55E3980EA0FADCBA317] - [06/07/2017 18:34:37] - |A| - [148480] - C:\WINDOWS\system32\umpo.dll[MD5.5B17D5E9FBF65ED93078DEB687357BAF] - [11/07/2017 23:04:33] - |AC| - [1177600] - C:\WINDOWS\system32\Unistore.dll[MD5.9DA408B507A0CC0FCA89486AF23728B2] - [11/07/2017 23:02:07] - |AC| - [411136] - C:\WINDOWS\system32\updatehandlers.dll[MD5.2A0C9401722F65615F1D912B38F2F2A8] - [11/07/2017 23:02:36] - |A| - [1802240] - C:\WINDOWS\system32\urlmon.dll[MD5.766B24C6F6B6369BBB1C273759FE5058] - [06/07/2017 18:34:35] - |AC| - [119296] - C:\WINDOWS\system32\UserDataTimeUtil.dll[MD5.65D70A530105E0576641493D6292C9EA] - [11/07/2017 23:02:10] - |AC| - [681984] - C:\WINDOWS\system32\usocore.dll[MD5.58A4C7CF9DFBF6A731992084B611530B] - [06/07/2017 18:34:35] - |AC| - [99328] - C:\WINDOWS\system32\utcutil.dll[MD5.032237382A049EC638F274042E07C6F5] - [11/07/2017 23:03:49] - |AC| - [588800] - C:\WINDOWS\system32\vbscript.dll[MD5.E99E2393AD8F3193772B692CBEE1CA9B] - [11/07/2017 23:03:20] - |AC| - [5776384] - C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe[MD5.5D543665EF9DD570A4D99BD30719DFD1] - [06/07/2017 18:34:37] - |AC| - [61952] - C:\WINDOWS\system32\vss_ps.dll[MD5.4D5CDE84068F3D4613C3C17CFEA4515D] - [11/07/2017 23:04:31] - |AC| - [942592] - C:\WINDOWS\system32\wbiosrvc.dll[MD5.9DDD15FCE0BE61F25C20CC7E2A96B77C] - [11/07/2017 23:01:52] - |A| - [802816] - C:\WINDOWS\system32\wcmsvc.dll[MD5.99088902C06A30645F3C1FBD2C4EE07C] - [11/07/2017 23:01:53] - |AC| - [1403392] - C:\WINDOWS\system32\wdc.dll[MD5.4DA5DA193E0E4F86F6F8FD43EF25329A] - [21/07/2017 11:12:33] - |A| - [1721576] - C:\WINDOWS\system32\WdfCoInstaller01009.dll[MD5.415E4EA3CFF08C461CEBBA4C647EBE09] - [22/07/2017 16:16:17] - |A| - [1804680] - C:\WINDOWS\system32\WdfCoInstaller01011.dll[MD5.13FDE4EB1857CDD43EBBEBDB4794DE7C] - [11/07/2017 23:01:50] - |A| - [241152] - C:\WINDOWS\system32\wdmaud.drv[MD5.575E7AE27B944F20ACCF52D0F32BC6FC] - [11/07/2017 23:01:36] - |AC| - [64000] - C:\WINDOWS\system32\WFDSConMgr.dll[MD5.4D64719B4819CA22A046EC32809BBD98] - [11/07/2017 23:01:53] - |AC| - [555008] - C:\WINDOWS\system32\WFDSConMgrSvc.dll[MD5.0DB78CDFFCFA2AD1ADDF99EC17E96F1A] - [11/07/2017 23:02:32] - |A| - [2055168] - C:\WINDOWS\system32\win32kbase.sys[MD5.289EE089E22AD9434AD7052C3F2F1E3E] - [11/07/2017 23:02:31] - |A| - [3670016] - C:\WINDOWS\system32\win32kfull.sys[MD5.1DA39F2A2BC346F32B25A0D415FD3B55] - [06/07/2017 18:34:22] - |AC| - [827392] - C:\WINDOWS\system32\win32spl.dll[MD5.E2783622109D8AC154B49D961698772F] - [11/07/2017 23:04:29] - |AC| - [327168] - C:\WINDOWS\system32\WinBioDataModel.dll[MD5.985A47A5C5A1885180A2CD3763F920E7] - [11/07/2017 23:04:28] - |AC| - [56832] - C:\WINDOWS\system32\WinBioDataModelOOBE.exe[MD5.BE93C9FEE7F67C6D6A1C89A00CB16D1B] - [11/07/2017 23:02:54] - |AC| - [188928] - C:\WINDOWS\system32\wincredui.dll[MD5.C31AC77A6DA08E22DE03994C9BFEB763] - [06/07/2017 18:33:51] - |A| - [616960] - C:\WINDOWS\system32\WindowManagement.dll[MD5.EEEDA5D86603F8592F51AD2A0798F3BE] - [11/07/2017 23:02:00] - |A| - [558920] - C:\WINDOWS\system32\Windows.ApplicationModel.dll[MD5.59F84AB686634BC4575C6BB9F6623D35] - [06/07/2017 18:34:34] - |AC| - [1911752] - C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll[MD5.5481E51B4E89053B736848CDADD409FC] - [11/07/2017 23:02:49] - |AC| - [7336448] - C:\WINDOWS\system32\Windows.Data.Pdf.dll[MD5.CCB976DEA82A12108B7A965833C62633] - [11/07/2017 23:03:05] - |AC| - [2171392] - C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll[MD5.C4E81707CAF2B402CA64A2088A6017E8] - [06/07/2017 18:34:08] - |AC| - [439808] - C:\WINDOWS\system32\Windows.Devices.Midi.dll[MD5.913CD31320128B8B89F495CB8DD835F2] - [11/07/2017 23:03:02] - |AC| - [626176] - C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll[MD5.92DD540BF9B920E2E0127E5884E48BC1] - [11/07/2017 23:01:39] - |AC| - [536064] - C:\WINDOWS\system32\Windows.Internal.Management.dll[MD5.DDEC9DB7D35DBB52E91AF7130656E5B9] - [11/07/2017 23:04:05] - |AC| - [6554928] - C:\WINDOWS\system32\Windows.Media.dll[MD5.42A286E65EED5201BD5EB35921AB026C] - [11/07/2017 23:02:27] - |AC| - [7904784] - C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll[MD5.993E0B34F344C559AB25247B1EE5E553] - [11/07/2017 23:04:31] - |AC| - [551424] - C:\WINDOWS\system32\Windows.Payments.dll[MD5.AEF445DACE6D3B1118EB1E21E143D34E] - [06/07/2017 18:34:27] - |AC| - [271872] - C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll[MD5.7CA2E9B6EDC87FCCA9C49D3D9BE62B65] - [06/07/2017 18:34:27] - |AC| - [192512] - C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll[MD5.C4537C7AD7AB96F615C6589DC5A3600D] - [11/07/2017 23:01:53] - |A| - [497152] - C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll[MD5.D37CC10A8FB198BAC61F98A4DAD5056D] - [11/07/2017 23:03:21] - |A| - [7325584] - C:\WINDOWS\system32\windows.storage.dll[MD5.93F9CF53D9F6B0D482C116CB743B0260] - [06/07/2017 18:34:52] - |A| - [601088] - C:\WINDOWS\system32\Windows.System.Launcher.dll[MD5.78BB715C266B3E98981205FBE669CB2E] - [11/07/2017 23:01:41] - |AC| - [144384] - C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll[MD5.A8961016D006CF08D14FF4A22CD0B3A2] - [06/07/2017 18:34:14] - |AC| - [476160] - C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll[MD5.E22455B77E2B178329D70D0CDF3C430F] - [11/07/2017 23:02:38] - |A| - [1050624] - C:\WINDOWS\system32\Windows.UI.dll[MD5.E9C6953E723D24409C83F54486389502] - [06/07/2017 18:34:38] - |A| - [1706496] - C:\WINDOWS\system32\Windows.UI.Immersive.dll[MD5.AB7111EE49D35A37F70E8AAB3FDBE14E] - [06/07/2017 18:34:36] - |AC| - [2625024] - C:\WINDOWS\system32\Windows.UI.Logon.dll[MD5.DCAB8DE37A17D500270C00E9BB73F512] - [11/07/2017 23:02:46] - |AC| - [17364992] - C:\WINDOWS\system32\Windows.UI.Xaml.dll[MD5.D655D5E7A077E4CB06B816A7594F5B8C] - [11/07/2017 23:02:04] - |AC| - [1420800] - C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll[MD5.C980EF408C48FBCDD4A584C6F443625C] - [11/07/2017 23:02:18] - |AC| - [2199552] - C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll[MD5.4921772259540486DB33E791C5CEACD4] - [06/07/2017 18:34:37] - |AC| - [232448] - C:\WINDOWS\system32\Windows.Web.Diagnostics.dll[MD5.98615EFE1642D3E1B226A1A95F6F3E78] - [11/07/2017 23:03:07] - |A| - [1760264] - C:\WINDOWS\system32\WindowsCodecs.dll[MD5.94B0D0B830A619DDB4C7B55D44009049] - [11/07/2017 23:02:53] - |AC| - [274944] - C:\WINDOWS\system32\WindowsCodecsExt.dll[MD5.252BAA471B22A9D594CD67B8ACE48997] - [11/07/2017 23:03:39] - |AC| - [32688336] - C:\WINDOWS\system32\WindowsCodecsRaw.dll[MD5.BC776B6B434641AF71ED0CC00BC859AA] - [11/07/2017 23:02:35] - |A| - [3307008] - C:\WINDOWS\system32\wininet.dll[MD5.B2DB5876B6F68D32E470F691C7088F3F] - [11/07/2017 23:02:57] - |A| - [318232] - C:\WINDOWS\system32\wininit.exe[MD5.9AB3931F7F21D7B3123ACF88AA86C407] - [11/07/2017 23:02:56] - |A| - [41376] - C:\WINDOWS\system32\wininitext.dll[MD5.42F564A458305F0D327914AFEAEDF11B] - [11/07/2017 23:03:00] - |A| - [1395152] - C:\WINDOWS\system32\winload.efi[MD5.12654B55EFFD53DE4C8759676F36A26F] - [11/07/2017 23:02:58] - |A| - [1186464] - C:\WINDOWS\system32\winload.exe[MD5.31E3287EF6D97C5864A301CEA75BBBA1] - [11/07/2017 23:03:22] - |A| - [706560] - C:\WINDOWS\system32\winlogon.exe[MD5.B00B927B9ED09809084A8DDDDC139971] - [11/07/2017 23:04:39] - |AC| - [1670496] - C:\WINDOWS\system32\winmde.dll[MD5.B0AB265F7256FC2D98EC52C590B6B0D3] - [11/07/2017 23:02:59] - |A| - [1065104] - C:\WINDOWS\system32\winresume.efi[MD5.D269C2DF448F8AC73BE12999416D24CB] - [11/07/2017 23:02:57] - |A| - [899824] - C:\WINDOWS\system32\winresume.exe[MD5.A5848D6720F0A23A51565D5A40D7FAEA] - [11/07/2017 23:04:13] - |A| - [545792] - C:\WINDOWS\system32\winspool.drv[MD5.981EC77511EBFE8AE5731C08A194A685] - [11/07/2017 23:02:34] - |A| - [64512] - C:\WINDOWS\system32\winsrv.dll[MD5.176ED102B39FF9874CF2D9DF753118A9] - [06/07/2017 18:34:38] - |A| - [88576] - C:\WINDOWS\system32\winsrvext.dll[MD5.D7776235513B0279048B7E37979E4EF8] - [11/07/2017 23:02:56] - |A| - [353280] - C:\WINDOWS\system32\Wldap32.dll[MD5.BD874187B1F74CE82A5DD1D7EE79209F] - [11/07/2017 23:01:39] - |AC| - [391168] - C:\WINDOWS\system32\WMPhoto.dll[MD5.DF1D0688D4F9B04A772757980D783548] - [11/07/2017 23:04:30] - |AC| - [2021680] - C:\WINDOWS\system32\wmpmde.dll[MD5.AD4A43BC6AAA275DAE5EE71E1435CC2B] - [06/07/2017 18:37:33] - |AC| - [387928] - C:\WINDOWS\system32\wmpps.dll[MD5.EF8BA6D82750C3C933B13009D07D29B0] - [11/07/2017 23:03:23] - |AC| - [422400] - C:\WINDOWS\system32\WpAXHolder.dll[MD5.5C2764078FCFC15B0E7039D2A9423484] - [11/07/2017 23:02:14] - |AC| - [925696] - C:\WINDOWS\system32\WpcWebFilter.dll[MD5.F703F293B6EE567D82ADEB48A2907F79] - [11/07/2017 23:04:02] - |AC| - [1674240] - C:\WINDOWS\system32\wpncore.dll[MD5.78CC7DAAEB238F6B190FFB02795BFB65] - [06/07/2017 18:34:22] - |AC| - [557568] - C:\WINDOWS\system32\wpnprv.dll[MD5.549347BCD4AACD63243D78E8F869DBB1] - [09/07/2017 09:01:45] - |A| - [466456] - C:\WINDOWS\system32\wrap_oal.dll[MD5.6CEDDC8B5DCBB37F02E582030B8749AA] - [11/07/2017 23:02:02] - |AC| - [986112] - C:\WINDOWS\system32\wuapi.dll[MD5.359A4FC47628C0E66894B80C97932C71] - [11/07/2017 23:02:33] - |AC| - [2444288] - C:\WINDOWS\system32\wuaueng.dll[MD5.306EBAD64DC58219F34F67233617F7F9] - [11/07/2017 23:03:30] - |AC| - [95232] - C:\WINDOWS\system32\wudriver.dll[MD5.FD3C067290C1FEA05A20BF5A3998FBF2] - [11/07/2017 23:01:48] - |AC| - [406528] - C:\WINDOWS\system32\wuuhext.dll[MD5.1F6D311985E2AD4532B5015FD22CCC75] - [11/07/2017 23:01:45] - |AC| - [113152] - C:\WINDOWS\system32\wuuhosdeployment.dll[MD5.55D6832E3168C125DED86CAB6D2C195D] - [11/07/2017 23:04:30] - |AC| - [820128] - C:\WINDOWS\system32\WWAHost.exe[MD5.627792928BFD77902C0066F2643D0BBB] - [11/07/2017 23:01:43] - |AC| - [81408] - C:\WINDOWS\system32\wwanprotdim.dll[MD5.B0C56930417D00E44B3FDBF6FC282943] - [11/07/2017 23:02:00] - |AC| - [1396224] - C:\WINDOWS\system32\wwansvc.dll[MD5.F77D5AB654881E683CFF6650916C424E] - [07/07/2017 11:40:58] - |A| - [16592] - C:\WINDOWS\system32\x3daudio1_0.dll[MD5.489E5B8BB1BD1028FF1C798EAAEC65E4] - [07/07/2017 11:55:07] - |A| - [17688] - C:\WINDOWS\system32\x3daudio1_1.dll[MD5.BC78D5328541410510DDE06B9FA92024] - [07/07/2017 11:59:52] - |A| - [21000] - C:\WINDOWS\system32\X3DAudio1_2.dll[MD5.C4C2ED69B18EE1C60026877FCC470FA7] - [07/07/2017 12:02:28] - |A| - [28168] - C:\WINDOWS\system32\X3DAudio1_3.dll[MD5.DE6004D16DBACD781ED4596C4FEA7D14] - [07/07/2017 12:04:48] - |A| - [28168] - C:\WINDOWS\system32\X3DAudio1_4.dll[MD5.CFF1C1F7B9F855DDEE431D7B5DCACDF8] - [07/07/2017 12:07:38] - |A| - [25936] - C:\WINDOWS\system32\X3DAudio1_5.dll[MD5.EEE871CC4F5563FF8B3C8385B32B0C5F] - [07/07/2017 12:09:57] - |A| - [24920] - C:\WINDOWS\system32\X3DAudio1_6.dll[MD5.B4FF2A39685C1A6D43F0E56EB350AF3A] - [07/07/2017 12:15:46] - |A| - [24920] - C:\WINDOWS\system32\X3DAudio1_7.dll[MD5.CE5753F9A27837259EB52F3F47F39593] - [07/07/2017 11:40:59] - |A| - [355536] - C:\WINDOWS\system32\xactengine2_0.dll[MD5.0CC809422AB40974DFF8078392E4D507] - [07/07/2017 11:48:12] - |A| - [352464] - C:\WINDOWS\system32\xactengine2_1.dll[MD5.E8932AF24786765859558CB79E385AC2] - [07/07/2017 12:00:09] - |A| - [411656] - C:\WINDOWS\system32\xactengine2_10.dll[MD5.DC5A914C34EB12056531777D4DD0F44E] - [07/07/2017 11:49:18] - |A| - [354072] - C:\WINDOWS\system32\xactengine2_2.dll[MD5.0396D2A98B0CCD4419B572EBF618E81E] - [07/07/2017 11:50:12] - |A| - [363288] - C:\WINDOWS\system32\xactengine2_3.dll[MD5.58BB51253427A834A8807B9245CC5965] - [07/07/2017 11:51:30] - |A| - [364824] - C:\WINDOWS\system32\xactengine2_4.dll[MD5.398FF46FF7354FED2F0F1AECDB546866] - [07/07/2017 11:53:14] - |A| - [390424] - C:\WINDOWS\system32\xactengine2_5.dll[MD5.4837A54574A6105D404A8560984B93DD] - [07/07/2017 11:53:35] - |A| - [393576] - C:\WINDOWS\system32\xactengine2_6.dll[MD5.8C970509E0AE10061E3ED6D51E34FEB9] - [07/07/2017 11:55:08] - |A| - [403304] - C:\WINDOWS\system32\xactengine2_7.dll[MD5.FA485E76F94B7457767E372F47757733] - [07/07/2017 11:57:04] - |A| - [409960] - C:\WINDOWS\system32\xactengine2_8.dll[MD5.A69C32C2BD01522A088D254342826866] - [07/07/2017 11:58:34] - |A| - [411496] - C:\WINDOWS\system32\xactengine2_9.dll[MD5.A8B5370B7B61D3777D840DA1C64A1C2D] - [07/07/2017 12:02:48] - |A| - [177672] - C:\WINDOWS\system32\xactengine3_0.dll[MD5.A2A098BF5A8C255A0090818AD8E87B0F] - [07/07/2017 12:04:59] - |A| - [177672] - C:\WINDOWS\system32\xactengine3_1.dll[MD5.CC8399A9E51B2AF1C2C20A26D85EB60E] - [07/07/2017 12:06:42] - |A| - [177672] - C:\WINDOWS\system32\xactengine3_2.dll[MD5.84B41FD03CAFC5048346B3B2AB92D199] - [07/07/2017 12:08:01] - |A| - [175440] - C:\WINDOWS\system32\xactengine3_3.dll[MD5.1BA01062450BD1F052C54C01C12248F6] - [07/07/2017 12:10:16] - |A| - [174936] - C:\WINDOWS\system32\xactengine3_4.dll[MD5.51D65BE2F794B944CADAF287B34EF603] - [07/07/2017 12:14:21] - |A| - [176968] - C:\WINDOWS\system32\xactengine3_5.dll[MD5.936DCC640B2991905D909395E03B64F9] - [07/07/2017 12:16:09] - |A| - [176984] - C:\WINDOWS\system32\xactengine3_6.dll[MD5.0E92D8C0ECA74B6D0A55ABAD53226113] - [07/07/2017 12:05:25] - |A| - [68104] - C:\WINDOWS\system32\XAPOFX1_0.dll[MD5.0F2DB378FBE2D124E4D3631B329688AE] - [07/07/2017 12:07:11] - |A| - [72200] - C:\WINDOWS\system32\XAPOFX1_1.dll[MD5.2F8F9B707FED2405A787380230CC6FA9] - [07/07/2017 12:08:43] - |A| - [74576] - C:\WINDOWS\system32\XAPOFX1_2.dll[MD5.37B348A79C4C9B8AB925B18FFD241E96] - [07/07/2017 12:14:59] - |A| - [73544] - C:\WINDOWS\system32\XAPOFX1_3.dll[MD5.A9724EB3D6CC032D0C4ECAFF4AD8C17F] - [07/07/2017 12:16:36] - |A| - [78680] - C:\WINDOWS\system32\XAPOFX1_4.dll[MD5.29AF48F6C894328A58DEFDC560A70CF3] - [07/07/2017 12:03:32] - |A| - [489480] - C:\WINDOWS\system32\XAudio2_0.dll[MD5.E9C0F926D7C9082A805F4FEF81DEEB30] - [07/07/2017 12:05:24] - |A| - [511496] - C:\WINDOWS\system32\XAudio2_1.dll[MD5.E335DF094836EE7030F1B9CE7429E884] - [07/07/2017 12:07:10] - |A| - [513544] - C:\WINDOWS\system32\XAudio2_2.dll[MD5.758139A39AECC1B512576275A27C1177] - [07/07/2017 12:08:42] - |A| - [518480] - C:\WINDOWS\system32\XAudio2_3.dll[MD5.B94F08069EFE2F8151DEF350E526E063] - [07/07/2017 12:10:46] - |A| - [521560] - C:\WINDOWS\system32\XAudio2_4.dll[MD5.C291AEFD47A587FF5F509E2F96613F7D] - [07/07/2017 12:14:58] - |A| - [517960] - C:\WINDOWS\system32\XAudio2_5.dll[MD5.05E88C8D8E652DFF03B469331F474CCE] - [07/07/2017 12:16:36] - |A| - [530776] - C:\WINDOWS\system32\XAudio2_6.dll[MD5.06E01EBE72917268D5AD7331801E377A] - [06/07/2017 18:34:52] - |AC| - [133120] - C:\WINDOWS\system32\XblGameSaveExt.dll[MD5.19820EEC2D1A4D264F051B789F79D51A] - [06/07/2017 18:34:52] - |AC| - [86016] - C:\WINDOWS\system32\xboxgipsynthetic.dll[MD5.EF83C2EF7F152DFDC6D9F1AEC6FBE66F] - [06/07/2017 18:34:52] - |AC| - [1067008] - C:\WINDOWS\system32\XboxNetApiSvc.dll[MD5.6F9D3289D8B166E478AFFF9EFA92C42C] - [07/07/2017 11:48:49] - |A| - [83664] - C:\WINDOWS\system32\xinput1_1.dll[MD5.06F15D3CB1AE0EAFA50F595B3FF8D9F5] - [07/07/2017 11:49:51] - |A| - [83736] - C:\WINDOWS\system32\xinput1_2.dll[MD5.BFB3091B167550EC6E6454813D3DB244] - [07/07/2017 11:55:48] - |A| - [107368] - C:\WINDOWS\system32\xinput1_3.dll[MD5.8C427F35B9A734C284AB8634A9BD8F51] - [22/07/2017 16:15:10] - |A| - [92400] - C:\WINDOWS\system32\Drivers\amd_sata.sys[MD5.E341406226901D67DF5469F1B8146BB3] - [22/07/2017 16:15:11] - |A| - [32496] - C:\WINDOWS\system32\Drivers\amd_xata.sys[MD5.E2BFD01BD0ECF2BDE9420022147952A4] - [06/07/2017 18:33:44] - |A| - [35840] - C:\WINDOWS\system32\Drivers\BasicRender.sys[MD5.670E6CFDA70C106342C0D63D014B6822] - [11/07/2017 23:03:31] - |AC| - [115712] - C:\WINDOWS\system32\Drivers\bridge.sys[MD5.F7A53768D087D2213AC72556AE6A7D72] - [07/07/2017 18:11:53] - |A| - [10224] - C:\WINDOWS\system32\Drivers\cdr4_xp.sys[MD5.D406291C2F658EF71427270D0FF9537B] - [07/07/2017 18:11:52] - |A| - [10224] - C:\WINDOWS\system32\Drivers\cdralw2k.sys[MD5.533CCBAFE41FDAC4301A2CAA2440E767] - [11/07/2017 08:16:48] - |A| - [24560] - C:\WINDOWS\system32\Drivers\CLBStor.sys[MD5.1BF9D74451B8AF166105E28F1D7A5C27] - [11/07/2017 23:02:57] - |AC| - [382368] - C:\WINDOWS\system32\Drivers\clfs.sys[MD5.236DEE76D47ACCF2391E390A3DE5AE5A] - [22/07/2017 15:35:58] - |A| - [44080] - C:\WINDOWS\system32\Drivers\cpwfpnd64.sys[MD5.F51953EC4B9AACD92A3B3CE66E05CEF4] - [06/07/2017 18:34:07] - |AC| - [112544] - C:\WINDOWS\system32\Drivers\dam.sys[MD5.2842202EC530FA28F1C80035C340803D] - [06/07/2017 12:00:41] - |A| - [66896] - C:\WINDOWS\system32\Drivers\dokan.sys[MD5.20C89F4852F141DF26C10D54D4745041] - [21/07/2017 18:24:11] - |A| - [174832] - C:\WINDOWS\system32\Drivers\dtldrvprotect64.sys[MD5.F000C7AF0F65D5DD3C8BA43FEDDD30F4] - [06/07/2017 18:33:44] - |AC| - [188824] - C:\WINDOWS\system32\Drivers\dumpsd.sys[MD5.D2D4095909DD26445139EC9B7C86DA5D] - [11/07/2017 23:02:32] - |A| - [2444696] - C:\WINDOWS\system32\Drivers\dxgkrnl.sys[MD5.0EE2587A3AF9E29DF991CE20833B5F1E] - [06/07/2017 18:34:15] - |A| - [712608] - C:\WINDOWS\system32\Drivers\dxgmms2.sys[MD5.19956478146DC7884812C24B74D7132E] - [07/07/2017 20:56:27] - |A| - [101784] - C:\WINDOWS\system32\Drivers\farflt.sys[MD5.C61014A176ECAAF97589E6FC979CE786] - [06/07/2017 18:34:09] - |A| - [363424] - C:\WINDOWS\system32\Drivers\fastfat.sys[MD5.1FF88AD06B2281E459A4B48AC8E5AABF] - [13/07/2017 14:10:42] - |A| - [3440] - C:\WINDOWS\system32\Drivers\fvstore.dat[MD5.BB102D444FE4E1ADC28FDEDE1A076EAE] - [21/07/2017 11:14:56] - |A| - [131160] - C:\WINDOWS\system32\Drivers\GeneStor.sys[MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - [11/07/2017 23:05:18] - |A| - [86528] - C:\WINDOWS\system32\Drivers\hdaudbus.sys[MD5.BB1AE72906564A6E81B79D73A05AE21F] - [11/07/2017 23:03:31] - |AC| - [1106848] - C:\WINDOWS\system32\Drivers\http.sys[MD5.D247D5C0F8747B52F6AFC7E6E0F3DCCD] - [11/07/2017 11:02:04] - |A| - [62208] - C:\WINDOWS\system32\Drivers\isedrv.sys[MD5.9778205F28DC4F2EFFCC146647FE5CF0] - [06/07/2017 18:34:15] - |AC| - [27136] - C:\WINDOWS\system32\Drivers\ksthunk.sys[MD5.A9E95471762BFCC39B1A3C391F00A2A1] - [21/07/2017 11:13:05] - |A| - [161864] - C:\WINDOWS\system32\Drivers\L1C63x64.sys[MD5.FB9372BC10F162645F64884A47B5F79D] - [06/07/2017 07:54:49] - |A| - [61304] - C:\WINDOWS\system32\Drivers\lpsport.sys[MD5.78BFF5425E044086E74E78650A359FBB] - [07/07/2017 19:28:10] - |A| - [27008] - C:\WINDOWS\system32\Drivers\mbam.sys[MD5.1239597BAB7EED2BB16D035AF87E65D9] - [07/07/2017 19:28:34] - |A| - [140672] - C:\WINDOWS\system32\Drivers\mbamchameleon.sys[MD5.84700F40C0E41AEA91F8F3D6218A8A68] - [11/07/2017 23:04:28] - |A| - [285696] - C:\WINDOWS\system32\Drivers\mrxsmb10.sys[MD5.B855479BA6A74349CEF8061808C90201] - [11/07/2017 23:01:44] - |A| - [228256] - C:\WINDOWS\system32\Drivers\mrxsmb20.sys[MD5.B6BA01EA6B2CCCB90A6FDCFF68F4A992] - [11/07/2017 23:05:36] - |AC| - [279968] - C:\WINDOWS\system32\Drivers\msiscsi.sys[MD5.C2939119A17E52D74191EFC1E4CDEE09] - [11/07/2017 23:01:41] - |AC| - [32768] - C:\WINDOWS\system32\Drivers\mskssrv.sys[MD5.898415AC0B5F1D2A9A48ABCB68A6DC4B] - [07/07/2017 20:56:15] - |A| - [65408] - C:\WINDOWS\system32\Drivers\mwac.sys[MD5.59F3D5FEF4A24871C07C279762DA8624] - [11/07/2017 23:03:31] - |AC| - [1242528] - C:\WINDOWS\system32\Drivers\ndis.sys[MD5.A6F77B81BAF734E1E15ACD4AC439710F] - [11/07/2017 23:03:30] - |AC| - [519584] - C:\WINDOWS\system32\Drivers\netio.sys[MD5.8D72D5038C5F91AFEF1B160FE524C2D9] - [11/07/2017 23:03:02] - |AC| - [2327456] - C:\WINDOWS\system32\Drivers\ntfs.sys[MD5.10E48E45A03A7F4C2B7C11738BE87816] - [11/07/2017 23:04:30] - |AC| - [117664] - C:\WINDOWS\system32\Drivers\pdc.sys[MD5.F2EECF8977BD3FE4E38743DDCFBECD20] - [07/07/2017 18:11:52] - |A| - [55952] - C:\WINDOWS\system32\Drivers\PxHlpa64.sys[MD5.498C3D4D44382A96812A0E0FF28D575B] - [22/07/2017 16:59:55] - |A| - [40240] - C:\WINDOWS\system32\Drivers\revoflt.sys[MD5.2BD6F409FFE5C39A1A77E2EA8D50E7D9] - [06/07/2017 18:34:36] - |AC| - [13312] - C:\WINDOWS\system32\Drivers\rootmdm.sys[MD5.1AEF1D37188B06AB4C741CC145C2DC0D] - [07/07/2017 14:21:12] - |A| - [59664] - C:\WINDOWS\system32\Drivers\rsblk.sys[MD5.5FE70A943CA346C5E55622921BDF6608] - [22/07/2017 16:04:41] - |A| - [12921403] - C:\WINDOWS\system32\Drivers\RTAIODAT.DAT[MD5.0658C48A7837798B8DE3D97003EFCC37] - [22/07/2017 15:30:06] - |A| - [5863904] - C:\WINDOWS\system32\Drivers\RTKVHD64.sys[MD5.D599F03A32372FE422090F09B29113FB] - [21/07/2017 11:24:17] - |A| - [419296] - C:\WINDOWS\system32\Drivers\RtsUer.sys[MD5.27DB9153D259D632D15483DEEAB799ED] - [07/07/2017 19:23:59] - |A| - [27120] - C:\WINDOWS\system32\Drivers\Sahdad64.sys[MD5.F77849D909B90BCACFCF7295AECF299B] - [07/07/2017 19:23:59] - |A| - [19952] - C:\WINDOWS\system32\Drivers\Saibad64.sys[MD5.704D415290A568F68DE20942DAC23F7E] - [07/07/2017 19:23:59] - |A| - [27632] - C:\WINDOWS\system32\Drivers\SaibVdAd64.sys[MD5.C5F3F88633062AF176BC7DA68148A0D1] - [07/07/2017 10:51:52] - |A| - [82992] - C:\WINDOWS\system32\Drivers\sbtis.sys[MD5.71A494A502F24465317E88E80F6C0C2C] - [06/07/2017 18:33:44] - |AC| - [287648] - C:\WINDOWS\system32\Drivers\sdbus.sys[MD5.FEAE3B8E52E277CEA6C1F8E3E3DAE0F7] - [21/07/2017 11:14:56] - |A| - [104960] - C:\WINDOWS\system32\Drivers\SET7E5A.tmp[MD5.F6D108E43CB91BD59877A9FEC9DB41CC] - [11/07/2017 13:38:06] - |A| - [1474832] - C:\WINDOWS\system32\Drivers\sfi.dat[MD5.D2DDE8F0BD39F90E43146DB0B3B5DA57] - [22/07/2017 12:11:34] - |A| - [30744] - C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys[MD5.576A818562069B1E091CC719C143AED2] - [06/07/2017 18:34:41] - |A| - [144288] - C:\WINDOWS\system32\Drivers\storahci.sys[MD5.93BD9CD169610D96D6074DAFD11427A6] - [06/07/2017 18:34:34] - |AC| - [546208] - C:\WINDOWS\system32\Drivers\storport.sys[MD5.039CFEDBC0D1A751A1308228A72C1CCD] - [22/07/2017 15:14:31] - |A| - [54896] - C:\WINDOWS\system32\Drivers\tapwindscribe0901.sys[MD5.DC0D1B5284152315F81894DAABBB2AF3] - [11/07/2017 23:04:46] - |AC| - [2681760] - C:\WINDOWS\system32\Drivers\tcpip.sys[MD5.892AB2637603A5E9507C39E61101C3C3] - [06/07/2017 18:34:34] - |A| - [119712] - C:\WINDOWS\system32\Drivers\tdx.sys[MD5.B2D09296EAB388A1B978D05842045E78] - [06/07/2017 18:34:35] - |AC| - [130464] - C:\WINDOWS\system32\Drivers\tm.sys[MD5.F76A92975340DAA99939DA297D677EA8] - [06/07/2017 18:33:44] - |AC| - [219040] - C:\WINDOWS\system32\Drivers\tpm.sys[MD5.B9651548CE196186A72CE8C6D0C094FC] - [11/07/2017 23:05:37] - |AC| - [554392] - C:\WINDOWS\system32\Drivers\USBHUB3.SYS[MD5.0E12F5F6B1C813D17AFDA197C4394423] - [06/07/2017 18:33:44] - |AC| - [730016] - C:\WINDOWS\system32\Drivers\vhdmp.sys[MD5.923200B78F5284D674A3712204D0FEFA] - [11/07/2017 23:03:15] - |AC| - [142752] - C:\WINDOWS\system32\Drivers\wcifs.sys[MD5.BF45B43BA47D0FA769CE5AFBF7104F01] - [11/07/2017 23:01:47] - |AC| - [757248] - C:\WINDOWS\system32\Drivers\WdiWiFi.sys[MD5.B10655A4C2EFDC25483D670EF52A4854] - [06/07/2017 18:33:44] - |AC| - [277504] - C:\WINDOWS\system32\Drivers\xboxgip.sys[MD5.E6415F7F0197764DB9D532B094DFD008] - [11/07/2017 23:06:29] - |AC| - [1019904] - C:\WINDOWS\syswow64\aadtb.dll[MD5.74EF3FA4C87C388044C30D98AD26C96E] - [11/07/2017 23:05:28] - |AC| - [247808] - C:\WINDOWS\syswow64\AboveLockAppHost.dll[MD5.72039D49F5284BD2EAE4D2E0002AD8B0] - [11/07/2017 23:06:15] - |AC| - [356864] - C:\WINDOWS\syswow64\ActivationManager.dll[MD5.59E3A3D1578958C01377268CD16D67EE] - [11/07/2017 23:05:44] - |AC| - [1494016] - C:\WINDOWS\syswow64\ActiveSyncProvider.dll[MD5.6EFA7A7F5DFD7F8751D233CB3C8826AD] - [11/07/2017 23:05:41] - |AC| - [192416] - C:\WINDOWS\syswow64\aepic.dll[MD5.52FA328B467508456767727977CC0C58] - [11/07/2017 23:05:22] - |A| - [584192] - C:\WINDOWS\syswow64\apphelp.dll[MD5.7D2E1A8ED68F135CE47E55EC7C589B9C] - [11/07/2017 23:06:31] - |AC| - [181656] - C:\WINDOWS\syswow64\AppxAllUserStore.dll[MD5.63EC4603B827BE619868BCAB35DE9FD4] - [06/07/2017 18:36:54] - |AC| - [519680] - C:\WINDOWS\syswow64\AppXDeploymentClient.dll[MD5.46A7F2D27048E082F4DBAB23483A9D06] - [11/07/2017 23:05:35] - |AC| - [1178528] - C:\WINDOWS\syswow64\AppxPackaging.dll[MD5.EF743491BC5345B1E9F81C5C55896E73] - [06/07/2017 18:37:00] - |AC| - [311200] - C:\WINDOWS\syswow64\atmfd.dll[MD5.2FD5EBA34E4132641753A97B4BC8C36A] - [06/07/2017 18:37:00] - |AC| - [38912] - C:\WINDOWS\syswow64\atmlib.dll[MD5.94D17699907FE34B61E6E39A1FD1EFBB] - [11/07/2017 23:05:47] - |AC| - [1195240] - C:\WINDOWS\syswow64\AudioEng.dll[MD5.B3EB9F4445A4631C2713E40354AE34C3] - [11/07/2017 23:05:44] - |AC| - [864240] - C:\WINDOWS\syswow64\AudioSes.dll[MD5.F09AEC96F24D28F822ED065AA5A010F1] - [11/07/2017 23:06:18] - |AC| - [1248768] - C:\WINDOWS\syswow64\AzureSettingSyncProvider.dll[MD5.DCC9FADC51B2A2DE1852CA3A2025E708] - [11/07/2017 23:05:46] - |AC| - [176032] - C:\WINDOWS\syswow64\basecsp.dll[MD5.8B875F6B44FC30D7EB951D5E6D78F0E0] - [11/07/2017 23:05:18] - |AC| - [734208] - C:\WINDOWS\syswow64\bcastdvr.exe[MD5.47D7894748CEEF6FE6F47269609B44EA] - [11/07/2017 23:06:00] - |AC| - [5719040] - C:\WINDOWS\syswow64\BingMaps.dll[MD5.A09C010DC4E7872BE72DE7975E507865] - [11/07/2017 23:05:34] - |AC| - [139776] - C:\WINDOWS\syswow64\BluetoothApis.dll[MD5.52FED9C596B0D957E1CB78BFFFA63E6B] - [06/07/2017 18:36:53] - |AC| - [266640] - C:\WINDOWS\syswow64\capauthz.dll[MD5.F24FC02D1D7E58DFA64B564156946850] - [11/07/2017 23:05:17] - |AC| - [641024] - C:\WINDOWS\syswow64\certca.dll[MD5.B24483A41EBDE6EDF20744DFD6B30FBF] - [11/07/2017 23:05:17] - |AC| - [342016] - C:\WINDOWS\syswow64\certcli.dll[MD5.84563ECBBCDA7609076524C00B3E6981] - [11/07/2017 23:05:48] - |AC| - [2750464] - C:\WINDOWS\syswow64\CertEnroll.dll[MD5.A062E82C94AA16954A73A59894DD1585] - [11/07/2017 23:05:24] - |AC| - [1171968] - C:\WINDOWS\syswow64\certutil.exe[MD5.A788F4DE343BF35B82B97D5340F63F40] - [11/07/2017 23:04:08] - |AC| - [6287360] - C:\WINDOWS\syswow64\Chakra.dll[MD5.5B5E5ECA05B6AB392BE8D7C0B2387746] - [11/07/2017 23:05:46] - |AC| - [50176] - C:\WINDOWS\syswow64\cldapi.dll[MD5.29D42248165D51432B98D44E4A3E228D] - [11/07/2017 23:05:27] - |AC| - [173568] - C:\WINDOWS\syswow64\ClipboardServer.dll[MD5.1A825938C178D6A1E89EBF8A33A229CA] - [11/07/2017 23:05:38] - |AC| - [123520] - C:\WINDOWS\syswow64\Clipc.dll[MD5.75048334A9613F100CDBA828B915427E] - [11/07/2017 23:05:33] - |AC| - [346016] - C:\WINDOWS\syswow64\CloudExperienceHostCommon.dll[MD5.160248BDDBF3DEEA538605C18B318350] - [11/07/2017 23:05:34] - |AC| - [138656] - C:\WINDOWS\syswow64\CloudExperienceHostUser.dll[MD5.00000000000000000000000000000000] - [07/07/2017 14:17:14] - |D| - [807423] - C:\WINDOWS\syswow64\Codecs[MD5.4E32BB47881128693BA7F46BBA79F7EF] - [11/07/2017 23:06:19] - |A| - [2330520] - C:\WINDOWS\syswow64\combase.dll[MD5.E790D9106A825607A736F8D138A3E2FD] - [06/07/2017 18:37:18] - |A| - [573856] - C:\WINDOWS\syswow64\comctl32.dll[MD5.BAA45E4A89758701925D57160171B6CF] - [11/07/2017 23:06:10] - |A| - [952832] - C:\WINDOWS\syswow64\comdlg32.dll[MD5.C68B06D7059D247F36A3EF242416AAE7] - [11/07/2017 23:06:20] - |A| - [583160] - C:\WINDOWS\syswow64\CoreMessaging.dll[MD5.5BC09E938D496A0235A6E7A9694263DF] - [11/07/2017 23:06:13] - |A| - [2259760] - C:\WINDOWS\syswow64\CoreUIComponents.dll[MD5.5ADE1AB65CC83770C76F99569FD8A402] - [11/07/2017 23:05:21] - |AC| - [201216] - C:\WINDOWS\syswow64\credprovhost.dll[MD5.D0C13CE23A24875587E70E99C184FFBC] - [11/07/2017 23:06:27] - |AC| - [5225984] - C:\WINDOWS\syswow64\d2d1.dll[MD5.39F1CFF1AB0304AEBB3CFB580ACEDBF5] - [11/07/2017 23:05:27] - |AC| - [430080] - C:\WINDOWS\syswow64\d2d1debug3.dll[MD5.6B981D1D8BA7B6EF7944B0D499043ED3] - [11/07/2017 23:05:32] - |AC| - [2475136] - C:\WINDOWS\syswow64\d3d10warp.dll[MD5.5F1B7068B05A5A603EEFBC45AC89E49C] - [11/07/2017 23:05:22] - |AC| - [5141504] - C:\WINDOWS\syswow64\d3d12warp.dll[MD5.FAE7E1D578C42A7C3D9D61A99D178BD5] - [07/07/2017 11:54:38] - |A| - [1123696] - C:\WINDOWS\syswow64\D3DCompiler_33.dll[MD5.75F206C195BBACA6EF28565B1C0CD75C] - [07/07/2017 11:56:28] - |A| - [1124720] - C:\WINDOWS\syswow64\D3DCompiler_34.dll[MD5.5B441670A4F5F8BCCE76741902B8AF56] - [07/07/2017 11:58:03] - |A| - [1358192] - C:\WINDOWS\syswow64\D3DCompiler_35.dll[MD5.FB4299688A0D3A37687C015AC2B9922D] - [07/07/2017 11:59:27] - |A| - [1374232] - C:\WINDOWS\syswow64\D3DCompiler_36.dll[MD5.EA752DBCE35045D3C830DC16578CC8AB] - [07/07/2017 12:01:34] - |A| - [1420824] - C:\WINDOWS\syswow64\D3DCompiler_37.dll[MD5.103CBFC5591008AD33046E20E8E1EEBE] - [07/07/2017 12:04:28] - |A| - [1491992] - C:\WINDOWS\syswow64\D3DCompiler_38.dll[MD5.C4F1972497FE2CEB7D900938C97FCF91] - [22/07/2017 07:15:55] - |A| - [1493528] - C:\WINDOWS\syswow64\D3DCompiler_39.dll[MD5.3384134EEB8F223178C2EB8323003EC0] - [07/07/2017 12:09:30] - |A| - [2036576] - C:\WINDOWS\syswow64\D3DCompiler_40.dll[MD5.781E8B5B6FDB3C9B4E4A4A9FB019960D] - [07/07/2017 12:11:58] - |A| - [1846632] - C:\WINDOWS\syswow64\D3DCompiler_41.dll[MD5.B33B21DB610116262D906305CE65C354] - [07/07/2017 12:13:58] - |A| - [1974616] - C:\WINDOWS\syswow64\D3DCompiler_42.dll[MD5.1C9B45E87528B8BB8CFA884EA0099A85] - [10/07/2017 21:37:15] - |A| - [2106216] - C:\WINDOWS\syswow64\D3DCompiler_43.dll[MD5.A8085B2ABF94FF9EDF8DF99472A010CD] - [11/07/2017 23:06:39] - |AC| - [3667456] - C:\WINDOWS\syswow64\D3DCompiler_47.dll[MD5.B337306DFB508A1BCEF1974BFBB8D924] - [07/07/2017 12:13:25] - |A| - [5501792] - C:\WINDOWS\syswow64\d3dcsx_42.dll[MD5.83EBA442F07AAB8D6375D2EEC945C46C] - [10/07/2017 21:37:24] - |A| - [1868128] - C:\WINDOWS\syswow64\d3dcsx_43.dll[MD5.6F34F7405807DCBF0B9BF6811C94C6D9] - [07/07/2017 11:52:58] - |A| - [440080] - C:\WINDOWS\syswow64\d3dx10.dll[MD5.37A8171ACCF46A9C196054066C28827F] - [07/07/2017 11:54:39] - |A| - [443752] - C:\WINDOWS\syswow64\d3dx10_33.dll[MD5.5AA9987F2E62B56D7661B6901901F927] - [07/07/2017 11:56:30] - |A| - [443752] - C:\WINDOWS\syswow64\d3dx10_34.dll[MD5.F3764552E45880DC49B82F38699AA87C] - [07/07/2017 11:58:04] - |A| - [444776] - C:\WINDOWS\syswow64\d3dx10_35.dll[MD5.D9158E78A368B08D9133043EB3058C12] - [07/07/2017 11:59:29] - |A| - [444776] - C:\WINDOWS\syswow64\d3dx10_36.dll[MD5.4A43E9A2B17E4CAFA9CB5FEC0B5B686B] - [07/07/2017 12:01:33] - |A| - [462864] - C:\WINDOWS\syswow64\d3dx10_37.dll[MD5.A2650B27472C21CDD817EEEDE65648E1] - [07/07/2017 12:04:28] - |A| - [467984] - C:\WINDOWS\syswow64\d3dx10_38.dll[MD5.E6C2F1D8B667DDC04CB55B9F0159EF97] - [22/07/2017 07:15:55] - |A| - [467984] - C:\WINDOWS\syswow64\d3dx10_39.dll[MD5.91B4AAD4412BB223B466F3DFB43E86DA] - [07/07/2017 12:09:29] - |A| - [452440] - C:\WINDOWS\syswow64\d3dx10_40.dll[MD5.1AA571774936717EE776DBED51E9EDF4] - [07/07/2017 12:11:57] - |A| - [453456] - C:\WINDOWS\syswow64\d3dx10_41.dll[MD5.501AC862517C5445742BEE8A2B88414E] - [07/07/2017 12:12:51] - |A| - [453456] - C:\WINDOWS\syswow64\d3dx10_42.dll[MD5.20C835843FCEC4DEDFCD7BFFA3B91641] - [10/07/2017 21:37:56] - |A| - [470880] - C:\WINDOWS\syswow64\d3dx10_43.dll[MD5.D09AC80A4B5312239852836C84DF3392] - [07/07/2017 12:13:06] - |A| - [235344] - C:\WINDOWS\syswow64\d3dx11_42.dll[MD5.8E0BB968FF41D80E5F2C747C04DB79AE] - [10/07/2017 21:38:10] - |A| - [248672] - C:\WINDOWS\syswow64\d3dx11_43.dll[MD5.9851F89665C9B2F7FCB7DB07CAE7CF9A] - [21/07/2017 10:56:07] - |A| - [276800] - C:\WINDOWS\syswow64\D3DX8Wrapper.dll[MD5.BC831661963763AC4D504C5CABB1FDD9] - [07/07/2017 11:31:34] - |A| - [2222800] - C:\WINDOWS\syswow64\d3dx9_24.dll[MD5.5B48FE9D6686F0D54B26A005ACE24D1D] - [07/07/2017 11:32:54] - |A| - [2337488] - C:\WINDOWS\syswow64\d3dx9_25.dll[MD5.523AB607EEF81CC4D909E7FEBD8A788E] - [07/07/2017 11:34:02] - |A| - [2297552] - C:\WINDOWS\syswow64\d3dx9_26.dll[MD5.852EDC778A7A50077694F84D8E601234] - [07/07/2017 11:35:21] - |A| - [2319568] - C:\WINDOWS\syswow64\d3dx9_27.dll[MD5.BE19B603DFBAA829EE5B7749B3BA97DB] - [07/07/2017 11:36:25] - |A| - [2323664] - C:\WINDOWS\syswow64\d3dx9_28.dll[MD5.99F4FC172A5ACE36CF00AA7038D23F2C] - [07/07/2017 11:38:08] - |A| - [2332368] - C:\WINDOWS\syswow64\d3dx9_29.dll[MD5.E415862612E65F10D7D888443ECD7594] - [07/07/2017 11:42:57] - |A| - [2388176] - C:\WINDOWS\syswow64\d3dx9_30.dll[MD5.797E24743937D67D69F28F2CF5052EE8] - [07/07/2017 11:50:40] - |A| - [2414360] - C:\WINDOWS\syswow64\d3dx9_31.dll[MD5.26AF232140C88B42D92A88F2198EDF6A] - [07/07/2017 11:52:41] - |A| - [3426072] - C:\WINDOWS\syswow64\d3dx9_32.dll[MD5.CDB1CD22BAFF21F48606B3C1A18B000B] - [07/07/2017 11:54:12] - |A| - [3495784] - C:\WINDOWS\syswow64\d3dx9_33.dll[MD5.1CA939918ED1B930059B3A882DE6F648] - [07/07/2017 11:56:03] - |A| - [3497832] - C:\WINDOWS\syswow64\d3dx9_34.dll[MD5.3EF18B78D17C962F2B71AC1CB7757684] - [07/07/2017 11:57:42] - |A| - [3727720] - C:\WINDOWS\syswow64\d3dx9_35.dll[MD5.44BFEC5C9C82A2EE9871D88FD3B9A0E2] - [07/07/2017 11:59:05] - |A| - [3734536] - C:\WINDOWS\syswow64\d3dx9_36.dll[MD5.AC3C517FB0FBBE45FE44007BCD3625A7] - [07/07/2017 12:00:49] - |A| - [3786760] - C:\WINDOWS\syswow64\D3DX9_37.dll[MD5.8F3EB548AC4ED90252394F60C77E3196] - [07/07/2017 12:04:06] - |A| - [3850760] - C:\WINDOWS\syswow64\D3DX9_38.dll[MD5.8CB3DEFB8887C4F0846DB1FC1304D6D2] - [22/07/2017 07:15:47] - |A| - [3851784] - C:\WINDOWS\syswow64\D3DX9_39.dll[MD5.EEA5E428CE63804F9B12D21C97B5968F] - [07/07/2017 12:09:09] - |A| - [4379984] - C:\WINDOWS\syswow64\D3DX9_40.dll[MD5.3FA06CF5079B84155D18B05C08F7131B] - [07/07/2017 12:11:21] - |A| - [4178264] - C:\WINDOWS\syswow64\D3DX9_41.dll[MD5.C6A44FC3CF2F5801561804272217B14D] - [07/07/2017 12:12:28] - |A| - [1892184] - C:\WINDOWS\syswow64\D3DX9_42.dll[MD5.86E39E9161C3D930D93822F1563C280D] - [10/07/2017 21:37:42] - |A| - [1998168] - C:\WINDOWS\syswow64\D3DX9_43.dll[MD5.848BF7577E0EC99DE1F79BD692EE9DDA] - [07/07/2017 14:10:15] - |A| - [234496] - C:\WINDOWS\syswow64\DartCertificate.dll[MD5.889C4A742EA54F1524C9016AFA5DA433] - [07/07/2017 14:10:15] - |A| - [386560] - C:\WINDOWS\syswow64\DartSecure2.dll[MD5.DA2C86B559173699976273924590850C] - [07/07/2017 14:10:15] - |A| - [425472] - C:\WINDOWS\syswow64\DartSock.dll[MD5.B5BD7518F010B253F45AC2FE005A5256] - [11/07/2017 23:05:42] - |AC| - [52224] - C:\WINDOWS\syswow64\dataclen.dll[MD5.9E7BCF3A44CE58816A54E3E320812110] - [11/07/2017 23:06:39] - |AC| - [365056] - C:\WINDOWS\syswow64\daxexec.dll[MD5.F160F1498936CCD7AB2F612AF4B0D850] - [11/07/2017 23:06:21] - |AC| - [4559360] - C:\WINDOWS\syswow64\dbgeng.dll[MD5.E3B34F7C3B9382AF4C09F819C94C107E] - [11/07/2017 23:06:34] - |A| - [1285120] - C:\WINDOWS\syswow64\dbghelp.dll[MD5.3EDEA696F47A5706D2BD2FA15DF6976E] - [11/07/2017 23:05:36] - |A| - [949920] - C:\WINDOWS\syswow64\dcomp.dll[MD5.FB8901C725A53EC6B8BDCDC7DA738786] - [06/07/2017 18:36:59] - |AC| - [1984000] - C:\WINDOWS\syswow64\DeviceFlows.DataModel.dll[MD5.DD98DC9458A7573FFE6C40C0445E431A] - [06/07/2017 18:37:11] - |AC| - [169984] - C:\WINDOWS\syswow64\devicengccredprov.dll[MD5.D6CD215CAC496FADF2D5074447A65928] - [11/07/2017 23:05:21] - |AC| - [502784] - C:\WINDOWS\syswow64\DevicePairing.dll[MD5.F60D62E2500AA824073147E18CFA6381] - [06/07/2017 18:36:53] - |AC| - [394240] - C:\WINDOWS\syswow64\DictationManager.dll[MD5.0902754B4F3041FD31673CB63B34012D] - [21/07/2017 17:18:00] - |A| - [232] - C:\WINDOWS\syswow64\dllhost.exe.config[MD5.59D4F6530A62E034376A2CF7B55D39F7] - [11/07/2017 23:05:37] - |AC| - [96128] - C:\WINDOWS\syswow64\dmcmnutils.dll[MD5.9FB080566C3A4FB15CE48ADD38CC70DC] - [10/07/2017 20:53:26] - |A| - [40448] - C:\WINDOWS\syswow64\dsofile.dll[MD5.C5F4DF45D3FDB92AFFA04A477E18EC5A] - [11/07/2017 23:05:30] - |A| - [125344] - C:\WINDOWS\syswow64\dwmapi.dll[MD5.B69BE4956A766D0CD0204DD63D2939F4] - [11/07/2017 23:06:28] - |AC| - [2298368] - C:\WINDOWS\syswow64\dwmcore.dll[MD5.B380662D9AFA360372A49C6002FC4777] - [06/07/2017 18:36:59] - |A| - [2341376] - C:\WINDOWS\syswow64\DWrite.dll[MD5.C9F57A11B349677F83649B550164AB1A] - [11/07/2017 23:04:06] - |AC| - [266240] - C:\WINDOWS\syswow64\dxtrans.dll[MD5.5ED309B79B131F57021AD7685AF29650] - [11/07/2017 23:05:16] - |AC| - [25088] - C:\WINDOWS\syswow64\eapprovp.dll[MD5.623A8CB497DF298E78091B6D48BA046A] - [21/07/2017 10:56:07] - |A| - [229184] - C:\WINDOWS\syswow64\EasyHook32.dll[MD5.D7FC64BABF8A9C643FDEBAA2A9028C19] - [11/07/2017 23:04:22] - |AC| - [20504576] - C:\WINDOWS\syswow64\edgehtml.dll[MD5.5F5B1647F3CC39ABB330FFAF9FFF50FC] - [11/07/2017 23:05:17] - |A| - [230912] - C:\WINDOWS\syswow64\edputil.dll[MD5.FC1145751AC6E4FF1656381BB09A5AA3] - [11/07/2017 23:06:08] - |AC| - [4469840] - C:\WINDOWS\syswow64\explorer.exe[MD5.FB4DDF2F088843529F9B726B82BB57CA] - [11/07/2017 23:05:57] - |AC| - [4417024] - C:\WINDOWS\syswow64\ExplorerFrame.dll[MD5.5C8874EE321F4623FFF7A1315039DDBC] - [11/07/2017 08:00:52] - |A| - [77824] - C:\WINDOWS\syswow64\fmcodec.DLL[MD5.BC88A1B76FD974696F88927FC7E0B369] - [11/07/2017 23:06:35] - |AC| - [626528] - C:\WINDOWS\syswow64\fontdrvhost.exe[MD5.308B4F7EA6616AD6EB8FEE8FAD8D8A17] - [11/07/2017 23:05:33] - |A| - [129184] - C:\WINDOWS\syswow64\gdi32.dll[MD5.5604CE7CE68CE66876360E3772C9FF13] - [06/07/2017 18:37:00] - |A| - [1409048] - C:\WINDOWS\syswow64\gdi32full.dll[MD5.C4210139FA34AD3D515DBF35FC3B610B] - [11/07/2017 23:05:25] - |A| - [1448960] - C:\WINDOWS\syswow64\GdiPlus.dll[MD5.D99EBDF9F6BB60084491656BA6A390B9] - [11/07/2017 23:04:23] - |AC| - [338432] - C:\WINDOWS\syswow64\iedkcs32.dll[MD5.2515055E7597213342660C576F276A06] - [11/07/2017 23:03:58] - |AC| - [11870720] - C:\WINDOWS\syswow64\ieframe.dll[MD5.82C0CD963AA63B679FB5C2E24B462AD2] - [11/07/2017 23:04:15] - |AC| - [124928] - C:\WINDOWS\syswow64\iepeers.dll[MD5.5563E85D9550212EC021AAD4074C5EB6] - [06/07/2017 18:37:18] - |AC| - [358400] - C:\WINDOWS\syswow64\ieproxy.dll[MD5.04C4AEF850010EDB1CDEB9D0210786F4] - [11/07/2017 23:06:30] - |A| - [2165752] - C:\WINDOWS\syswow64\iertutil.dll[MD5.D526CEB1C13F512D73831CEB3A9CE2C0] - [11/07/2017 23:04:12] - |AC| - [2008576] - C:\WINDOWS\syswow64\inetcpl.cpl[MD5.86B4907B3ACFDABF5C9967208FECA409] - [11/07/2017 23:06:14] - |AC| - [2211328] - C:\WINDOWS\syswow64\InputService.dll[MD5.EA5CFA823838AD595883DCE7741692E4] - [11/07/2017 23:06:34] - |AC| - [329728] - C:\WINDOWS\syswow64\InstallAgent.exe[MD5.C6814D342680E7FCD2C5DEE188DB33ED] - [11/07/2017 23:06:38] - |AC| - [368128] - C:\WINDOWS\syswow64\InstallAgentUserBroker.exe[MD5.260A7E98E23B77C9C64AB37AC8868AB1] - [11/07/2017 11:02:04] - |A| - [205536] - C:\WINDOWS\syswow64\iseguard32.dll[MD5.26EABBAC403B690886CBCE63AE5C371D] - [11/07/2017 23:04:17] - |AC| - [3656704] - C:\WINDOWS\syswow64\jscript9.dll[MD5.643571B6D1A42BEF99F4E6E57A6B9660] - [11/07/2017 23:05:46] - |AC| - [754176] - C:\WINDOWS\syswow64\kerberos.dll[MD5.1642AB5F2291157C96016FADD53EB019] - [11/07/2017 23:06:18] - |A| - [1839872] - C:\WINDOWS\syswow64\KernelBase.dll[MD5.5E1D001F58CBC2BF0A31A14528081FC5] - [11/07/2017 23:06:04] - |AC| - [754592] - C:\WINDOWS\syswow64\LicenseManager.dll[MD5.F3AB3B25CADE06BF90E1055C13EF195F] - [06/07/2017 18:37:05] - |AC| - [2088960] - C:\WINDOWS\syswow64\MapGeocoder.dll[MD5.89F423C0E4BB8098BF3741A5A8CF5ABE] - [11/07/2017 23:05:56] - |AC| - [2588160] - C:\WINDOWS\syswow64\MapRouter.dll[MD5.FCBA13336C85A299EF4D296F36ADA266] - [11/07/2017 23:05:40] - |AC| - [646656] - C:\WINDOWS\syswow64\MbaeApi.dll[MD5.D018CB133EF508FA05EAD89FC1DDB2D4] - [06/07/2017 18:36:54] - |AC| - [754176] - C:\WINDOWS\syswow64\MessagingDataModel2.dll[MD5.4F4CEDC6D26023D2619EFCDFCC9410FD] - [11/07/2017 23:05:39] - |AC| - [443728] - C:\WINDOWS\syswow64\MFCaptureEngine.dll[MD5.EECE5E1EF2DF99ADABDDBBB4B2BBD873] - [06/07/2017 18:37:05] - |AC| - [4672848] - C:\WINDOWS\syswow64\mfcore.dll[MD5.A95E33AD35E9ACAAFC2117CAECBE1D8C] - [11/07/2017 23:06:33] - |AC| - [4056576] - C:\WINDOWS\syswow64\MFMediaEngine.dll[MD5.185A14B98C9BDEE8A25FEE6655E0F21E] - [06/07/2017 18:37:05] - |AC| - [2424016] - C:\WINDOWS\syswow64\mfmp4srcsnk.dll[MD5.E1D65E7239D8944F6334EE46F714A37E] - [06/07/2017 18:37:05] - |AC| - [1455592] - C:\WINDOWS\syswow64\mfplat.dll[MD5.F41476B5AF2E1715AAE75A287E7B338F] - [11/07/2017 23:06:38] - |AC| - [1121928] - C:\WINDOWS\syswow64\mfsvr.dll[MD5.00000000000000000000000000000000] - [11/07/2017 11:32:13] - |SD| - [0] - C:\WINDOWS\syswow64\Microsoft[MD5.BCBC7EEEE7E9E20972F62613FF79CA77] - [11/07/2017 23:05:29] - |AC| - [132096] - C:\WINDOWS\syswow64\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll[MD5.1B03FDA61DAC7D2ADD6FFF33B6ED21E6] - [11/07/2017 23:05:52] - |AC| - [354400] - C:\WINDOWS\syswow64\MMDevAPI.dll[MD5.655873ECBA1C77581D6B410272AC7CFA] - [11/07/2017 23:05:20] - |AC| - [646144] - C:\WINDOWS\syswow64\mmsys.cpl[MD5.F6530CF930697C6A7B25F85F9D0BE358] - [11/07/2017 23:05:42] - |AC| - [6123520] - C:\WINDOWS\syswow64\mos.dll[MD5.4749D39D6E1B09C8FF44B390F0D59097] - [11/07/2017 23:05:33] - |A| - [49656] - C:\WINDOWS\syswow64\msasn1.dll[MD5.E76737145FD4AFDFDE6B67B94A7850DF] - [11/07/2017 23:05:51] - |AC| - [455104] - C:\WINDOWS\syswow64\MSAudDecMFT.dll[MD5.C9266DD7955FE56CA7316B0CDFB659C9] - [06/07/2017 18:37:18] - |A| - [1333136] - C:\WINDOWS\syswow64\msctf.dll[MD5.EFD4D99EA40F7BD8DD5235D8E5BD5DBB] - [11/07/2017 23:05:26] - |AC| - [899072] - C:\WINDOWS\syswow64\msctfuimanager.dll[MD5.2AACD12BAEE1736D3496B70BF20AF40B] - [11/07/2017 23:04:24] - |AC| - [663040] - C:\WINDOWS\syswow64\msfeeds.dll[MD5.7367FBBCD782B6EF5D403E1BDB0E1F8F] - [11/07/2017 23:05:44] - |AC| - [2782720] - C:\WINDOWS\syswow64\msftedit.dll[MD5.8386DAB864FA758C30783B1119EBA67F] - [11/07/2017 23:04:11] - |AC| - [19335168] - C:\WINDOWS\syswow64\mshtml.dll[MD5.5D00C40C75DDB4D89F3FA75C1DBEA72C] - [11/07/2017 23:03:26] - |AC| - [64000] - C:\WINDOWS\syswow64\MshtmlDac.dll[MD5.C166E704CD9BF17C3D7A4A4999A642DD] - [11/07/2017 23:04:23] - |AC| - [80384] - C:\WINDOWS\syswow64\mshtmled.dll[MD5.F64A0C0294C2855F530E6F697BF90054] - [11/07/2017 23:05:32] - |AC| - [338432] - C:\WINDOWS\syswow64\msinfo32.exe[MD5.E493EF0DED31A57E9A20D6E4E9FF60C1] - [06/07/2017 18:37:05] - |AC| - [6535168] - C:\WINDOWS\syswow64\mspaint.exe[MD5.C9A30D05688D4EE7C80F270EEAE38CDB] - [11/07/2017 23:06:36] - |AC| - [2132480] - C:\WINDOWS\syswow64\mssrch.dll[MD5.92B712DF390367BFA4252A48D9D71D51] - [10/07/2017 20:53:23] - |A| - [118784] - C:\WINDOWS\syswow64\MSSTDFMT.DLL[MD5.F454B426C7BF70F6B568353AFC35EC4D] - [11/07/2017 23:05:50] - |AC| - [7596544] - C:\WINDOWS\syswow64\mstscax.dll[MD5.D530C4D0BEF7EAB0E3C15A32E74B2024] - [11/07/2017 23:05:53] - |AC| - [349600] - C:\WINDOWS\syswow64\msv1_0.dll[MD5.3DBD274B5BB0AB26601861CD8A25E233] - [06/07/2017 18:37:06] - |AC| - [1292288] - C:\WINDOWS\syswow64\MSVPXENC.dll[MD5.1367E7BA83C671D0886EDB821CB7AC1B] - [11/07/2017 23:05:41] - |AC| - [1565184] - C:\WINDOWS\syswow64\msxml3.dll[MD5.1D24FF1C3191D89E4F971E170CC360C3] - [05/07/2017 17:35:40] - |A| - [1328968] - C:\WINDOWS\syswow64\msxml4.dll[MD5.00000000000000000000000000000000] - [08/07/2017 14:36:23] - |D| - [658752] - C:\WINDOWS\syswow64\Npcap[MD5.EBF4D15189F5CE071D3F3B1C400F0982] - [06/07/2017 18:37:06] - |AC| - [128000] - C:\WINDOWS\syswow64\NPSM.dll[MD5.ABD6194288A36B25E33D167C2CD4D262] - [06/07/2017 18:37:06] - |AC| - [826368] - C:\WINDOWS\syswow64\NPSMDesktopProvider.dll[MD5.3F403A66F986EC2C7E3821F3F2BC2336] - [11/07/2017 23:03:01] - |A| - [1620368] - C:\WINDOWS\syswow64\ntdll.dll[MD5.50B0B2122AAABD76A64CDD52AFFF83C8] - [22/07/2017 15:34:37] - |A| - [4160] - C:\WINDOWS\syswow64\ocsvc.ini[MD5.26C812B50D31694461513EF308D30222] - [22/07/2017 15:34:38] - |A| - [12560] - C:\WINDOWS\syswow64\ocsvcOff.ini[MD5.0A0498D4BFC7AE6F1CE716F9BDEA4577] - [06/07/2017 18:37:04] - |AC| - [25088] - C:\WINDOWS\syswow64\odbcconf.dll[MD5.3F8EB3DA29236AEBD5CC574EFC3B5BE4] - [11/07/2017 23:06:32] - |A| - [988168] - C:\WINDOWS\syswow64\ole32.dll[MD5.5189623CC57A23A0F2C528359C175E22] - [11/07/2017 23:05:19] - |A| - [331776] - C:\WINDOWS\syswow64\oleacc.dll[MD5.A6C1630C415570B07ACAC44DF5E21B6C] - [06/07/2017 18:37:08] - |A| - [606960] - C:\WINDOWS\syswow64\oleaut32.dll[MD5.6C8C15DD22F39A0C4823DF4FF9F5F24E] - [11/07/2017 23:06:37] - |A| - [89088] - C:\WINDOWS\syswow64\olepro32.dll[MD5.811DEBAE09ECD713E35D5856178E6189] - [06/07/2017 18:37:12] - |AC| - [476672] - C:\WINDOWS\syswow64\OneDriveSettingSyncProvider.dll[MD5.E82AEB861B09251BC49B17956CDB561C] - [11/07/2017 23:05:48] - |AC| - [1355264] - C:\WINDOWS\syswow64\OpcServices.dll[MD5.235355A8DD26903E75D5E812ECF50E53] - [09/07/2017 09:01:45] - |A| - [109080] - C:\WINDOWS\syswow64\OpenAL32.dll[MD5.01360A560CA9073E23DAD25CE40B7986] - [11/07/2017 23:03:29] - |AC| - [508416] - C:\WINDOWS\syswow64\PhotoScreensaver.scr[MD5.A04ABE1D8976832869EB8E87404A0CA2] - [11/07/2017 23:05:23] - |AC| - [334848] - C:\WINDOWS\syswow64\PlayToDevice.dll[MD5.DF280E03AC86920A9E22DF16DBF95470] - [11/07/2017 23:05:40] - |A| - [406032] - C:\WINDOWS\syswow64\policymanager.dll[MD5.614E27D395238FF60B21CB2286F5032E] - [11/07/2017 23:05:29] - |AC| - [760832] - C:\WINDOWS\syswow64\rasapi32.dll[MD5.BA26CBCE3791E15CE2A74FA402EA898D] - [11/07/2017 23:05:16] - |AC| - [117248] - C:\WINDOWS\syswow64\raschap.dll[MD5.3B78C389290252F413B0FA432C44910D] - [11/07/2017 23:05:17] - |AC| - [446464] - C:\WINDOWS\syswow64\rastls.dll[MD5.07F0F4537C0CF18599813CA0100BC898] - [11/07/2017 23:05:20] - |AC| - [157696] - C:\WINDOWS\syswow64\rpchttp.dll[MD5.56D22A73BE231B5ACBAEA91517F60AEC] - [11/07/2017 23:05:38] - |A| - [787712] - C:\WINDOWS\syswow64\rpcrt4.dll[MD5.6B818AB7505D81F689567C7C552FA9EA] - [21/07/2017 11:24:14] - |A| - [9891328] - C:\WINDOWS\syswow64\RsCRIcon.dll[MD5.160503CA8FE65326FD7E9B5A6F1A9409] - [06/07/2017 18:37:18] - |AC| - [174080] - C:\WINDOWS\syswow64\RstrtMgr.dll[MD5.362953DCB3EEBD41DC91F24746DC08CC] - [11/07/2017 23:05:45] - |AC| - [226304] - C:\WINDOWS\syswow64\scksp.dll[MD5.00000000000000000000000000000000] - [21/07/2017 11:15:42] - |D| - [134144] - C:\WINDOWS\syswow64\sda[MD5.FD74BADBCF30F3F6C9D6E3D6B3E42FA5] - [06/07/2017 18:37:33] - |AC| - [797184] - C:\WINDOWS\syswow64\SearchIndexer.exe[MD5.4F6E66C0C43361B1AFE003247816CDDF] - [11/07/2017 23:05:27] - |AC| - [312320] - C:\WINDOWS\syswow64\SearchProtocolHost.exe[MD5.27256FF0D70FA8EDB2F35B94AFAC8687] - [11/07/2017 23:05:26] - |AC| - [121856] - C:\WINDOWS\syswow64\sendmail.dll[MD5.E6E69C6E6CB1BCC3C7794B0F24C06583] - [11/07/2017 23:05:37] - |AC| - [329216] - C:\WINDOWS\syswow64\SensorsApi.dll[MD5.99216B5A39866090E259A42AD06CA80F] - [06/07/2017 18:37:12] - |AC| - [909312] - C:\WINDOWS\syswow64\SettingSyncCore.dll[MD5.ABC895B0C536B38A0D439AD05C61ADB8] - [06/07/2017 18:36:53] - |AC| - [1035264] - C:\WINDOWS\syswow64\ShareHost.dll[MD5.6336C8238F91ED0686155C0A7103BDDB] - [11/07/2017 23:06:06] - |A| - [20373408] - C:\WINDOWS\syswow64\shell32.dll[MD5.C2311AB2B2D4C26CA342992E6E3FB4C7] - [11/07/2017 23:05:24] - |AC| - [648192] - C:\WINDOWS\syswow64\SmartcardCredentialProvider.dll[MD5.554015FE4CD38DBBE116F932644017CE] - [06/07/2017 18:37:13] - |AC| - [141824] - C:\WINDOWS\syswow64\smartscreenps.dll[MD5.E9EA23A8EF9706F5938C6E1D60F988B7] - [11/07/2017 23:05:34] - |AC| - [601088] - C:\WINDOWS\syswow64\SndVolSSO.dll[MD5.192ADDDAC48E1503FAAB03D1432127C2] - [11/07/2017 23:06:37] - |AC| - [2679296] - C:\WINDOWS\syswow64\SRH.dll[MD5.31893402832A67F3E9BC3188B3003DF1] - [06/07/2017 18:37:14] - |AC| - [807424] - C:\WINDOWS\syswow64\StoreAgent.dll[MD5.BF9E024536D88BCDD4E3D137806FB3A9] - [11/07/2017 23:05:23] - |AC| - [2814464] - C:\WINDOWS\syswow64\themeui.dll[MD5.BAD403C3E42A0875807A2E6290C28BF5] - [11/07/2017 23:05:32] - |A| - [278944] - C:\WINDOWS\syswow64\thumbcache.dll[MD5.20C02552679B38FE8EB3A55D47DAB767] - [11/07/2017 23:05:30] - |AC| - [38400] - C:\WINDOWS\syswow64\TokenBrokerUI.dll[MD5.EDAB8316B3206BCEC3E4625DB25B2323] - [06/07/2017 18:37:13] - |AC| - [467456] - C:\WINDOWS\syswow64\TpmCoreProvisioning.dll[MD5.B051F36E5B8FE600956B6B2B459266B3] - [11/07/2017 23:06:25] - |A| - [2671616] - C:\WINDOWS\syswow64\tquery.dll[MD5.74B6A4D3810C53B94E6796EACB6B5E1D] - [06/07/2017 18:37:13] - |A| - [1266544] - C:\WINDOWS\syswow64\twinapi.appcore.dll[MD5.AFCF97E17DD526DB62013712B17EC59B] - [06/07/2017 18:37:13] - |AC| - [899584] - C:\WINDOWS\syswow64\twinui.appcore.dll[MD5.0C653981B5CAD5512A8BF183C9E66A2C] - [11/07/2017 23:06:11] - |AC| - [6728192] - C:\WINDOWS\syswow64\twinui.dll[MD5.7E70A500A9C009A6675BD0C7C0DF96A0] - [06/07/2017 18:37:00] - |AC| - [2560] - C:\WINDOWS\syswow64\tzres.dll[MD5.F38A810176E47A60A6AA128F96CD2B48] - [11/07/2017 23:03:07] - |A| - [1150784] - C:\WINDOWS\syswow64\ucrtbase.dll[MD5.B5C52DD49EA14B0B22841974E65B9ECF] - [11/07/2017 23:06:22] - |AC| - [1451008] - C:\WINDOWS\syswow64\UIAutomationCore.dll[MD5.B1504349AD2D86E51FE3D4E5CBF19AAF] - [06/07/2017 18:37:14] - |AC| - [584192] - C:\WINDOWS\syswow64\UIRibbonRes.dll[MD5.E1102CEDF0C818984C2ACA2A666D4C5F] - [10/07/2017 20:41:35] - |A| - [245408] - C:\WINDOWS\syswow64\unicows.dll[MD5.8699FF910F5156A713543454A1C06395] - [11/07/2017 23:05:49] - |AC| - [969728] - C:\WINDOWS\syswow64\Unistore.dll[MD5.9A03A5C76D99AB14502AE4322346E22A] - [11/07/2017 23:05:55] - |A| - [1626624] - C:\WINDOWS\syswow64\urlmon.dll[MD5.77ED1D2C275A6D6E94FDE682905A7B06] - [06/07/2017 18:37:14] - |AC| - [94720] - C:\WINDOWS\syswow64\UserDataTimeUtil.dll[MD5.9F44B8E90BF767159CAC7B870DE1A7F0] - [11/07/2017 23:05:21] - |AC| - [471040] - C:\WINDOWS\syswow64\VAN.dll[MD5.6FBC8680275BD9B0871CF2A0A7BBAABA] - [10/07/2017 20:41:35] - |A| - [751616] - C:\WINDOWS\syswow64\VBOLock.ocx[MD5.A40EFB7B05D727D9D0B5D7ED9C8B87C4] - [10/07/2017 20:41:35] - |A| - [1069] - C:\WINDOWS\syswow64\vbrun60.inf[MD5.6AE6698EF3F9C3C32DF6FECA7B8643D9] - [11/07/2017 23:06:24] - |AC| - [506368] - C:\WINDOWS\syswow64\vbscript.dll[MD5.37897B8DFC69E4B43A64335474B56FE1] - [11/07/2017 23:06:31] - |AC| - [4544000] - C:\WINDOWS\syswow64\VsGraphicsDesktopEngine.exe[MD5.4B568D6D7B17BFA60ECD7D40484BCE2A] - [11/07/2017 23:05:38] - |AC| - [1301504] - C:\WINDOWS\syswow64\wdc.dll[MD5.A5E5876505405B3374D805A0A25E4A47] - [11/07/2017 23:05:24] - |AC| - [209920] - C:\WINDOWS\syswow64\wdmaud.drv[MD5.E08885E10DC923D436D69E83A4ED8798] - [11/07/2017 23:04:27] - |AC| - [329728] - C:\WINDOWS\syswow64\webplatstorageserver.dll[MD5.72454CF1370EC99B538F56CB3C41EC15] - [11/07/2017 23:05:43] - |AC| - [1077496] - C:\WINDOWS\syswow64\webservices.dll[MD5.B9349FCF77164E8A8099F6CB143FC178] - [11/07/2017 23:06:23] - |AC| - [2956800] - C:\WINDOWS\syswow64\win32kfull.sys[MD5.0092845964B2B95D819E0BBDFD00D0C8] - [11/07/2017 23:05:30] - |AC| - [151552] - C:\WINDOWS\syswow64\wincredui.dll[MD5.A5A75C2D51F2DEDB96F109A8E155207B] - [11/07/2017 23:05:45] - |AC| - [438096] - C:\WINDOWS\syswow64\Windows.ApplicationModel.dll[MD5.335A2C3F8068A8B99794B638D9841A20] - [06/07/2017 18:37:13] - |AC| - [1474800] - C:\WINDOWS\syswow64\Windows.ApplicationModel.Store.dll[MD5.2D1F278DF37027730F0F02747FA75158] - [11/07/2017 23:06:02] - |AC| - [5961216] - C:\WINDOWS\syswow64\Windows.Data.Pdf.dll[MD5.1C4218B4E8053D295835A5C9CF0DEE53] - [11/07/2017 23:05:49] - |AC| - [1492480] - C:\WINDOWS\syswow64\Windows.Devices.Bluetooth.dll[MD5.85A3DA8F3A33C33D4CA0144B2C264204] - [06/07/2017 18:36:59] - |AC| - [332800] - C:\WINDOWS\syswow64\Windows.Devices.Midi.dll[MD5.EE8241753FC1DB2BB59FDA97FC09D59E] - [11/07/2017 23:05:39] - |AC| - [433152] - C:\WINDOWS\syswow64\Windows.Internal.Bluetooth.dll[MD5.4263E3E59FC91D6B1998897DFAD055EF] - [11/07/2017 23:05:19] - |AC| - [394240] - C:\WINDOWS\syswow64\Windows.Internal.Management.dll[MD5.3FAA1078029985A5D030AFAAAA61E1BB] - [11/07/2017 23:06:20] - |AC| - [5806048] - C:\WINDOWS\syswow64\Windows.Media.dll[MD5.4F5B5F01CB823F8C6C43733E74CA660F] - [11/07/2017 23:06:09] - |AC| - [6759512] - C:\WINDOWS\syswow64\Windows.Media.Protection.PlayReady.dll[MD5.8FD0834BABC8C025F53D3FB0DC761249] - [11/07/2017 23:05:37] - |AC| - [387584] - C:\WINDOWS\syswow64\Windows.Payments.dll[MD5.7E89208C2123988FE4B95B86B69BBCD9] - [06/07/2017 18:37:11] - |AC| - [198656] - C:\WINDOWS\syswow64\Windows.Security.Authentication.Identity.Provider.dll[MD5.6B0454C6C37546CE284DD8A7AC8BE256] - [11/07/2017 23:06:12] - |A| - [5820984] - C:\WINDOWS\syswow64\windows.storage.dll[MD5.81363F1DCFEE2C1590D1C7262230B9A6] - [06/07/2017 18:37:15] - |AC| - [444928] - C:\WINDOWS\syswow64\Windows.System.Launcher.dll[MD5.90B8A52C8B275874B073139D9AAE7D0C] - [11/07/2017 23:05:26] - |AC| - [111104] - C:\WINDOWS\syswow64\Windows.System.Profile.RetailInfo.dll[MD5.B5A271E9DE1A377E0501E420C7900E39] - [11/07/2017 23:06:14] - |A| - [790016] - C:\WINDOWS\syswow64\Windows.UI.dll[MD5.A4BB98F27B8C8F5D0956E70F1AC4789B] - [06/07/2017 18:37:14] - |AC| - [1536512] - C:\WINDOWS\syswow64\Windows.UI.Immersive.dll[MD5.C896A8C1BC92D733624FAE7C92FF88D7] - [11/07/2017 23:06:17] - |AC| - [13839872] - C:\WINDOWS\syswow64\Windows.UI.Xaml.dll[MD5.518D8095173F563660BFA448CBC0CCE1] - [11/07/2017 23:05:47] - |AC| - [1237504] - C:\WINDOWS\syswow64\Windows.UI.Xaml.Maps.dll[MD5.43681EB7AA953A795E5B63951358B363] - [11/07/2017 23:06:27] - |AC| - [2199552] - C:\WINDOWS\syswow64\Windows.UI.Xaml.Resources.dll[MD5.2E504BC65DA2B186966B1A4F176AC017] - [06/07/2017 18:37:14] - |AC| - [174080] - C:\WINDOWS\syswow64\Windows.Web.Diagnostics.dll[MD5.E85CB53C40B01B822A159AF9F412FB8B] - [11/07/2017 23:06:36] - |A| - [1518088] - C:\WINDOWS\syswow64\WindowsCodecs.dll[MD5.66184FDE48576468638B1BB6ABEDE92F] - [11/07/2017 23:05:28] - |AC| - [241152] - C:\WINDOWS\syswow64\WindowsCodecsExt.dll[MD5.0B926FFB46A9EE06366FFD2714F30613] - [11/07/2017 23:03:34] - |AC| - [31652264] - C:\WINDOWS\syswow64\WindowsCodecsRaw.dll[MD5.891EDEA873711E8277C9F556E73B62DF] - [11/07/2017 23:06:04] - |A| - [2859520] - C:\WINDOWS\syswow64\wininet.dll[MD5.389031E251A75820E60643D7C6E37241] - [11/07/2017 23:05:37] - |AC| - [35232] - C:\WINDOWS\syswow64\wininitext.dll[MD5.A2A5B4DFF476719BDA61A8177A91EC69] - [11/07/2017 23:06:33] - |AC| - [1529384] - C:\WINDOWS\syswow64\winmde.dll[MD5.F5888E94AEAAC5F4D6970FF3BEEE24F0] - [11/07/2017 23:05:40] - |A| - [312320] - C:\WINDOWS\syswow64\Wldap32.dll[MD5.E978814497BF7D565DB1BAB7A2975A07] - [11/07/2017 23:05:21] - |AC| - [342528] - C:\WINDOWS\syswow64\WMPhoto.dll[MD5.9382C74D9737B665027BA8569904452A] - [11/07/2017 23:04:30] - |AC| - [1339352] - C:\WINDOWS\syswow64\wmpmde.dll[MD5.9A7B61AB15C061460B77BB0D94D8F48E] - [11/07/2017 23:05:53] - |AC| - [636416] - C:\WINDOWS\syswow64\WpcWebFilter.dll[MD5.D494267BC169604FAC5E3679B9A97FED] - [09/07/2017 09:01:45] - |A| - [444952] - C:\WINDOWS\syswow64\wrap_oal.dll[MD5.7D97F7C5965D162BC32BBEEC8E6CB3AA] - [11/07/2017 23:05:43] - |AC| - [787456] - C:\WINDOWS\syswow64\wuapi.dll[MD5.DA8AA467F9A9CE6E4E866932BA769198] - [11/07/2017 23:05:28] - |AC| - [79872] - C:\WINDOWS\syswow64\wudriver.dll[MD5.5451383983D66A3D8BDB06A7EB33F117] - [11/07/2017 23:05:39] - |AC| - [750496] - C:\WINDOWS\syswow64\WWAHost.exe[MD5.4E961525CC7FF0E5D7DA19E170B7C14C] - [07/07/2017 11:40:15] - |A| - [14032] - C:\WINDOWS\syswow64\x3daudio1_0.dll[MD5.121B131EAA369D8F58DACC5C39A77D80] - [07/07/2017 11:53:35] - |A| - [15128] - C:\WINDOWS\syswow64\x3daudio1_1.dll[MD5.F6A9FC2AD2F9111372B5AB3BBA3707EC] - [07/07/2017 11:58:34] - |A| - [17928] - C:\WINDOWS\syswow64\X3DAudio1_2.dll[MD5.C593FD0A96EE4B6390B653C4C641313F] - [07/07/2017 12:02:24] - |A| - [25608] - C:\WINDOWS\syswow64\X3DAudio1_3.dll[MD5.E3832514BD21236067B7227F6165EF95] - [07/07/2017 12:04:44] - |A| - [25608] - C:\WINDOWS\syswow64\X3DAudio1_4.dll[MD5.350FEFE18B86BD4D9AB2A96D00215A49] - [07/07/2017 12:07:35] - |A| - [23376] - C:\WINDOWS\syswow64\X3DAudio1_5.dll[MD5.E763798CAD2A90B6AB61854F50CD47DD] - [07/07/2017 12:09:52] - |A| - [22360] - C:\WINDOWS\syswow64\X3DAudio1_6.dll[MD5.C811E70C8804CFFF719038250A43B464] - [07/07/2017 12:15:40] - |A| - [22360] - C:\WINDOWS\syswow64\X3DAudio1_7.dll[MD5.2112FE0C46662D429347A7D7B49E3ECE] - [07/07/2017 11:40:17] - |A| - [230096] - C:\WINDOWS\syswow64\xactengine2_0.dll[MD5.7C9952111F4C743B9F0D8B68B6ED93C9] - [07/07/2017 11:48:07] - |A| - [229584] - C:\WINDOWS\syswow64\xactengine2_1.dll[MD5.73E055AF78A64F9B2779D44407CA2AB6] - [07/07/2017 12:00:04] - |A| - [267272] - C:\WINDOWS\syswow64\xactengine2_10.dll[MD5.5C4D3843B491C047B7A619901FBD2EC1] - [07/07/2017 11:49:13] - |A| - [230168] - C:\WINDOWS\syswow64\xactengine2_2.dll[MD5.69D841744B2BAE38FBB2D40A230A549C] - [07/07/2017 11:50:04] - |A| - [236824] - C:\WINDOWS\syswow64\xactengine2_3.dll[MD5.6550E1A0A7BE611592C31222FCB981FB] - [07/07/2017 11:51:13] - |A| - [237848] - C:\WINDOWS\syswow64\xactengine2_4.dll[MD5.86C93789E9006F1AC47ED9DD47D4C8A1] - [07/07/2017 11:53:10] - |A| - [251672] - C:\WINDOWS\syswow64\xactengine2_5.dll[MD5.39000E033D39D19CCCE21AEAFCCE2476] - [07/07/2017 11:53:26] - |A| - [255848] - C:\WINDOWS\syswow64\xactengine2_6.dll[MD5.7FEBB8CE2233CBAE738B16D42ED29674] - [07/07/2017 11:55:00] - |A| - [261480] - C:\WINDOWS\syswow64\xactengine2_7.dll[MD5.499210C45AFEAADEE8CF4DCF7D5E570B] - [07/07/2017 11:56:59] - |A| - [266088] - C:\WINDOWS\syswow64\xactengine2_8.dll[MD5.46EE68F04A75A1CCF40235EA6F1CBA05] - [07/07/2017 11:58:28] - |A| - [267112] - C:\WINDOWS\syswow64\xactengine2_9.dll[MD5.8A83673F0AB001870583FDE2B004FA59] - [07/07/2017 12:02:45] - |A| - [238088] - C:\WINDOWS\syswow64\xactengine3_0.dll[MD5.2E0E25252E1D41752876E9FE12ADE175] - [07/07/2017 12:04:55] - |A| - [238088] - C:\WINDOWS\syswow64\xactengine3_1.dll[MD5.F3C6BE26949CAADB11DBF0086082FAC9] - [07/07/2017 12:06:36] - |A| - [238088] - C:\WINDOWS\syswow64\xactengine3_2.dll[MD5.8BA296419AF3417D1E9806B83166E472] - [07/07/2017 12:07:51] - |A| - [235856] - C:\WINDOWS\syswow64\xactengine3_3.dll[MD5.686F8D1B4926D48227A06ACD4D41CD1E] - [07/07/2017 12:10:11] - |A| - [235352] - C:\WINDOWS\syswow64\xactengine3_4.dll[MD5.DB3C93E87452B8DAB4F58ED1FD2B1998] - [07/07/2017 12:14:17] - |A| - [238936] - C:\WINDOWS\syswow64\xactengine3_5.dll[MD5.F81C4678A55FFEE585AC75825FAF5582] - [07/07/2017 12:16:01] - |A| - [238936] - C:\WINDOWS\syswow64\xactengine3_6.dll[MD5.DD165760F1B95200A3DA2D9DFDB84234] - [07/07/2017 12:05:19] - |A| - [65032] - C:\WINDOWS\syswow64\XAPOFX1_0.dll[MD5.D95EAABF5D277EF91D9CA70151209E56] - [07/07/2017 12:07:05] - |A| - [68616] - C:\WINDOWS\syswow64\XAPOFX1_1.dll[MD5.295E47A75F278580F9441041EAAEA3D2] - [07/07/2017 12:08:32] - |A| - [70992] - C:\WINDOWS\syswow64\XAPOFX1_2.dll[MD5.30686ECE80545E06D78D156EB9F7D463] - [07/07/2017 12:10:46] - |A| - [69464] - C:\WINDOWS\syswow64\XAPOFX1_3.dll[MD5.E4CE2AF32F501A7F7DDDD908704A0EE6] - [07/07/2017 12:16:31] - |A| - [74072] - C:\WINDOWS\syswow64\XAPOFX1_4.dll[MD5.418CDC57E55EE79C3F86C13A19B3D5E3] - [07/07/2017 12:03:10] - |A| - [479752] - C:\WINDOWS\syswow64\XAudio2_0.dll[MD5.E34FF0115B1EE3B4E03D22AE9840EE03] - [07/07/2017 12:05:19] - |A| - [507400] - C:\WINDOWS\syswow64\XAudio2_1.dll[MD5.50F4A0D5E6A0BAFEFA78F353533B8E06] - [07/07/2017 12:07:04] - |A| - [509448] - C:\WINDOWS\syswow64\XAudio2_2.dll[MD5.47ED15DC87AE334C13C4DACD1BE2CCED] - [07/07/2017 12:08:32] - |A| - [514384] - C:\WINDOWS\syswow64\XAudio2_3.dll[MD5.E684C5FA18ADF9EA14737757413BF727] - [07/07/2017 12:10:39] - |A| - [517448] - C:\WINDOWS\syswow64\XAudio2_4.dll[MD5.8B01FB723F3B30AB3DEBDDBF97CFE577] - [07/07/2017 12:14:48] - |A| - [515416] - C:\WINDOWS\syswow64\XAudio2_5.dll[MD5.4976243BD70FAE3D1D24E49739AB2710] - [07/07/2017 12:16:30] - |A| - [528216] - C:\WINDOWS\syswow64\XAudio2_6.dll[MD5.B6F89F4C37052969C0E5A8CF47C103D5] - [06/07/2017 18:37:15] - |AC| - [59904] - C:\WINDOWS\syswow64\xboxgipsynthetic.dll[MD5.F1726346E583442541FE73429F8E9C10] - [07/07/2017 11:48:42] - |A| - [62672] - C:\WINDOWS\syswow64\xinput1_1.dll[MD5.33B62BE226934E1B01F5043870C70427] - [07/07/2017 11:49:46] - |A| - [62744] - C:\WINDOWS\syswow64\xinput1_2.dll[MD5.77F595DEE5FFACEA72B135B1FCE1312E] - [07/07/2017 11:55:42] - |A| - [81768] - C:\WINDOWS\syswow64\xinput1_3.dll[MD5.214BF440424F4B02151D977223008E4B] - [21/07/2017 19:53:35] - |A| - [77824] - C:\WINDOWS\syswow64\xvid.ax ---------- | Drives D: [18/05/2017 17:27:00] - |A| - (.Copyright (C) 2013-2015 SosVirus Software - ZeroAccess Killer.) - [1760392] - (6.8.2015.1) - D:\UnZAcMe.exe[18/05/2017 11:25:06] - |H| - (. - .) - [16] - (0.0.0.0) - D:\AUTORUN.INF[10/05/2017 22:03:43] - |A| - (. - .) - [415] - (0.0.0.0) - D:\SmartClean.ini E: [14/07/2017 14:48:24] - |H| - (. - .) - [16] - (0.0.0.0) - E:\AUTORUN.INF F: [14/09/2016 14:37:03] - |R| - (. - .) - [22322] - (0.0.0.0) - F:\SPL1.EXE[14/09/2016 14:37:03] - |R| - (. - .) - [22322] - (0.0.0.0) - F:\SPL2.EXE[14/09/2016 14:37:03] - |R| - (. - .) - [22322] - (0.0.0.0) - F:\SPL3.EXE[14/09/2016 14:37:03] - |R| - (. - .) - [22322] - (0.0.0.0) - F:\SPL4.EXE[14/09/2016 14:37:03] - |R| - (. - .) - [31997] - (0.0.0.0) - F:\bootmenu.exe[14/09/2016 14:37:03] - |R| - (. - .) - [4850] - (0.0.0.0) - F:\mouse.com H: U: [31/01/2016 11:57:05] - |N| - (. - .) - [983040] - (0.8.0.5) - U:\Framakey.exe[31/01/2016 11:43:52] - |N| - (. - .) - [2141] - (0.0.0.0) - U:\Framakey.ini ---------- | C: [10/11/2016 16:26:48] - |HD| - [145170] - C:\$GetCurrent[06/07/2017 07:47:19] - |SHD| - [1035391454] - C:\$RECYCLE.BIN[22/07/2017 07:05:42] - |D| - [203027278] - C:\AdsFix[MD5.E9A0112C4748384DC27DC678A076603A] - [29/04/2017 21:54:18] - |A| - (. - .) - [39356] - (0.0.0.0) - C:\AdsFix.txt[10/11/2016 21:49:12] - |SHD| - [1691084573] - C:\AdwCleaner[26/04/2017 13:54:01] - |D| - [0] - C:\AeroGlass[02/05/2017 10:36:24] - |D| - [1902787072] - C:\AmazingSave[10/11/2016 20:17:35] - |D| - [1216033687] - C:\AMD[07/07/2017 21:06:02] - |D| - [4073984] - C:\AppData[02/08/2012 04:02:18] - |SHD| - [18163348] - C:\Boot[MD5.21BF183C15AFE62A8D1137BB9007B2A3] - [26/07/2012 10:18:43] - |RASH| - (. - .) - [398156] - (0.0.0.0) - C:\bootmgr[MD5.93B885ADFE0DA089CDF634904FD59F71] - [26/07/2012 10:18:43] - |ASH| - (. - .) - [1] - (0.0.0.0) - C:\BOOTNXT[15/07/2017 14:40:22] - |D| - [865859] - C:\Clean_Dns[21/07/2017 19:09:49] - |D| - [8552494] - C:\Clear ThemePack[07/07/2017 10:39:42] - |SD| - [4036824] - C:\CodySafe[10/11/2016 16:47:21] - |SHD| - [110592] - C:\Config.Msi[MD5.A2C8BC551DF43148A74DE30F282FC14E] - [22/07/2017 15:36:10] - |A| - (. - .) - [211220] - (0.0.0.0) - C:\Configuration.xml[07/07/2017 10:39:43] - |SD| - [573] - C:\Documents[26/07/2012 09:22:08] - |SD| - [0] - C:\Documents and Settings[23/04/2017 14:05:27] - |D| - [0] - C:\EverySync[MD5.6AEEC8720342E5726CFD9F4E8E691CDD] - [27/04/2017 10:27:36] - |A| - (. - .) - [3450] - (0.0.0.0) - C:\FyK_Kill.txt[MD5.6DA0208705E997AEC50A8F356A724339] - [01/05/2017 21:50:57] - |A| - (. - .) - [2239] - (0.0.0.0) - C:\GUDownLoaddebug.txt[07/01/2013 13:49:41] - |RSD| - [3776839] - C:\hp[09/07/2017 09:47:50] - |D| - [65738004] - C:\IconPack[07/07/2017 15:17:32] - |D| - [256878] - C:\kitkat ThemePack[06/07/2017 15:32:50] - |D| - [256878] - C:\Kongo ThemePack[26/04/2017 12:14:47] - |D| - [269222] - C:\Look_my_hardware[11/11/2016 18:27:25] - |D| - [920894] - C:\MARMITON[08/07/2017 10:04:29] - |D| - [158047448] - C:\MyDrivers[10/07/2017 22:09:30] - |SHD| - [12330156] - C:\Nsi.pending[27/04/2017 10:34:27] - |HD| - [0] - C:\OneDriveTemp[MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/03/2013 09:30:46] - |RAS| - (. - .) - [0] - (0.0.0.0) - C:\OS[MD5.D41D8CD98F00B204E9800998ECF8427E] - [07/07/2017 12:57:17] - |ASH| - (. - .) - [3892314112] - (0.0.0.0) - C:\pagefile.sys[06/07/2017 15:20:03] - |D| - [13164256] - C:\PatchMyPCUpdates[18/03/2017 23:03:28] - |D| - [0] - C:\PerfLogs[07/07/2017 10:39:43] - |D| - [0] - C:\PortableApps[22/07/2017 07:28:15] - |D| - [202007387] - C:\Pre_Scan[MD5.CF89BFFF26E3D7A6C1B74B42B6EDA13D] - [03/05/2017 20:51:41] - |A| - (. - .) - [15218] - (0.0.0.0) - C:\Pre_Scan.txt[MD5.9E0F42B80FE950AFB570C4729F6C0299] - [11/11/2016 20:54:33] - |RA| - (. - .) - [11250] - (0.0.0.0) - C:\Pre_Scan_11_11_2016_19_54_32.txt[18/03/2017 23:03:28] - |D| - [12689208773] - C:\Program Files[18/03/2017 23:03:28] - |D| - [37353505154] - C:\Program Files (x86)[18/03/2017 23:03:29] - |HD| - [159810864377] - C:\ProgramData[10/11/2016 20:27:11] - |D| - [291001802339] - C:\QuickDiag[MD5.4A5392745581C68067EFC905492E3B89] - [22/07/2017 16:08:44] - |A| - (. - .) - [541995] - (0.0.0.0) - C:\QuickDiag.txt[MD5.455D0DC10A9E340E226952D9CB725F96] - [28/04/2017 05:45:47] - |RA| - (. - .) - [807052] - (0.0.0.0) - C:\QuickDiag_28_04_2017_05_45_47.txt[MD5.1997D513A3884EDCBAB050E25DE3B64D] - [17/07/2017 17:56:17] - |A| - (. - .) - [11659168] - (0.0.0.0) - C:\QuickScript.txt[26/04/2017 19:45:05] - |SHD| - [1006] - C:\Recovery[MD5.7DE4B0DB9635619A08B8B8DD7FE729B3] - [17/07/2017 18:03:43] - |A| - (. - .) - [8621] - (0.0.0.0) - C:\Rem-VBS.log[10/07/2017 12:07:37] - |D| - [579] - C:\Rem-VBSqt[25/04/2017 18:18:12] - |D| - [512512] - C:\SkinPack[21/07/2017 16:47:47] - |D| - [117147039] - C:\SkinPack Creator[MD5.7FEA5C981C720D6A89CE65D95AE13E38] - [14/02/2010 00:18:58] - |A| - (.Codyssey.com - StartCodySafe - Starter for CodySafe portable environment.) - [182756] - (0.2.0.3) - C:\StartCodySafe.exe[MD5.D41D8CD98F00B204E9800998ECF8427E] - [06/07/2017 07:29:55] - |ASH| - (. - .) - [268435456] - (0.0.0.0) - C:\swapfile.sys[02/08/2012 05:15:28] - |AD| - [1021170132] - C:\SWSETUP[07/07/2017 20:45:13] - |D| - [0] - C:\System Rollback Data[06/07/2017 07:29:53] - |SHD| - [0] - C:\System Volume Information[01/08/2012 11:57:15] - |RASD| - [5674404] - C:\SYSTEM.SAV[10/07/2017 22:58:00] - |D| - [0] - C:\temp[MD5.B69E8D79D7BC1613BBFB3C2B328CAC46] - [30/04/2017 18:19:34] - |A| - (. - .) - [18104] - (0.0.0.0) - C:\Trace.txt[12/05/2017 06:11:03] - |RD| - [131735791] - C:\Unreal Commander[11/11/2016 11:26:34] - |D| - [4534884] - C:\UsbFix[18/03/2017 13:40:20] - |RD| - [408191434531] - C:\Users[13/07/2017 14:11:04] - |HD| - [0] - C:\VTRoot[21/07/2017 21:09:57] - |HD| - [139013632] - C:\W7P_Backups[18/03/2017 13:40:20] - |D| - [25841507012] - C:\Windows[10/11/2016 16:25:37] - |D| - [20424513] - C:\Windows10Upgrade[07/07/2017 10:13:03] - |HD| - [53256] - C:\_Backup[07/07/2017 10:13:14] - |RSHD| - [8605928] - C:\_Backup.RC[17/07/2017 23:34:32] - |D| - [380626] - C:\_OTL ---------- | C:\WINDOWS [MD5.D41D8CD98F00B204E9800998ECF8427E] - [21/07/2017 19:10:32] - |A| - (. - .) - [0] - (0.0.0.0) - C:\WINDOWS\1[MD5.B41D04BE43922A6FF4FA8D90BA045252] - [04/08/2004 09:56:46] - |AH| - (. - .) - [18] - (0.0.0.0) - C:\WINDOWS\1d1xf5b2m4m8o7e[18/03/2017 23:03:29] - |D| - [802] - C:\WINDOWS\addins[18/03/2017 23:03:29] - |D| - [7723514] - C:\WINDOWS\appcompat[18/03/2017 23:03:29] - |D| - [12470076] - C:\WINDOWS\AppPatch[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\AppReadiness[18/03/2017 23:03:28] - |RSD| - [2805516112] - C:\WINDOWS\assembly[MD5.D41D8CD98F00B204E9800998ECF8427E] - [26/04/2017 18:50:25] - |A| - (. - .) - [0] - (0.0.0.0) - C:\WINDOWS\ativpsrm.bin[MD5.8B138ED363128BFF2C2E1E7FEA9793B4] - [01/05/2017 17:03:34] - |A| - (. - .) - [38] - (0.0.0.0) - C:\WINDOWS\avisplitter.ini[18/03/2017 23:03:29] - |D| - [639657] - C:\WINDOWS\bcastdvr[MD5.293283CF350E00AF8C4A2770BDBF4D50] - [06/07/2017 18:33:58] - |AC| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [64512] - (10.0.15063.413) - C:\WINDOWS\bfsvc.exe[MD5.6DA84A49B7053EA6EE0BCF03932EE6AB] - [07/03/2014 14:55:56] - |A| - (.© 2003-2012 University of California - Charity Engine Screensaver.) - [808592] - (7.0.80.0) - C:\WINDOWS\boinc.scr[18/03/2017 23:03:29] - |D| - [38058819] - C:\WINDOWS\Boot[MD5.A8CADF816E305341E74BEE0ECA411DC4] - [26/04/2017 18:49:14] - |AS| - (. - .) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat[18/03/2017 23:03:29] - |D| - [2447960] - C:\WINDOWS\Branding[18/03/2017 22:51:24] - |D| - [0] - C:\WINDOWS\CbsTemp[MD5.F471CF70EE6D49C5650A4D5295531435] - [20/03/2017 07:12:07] - |A| - (. - .) - [34390] - (0.0.0.0) - C:\WINDOWS\Core.xml[18/03/2017 23:03:29] - |D| - [9095496] - C:\WINDOWS\Cursors[18/03/2017 23:03:29] - |D| - [383164] - C:\WINDOWS\debug[MD5.0E359EF178B73AAAE2C6D6AC11B4FE15] - [26/04/2017 20:15:35] - |A| - (. - .) - [11433] - (0.0.0.0) - C:\WINDOWS\diagerr.xml[18/03/2017 23:03:29] - |D| - [4450554] - C:\WINDOWS\diagnostics[MD5.0E359EF178B73AAAE2C6D6AC11B4FE15] - [26/04/2017 20:15:35] - |A| - (. - .) - [11433] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml[20/03/2017 07:10:26] - |D| - [0] - C:\WINDOWS\DigitalLocker[MD5.A2D3EB8406C58E919AE3A92A38F197E5] - [22/07/2017 07:12:32] - |A| - (. - .) - [17627] - (0.0.0.0) - C:\WINDOWS\DirectX.log[MD5.D41D8CD98F00B204E9800998ECF8427E] - [29/04/2017 20:57:52] - |A| - (. - .) - [0] - (0.0.0.0) - C:\WINDOWS\diskptex.dat[05/05/2017 13:28:07] - |D| - [84854784] - C:\WINDOWS\Downloaded Installations[18/03/2017 23:03:29] - |SD| - [65] - C:\WINDOWS\Downloaded Program Files[18/03/2017 23:03:29] - |HD| - [44632] - C:\WINDOWS\ELAMBKUP[20/03/2017 07:10:26] - |D| - [0] - C:\WINDOWS\en-US[MD5.CA3BF0F15BA4F24D511BFEE725CC89BD] - [11/07/2017 23:03:18] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4847424] - (10.0.15063.447) - C:\WINDOWS\explorer.exe[18/03/2017 23:03:29] - |RSD| - [382880739] - C:\WINDOWS\Fonts[20/03/2017 07:10:26] - |D| - [109056] - C:\WINDOWS\fr-FR[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\GameBarPresenceWriter[18/03/2017 23:03:29] - |D| - [45967119] - C:\WINDOWS\Globalization[18/03/2017 23:03:29] - |D| - [1598646] - C:\WINDOWS\Help[MD5.E064A38A807C83ADC8AD9E1B54C85CF9] - [06/07/2017 18:34:10] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [975360] - (10.0.15063.413) - C:\WINDOWS\HelpPane.exe[MD5.40CBB6FF53388188A2CDA538D5F26A59] - [18/03/2017 22:57:33] - |AC| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.15063.0) - C:\WINDOWS\hh.exe[20/03/2017 07:11:49] - |D| - [14071088] - C:\WINDOWS\HoloShell[18/03/2017 23:03:29] - |D| - [173056880] - C:\WINDOWS\IME[18/03/2017 23:03:29] - |RD| - [8336344] - C:\WINDOWS\ImmersiveControlPanel[18/03/2017 23:01:21] - |D| - [116724297] - C:\WINDOWS\INF[18/03/2017 23:03:29] - |D| - [1171230124] - C:\WINDOWS\InfusedApps[18/03/2017 23:03:29] - |D| - [38340109] - C:\WINDOWS\InputMethod[18/03/2017 23:03:29] - |SHD| - [3920910497] - C:\WINDOWS\Installer[27/04/2017 15:07:30] - |D| - [0] - C:\WINDOWS\IObit[18/03/2017 23:03:29] - |D| - [94096] - C:\WINDOWS\L2Schemas[22/07/2017 16:11:49] - |D| - [133328152] - C:\WINDOWS\LastGood[21/07/2017 11:15:36] - |D| - [53029553] - C:\WINDOWS\LastGood.Tmp[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\LiveKernelReports[18/03/2017 13:40:24] - |D| - [31025062] - C:\WINDOWS\Logs[18/03/2017 23:03:29] - |RSD| - [20316123] - C:\WINDOWS\Media[MD5.04B0D40C4FA88E6FAB7EACD5D9CD64B9] - [19/07/2017 13:21:07] - |A| - (. - .) - [480644444] - (0.0.0.0) - C:\WINDOWS\MEMORY.DMP[MD5.23AF90D2355D8C83AA4567EF1763B467] - [18/03/2017 22:57:03] - |AC| - (. - .) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin[18/03/2017 23:03:28] - |RD| - [1013092297] - C:\WINDOWS\Microsoft.NET[18/03/2017 23:03:29] - |D| - [2751] - C:\WINDOWS\Migration[02/05/2017 14:42:10] - |D| - [1645700] - C:\WINDOWS\Minidump[18/03/2017 23:03:29] - |RD| - [487308] - C:\WINDOWS\MiracastView[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\ModemLogs[MD5.F60A9D3A9461F68DE0FCCEBB0C6CB31A] - [18/03/2017 22:58:25] - |AC| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [246784] - (10.0.15063.0) - C:\WINDOWS\notepad.exe[20/03/2017 07:11:22] - |D| - [199472] - C:\WINDOWS\OCR[18/03/2017 23:03:29] - |RD| - [65] - C:\WINDOWS\Offline Web Pages[26/04/2017 16:34:14] - |DC| - [97875] - C:\WINDOWS\Panther[MD5.F007C4273BA24B52A56387E899311DB7] - [24/04/2017 09:23:13] - |A| - (.Eastman Kodak Company Copyright 1995 - PCDLIB32.) - [212480] - (3.0.0.0) - C:\WINDOWS\pcdlib32.dll[18/03/2017 23:03:29] - |D| - [29310348] - C:\WINDOWS\Performance[MD5.D442530453C42CBD1D8874C8E5A5869B] - [17/07/2017 08:28:47] - |A| - (. - .) - [335664] - (0.0.0.0) - C:\WINDOWS\PFRO.log[MD5.1B2C7EFB196140F81412A308E7F507FA] - [24/04/2017 10:24:44] - |A| - (. - .) - [21] - (0.0.0.0) - C:\WINDOWS\PI4_setup.ini[18/03/2017 23:03:29] - |D| - [1136442] - C:\WINDOWS\PLA[18/03/2017 23:03:29] - |D| - [2730616] - C:\WINDOWS\PolicyDefinitions[26/04/2017 18:48:40] - |D| - [29235383] - C:\WINDOWS\Prefetch[18/03/2017 23:03:29] - |RD| - [2168600] - C:\WINDOWS\PrintDialog[MD5.09394999ADB19901C665454EE964B13C] - [26/04/2017 16:24:33] - |A| - (. - .) - [36] - (0.0.0.0) - C:\WINDOWS\progress.ini[18/03/2017 23:03:29] - |D| - [2884514] - C:\WINDOWS\Provisioning[MD5.A3B1FC6C72EA944C2E1B359A19CB40AB] - [18/03/2017 22:57:08] - |AC| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [321024] - (10.0.15063.0) - C:\WINDOWS\regedit.exe[18/03/2017 23:03:29] - |D| - [1095144] - C:\WINDOWS\Registration[18/03/2017 23:03:29] - |D| - [6101285] - C:\WINDOWS\Resources[MD5.0DD3698CBEE8CB6ACEC3379A813F62C1] - [21/07/2017 11:24:13] - |A| - (.Copyright (C) Realtek Semiconductor Corp. - RtCRU.) - [4332032] - (1.13.0.0) - C:\WINDOWS\RtCRU64.exe[MD5.A095B3E67C8EB8F2137EAC63687F2F5B] - [09/07/2017 07:32:27] - |A| - (.Copyright (C) 2016 Realtek Semiconductor Corp. - RtlExUpd DLL for setup utility function.) - [2839520] - (1.0.7.0) - C:\WINDOWS\RtlExUpd.dll[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\SchCache[18/03/2017 23:03:29] - |D| - [121229] - C:\WINDOWS\schemas[18/03/2017 23:03:29] - |D| - [7762340] - C:\WINDOWS\security[26/04/2017 19:26:27] - |D| - [42112048] - C:\WINDOWS\ServiceProfiles[18/03/2017 13:40:20] - |D| - [72899099] - C:\WINDOWS\servicing[18/03/2017 23:06:43] - |D| - [349] - C:\WINDOWS\Setup[MD5.114B5AAEF0C4CF3734C7973A7C642673] - [17/07/2017 12:27:44] - |A| - (. - .) - [9950] - (0.0.0.0) - C:\WINDOWS\setupact.log[MD5.D41D8CD98F00B204E9800998ECF8427E] - [17/07/2017 12:27:44] - |A| - (. - .) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log[18/03/2017 23:03:29] - |D| - [41940992] - C:\WINDOWS\ShellExperiences[12/11/2016 16:30:14] - |D| - [5151] - C:\WINDOWS\ShellNew[20/03/2017 07:11:06] - |D| - [3070736] - C:\WINDOWS\SKB[09/07/2017 09:02:17] - |D| - [4110280] - C:\WINDOWS\SmartFix[12/11/2016 10:01:33] - |D| - [81208192] - C:\WINDOWS\SoftwareDistribution[18/03/2017 23:03:29] - |D| - [86037185] - C:\WINDOWS\Speech[18/03/2017 23:03:29] - |D| - [58890509] - C:\WINDOWS\Speech_OneCore[MD5.31F324879B791EBF76E0005D1ABDE10E] - [18/03/2017 22:58:24] - |AC| - (.© Microsoft Corporation. All rights reserved. - Print driver host for applications.) - [130560] - (10.0.15063.0) - C:\WINDOWS\splwow64.exe[MD5.3135B6A59B0BDAD940AF864F9917E4E2] - [29/12/2016 10:21:02] - |A| - (. - .) - [97784] - (0.0.0.0) - C:\WINDOWS\suite.vssMgr.exe[12/11/2016 14:22:54] - |D| - [11776] - C:\WINDOWS\symbols[18/03/2017 23:03:29] - |D| - [31039] - C:\WINDOWS\System[MD5.286A9EDB379DC3423A528B0864A0F111] - [12/11/2016 09:22:43] - |A| - (. - .) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini[18/03/2017 13:40:20] - |D| - [5727660394] - C:\WINDOWS\System32[18/03/2017 23:03:29] - |D| - [189919934] - C:\WINDOWS\SystemApps[18/03/2017 23:03:29] - |D| - [19463543] - C:\WINDOWS\SystemResources[18/03/2017 13:40:24] - |D| - [1677748192] - C:\WINDOWS\SysWOW64[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\TAPI[12/11/2016 09:22:36] - |D| - [22868] - C:\WINDOWS\Tasks[18/03/2017 23:03:29] - |D| - [558124] - C:\WINDOWS\Temp[18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\tracing[18/03/2017 23:03:29] - |D| - [43083340] - C:\WINDOWS\twain_32[MD5.C0792EA1BA08CA6E6420C9BB8E14CB3E] - [18/03/2017 22:58:54] - |AC| - (. - Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [65536] - (1.7.1.3) - C:\WINDOWS\twain_32.dll[MD5.ADFD9CF83AD65D38F107909521159EFD] - [22/07/2017 16:55:53] - |A| - (. - .) - [190806] - (0.0.0.0) - C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt[MD5.4C364F600CC7370E0ED056B86E373556] - [05/07/2017 12:15:00] - |A| - (. - .) - [51621] - (0.0.0.0) - C:\WINDOWS\uninstaller.dat[MD5.5D5FC880C46C1F08D72464250C8B0D70] - [01/03/2015 00:22:50] - |A| - (.Copyright (c) 2014 - Unsigned Themes service executable.) - [22184] - (0.2.4.1) - C:\WINDOWS\unsignedthemes.exe[MD5.E6E7ED3CEEBFC47D7C23F71665110432] - [24/04/2017 09:40:59] - |A| - (. - .) - [433] - (0.0.0.0) - C:\WINDOWS\videoimp.ini[MD5.1B2C7EFB196140F81412A308E7F507FA] - [24/04/2017 09:23:20] - |A| - (. - .) - [21] - (0.0.0.0) - C:\WINDOWS\VI_setup.ini[18/03/2017 23:03:29] - |D| - [12420] - C:\WINDOWS\Vss[MD5.3135B6A59B0BDAD940AF864F9917E4E2] - [29/12/2016 10:21:02] - |A| - (. - .) - [97784] - (0.0.0.0) - C:\WINDOWS\vssMgr.exe[MD5.321E59EE3B05221A53AC7041C7160FFA] - [21/07/2017 19:10:38] - |A| - (. - .) - [2434] - (0.0.0.0) - C:\WINDOWS\W7Patcher_x64_Uninstall.log[18/03/2017 23:03:30] - |D| - [15939567] - C:\WINDOWS\Web[MD5.3E871300AD274CEA32DFCD4AB3901D45] - [12/11/2016 09:22:43] - |A| - (. - .) - [128] - (0.0.0.0) - C:\WINDOWS\win.ini[MD5.C844CA459F3B209329984772269B6E56] - [18/03/2017 22:58:27] - |RAHC| - (. - .) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest[MD5.038356387332650843BCB352BB89A101] - [17/07/2017 08:29:55] - |A| - (. - .) - [275] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log[MD5.6E6947D6368FA11E9146C4767F31286E] - [18/03/2017 22:58:42] - |AC| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [10240] - (10.0.15063.0) - C:\WINDOWS\winhlp32.exe[MD5.E7633AA6A479BBBE82DBE794126BBECA] - [07/07/2017 12:47:35] - |A| - (. - .) - [132] - (0.0.0.0) - C:\WINDOWS\wininit.ini[18/03/2017 13:40:20] - |D| - [7053005786] - C:\WINDOWS\WinSxS[MD5.9A2DB1C46E2093A7FD23A9B850D17013] - [15/07/2017 16:24:27] - |A| - (. - .) - [52038142] - (0.0.0.0) - C:\WINDOWS\WinSxS_NTFS.acl[MD5.F1D3FF8443297732862DF21DC4E57262] - [07/07/2017 09:57:06] - |ASH| - (. - .) - [4] - (0.0.0.0) - C:\WINDOWS\wisefs.dat[MD5.0F4092E1E0DC29C0D790830964490522] - [07/07/2017 09:57:06] - |A| - (.WiseCleaner.com - Wise Folder Hider.) - [55712] - (2.0.2.209) - C:\WINDOWS\WiseFs64.sys[MD5.2449E01AA5EFCA4A6862B6D8B040A97C] - [27/05/2011 02:27:44] - |RA| - (. - .) - [37916] - (0.0.0.0) - C:\WINDOWS\wmprffra.prx[MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [18/03/2017 22:56:51] - |AC| - (. - .) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx[MD5.72F2D357120F95C1E725C22915FE95E1] - [07/07/2017 10:36:03] - |A| - (. - .) - [193] - (0.0.0.0) - C:\WINDOWS\WORDPAD.INI[MD5.ECEB16331FDDE0EBD7BE30BE085AD3D9] - [18/03/2017 22:58:25] - |AC| - (.© Microsoft Corporation. All rights reserved. - Windows Write.) - [11264] - (10.0.15063.0) - C:\WINDOWS\write.exe[MD5.7A207B6C9BC806F2156C66B9A21F5611] - [07/07/2017 13:07:22] - |A| - (. - .) - [25824] - (0.0.0.0) - C:\WINDOWS\ZAM.krnl.trace[MD5.983E0FBBE45EFC38FA95FD591BF7EC16] - [07/07/2017 13:07:22] - |A| - (. - .) - [2148] - (0.0.0.0) - C:\WINDOWS\ZAM_Guard.krnl.trace ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [05/05/2017 13:28:08] - C:\WINDOWS\Installer\138ded.msi : (PDQ Deploy - Admin Arsenal) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][05/05/2017 13:29:15] - C:\WINDOWS\Installer\138df0.msi : (PDQ Inventory - Admin Arsenal) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 10:36:17] - C:\WINDOWS\Installer\19afc4.msi : (AntimalwareEngine - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 10:41:42] - C:\WINDOWS\Installer\19afcb.msi : (FirewallEngine - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 10:43:59] - C:\WINDOWS\Installer\19afd2.msi : (ProxyEngine - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 10:45:56] - C:\WINDOWS\Installer\19afd9.msi : (OnlineThreatsEngine - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 10:46:53] - C:\WINDOWS\Installer\19afe0.msi : (AntispamEngine - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 10:47:10] - C:\WINDOWS\Installer\19afe7.msi : (AvcEngine - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][09/06/2017 20:27:55] - C:\WINDOWS\Installer\1aff93.msi : (LiteManager Pro - Server - LiteManagerTeam) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][09/06/2017 20:27:57] - C:\WINDOWS\Installer\1aff98.msi : (LiteManager Pro - Viewer - LiteManagerTeam) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:26:12] - C:\WINDOWS\Installer\1affa1.msi : (Nero 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:30:41] - C:\WINDOWS\Installer\1affa7.msi : (NeroControlCenter - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:30:34] - C:\WINDOWS\Installer\1affae.msi : (Nero Core Components - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:46] - C:\WINDOWS\Installer\1affb5.msi : (Nero 12 Disc Menus Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:39] - C:\WINDOWS\Installer\1affbc.msi : (Nero 12 Kwik Themes Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:30:45] - C:\WINDOWS\Installer\1affc3.msi : (Nero Burning ROM 15 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:29:33] - C:\WINDOWS\Installer\1affca.msi : (Nero 12 Effects Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:37] - C:\WINDOWS\Installer\1affd1.msi : (Nero 12 PiP Effects Basic - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:36] - C:\WINDOWS\Installer\1affd8.msi : (Nero Prerequisites - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:12] - C:\WINDOWS\Installer\1affdf.msi : (Nero SharedVideoCodecs - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:29:53] - C:\WINDOWS\Installer\1affe6.msi : (Nero CoverDesigner - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:29:31] - C:\WINDOWS\Installer\1affed.msi : (Nero Express 15 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:56] - C:\WINDOWS\Installer\1afff4.msi : (Nero MediaHome - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:22] - C:\WINDOWS\Installer\1afffb.msi : (Nero RescueAgent 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:24] - C:\WINDOWS\Installer\1b0002.msi : (Nero Recode 10 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:26:31] - C:\WINDOWS\Installer\1b0009.msi : (Nero Video 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:20] - C:\WINDOWS\Installer\1b0010.msi : (Nero 12 Video Samples - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:10] - C:\WINDOWS\Installer\1b0016.msi : (Nero Update - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:49] - C:\WINDOWS\Installer\1b001c.msi : (Nero Launcher - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:29:37] - C:\WINDOWS\Installer\1b0023.msi : (Nero Disc to Device - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:30:47] - C:\WINDOWS\Installer\1b002a.msi : (Nero BurningCore 15 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:29:28] - C:\WINDOWS\Installer\1b0031.msi : (Nero Info - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:29:50] - C:\WINDOWS\Installer\1b0038.msi : (Nero Device Updates - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:27:11] - C:\WINDOWS\Installer\1b003f.msi : (Nero Video 2016 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:05] - C:\WINDOWS\Installer\1b0044.msi : (Nero 2016 Content Pack - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:14] - C:\WINDOWS\Installer\1b004a.msi : (Nero 12 Image Samples - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:42:15] - C:\WINDOWS\Installer\1b0051.msi : (Nero Family and Events Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:58] - C:\WINDOWS\Installer\1b0058.msi : (Nero Football (Soccer) Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:34] - C:\WINDOWS\Installer\1b005f.msi : (Nero Retro Film Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:20] - C:\WINDOWS\Installer\1b0066.msi : (Nero 12 PiP Effects 1 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:17] - C:\WINDOWS\Installer\1b006d.msi : (Nero Platinum Effects 12 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:41:12] - C:\WINDOWS\Installer\1b0074.msi : (Nero 12 Video Transitions 1 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:44:50] - C:\WINDOWS\Installer\1b007c.msi : (Nero 12 Cliparts - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:44:41] - C:\WINDOWS\Installer\1b0083.msi : (Nero 12 Disc Menus 1 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:44:05] - C:\WINDOWS\Installer\1b008a.msi : (Nero 12 Disc Menus 2 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:43:39] - C:\WINDOWS\Installer\1b0091.msi : (Nero 12 Disc Menus 3 - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:43:21] - C:\WINDOWS\Installer\1b0098.msi : (Nero Abstract Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 07:42:58] - C:\WINDOWS\Installer\1b009f.msi : (Nero Holiday and Sports Themes - Nero AG) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][15/11/2016 22:53:00] - C:\WINDOWS\Installer\1bd715.msi : (Rebit Pro - Rebit, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/11/2014 10:49:56] - C:\WINDOWS\Installer\1ebd12d.msi : (Branding - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:16] - C:\WINDOWS\Installer\1ebd132.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:22] - C:\WINDOWS\Installer\1ebd137.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:30] - C:\WINDOWS\Installer\1ebd13c.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:36] - C:\WINDOWS\Installer\1ebd141.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:44] - C:\WINDOWS\Installer\1ebd146.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:52] - C:\WINDOWS\Installer\1ebd14b.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:00] - C:\WINDOWS\Installer\1ebd150.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:06] - C:\WINDOWS\Installer\1ebd155.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:16] - C:\WINDOWS\Installer\1ebd15a.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:22] - C:\WINDOWS\Installer\1ebd15f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:30] - C:\WINDOWS\Installer\1ebd164.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:38] - C:\WINDOWS\Installer\1ebd169.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:46] - C:\WINDOWS\Installer\1ebd16e.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:54] - C:\WINDOWS\Installer\1ebd173.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:02] - C:\WINDOWS\Installer\1ebd178.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:10] - C:\WINDOWS\Installer\1ebd17d.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:18] - C:\WINDOWS\Installer\1ebd182.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:26] - C:\WINDOWS\Installer\1ebd187.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:34] - C:\WINDOWS\Installer\1ebd18c.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:42] - C:\WINDOWS\Installer\1ebd191.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:50] - C:\WINDOWS\Installer\1ebd196.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:58] - C:\WINDOWS\Installer\1ebd19b.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:06] - C:\WINDOWS\Installer\1ebd1a0.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:40] - C:\WINDOWS\Installer\1ebd1a5.msi : (Catalyst Control Center Utility 64 - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:07:30] - C:\WINDOWS\Installer\1ebd1aa.msi : (AMD Fuel - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:12] - C:\WINDOWS\Installer\1ebd1af.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][04/05/2017 20:41:00] - C:\WINDOWS\Installer\218d826.msi : (FileOpen - Foxit Software Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][09/11/2009 17:00:00] - C:\WINDOWS\Installer\23dcc0c.msi : ( - Lukas Fellechner) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/05/2011 12:24:36] - C:\WINDOWS\Installer\2d628fd.msi : (Blank Project Template - Avanquest) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][12/05/2017 07:11:33] - C:\WINDOWS\Installer\3244f7.msi : (Fast HTML Checker - WebTweakTools.com) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][23/06/2016 20:57:14] - C:\WINDOWS\Installer\38dda8.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][23/06/2016 21:10:27] - C:\WINDOWS\Installer\38ddac.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][26/07/2011 20:36:38] - C:\WINDOWS\Installer\38ddb3.msi : ( - DivX, Inc) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][23/06/2016 21:30:13] - C:\WINDOWS\Installer\38ddb7.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][23/06/2016 21:33:02] - C:\WINDOWS\Installer\38ddbb.msi : (Blank Project Template - CyberLink Corp.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][07/07/2017 07:13:20] - C:\WINDOWS\Installer\39e5938.msi : (Folder Size - Brio) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][19/07/2010 02:52:44] - C:\WINDOWS\Installer\39e5948.msi : (Blank Project Template - Sonic Solutions) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][01/06/2011 11:17:38] - C:\WINDOWS\Installer\39e594e.msi : (VirtualDrive 64 bit installer - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][14/02/2011 19:41:28] - C:\WINDOWS\Installer\39e5954.msi : (Driver Installation - Roxio) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][01/05/2017 13:50:47] - C:\WINDOWS\Installer\3e481c0.msi : (Paramount Software (UK) Ltd - Paramount Software (UK) Ltd.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][09/07/2017 09:01:43] - C:\WINDOWS\Installer\4251bf.msi : (calibre Installer - Kovid Goyal) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][23/04/2017 11:35:38] - C:\WINDOWS\Installer\42fab6e.msi : (Google Update Helper - Google Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][30/06/2017 08:10:36] - C:\WINDOWS\Installer\43a24a0.msi : (COMODO Secure Shopping - COMODO) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][25/04/2017 09:05:42] - C:\WINDOWS\Installer\46a8d78.msi : (SearchGUARDIAN - UTILILAB GmbH) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/04/2017 04:44:00] - C:\WINDOWS\Installer\482399e.msi : (Epson Software Updater - SEIKO EPSON CORPORATION) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][26/04/2017 21:11:08] - C:\WINDOWS\Installer\4a0ad7.msi : (Blank Project Template - adaware) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:24] - C:\WINDOWS\Installer\528ea.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:24] - C:\WINDOWS\Installer\646d7.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/11/2014 10:49:56] - C:\WINDOWS\Installer\646df.msi : (Branding - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:16] - C:\WINDOWS\Installer\646e7.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:22] - C:\WINDOWS\Installer\646ef.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:30] - C:\WINDOWS\Installer\646f7.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:36] - C:\WINDOWS\Installer\646ff.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:44] - C:\WINDOWS\Installer\64707.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:52] - C:\WINDOWS\Installer\6470f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:00] - C:\WINDOWS\Installer\64717.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:06] - C:\WINDOWS\Installer\6471f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:16] - C:\WINDOWS\Installer\64727.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:22] - C:\WINDOWS\Installer\6472f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:30] - C:\WINDOWS\Installer\64737.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:38] - C:\WINDOWS\Installer\6473f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:46] - C:\WINDOWS\Installer\64747.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:04:54] - C:\WINDOWS\Installer\6474f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:02] - C:\WINDOWS\Installer\64757.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:10] - C:\WINDOWS\Installer\6475f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:18] - C:\WINDOWS\Installer\64767.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:26] - C:\WINDOWS\Installer\6476f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:34] - C:\WINDOWS\Installer\64777.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:42] - C:\WINDOWS\Installer\6477f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:50] - C:\WINDOWS\Installer\64787.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:05:58] - C:\WINDOWS\Installer\6478f.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:06] - C:\WINDOWS\Installer\64797.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:06:40] - C:\WINDOWS\Installer\6479f.msi : (Catalyst Control Center Utility 64 - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:07:30] - C:\WINDOWS\Installer\647a7.msi : (AMD Fuel - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/08/2015 20:03:12] - C:\WINDOWS\Installer\647af.msi : (Catalyst Control Center - Advanced Micro Devices, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][01/03/2015 00:23:12] - C:\WINDOWS\Installer\664730d.msi : (UxStyle - The Within Network, LLC) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/09/2015 15:21:54] - C:\WINDOWS\Installer\666bd76.msi : (Jing - TechSmith Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 09:01:51] - C:\WINDOWS\Installer\679227.msi : (Lavasoft Privacy Toolbox - Lavasoft) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 10:29:56] - C:\WINDOWS\Installer\69f2519.msi : (Caisse Epargne - e-Carte Bleue Caisse d'Epargne) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 10:42:34] - C:\WINDOWS\Installer\6ab0003.msi : (Autorun File Remover - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 10:47:25] - C:\WINDOWS\Installer\6ab0006.msi : (Advanced Windows Service Manager - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 10:51:10] - C:\WINDOWS\Installer\6ab0009.msi : (Google Ad Blocker - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 10:52:42] - C:\WINDOWS\Installer\6ab000c.msi : (Spy BHO Remover - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 10:56:42] - C:\WINDOWS\Installer\6ab000f.msi : (SX Antivirus Kit - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][05/01/2017 18:05:59] - C:\WINDOWS\Installer\6ab0012.msi : (SX Blocker Suite - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][05/01/2017 16:36:24] - C:\WINDOWS\Installer\6ab0015.msi : (SX Network Suite - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 11:06:19] - C:\WINDOWS\Installer\6ab0018.msi : (SX System Suite - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/04/2017 11:09:53] - C:\WINDOWS\Installer\6ab001b.msi : (SX WiFi Security Suite - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][25/04/2017 19:41:32] - C:\WINDOWS\Installer\6b0ab6d.msi : (YouTube Video Ad Blocker - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][25/04/2017 19:42:28] - C:\WINDOWS\Installer\6b0ab70.msi : (VirusTotal Scanner - SecurityXploded) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][29/01/2016 13:09:58] - C:\WINDOWS\Installer\729c084.msi : (Epson Event Manager - Seiko Epson Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][01/04/2016 13:20:00] - C:\WINDOWS\Installer\729c08c.msi : (MyEpson Portal Setup - SEIKO EPSON CORPORATION) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][25/03/2016 01:00:00] - C:\WINDOWS\Installer\729c094.msi : ( - ) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][24/10/2016 22:00:00] - C:\WINDOWS\Installer\72bd7b.msi : (WinZip Compression Utility - Copyright (c) 1991-2016 VAPC (Lux) S.a.r.L. All rights reserved.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][02/07/2017 14:26:59] - C:\WINDOWS\Installer\8a13b9.msi : (Paragon ExtFS for Windows - Paragon Software) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 09:58:57] - C:\WINDOWS\Installer\9be001.msi : (Charity Engine - Charity Engine) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][10/05/2016 15:59:07] - C:\WINDOWS\Installer\a0904e9.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 11:39:16] - C:\WINDOWS\Installer\b4893.msi : (Paragon Backup & Recovery™ 16 - Paragon Software) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 11:39:38] - C:\WINDOWS\Installer\b4898.msi : (Paragon UIM - Paragon Software) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][04/06/2010 08:54:38] - C:\WINDOWS\Installer\c09ebc.msi : (Blank Project Template - SmartSound Software Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][21/07/2011 16:29:36] - C:\WINDOWS\Installer\c09ec2.msi : (Roxio Creator 2012 Pro - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/06/2011 10:08:38] - C:\WINDOWS\Installer\c09ec7.msi : (RBVirtualFolder 64 bit installer - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/06/2011 04:37:24] - C:\WINDOWS\Installer\c09ecd.msi : (1 - Roxio) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][21/07/2011 17:26:28] - C:\WINDOWS\Installer\c09ee9.msi : (Roxio Easy Media Creator 8 - Roxio) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][23/10/2010 05:14:08] - C:\WINDOWS\Installer\c09eef.msi : (Roxio CinePlayer Decoder Pack - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2011 02:57:20] - C:\WINDOWS\Installer\c09f08.msi : (Roxio CinePlayer - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][16/07/2011 11:20:08] - C:\WINDOWS\Installer\c09f1f.msi : (Roxio BackOnTrack - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][14/07/2011 02:54:36] - C:\WINDOWS\Installer\c09f25.msi : (Roxio BackOnTrack - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][30/06/2011 22:22:08] - C:\WINDOWS\Installer\c09f2b.msi : (Roxio System Rollback Recovery Disk - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][15/07/2011 02:50:46] - C:\WINDOWS\Installer\c09f3b.msi : (Roxio Burn - Secure - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][15/07/2011 11:49:50] - C:\WINDOWS\Installer\c09f41.msi : (Roxio System Rollback - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][04/06/2010 08:54:54] - C:\WINDOWS\Installer\c09f45.msi : (Blank Project Template - SmartSound Software Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][28/06/2011 01:00:00] - C:\WINDOWS\Installer\c09f49.msi : (Blank Project Template - SmartSound Software Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][19/07/2011 12:28:48] - C:\WINDOWS\Installer\c09f4d.msi : (Roxio WinOnCD 8 Content - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][18/06/2011 01:53:44] - C:\WINDOWS\Installer\c09f9c.msi : (Roxio WinOnCD 8 Content - Roxio, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/09/2012 01:34:20] - C:\WINDOWS\Installer\c525d4c.msi : (LWS Help_main - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/09/2012 09:41:18] - C:\WINDOWS\Installer\c525d54.msi : (LWS Webcam Software - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/09/2012 09:41:16] - C:\WINDOWS\Installer\c525d5c.msi : (CameraHelperMsi - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][26/10/2012 19:55:20] - C:\WINDOWS\Installer\c525d6c.msi : (Logitech eReg 1.12 merge module-to-MSI converter - Logitech, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][24/07/2012 00:15:18] - C:\WINDOWS\Installer\c525d74.msi : (LWS Facebook - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/09/2012 00:19:08] - C:\WINDOWS\Installer\c525d7c.msi : (LWS Gallery - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/09/2012 01:36:58] - C:\WINDOWS\Installer\c6d966a.msi : (LWS Launcher - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/09/2012 09:41:12] - C:\WINDOWS\Installer\c6d9672.msi : (LWS Motion Detection - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/09/2012 09:41:22] - C:\WINDOWS\Installer\c6d967a.msi : (LWS Pictures And Video - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/07/2011 04:51:16] - C:\WINDOWS\Installer\c6d9682.msi : (LWS Twitter - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][13/06/2011 05:26:48] - C:\WINDOWS\Installer\c6d968a.msi : (LWS WLM Plugin - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][12/11/2011 00:14:28] - C:\WINDOWS\Installer\c6d9692.msi : (LWS YouTube Plugin - Logitech) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][18/06/2017 10:58:43] - C:\WINDOWS\Installer\d21f7.msi : (Online Application - Microleaves) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][12/11/2016 13:51:42] - C:\WINDOWS\Installer\d5be64.msi : (Laplink PCmover Professional - Laplink Software, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][21/06/2016 05:44:30] - C:\WINDOWS\Installer\e89933.msi : (PreEmptive Solutions provides analytics, obfuscation, tamper defense, and shelf life. - PreEmptive Solutions LLC) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][21/06/2016 05:44:08] - C:\WINDOWS\Installer\e8993b.msi : (Les services d'instrumentation post-build PreEmptive Solutions offrent des fonctions d'obfuscation, de protection contre la falsification, de durée de conservation et d'exécution. - PreEmptive Solutions LLC) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/06/2015 04:09:05] - C:\WINDOWS\Installer\e89943.msi : (PreEmptive Analytics Visual Studio Components - PreEmptive Solutions) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][08/06/2015 04:11:26] - C:\WINDOWS\Installer\e8994b.msi : (PreEmptive Analytics Client French Language Pack - PreEmptive Solutions) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][27/04/2017 11:59:32] - C:\WINDOWS\Installer\fc0e02.msi : (Silent Install Builder 5 - Aprel Tech, LLC) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][01/05/2017 13:50:46] - C:\WINDOWS\Installer\reflect_setupv6.3.1745-x64-00.msi : (Paramount Software (UK) Ltd - Paramount Software (UK) Ltd.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000][11/07/2017 08:21:42] - [301040] - C:\WINDOWS\Installer\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:26:42] - [43504] - C:\WINDOWS\Installer\{0517F875-BBB2-4812-A63E-733B33CEF215}\BackupCentral.exe () - ()[11/07/2017 08:11:08] - [313328] - C:\WINDOWS\Installer\{05C6B128-1B40-4495-9CB9-090B368BFA0A}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:29:33] - [88102] - C:\WINDOWS\Installer\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}\ARPPRODUCTICON.exe () - ()[27/04/2017 10:39:12] - [59352] - C:\WINDOWS\Installer\{06D33B93-9458-4E28-BDEA-F5ECB2C3C30E}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[09/07/2017 20:28:20] - [88102] - C:\WINDOWS\Installer\{07326A3E-02B3-1078-25D7-B8666BA8FE15}\ARPPRODUCTICON.exe () - ()[25/04/2017 19:42:03] - [167036] - C:\WINDOWS\Installer\{07CF5846-FAEA-4A01-8B70-9014216AA707}\SystemFoldermsiexec.exe () - ()[25/04/2017 19:42:03] - [154677] - C:\WINDOWS\Installer\{07CF5846-FAEA-4A01-8B70-9014216AA707}\VistaUACMaker.exe () - ()[09/07/2017 20:27:49] - [88102] - C:\WINDOWS\Installer\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}\ARPPRODUCTICON.exe () - ()[28/04/2017 14:21:45] - [25214] - C:\WINDOWS\Installer\{08C03D14-B619-4CD6-938F-C2BB569364E0}\_6FEFF9B68218417F98F549.exe () - ()[28/04/2017 14:21:45] - [25214] - C:\WINDOWS\Installer\{08C03D14-B619-4CD6-938F-C2BB569364E0}\_E12803CE05B6ADEA321A01.exe () - ()[09/07/2017 20:26:34] - [10134] - C:\WINDOWS\Installer\{11087D24-567D-7D88-69C6-D7A08B5F4C47}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:44:58] - [313328] - C:\WINDOWS\Installer\{150D88F1-40AF-4678-A39D-BCE2332F34E5}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:26:54] - [88102] - C:\WINDOWS\Installer\{1AD99E77-37CC-744E-39CA-67F6FD34565A}\ARPPRODUCTICON.exe () - ()[11/07/2017 07:49:40] - [313328] - C:\WINDOWS\Installer\{1B6F5E51-575E-4693-BCA2-7543570D076D}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:27:39] - [88102] - C:\WINDOWS\Installer\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}\ARPPRODUCTICON.exe () - ()[07/07/2017 19:45:16] - [315664] - C:\WINDOWS\Installer\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}\ARPPRODUCTICON.exe (Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:45:16] - [315664] - C:\WINDOWS\Installer\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}\NewShortcut1_D9F5C0BDCADB44D6845BE4049DC2A092.exe (Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:45:16] - [315664] - C:\WINDOWS\Installer\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}\NewShortcut21_327B98C6A44E4D4A974678CA6821860F.exe (Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:27:54] - [88102] - C:\WINDOWS\Installer\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:33:42] - [313328] - C:\WINDOWS\Installer\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:28:52] - [88102] - C:\WINDOWS\Installer\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}\ARPPRODUCTICON.exe () - ()[27/04/2017 10:46:39] - [59352] - C:\WINDOWS\Installer\{26F31E12-3722-45FD-903B-49012286BB4C}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 08:36:13] - [313328] - C:\WINDOWS\Installer\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 07:51:29] - [313328] - C:\WINDOWS\Installer\{29F67D84-3A70-456E-806A-52301B02070B}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:28:00] - [88102] - C:\WINDOWS\Installer\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}\ARPPRODUCTICON.exe () - ()[07/07/2017 20:02:40] - [401408] - C:\WINDOWS\Installer\{2DDBB2E7-CB4E-4E65-A6B9-B9C95ED77D42}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:27:21] - [229195] - C:\WINDOWS\Installer\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}\ARPPRODUCTICON.exe () - ()[07/07/2017 19:19:49] - [298480] - C:\WINDOWS\Installer\{302763FD-5CEA-4DFF-80C8-9B41414C4822}\CPIcon.exe () - ()[25/04/2017 09:06:23] - [5430] - C:\WINDOWS\Installer\{313FC459-42E4-4F49-9053-E6A7D6456ACC}\main_1.exe () - ()[25/04/2017 09:06:23] - [14534] - C:\WINDOWS\Installer\{313FC459-42E4-4F49-9053-E6A7D6456ACC}\SystemFolder_msiexec.exe () - ()[09/07/2017 20:27:45] - [88102] - C:\WINDOWS\Installer\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:29:19] - [88102] - C:\WINDOWS\Installer\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}\ARPPRODUCTICON.exe () - ()[29/04/2017 11:00:38] - [162342] - C:\WINDOWS\Installer\{35AB7D6C-C217-4470-B2D7-021291708FF4}\SXPasswordDumpSuite.exe () - ()[29/04/2017 11:00:39] - [167036] - C:\WINDOWS\Installer\{35AB7D6C-C217-4470-B2D7-021291708FF4}\SystemFoldermsiexec.exe () - ()[27/04/2017 10:48:09] - [59352] - C:\WINDOWS\Installer\{3E5BEF30-3962-4B47-AECA-937B6CBB0A68}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[25/04/2017 19:43:00] - [165365] - C:\WINDOWS\Installer\{43C5B500-38EB-456F-8C71-CE7B1F7F9976}\GooglePasswordDecryptor.exe () - ()[25/04/2017 19:43:00] - [167036] - C:\WINDOWS\Installer\{43C5B500-38EB-456F-8C71-CE7B1F7F9976}\SystemFoldermsiexec.exe () - ()[11/07/2017 08:28:42] - [313320] - C:\WINDOWS\Installer\{4D25D881-7183-462F-95C8-990CA1944E0B}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:46:01] - [313328] - C:\WINDOWS\Installer\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 07:40:02] - [61136] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\ARPPRODUCTICON.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:40:02] - [65232] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\NewShortcut11_F03B5AE20F664337BCBB912BCEBD64FA.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:40:02] - [65232] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\NewShortcut1_6AB92848793642629CC7DA100B1ED13A.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:40:02] - [52944] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\NewShortcut2_3E8C8228BDAA49F09CEDF0D9E384E2FE.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:40:02] - [65232] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\NewShortcut4_091CC2A3CD4F401D84D7DD1277026C3E.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:40:02] - [57040] - C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\UNINST_Uninstall_L_0CC25913205648D8812BEBFC4BCD4007.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[27/04/2017 15:51:45] - [197853] - C:\WINDOWS\Installer\{581697C8-33DC-44BA-A7C3-992B5D29C011}\AdvancedInstaller.exe () - ()[27/04/2017 15:51:45] - [22486] - C:\WINDOWS\Installer\{581697C8-33DC-44BA-A7C3-992B5D29C011}\ext.exe () - ()[27/04/2017 15:51:45] - [49334] - C:\WINDOWS\Installer\{581697C8-33DC-44BA-A7C3-992B5D29C011}\ext_1.exe () - ()[01/05/2017 13:52:55] - [43646] - C:\WINDOWS\Installer\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}\ImgToVHD.exe () - ()[01/05/2017 13:52:55] - [19942] - C:\WINDOWS\Installer\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}\xReflect.exe () - ()[29/04/2017 10:53:42] - [372526] - C:\WINDOWS\Installer\{5DD7489B-EC46-47AF-BB68-22F47253228B}\BHORemover.exe () - ()[29/04/2017 10:53:42] - [167036] - C:\WINDOWS\Installer\{5DD7489B-EC46-47AF-BB68-22F47253228B}\SystemFoldermsiexec.exe () - ()[11/07/2017 07:55:21] - [301392] - C:\WINDOWS\Installer\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:01:13] - [587760] - C:\WINDOWS\Installer\{60251665-84B4-41D6-84BF-6D50CE68DD08}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[26/04/2017 18:51:45] - [88102] - C:\WINDOWS\Installer\{64D5A142-BD50-726E-ED9E-D2508D2A17E2}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:11:37] - [69632] - C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 08:10:21] - [587760] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:10:21] - [587760] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ScVisionDestop_7F7E5B0B4C2946E6A57D5A77942B7F3A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:10:21] - [587760] - C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ScVisionStartMenu_88036A9DCD1D412A84701A23A35FB37B.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:27:21] - [88102] - C:\WINDOWS\Installer\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}\ARPPRODUCTICON.exe () - ()[11/07/2017 07:38:43] - [61136] - C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}\ARPPRODUCTICON.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:38:43] - [65232] - C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}\config_server_B6BD2967C67B44649764F06ADFFD6458.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:38:43] - [65232] - C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}\ROMServer.exe_9D09B2BC25A2414CBD848E2B75898676.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:38:43] - [65232] - C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}\stop_server_51B516B87C64408FA3C56354EA2277C2.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:38:43] - [57040] - C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}\UNINST_Uninstall_L_78AA5B6662514D94A847D6C603AF0895.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[07/07/2017 19:22:44] - [397312] - C:\WINDOWS\Installer\{729B89D0-946A-407E-A121-343BD3320C40}\BOTStartMenu.91E5A071_BE9F_448E_9A60_DD53610492D4.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 18:11:59] - [367104] - C:\WINDOWS\Installer\{77CDA026-3860-4C95-8233-34F3CEF121FB}\RxCIcon.exe () - ()[09/07/2017 20:29:26] - [88102] - C:\WINDOWS\Installer\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}\ARPPRODUCTICON.exe () - ()[04/05/2017 19:37:07] - [733166] - C:\WINDOWS\Installer\{7BA87AB0-2055-11E7-8E16-000C2992F709}\IconName.exe () - ()[11/07/2017 08:24:59] - [313328] - C:\WINDOWS\Installer\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[27/04/2017 10:47:03] - [59352] - C:\WINDOWS\Installer\{7DE129E5-BB4A-4517-A6CD-C69EEB346781}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 08:05:18] - [190448] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\NeroKwikMedia._63C8A7B0BBE5459F9AC436392B2FF50D.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:05:19] - [190448] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\ScKwikMediaDesk_DAE4ED9540AC4C38962344CC52ED8A73.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:05:18] - [190448] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\ScKwikMediaStar_594597E2768645E1995B7F203ACC4488.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:05:19] - [194544] - C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\ScMediaBrowser_9BF9A3F46C13407797C1395E985F61EA.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:06:16] - [587760] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:06:16] - [587760] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\NeroRescueAgent.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:06:16] - [587752] - C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\ScRescueAgentStart_322CFA6F80AB4438A8748366873E3688.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[27/04/2017 10:44:52] - [59352] - C:\WINDOWS\Installer\{7F7C8AE0-961B-4AED-B99A-D9BE29C0F24C}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[09/07/2017 20:28:06] - [88102] - C:\WINDOWS\Installer\{82CA1714-13EA-F419-91FE-12834424745E}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:27:32] - [313328] - C:\WINDOWS\Installer\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 12:21:52] - [58736] - C:\WINDOWS\Installer\{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:30:56] - [313328] - C:\WINDOWS\Installer\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[29/04/2017 09:28:54] - [316416] - C:\WINDOWS\Installer\{8C784F8B-89D0-4A59-A000-7EEF129E1574}\IconA17C9A58.exe () - ()[09/07/2017 20:29:13] - [88102] - C:\WINDOWS\Installer\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}\ARPPRODUCTICON.exe () - ()[29/04/2017 10:43:22] - [123790] - C:\WINDOWS\Installer\{8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}\GooglePasswordDecryptor.exe () - ()[29/04/2017 10:43:22] - [167036] - C:\WINDOWS\Installer\{8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}\SystemFoldermsiexec.exe () - ()[15/11/2016 11:43:46] - [291445] - C:\WINDOWS\Installer\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:28:59] - [88102] - C:\WINDOWS\Installer\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}\ARPPRODUCTICON.exe () - ()[11/07/2017 07:59:58] - [587760] - C:\WINDOWS\Installer\{92EBE575-0C6E-4713-B095-34BB927E5AC6}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[12/11/2016 15:39:44] - [216358] - C:\WINDOWS\Installer\{94E1227C-08A9-4962-B388-1F05D89AEA75}\MSDeployIcon.exe () - ()[11/07/2017 08:23:56] - [313328] - C:\WINDOWS\Installer\{955BF340-C379-4375-AA2F-F3BCB2A498AB}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[29/04/2017 11:03:58] - [183363] - C:\WINDOWS\Installer\{9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}\sxnetworksuite.exe () - ()[29/04/2017 11:03:59] - [167036] - C:\WINDOWS\Installer\{9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}\SystemFoldermsiexec.exe () - ()[11/07/2017 07:45:34] - [301040] - C:\WINDOWS\Installer\{9C637A56-4287-487F-95BF-1422FC1AA879}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 18:13:27] - [53248] - C:\WINDOWS\Installer\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[13/11/2016 19:25:35] - [1241296] - C:\WINDOWS\Installer\{9F205E94-9E42-4486-A92A-DF3F6CB85444}\icon.exe (Copyright (C) 2011) - (EProjManager Application)[09/07/2017 20:28:32] - [88102] - C:\WINDOWS\Installer\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:29:06] - [88102] - C:\WINDOWS\Installer\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}\ARPPRODUCTICON.exe () - ()[27/04/2017 10:42:49] - [59352] - C:\WINDOWS\Installer\{AAF4B2C1-2E27-46EF-9B9E-2B2130F056F3}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[11/07/2017 07:46:56] - [587760] - C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 07:46:56] - [587752] - C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ScControlCenterSta_FC2653898C5047A6A872CAF6433C43A8.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 07:53:54] - [313328] - C:\WINDOWS\Installer\{ACE49D50-19CD-44A6-B192-46F985283B26}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[15/11/2016 11:55:14] - [75223] - C:\WINDOWS\Installer\{ADD5DB49-72CF-11D8-9D75-000129760D75}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:30:18] - [88102] - C:\WINDOWS\Installer\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:07:58] - [301040] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:07:58] - [301040] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ScRecodeStartMenu1_729B957FFE3C40528A62D7F32390F7C3.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:07:58] - [301040] - C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ScRecodeStartMenu_563A75F05683422E8C558ED3B6DA617D.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:28:46] - [88102] - C:\WINDOWS\Installer\{B839153C-D4D2-F89C-5033-0A160C62706B}\ARPPRODUCTICON.exe () - ()[07/07/2017 18:10:22] - [220856] - C:\WINDOWS\Installer\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}\ARPPRODUCTICON.exe () - ()[29/04/2017 10:58:21] - [197719] - C:\WINDOWS\Installer\{BBD54A11-C598-4789-8F12-AA189B3374C2}\SXAntivirusKit.exe () - ()[29/04/2017 10:58:21] - [167036] - C:\WINDOWS\Installer\{BBD54A11-C598-4789-8F12-AA189B3374C2}\SystemFoldermsiexec.exe () - ()[11/07/2017 08:14:22] - [206832] - C:\WINDOWS\Installer\{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}\ScDisc2DeviceStart_31C5D7D15DA846FBB6553A0819A0C381.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[26/04/2017 21:20:11] - [358360] - C:\WINDOWS\Installer\{BECD7155-DC57-4F89-B1A8-A90B033C6209}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[09/07/2017 20:28:13] - [88102] - C:\WINDOWS\Installer\{C1EA3764-1138-AE27-AD63-549BAD99BA15}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:27:05] - [88102] - C:\WINDOWS\Installer\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:22:02] - [313328] - C:\WINDOWS\Installer\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[15/11/2016 11:37:07] - [97873] - C:\WINDOWS\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:28:26] - [88102] - C:\WINDOWS\Installer\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}\ARPPRODUCTICON.exe () - ()[12/11/2016 12:05:44] - [429568] - C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410B}\IconCD95F66111.exe () - ()[12/11/2016 12:05:44] - [230400] - C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410B}\IconCD95F66112.exe () - ()[12/11/2016 12:05:44] - [316928] - C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410B}\IconCD95F66114.exe () - ()[12/11/2016 12:05:45] - [374272] - C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410B}\IconCD95F66117.exe () - ()[07/07/2017 19:48:55] - [401408] - C:\WINDOWS\Installer\{CDE9C04A-7F8B-40A8-A4A5-875E228254A6}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:44:31] - [313328] - C:\WINDOWS\Installer\{CE675FBD-75C3-45F1-B6AF-8D250861D536}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 18:13:54] - [401408] - C:\WINDOWS\Installer\{CE86D656-C887-4EF1-B2D7-2A1075435964}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 18:13:54] - [401408] - C:\WINDOWS\Installer\{CE86D656-C887-4EF1-B2D7-2A1075435964}\NewShortcut1_CB29CAFADE4640CFA655446B98BD0572.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 07:50:04] - [587760] - C:\WINDOWS\Installer\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[14/11/2016 08:53:30] - [212024] - C:\WINDOWS\Installer\{D25D3E15-CABD-420c-B62C-70C1C5EE63FD}\ARPPRODUCTICON.exe () - ()[29/04/2017 11:08:40] - [195098] - C:\WINDOWS\Installer\{D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}\sxsystemsuite.exe () - ()[29/04/2017 11:08:41] - [167036] - C:\WINDOWS\Installer\{D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}\SystemFoldermsiexec.exe () - ()[27/04/2017 10:54:17] - [358360] - C:\WINDOWS\Installer\{D7BF2029-EB2D-4523-AFA0-95CE605E696E}\ARPPRODUCTICON.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[27/04/2017 10:54:17] - [358360] - C:\WINDOWS\Installer\{D7BF2029-EB2D-4523-AFA0-95CE605E696E}\NewShortcut1_9D26517437AB43F988CAFF4AC3CA05DE.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[27/04/2017 10:54:17] - [358360] - C:\WINDOWS\Installer\{D7BF2029-EB2D-4523-AFA0-95CE605E696E}\NewShortcut6_46B5678CC4A24F4AA166FBA0D99B16EE.exe (Copyright (c) 2012 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[29/04/2017 10:30:21] - [56568] - C:\WINDOWS\Installer\{D881F038-D767-45AA-90C1-1E5411A9670A}\ARPPRODUCTICON.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[29/04/2017 10:30:21] - [56568] - C:\WINDOWS\Installer\{D881F038-D767-45AA-90C1-1E5411A9670A}\NewShortcut11_3A13657E2A9B474C9CBE8FC99A3952AD.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[29/04/2017 10:30:21] - [56568] - C:\WINDOWS\Installer\{D881F038-D767-45AA-90C1-1E5411A9670A}\NewShortcut1_668AB6C34E564B2590F1D18F53BCB9E4.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[29/04/2017 10:30:21] - [56568] - C:\WINDOWS\Installer\{D881F038-D767-45AA-90C1-1E5411A9670A}\UNINST_Uninstall_C_A54A9B508C1B4A67A668BB79335F88A9.exe (Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.) - (InstallShield)[07/07/2017 12:20:23] - [53248] - C:\WINDOWS\Installer\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[29/04/2017 10:51:57] - [167036] - C:\WINDOWS\Installer\{DD3D64A7-3165-458D-96D4-06FBC609C22A}\SystemFoldermsiexec.exe () - ()[29/04/2017 10:51:57] - [123790] - C:\WINDOWS\Installer\{DD3D64A7-3165-458D-96D4-06FBC609C22A}\VistaUACMaker.exe () - ()[11/07/2017 07:48:53] - [313328] - C:\WINDOWS\Installer\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[15/11/2016 11:56:44] - [82613] - C:\WINDOWS\Installer\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\ARPPRODUCTICON.exe () - ()[29/04/2017 10:48:18] - [167036] - C:\WINDOWS\Installer\{E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}\SystemFoldermsiexec.exe () - ()[29/04/2017 10:48:18] - [132914] - C:\WINDOWS\Installer\{E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}\WinServiceManager.exe () - ()[09/07/2017 20:29:44] - [4846] - C:\WINDOWS\Installer\{E7366CA8-7179-77AE-E712-BA18D70A0A07}\ARPPRODUCTICON.exe () - ()[09/07/2017 20:28:39] - [88102] - C:\WINDOWS\Installer\{E817E580-6318-AFC8-2102-322C73117EC4}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:38:02] - [313328] - C:\WINDOWS\Installer\{EEBF1676-AF87-4266-93D8-0C14A34C4217}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:12:01] - [296944] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:12:01] - [296944] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\NeroLauncher.ex_06255901E67449719980557FAA5EC1C6.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:12:01] - [296944] - C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\NeroLauncher.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[11/07/2017 08:17:19] - [296944] - C:\WINDOWS\Installer\{F030BFE8-8476-4C08-A553-233DE80A2BE1}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[06/07/2017 12:00:33] - [4963152] - C:\WINDOWS\Installer\{F0CF025B-D6F3-4F7C-939B-23291F52875C}\ParagonExtFSforWindows.exe (Copyright (C) 2017) - (Graphic user interface for Paragon ExtFS for Windows mounter)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\CreatorClassicShor_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\JustBurnShortcut_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\LabelCreatorShortc_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\MusicDiscCreatorSh_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\MyDVDShortcut_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [393216] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\NewShortcut4_6867FCADEAC145408C976B281636C8BD.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\PhotoSuiteShortcut_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [65536] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\Samples3DShortcut_D0DF8F611E3F48FE9118660DE37C8731.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\SoundEditorShortcu_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [172032] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\TripleScoopShortcu_1D7186847A244C0ABFE0D5B42F0EA045.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [65536] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\Video3DShortcut_BE64BD4FCE81490FBF71DAB484FD436F.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\VideoConvertShortc_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:00:19] - [327680] - C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\VideoWaveShortcut_2099C17679884B91BF99B6C0521D142A.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[09/07/2017 20:27:29] - [88102] - C:\WINDOWS\Installer\{F77474EE-EB6C-C87B-88AF-3310C848E068}\ARPPRODUCTICON.exe () - ()[29/04/2017 11:11:51] - [183914] - C:\WINDOWS\Installer\{F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}\APPDIR_1.exe () - ()[29/04/2017 11:11:51] - [167036] - C:\WINDOWS\Installer\{F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}\SystemFoldermsiexec.exe () - ()[12/11/2016 13:52:52] - [134817] - C:\WINDOWS\Installer\{F8C774EE-B937-4694-9BE4-D20167FCF20F}\ARPPRODUCTICON.exe () - ()[12/11/2016 13:52:52] - [176128] - C:\WINDOWS\Installer\{F8C774EE-B937-4694-9BE4-D20167FCF20F}\FR_DskTp_ShrtCt_6242ECAD76714BAA83F0791073A22A60.exe (Copyright (C) 2006 Macrovision Corporation) - (InstallShield)[12/11/2016 13:52:52] - [176128] - C:\WINDOWS\Installer\{F8C774EE-B937-4694-9BE4-D20167FCF20F}\FR_PCm_Mnu_ShrtCt_6242ECAD76714BAA83F0791073A22A60.exe (Copyright (C) 2006 Macrovision Corporation) - (InstallShield)[12/11/2016 13:52:52] - [65536] - C:\WINDOWS\Installer\{F8C774EE-B937-4694-9BE4-D20167FCF20F}\Fr_StartUpThis_Shr_6242ECAD76714BAA83F0791073A22A60.exe (Copyright (C) 2006 Macrovision Corporation) - (InstallShield)[09/07/2017 20:27:15] - [88102] - C:\WINDOWS\Installer\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}\ARPPRODUCTICON.exe () - ()[11/07/2017 08:43:29] - [313328] - C:\WINDOWS\Installer\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}\ARPPRODUCTICON.exe (Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.) - (InstallShield)[07/07/2017 19:18:18] - [18944] - C:\WINDOWS\Installer\{FFAC39DA-CF79-434B-A6E0-4055689667D9}\CPIcon.exe () - () ---------- | %System%\*.in* [18/03/2017 22:56:50] - [3458] - C:\WINDOWS\System32\ieuinit.inf[26/10/2012 17:42:24] - [29494] - C:\WINDOWS\System32\lvcoin64.ini[22/07/2017 15:35:37] - [4160] - C:\WINDOWS\System32\ocsvc.ini[22/07/2017 15:34:38] - [12560] - C:\WINDOWS\System32\ocsvcOff.ini[26/04/2017 18:52:14] - [3559480] - C:\WINDOWS\System32\PerfStringBackup.INI[18/03/2017 22:58:24] - [60124] - C:\WINDOWS\System32\tcpmon.ini[18/03/2017 22:57:50] - [2307] - C:\WINDOWS\System32\WimBootCompress.ini[18/03/2017 22:59:49] - [3458] - C:\WINDOWS\Syswow64\ieuinit.inf[22/07/2017 15:34:37] - [4160] - C:\WINDOWS\Syswow64\ocsvc.ini[22/07/2017 15:34:38] - [12560] - C:\WINDOWS\Syswow64\ocsvcOff.ini[26/04/2017 18:52:03] - [1978024] - C:\WINDOWS\Syswow64\PerfStringBackup.INI[10/07/2017 20:41:35] - [1069] - C:\WINDOWS\Syswow64\vbrun60.inf[18/03/2017 22:58:48] - [2307] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan [MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1.36 Ko] - C:\WINDOWS\AppPatch\Custom\Custom64[MD5.5168D79177585FF036B6B44D9E3B875F] - |A| - [12/11/2016 16:14:01] - (. - .) - [1.36 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\Custom\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb[MD5.A681527B9F23DD5F1A6C8D3F621E814E] - |AC| - [18/03/2017 22:57:20] - (. - .) - [14.73 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\AppPatch64\pcamain.sdb[MD5.5FDD24FAC55C4D679046EE4ECA3F7D46] - |AC| - [11/07/2017 23:02:50] - (. - .) - [552.6 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\AppPatch64\sysmain.sdb[MD5.00000000000000000000000000000000] - |D| - [21/07/2017 17:52:11] - [1.44 Ko] - C:\WINDOWS\Temp\Comodo LogsFolder[MD5.5471BD911D4641352724586B803E42CC] - |A| - [22/07/2017 15:35:22] - (. - .) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\cpinstall.log[MD5.C051CD25A8DD48D1DD7269F7DBFED7D5] - |A| - [22/07/2017 15:35:22] - (.Copyright (C) 2008-2011 NordNet S.A. - Désinstalleur Du Contrôle Parental .) - [381.5 Ko] - (6.5.1.0) - C:\WINDOWS\Temp\cpremove64.exe[MD5.00000000000000000000000000000000] - |D| - [22/07/2017 17:24:49] - [0.04 Ko] - C:\WINDOWS\Temp\Crashpad[MD5.D59A42EB178ED99FC4E841DBC45AFFC5] - |A| - [22/07/2017 15:35:14] - (. - .) - [0.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ctengine_custom_cat_repl_kit.ini[MD5.07DC96EF36A5DE38D031F08C2F2DACFE] - |A| - [22/07/2017 15:35:13] - (. - .) - [12.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ctengine_repl_kit_1.ini[MD5.0D649E34C2552C4965694F51A18AEB15] - |A| - [22/07/2017 15:35:12] - (. - .) - [67.37 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ctengine_tld.dat[MD5.00000000000000000000000000000000] - |D| - [22/07/2017 15:35:14] - [0 Ko] - C:\WINDOWS\Temp\cteng_ccpd[MD5.00000000000000000000000000000000] - |D| - [22/07/2017 15:35:02] - [0 Ko] - C:\WINDOWS\Temp\customRules[MD5.EE5EC98179105AA1A19006794A955EBD] - |A| - [21/07/2017 17:52:13] - (. - .) - [14.23 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LFSULTRA-WIDEN-20170721-1752.log[MD5.EA16B2FD472A1906ED77784F4A98BFA6] - |A| - [21/07/2017 13:36:38] - (. - .) - [1.98 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpCmdRun.log[MD5.D43F500CD6D337D90DED09A34A4D77E5] - |A| - [22/07/2017 15:35:10] - (. - .) - [54.05 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ocsvc.log[MD5.2A795B7A3746E8E03E4A9EC8870DF6FC] - |A| - [22/07/2017 15:35:09] - (. - .) - [7.4 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ocsvcr.log[MD5.4F26C2ADBED03F064BC7D5BC5BFE16AE] - |A| - [22/07/2017 15:35:22] - (. - .) - [3.5 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\RegisterLsp.log[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:26] - [0 Ko] - C:\WINDOWS\System32\0409[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 11:45:55] - [410.05 Ko] - C:\WINDOWS\System32\1033[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 11:11:16] - [29.19 Ko] - C:\WINDOWS\System32\1036[MD5.82C37C3E27020AF6C2E018E944284676] - |AC| - [18/03/2017 22:57:42] - (. - .) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AudioToastIcon.png[MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |AC| - [18/03/2017 22:58:18] - (. - .) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@BackgroundAccessToastIcon.png[MD5.3937359E324E15F6A7A7092D4DAEBD64] - |AC| - [18/03/2017 22:57:25] - (. - .) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@bitlockertoastimage.png[MD5.495C1F072039B434827A5FE0D9761E4D] - |AC| - [18/03/2017 22:58:17] - (. - .) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@EnrollmentToastIcon.png[MD5.373CF57FF3DAAEEB629F90CE7226B30D] - |AC| - [18/03/2017 22:58:29] - (. - .) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@language_notification_icon.png[MD5.46DACDA5036EBECEDF08427407E3017C] - |AC| - [18/03/2017 22:58:29] - (. - .) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@optionalfeatures.png[MD5.1622DE67156496C78D6B7BE9B471645B] - |AC| - [18/03/2017 22:58:21] - (. - .) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@VpnToastIcon.png[MD5.7AC3EA1A5175106ED6467FF0C5315541] - |AC| - [18/03/2017 22:58:18] - (. - .) - [14.75 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WiFiNotificationIcon.png[MD5.13EF2C8D799F7B6E9D8E3D6BACB9C779] - |AC| - [18/03/2017 22:57:53] - (. - .) - [0.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsHelloFaceToastIcon.png[MD5.F553B252FEC3134D4F5303D9B25298B3] - |AC| - [18/03/2017 22:56:40] - (. - .) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.png[MD5.D0FCF781D0801ABF5F74B54E98076A5B] - |AC| - [18/03/2017 22:58:13] - (. - .) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WwanNotificationIcon.png[MD5.85D91E478AF18125007C531227FF6E59] - |AC| - [18/03/2017 22:58:13] - (. - .) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WwanSimLockIcon.png[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:24] - [2979.4 Ko] - C:\WINDOWS\System32\AdvancedInstallers[MD5.4B10D8998C824DD84AD597F9E058F6F0] - |A| - [30/07/2015 22:58:04] - (. - .) - [171.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amde31a.dat[MD5.C7628FE6341B7919D2F62DB9057DB4FC] - |A| - [21/10/2015 03:14:42] - (. - .) - [208.48 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amdgfxinfo64.dll[MD5.AF1928F5E15921A29877C2E18626F80E] - |A| - [21/10/2015 03:14:42] - (. - .) - [139.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amdhdl64.dll[MD5.DDEB20626133878B0CE79CCE29B031B9] - |A| - [23/07/2015 12:52:32] - (. - .) - [814.26 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amdicdxx.dat[MD5.82CAB4EAF1E1CBA85AE5DEBB4C068EE2] - |A| - [21/10/2015 03:14:42] - (.Advanced Micro Devices, Inc. Copyright (C) 2015 - LiquidVR SDK 1.0.) - [616.48 Ko] - (1.0.3.8) - C:\WINDOWS\System32\amdlvr64.dll[MD5.C366C5A2EE8F1F586691E4511AB56040] - |A| - [21/10/2015 03:14:42] - (.Copyright (C) 2013 AMD Inc. - Mantle driver, support for SI family and above.) - [6529.48 Ko] - (9.1.10.83) - C:\WINDOWS\System32\amdmantle64.dll[MD5.3960C946E67311C9831550AEDC649C3A] - |A| - [21/10/2015 03:14:54] - (. - .) - [460.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amdmiracast.dll[MD5.4CA9A0DF33972919623BBFF8FBD1A501] - |A| - [21/10/2015 03:14:42] - (.Copyright (c) 2013 Advanced Micro Devices, Inc. - Radeon MMOCL Universal Driver.) - [57.98 Ko] - (1.6.0.0) - C:\WINDOWS\System32\amdmmcl6.dll[MD5.7BA9A6BBF176D945D7B201865897E158] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD COMPILER OpenCL 1.1 Compiler.) - [26898.98 Ko] - (0.8.0.0) - C:\WINDOWS\System32\amdocl12cl64.dll[MD5.AFF92249DA8E62FF8C6D2B89977D3245] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OpenCL 2.0 Runtime.) - [46673.98 Ko] - (10.0.1800.11) - C:\WINDOWS\System32\amdocl64.dll[MD5.8305AA2FEBE5CAD45AB8D208C17DA930] - |A| - [21/10/2015 03:14:44] - (. - .) - [1168 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amdocl_as64.exe[MD5.187EB6A72565FAAF01AAE0CDD63DE56F] - |A| - [21/10/2015 03:14:44] - (. - .) - [1045.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amdocl_ld64.exe[MD5.2B79CD2445F85D54959702583ECBCC04] - |A| - [21/10/2015 03:14:54] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [85.94 Ko] - (8.14.10.23) - C:\WINDOWS\System32\amdpcom64.dll[MD5.C0F1FF923616DEDEAA7655F7FA03FD06] - |A| - [24/04/2017 15:30:37] - (. - .) - [3117.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\APMBoot.exe[MD5.E21E74D118E16FF9BA42A6F87F34E9B0] - |AC| - [18/03/2017 22:57:00] - (. - .) - [435.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ApnDatabase.xml[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\AppLocker[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2480.52 Ko] - C:\WINDOWS\System32\appraiser[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [273.5 Ko] - C:\WINDOWS\System32\ar-SA[MD5.28DF09388444100467873AC906FD6CB2] - |A| - [21/10/2015 03:14:44] - (.Copyright (C) 2008-2014 Advanced Micro Devices, Inc. - ADL.) - [1226.98 Ko] - (7.15.20.1301) - C:\WINDOWS\System32\atiadlxx.dll[MD5.53650482B8E621276DC55E50C9FB2FEE] - |A| - [22/08/2015 02:53:34] - (. - .) - [646.87 Ko] - (0.0.0.0) - C:\WINDOWS\System32\atiapfxx.blb[MD5.CC2470CA903EA355A24F05520D79BDB8] - |A| - [21/10/2015 03:14:44] - (.Copyright (C) 2009 Advanced Micro Devices, Inc. - atiapfxx Application.) - [366.98 Ko] - (6.14.10.1001) - C:\WINDOWS\System32\atiapfxx.exe[MD5.279066332FA267076E3BEE81C4297F87] - |A| - [21/10/2015 03:14:44] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL compiler runtime.) - [62.98 Ko] - (6.14.10.1848) - C:\WINDOWS\System32\aticalcl64.dll[MD5.3A0F17C7C8E37DCEAE1DA76B7D761702] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL DD.) - [15356.98 Ko] - (6.14.10.1848) - C:\WINDOWS\System32\aticaldd64.dll[MD5.D22A08EE217DE15B6A41AE518B4F4FBE] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL runtime.) - [69.48 Ko] - (6.14.10.1848) - C:\WINDOWS\System32\aticalrt64.dll[MD5.BE92AD0155D4A23D0073AF51BE808B29] - |A| - [21/10/2015 03:14:54] - (.Copyright (C) 1998-2012 AMD Inc. - aticfx64.dll.) - [1445.13 Ko] - (8.17.10.1404) - C:\WINDOWS\System32\aticfx64.dll[MD5.B565601728AF96EEFCF7E9CDE3CDD2BE] - |A| - [21/10/2015 03:14:46] - (.2002-2012 - Graphics DEM.) - [440.48 Ko] - (4.5.5711.37472) - C:\WINDOWS\System32\atidemgy.dll[MD5.8700278344BED8D4A3A5AC2875359584] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 1998-2011 AMD Inc. - atidxx64.dll.) - [11804.69 Ko] - (8.17.10.625) - C:\WINDOWS\System32\atidxx64.dll[MD5.69F82C40A189962A65F6D5A02DF8599F] - |A| - [21/10/2015 03:14:46] - (. - .) - [164.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\atieah64.exe[MD5.B96BD9F5B2B0CD6549EE59FD242A6D56] - |A| - [21/10/2015 03:14:46] - (.Copyright © 2008-2009 AMD - AMD External Events Client Module.) - [667.48 Ko] - (6.14.11.1199) - C:\WINDOWS\System32\atieclxx.exe[MD5.521248FA26458669BAAE6AB7DB21F3AC] - |A| - [21/10/2015 03:14:46] - (.Copyright © 2008-2009 AMD - AMD External Events Service Module.) - [249.48 Ko] - (6.14.11.1199) - C:\WINDOWS\System32\atiesrxx.exe[MD5.E4F96DFF0501430BF7C6E90841A7282D] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiglpxx.dll.) - [81.98 Ko] - (8.14.1.6463) - C:\WINDOWS\System32\atig6pxx.dll[MD5.86F2AE002AF9222F34937823B98753C2] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atigktxx.dll.) - [161.48 Ko] - (8.14.1.6463) - C:\WINDOWS\System32\atig6txx.dll[MD5.0C3156664885AF41100B63853EBCE037] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiglpxx.dll.) - [76.48 Ko] - (8.14.1.6463) - C:\WINDOWS\System32\atiglpxx.dll[MD5.079EFFD5BECB418FE6596229B28D7324] - |A| - [06/11/2014 11:53:26] - (. - .) - [720.13 Ko] - (0.0.0.0) - C:\WINDOWS\System32\atiicdxx.dat[MD5.FE4E7138E51DA7EF01E51F28128A7F53] - |A| - [21/10/2015 03:14:54] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [85.94 Ko] - (8.14.10.23) - C:\WINDOWS\System32\atimpc64.dll[MD5.C84C24F13663EF5A59C1E598A350C8C3] - |A| - [21/10/2015 03:14:46] - (.Copyright ? 2009 AMD - Multi-language DPPE DLL.) - [37.48 Ko] - (6.14.10.1002) - C:\WINDOWS\System32\atimuixx.dll[MD5.7D9CCB5DD8837D6AC954956A5812112C] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 1998-2011 Advanced Micro Devices, Inc. - AMD OpenGL driver.) - [30054.98 Ko] - (6.14.10.13399) - C:\WINDOWS\System32\atio6axx.dll[MD5.0E89795F721B2BC02D0A12C470750DF6] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2008 - ATIODCLI Application.) - [58.48 Ko] - (1.0.0.1) - C:\WINDOWS\System32\ATIODCLI.exe[MD5.C7A506822BE45CD42415710979CDAE7F] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2008 - ATIODE Application.) - [333.48 Ko] - (1.0.0.1) - C:\WINDOWS\System32\ATIODE.exe[MD5.3FE40633FC3BC5AE41EACDA0E1BA72FE] - |A| - [21/10/2015 03:14:46] - (.Copy Right © 2012 Advanced Micro Devices, Inc - TMM Clone Control Module.) - [194.98 Ko] - (6.14.11.25) - C:\WINDOWS\System32\atitmm64.dll[MD5.067CED045532C58B46E6527BCE3CB47F] - |A| - [21/10/2015 03:14:54] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiu9pag.dll.) - [127.02 Ko] - (8.14.1.6463) - C:\WINDOWS\System32\atiu9p64.dll[MD5.AC6970C74B7457B291BB2C0035AA7DAE] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 1998-2011 AMD Inc. - atiumd64.dll.) - [8657.15 Ko] - (9.14.10.1128) - C:\WINDOWS\System32\atiumd64.dll[MD5.486D6985E7B7826DBBEAE12755851027] - |A| - [22/08/2015 02:55:34] - (. - .) - [3357.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\atiumd6a.cap[MD5.0A9CA09952D768F768D2903F984102DC] - |A| - [21/10/2015 03:14:56] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon Video Acceleration Universal Driver.) - [8771.91 Ko] - (8.14.10.513) - C:\WINDOWS\System32\atiumd6a.dll[MD5.AE81C76C930DD6875E5D9C6BEA2F0966] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiuxpag.dll.) - [158.43 Ko] - (8.14.1.6463) - C:\WINDOWS\System32\atiuxp64.dll[MD5.EFA5E3D55F1CC185BC690B7D79D015A9] - |A| - [24/07/2015 22:44:06] - (. - .) - [98.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativce02.dat[MD5.B974290EEE645249EE212FF62DD0824A] - |A| - [30/07/2015 23:00:06] - (. - .) - [173.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativce03.dat[MD5.5EBC73A78E5903E7CE6F6B25E4A6BE8F] - |A| - [29/05/2015 02:00:42] - (. - .) - [228.93 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_cik.dat[MD5.C55D2CBC17AAE1FBAC9135E7C31A4D31] - |A| - [29/05/2015 01:58:32] - (. - .) - [227.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_cik_nd.dat[MD5.0770A5AB5218E6D3134A7A7239B9A216] - |A| - [29/05/2015 02:21:32] - (. - .) - [249.81 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_cz_nd.dat[MD5.A81F68A0D3387A06182EFA3880D3F0BD] - |A| - [29/05/2015 02:17:24] - (. - .) - [245 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_FJ.dat[MD5.7EE8F6853798F7A900DB15F3054A0277] - |A| - [29/05/2015 02:15:12] - (. - .) - [243.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_FJ_nd.dat[MD5.11355CAC5334C8999211C09CAAE194EF] - |A| - [29/05/2015 02:10:58] - (. - .) - [315.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_vi.dat[MD5.3544D6AF6E0C9783C2CF6FA9CE42D520] - |A| - [29/05/2015 02:08:18] - (. - .) - [313.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvaxy_vi_nd.dat[MD5.7C163EDE63854539828F5B2C1BC529FD] - |A| - [22/08/2015 02:54:10] - (. - .) - [153.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvsva.dat[MD5.219D7091DD1D93728392337FE9C7ADD6] - |A| - [22/08/2015 02:54:10] - (. - .) - [200.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ativvsvl.dat[MD5.EFFD0ABB4DDD2CCDD511F903D042AD5B] - |AC| - [18/03/2017 22:57:05] - (. - .) - [77.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AverageRoom.bin[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [255.5 Ko] - C:\WINDOWS\System32\bg-BG[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4546.61 Ko] - C:\WINDOWS\System32\Boot[MD5.B13766AFE48C3CF775F53CE90488F7DE] - |AC| - [18/03/2017 22:57:03] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [90.5 Ko] - (1.0.0.1) - C:\WINDOWS\System32\BthpanContextHandler.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.93 Ko] - C:\WINDOWS\System32\Bthprops[MD5.4B307488C9D3D1030DEC61FA4DAC7EE0] - |RAC| - [18/03/2017 22:59:10] - (. - .) - [116.23 Ko] - (0.0.0.0) - C:\WINDOWS\System32\CaptureBrackets.hcp[MD5.DC112F4CFDF23AAF5CB0F46BE92CB1CE] - |RAC| - [18/03/2017 22:59:10] - (. - .) - [122.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\CaptureCountdown.hcp[MD5.F80C2CB1D5A28528D662B0DDF440F0F3] - |RAC| - [18/03/2017 22:59:10] - (. - .) - [17.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\CaptureToast.hcp[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [124398.02 Ko] - C:\WINDOWS\System32\CatRoot[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [86308.76 Ko] - C:\WINDOWS\System32\catroot2[MD5.F18E1F295EBB5FDD7E6D93571113E5A8] - |A| - [28/04/2017 13:10:08] - (.Copyright © 2001-2015 GoPro Inc. - CineForm DirectShow Decoder.) - [1221 Ko] - (9.2.1.690) - C:\WINDOWS\System32\CFDecode64.ax[MD5.F2D598B11C294EE360FDA0D3E81DA7EC] - |A| - [21/10/2015 03:14:48] - (. - .) - [237.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\clinfo.exe[MD5.CAD88BE2600A38A7E418DC6442334C77] - |A| - [08/06/2017 04:45:56] - (.2005-2017 COMODO. All rights reserved. - COMODO Internet Security.) - [50.59 Ko] - (10.0.1.6258) - C:\WINDOWS\System32\cmdcsr.dll[MD5.95E47BB303FCDCFD0252917F89BFC707] - |A| - [08/06/2017 04:43:12] - (.2005-2017 COMODO. All rights reserved. - COMODO Internet Security.) - [446.69 Ko] - (10.0.1.6258) - C:\WINDOWS\System32\cmdvrt64.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2938.57 Ko] - C:\WINDOWS\System32\CodeIntegrity[MD5.A0E91D21C945781D03EA0BA1C95F821E] - |A| - [21/10/2015 03:14:48] - (.AMD. - CoInstaller DLL.) - [853.98 Ko] - (1.0.5.9) - C:\WINDOWS\System32\coinst_15.20.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [357.5 Ko] - C:\WINDOWS\System32\Com[MD5.71FE8439182F423E4A93E3BFFF3525F8] - |A| - [22/07/2017 15:29:56] - (.2013 © Real Sound Lab SIA, iSoft Solutions - CONEQ™ Media Suite APO GUI Library.) - [119.45 Ko] - (1.0.0.4) - C:\WINDOWS\System32\CONEQMSAPOGUILibrary.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [570414.9 Ko] - C:\WINDOWS\System32\config[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [51.27 Ko] - C:\WINDOWS\System32\Configuration[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [300.5 Ko] - C:\WINDOWS\System32\cs-CZ[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [295 Ko] - C:\WINDOWS\System32\da-DK[MD5.75BC227ACD70C906785DB11F853165E4] - |AC| - [18/03/2017 22:58:29] - (. - .) - [84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DataStoreCacheDumpTool.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [190.86 Ko] - C:\WINDOWS\System32\DDFs[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [333 Ko] - C:\WINDOWS\System32\de-DE[MD5.618BA9E529EAB7E11DBA43469481835F] - |AC| - [18/03/2017 22:57:05] - (. - .) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultHrtfs.bin[MD5.664AA698FC0106A2B075A641E8DC6302] - |A| - [18/03/2017 23:03:37] - (. - .) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultQuestions.json[MD5.B227DF8720C51EE0A80CB23CCCEF1EC6] - |A| - [26/10/2012 17:42:24] - (. - .) - [328.35 Ko] - (13.80.853.0) - C:\WINDOWS\System32\DevManagerCore.dll[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [870 Ko] - C:\WINDOWS\System32\DiagSvcs[MD5.E82380D30048D73E4D4CB8C925F6E721] - |AC| - [18/03/2017 22:57:58] - (. - .) - [90.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DiskSnapshot.conf[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:22] - [7526.04 Ko] - C:\WINDOWS\System32\Dism[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:22] - [1126.54 Ko] - C:\WINDOWS\System32\downlevel[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:02:55] - [133866.19 Ko] - C:\WINDOWS\System32\drivers[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [1437776.96 Ko] - C:\WINDOWS\System32\DriverStore[MD5.00000000000000000000000000000000] - |DC| - [15/11/2016 11:34:26] - [907.36 Ko] - C:\WINDOWS\System32\DRVSTORE[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [159 Ko] - C:\WINDOWS\System32\dsc[MD5.B438E6C7A6C395E0C2B31E80112C3ACE] - |AC| - [11/07/2017 23:03:03] - (. - .) - [31.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\edgehtmlpluginpolicy.bin[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [329.5 Ko] - C:\WINDOWS\System32\el-GR[MD5.45753B2B17E144450F611AE8C5AEB447] - |A| - [26/04/2017 20:07:12] - (. - .) - [22.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\emptyregdb.dat[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:26] - [0 Ko] - C:\WINDOWS\System32\en[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [242.5 Ko] - C:\WINDOWS\System32\en-GB[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2159.03 Ko] - C:\WINDOWS\System32\en-US[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [322 Ko] - C:\WINDOWS\System32\es-ES[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [266 Ko] - C:\WINDOWS\System32\es-MX[MD5.BAC5074667751F72A9CE48CDC31BAC48] - |A| - [10/11/2016 19:36:30] - (.Copyright (C) 2007 SEIKO EPSON CORP. - E_GCINST.) - [10.5 Ko] - (1.0.0.6) - C:\WINDOWS\System32\E_GCINST.DLL[MD5.8159960E8BA20F1C4A4EBCF0DAEC60E5] - |A| - [10/11/2016 19:36:28] - (.Copyright (C) SEIKO EPSON CORPORATION 2005-2010. All rights reserved. - ECBTEGB AMD64.) - [82 Ko] - (3.3.0.0) - C:\WINDOWS\System32\E_ID4BLPE.DLL[MD5.2E21840342850A8A7F28D28D6DD3A1CD] - |A| - [10/11/2016 19:36:28] - (.Copyright (C) SEIKO EPSON CORPORATION 2005-2013. All rights reserved. - EPSON Bi-directional Monitor AMD64.) - [175.5 Ko] - (4.4.0.0) - C:\WINDOWS\System32\E_ILMBLPE.DLL[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [28452.16 Ko] - C:\WINDOWS\System32\F12[MD5.E5421FB92280483FA59B6518C70B3319] - |A| - [14/11/2016 09:12:40] - (.Copyright (C) 2005-2011 CHENGDU YIWO Tech Development Co., Ltd. All rights reserved. - EaseUS Todo Backup Application.) - [23.54 Ko] - (3.0.0.1) - C:\WINDOWS\System32\fbnative.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [300.5 Ko] - C:\WINDOWS\System32\fi-FI[MD5.C864A615CB48497666C66943C0632C2D] - |A| - [17/07/2017 08:29:01] - (. - .) - [401.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FNTCACHE.DAT[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:26] - [3402.5 Ko] - C:\WINDOWS\System32\fr[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [273 Ko] - C:\WINDOWS\System32\fr-CA[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [44637.75 Ko] - C:\WINDOWS\System32\fr-FR[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\FxsTmp[MD5.D07F2281427BD098356EE74B6CB26B86] - |AC| - [18/03/2017 22:57:02] - (. - .) - [89 Ko] - (0.0.0.0) - C:\WINDOWS\System32\gatherNetworkInfo.vbs[MD5.11A5AB0B1F9D8A9E6E1A71DB425F1715] - |A| - [22/07/2017 16:15:27] - (.Copyright c 2003 - GeneIcon.) - [5504.19 Ko] - (1.2.0.0) - C:\WINDOWS\System32\GeneIcon.dll[MD5.42BAF90B44A46A7B1DCB240947A4AAE9] - |A| - [21/07/2017 11:12:32] - (.Copyright (C) 2015 - GeneStor co-installer .) - [150.16 Ko] - (2.0.0.1) - C:\WINDOWS\System32\GSCoinst.dll[MD5.C08851203DCB142441C6E33B78EF6002] - |A| - [08/06/2017 04:45:38] - (.2005-2017 COMODO. All rights reserved. - COMODO Internet Security.) - [920.2 Ko] - (10.0.1.6258) - C:\WINDOWS\System32\guard64.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [260.5 Ko] - C:\WINDOWS\System32\he-IL[MD5.762F865F75F21FCB260E7C95404B5110] - |AC| - [18/03/2017 22:58:18] - (. - .) - [122.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeatCore.dll[MD5.7B7859030FF4D38A912A7BCC4A1B3B5E] - |AC| - [18/03/2017 22:59:09] - (. - .) - [14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HolographicShareInterop.ProxyStub.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [249 Ko] - C:\WINDOWS\System32\hr-HR[MD5.77071BF934BEF16D5F02E31624258A91] - |A| - [21/10/2015 03:14:48] - (. - .) - [108.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\hsa-thunk64.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [304.5 Ko] - C:\WINDOWS\System32\hu-HU[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:11:49] - [31.52 Ko] - C:\WINDOWS\System32\Hydrogen[MD5.A565537F1580872AE5B95D0CA457D780] - |AC| - [18/03/2017 22:58:01] - (. - .) - [44.4 Ko] - (0.0.0.0) - C:\WINDOWS\System32\hypervisor.mof[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [5.36 Ko] - C:\WINDOWS\System32\ias[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [36.27 Ko] - C:\WINDOWS\System32\icsxml[MD5.6DF9BA3AD0CD866EE939C4C49CEA7B30] - |AC| - [18/03/2017 22:57:35] - (. - .) - [188.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\IHDS.dll[MD5.FC70C3475E474302DC500F735442BCD2] - |A| - [10/03/2017 03:36:06] - (. - .) - [696.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\im-fre.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [25951.17 Ko] - C:\WINDOWS\System32\IME[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\inetsrv[MD5.479B7966309A411BF4FC34898AC96557] - |A| - [18/03/2017 22:58:10] - (. - .) - [134.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputHost.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [6446.5 Ko] - C:\WINDOWS\System32\InputMethod[MD5.D506921989872994B9C5615D4761882C] - |A| - [22/07/2017 12:11:34] - (.Copyright © 2005-2016 - IObit Smart Defrag Extension.) - [125.28 Ko] - (1.0.0.25) - C:\WINDOWS\System32\IObitSmartDefragExtension.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\Ipmi[MD5.BBD33293FB4F5C2461C1C399BE293717] - |A| - [11/07/2017 11:02:04] - (.2005-2017 COMODO. All rights reserved. - Internet Security Essentials.) - [250.04 Ko] - (1.2.28809.92) - C:\WINDOWS\System32\iseguard64.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [326.5 Ko] - C:\WINDOWS\System32\it-IT[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [236 Ko] - C:\WINDOWS\System32\ja-jp[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [233.5 Ko] - C:\WINDOWS\System32\ko-KR[MD5.050BC9351A3386458B696F8BCA78B27B] - |AC| - [18/03/2017 22:57:05] - (. - .) - [145.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LargeRoom.bin[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [79.18 Ko] - C:\WINDOWS\System32\Licenses[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1093 Ko] - C:\WINDOWS\System32\LogFiles[MD5.B65E8E52916A527F88486875EE291AA8] - |A| - [26/10/2012 17:42:22] - (. - .) - [10663.85 Ko] - (13.80.853.0) - C:\WINDOWS\System32\LogiDPP.dll[MD5.24764C249F769991079F6D4B14B822AF] - |A| - [26/10/2012 17:42:22] - (. - .) - [100.85 Ko] - (13.80.853.0) - C:\WINDOWS\System32\LogiDPPApp.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [244.5 Ko] - C:\WINDOWS\System32\lt-LT[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [246.5 Ko] - C:\WINDOWS\System32\lv-LV[MD5.4D4248F6D008D86D5575EE5B154971AE] - |A| - [26/10/2012 17:42:22] - (.(c) 1996-2012 Logitech. All rights reserved. - Logitech Co-Installer.) - [256.28 Ko] - (13.80.853.0) - C:\WINDOWS\System32\lvco1380853.dll[MD5.FF510CF2A7FA73192E7DB06D7C311799] - |A| - [26/10/2012 17:42:24] - (.(c) 1996-2012 Logitech. All rights reserved. - Video Codec.) - [171.28 Ko] - (13.80.853.0) - C:\WINDOWS\System32\lvcod64.dll[MD5.1A8AE8A66B6C289046276453768EF270] - |A| - [26/10/2012 17:42:24] - (. - .) - [28.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\lvcoin64.ini[MD5.B4CD287DFAA6578AC763A3800F0C2DC8] - |A| - [26/10/2012 17:42:24] - (.(c) 1996-2012 Logitech. All rights reserved. - Logitech Camera Property Pages.) - [750.28 Ko] - (13.80.853.0) - C:\WINDOWS\System32\LVUI64.dll[MD5.CCFDDF84B42198B0AAD27D11ACFD254E] - |A| - [26/10/2012 17:42:22] - (.(c) 1996-2012 Logitech. All rights reserved. - Logitech Camera Property Pages.) - [547.28 Ko] - (13.80.853.0) - C:\WINDOWS\System32\LVUIRC64.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [29884.3 Ko] - C:\WINDOWS\System32\Macromed[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [32.68 Ko] - C:\WINDOWS\System32\MailContactsCalendarSync[MD5.D3F4E00C322EDA78873848BE75ACC8A4] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 2013 AMD Inc. - Mantle loader.) - [132.98 Ko] - (9.1.10.83) - C:\WINDOWS\System32\mantle64.dll[MD5.EA33454E28EE1F3CA432DA87203DA24F] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 2013 AMD Inc. - Mantle extension library.) - [100.98 Ko] - (9.1.10.83) - C:\WINDOWS\System32\mantleaxl64.dll[MD5.E8B2CB14CA0238566BDB20BD2A06D733] - |AC| - [06/07/2017 18:34:32] - (. - .) - [760 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MBR2GPT.EXE[MD5.CF17A39BA7D1D1E386FD0C1303642B91] - |A| - [25/02/2013 11:10:02] - (. - .) - [20.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MDA_NTDRV.sys[MD5.BC74BDA8DC53F722C2CA686071600AE2] - |AC| - [18/03/2017 22:57:05] - (. - .) - [107.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediumRoom.bin[MD5.00000000000000000000000000000000] - |D| - [26/04/2017 19:26:27] - [6.93 Ko] - C:\WINDOWS\System32\Microsoft[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [5497.13 Ko] - C:\WINDOWS\System32\migration[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [47457.11 Ko] - C:\WINDOWS\System32\migwiz[MD5.00000000000000000000000000000000] - |D| - [13/11/2016 22:44:33] - [26.58 Ko] - C:\WINDOWS\System32\MRT[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [45.5 Ko] - C:\WINDOWS\System32\MSDRM[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [52.28 Ko] - C:\WINDOWS\System32\MsDtc[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [19.15 Ko] - C:\WINDOWS\System32\MUI[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [290 Ko] - C:\WINDOWS\System32\nb-NO[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\NDF[MD5.DABD3C78809D580EBCF04B4D183ECFC9] - |A| - [12/04/2017 05:38:36] - (. - .) - [696.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ndw-fre.exe[MD5.C146E873B22C3B300B21A859FE66C27A] - |AC| - [18/03/2017 22:57:02] - (. - .) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetTrace.PLA.Diagnostics.xml[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [51 Ko] - C:\WINDOWS\System32\networklist[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [311.5 Ko] - C:\WINDOWS\System32\nl-NL[MD5.00000000000000000000000000000000] - |D| - [08/07/2017 14:36:28] - [735.81 Ko] - C:\WINDOWS\System32\Npcap[MD5.DABD3C78809D580EBCF04B4D183ECFC9] - |A| - [12/04/2017 05:38:36] - (. - .) - [696.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\npe-fre.exe[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [16570.66 Ko] - C:\WINDOWS\System32\Nui[MD5.50B0B2122AAABD76A64CDD52AFFF83C8] - |A| - [22/07/2017 15:35:37] - (. - .) - [4.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ocsvc.ini[MD5.26C812B50D31694461513EF308D30222] - |A| - [22/07/2017 15:34:38] - (. - .) - [12.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ocsvcOff.ini[MD5.C9246EF96F14CB2F0C393F73A20590D8] - |A| - [18/03/2017 23:03:38] - (. - .) - [15.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OEMDefaultAssociations.xml[MD5.2901049544FDF863362FABA2363EB647] - |AC| - [18/03/2017 22:57:12] - (. - .) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\onlinesetup.cmd[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [13183.45 Ko] - C:\WINDOWS\System32\oobe[MD5.2AD7B4F3C8D2BB686D231EDFF404B7A4] - |A| - [09/07/2017 09:01:45] - (.Copyright (C) 2000-2006 - Standard OpenAL(TM) Implementation.) - [120.02 Ko] - (6.14.357.24) - C:\WINDOWS\System32\OpenAL32.dll[MD5.42D2360079B1DF3230024AE920737367] - |AC| - [18/03/2017 22:57:05] - (. - .) - [45.81 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OutdoorAudioEnvironment.bin[MD5.1BD31AF098E9E4A4A48D2ECFF0A12F30] - |A| - [30/04/2017 18:28:03] - (.© 2003 Glyph & Cog, LLC - Xpdf: utilities for PDF documents.) - [502.5 Ko] - (2.3.1382.39045) - C:\WINDOWS\System32\pdfinfo.exe[MD5.1FEFCBFFE96D2C5EE074AAE27846C30E] - |A| - [30/04/2017 18:28:03] - (.© 2003 Glyph & Cog, LLC - Xpdf: utilities for PDF documents.) - [539.5 Ko] - (2.3.1382.39045) - C:\WINDOWS\System32\pdftotext.exe[MD5.F57FFF76BAD3FE57067E18E0DFFB8F44] - |A| - [18/03/2017 23:05:34] - (. - .) - [362.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc009.dat[MD5.90DFC113AAF457D0911E34FC3D003A78] - |A| - [20/03/2017 07:10:29] - (. - .) - [408.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc00C.dat[MD5.1E60BC5E525063B96078DF17FBD3C4E1] - |A| - [18/03/2017 23:05:34] - (. - .) - [32.64 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd009.dat[MD5.9F9AF8517189B0D61B2615007E071084] - |A| - [20/03/2017 07:10:29] - (. - .) - [39.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd00C.dat[MD5.724AEF716A09C17E9DCC2B537F26F8E8] - |A| - [18/03/2017 23:05:34] - (. - .) - [1046.99 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh009.dat[MD5.15F65982A05AC8E1628F4129CE77BE0B] - |A| - [20/03/2017 07:10:29] - (. - .) - [1598.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh00C.dat[MD5.B3029443C3A5A29D47D2F457790814E9] - |A| - [26/04/2017 18:52:14] - (. - .) - [3476.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PerfStringBackup.INI[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [310 Ko] - C:\WINDOWS\System32\pl-PL[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [634.5 Ko] - C:\WINDOWS\System32\PointOfService[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [420.42 Ko] - C:\WINDOWS\System32\Printing_Admin_Scripts[MD5.0225FC6F0D91F84B44CE252487D8D725] - |A| - [29/04/2017 18:19:45] - (.Copyright (C) 2008-2013 - Video-Codec by proDAD.) - [593.02 Ko] - (1.0.18.0) - C:\WINDOWS\System32\prodad-codec.dll[MD5.E5FCE41A5114E40EE573AB8631925BF3] - |A| - [29/04/2017 18:19:30] - (.Copyright (C) 2008 - Part of the proDAD.) - [367.52 Ko] - (1.0.4.0) - C:\WINDOWS\System32\proDAD-PA-Support.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\ProximityToast[MD5.007893E8374C766471239EB291BA8C17] - |AC| - [18/03/2017 22:57:54] - (. - .) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\psmodulediscoveryprovider.mof[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [311.5 Ko] - C:\WINDOWS\System32\pt-BR[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [307 Ko] - C:\WINDOWS\System32\pt-PT[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [23.75 Ko] - C:\WINDOWS\System32\ras[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\System32\RasToast[MD5.692DC6EF573FFCDD9DFB55D1C783DB93] - |AC| - [18/03/2017 22:58:01] - (. - .) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\removehypervisor.mof[MD5.C6CA43573C21CA6392F57F238C8391FC] - |A| - [26/10/2012 17:42:22] - (. - .) - [39.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Repository.reg[MD5.D9DF00023703568AE6B4303E3C5C90BB] - |AC| - [18/03/2017 22:57:47] - (. - .) - [8.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageList[MD5.99C7924C7268BABB5C4E3CFD2EE03331] - |AC| - [18/03/2017 22:57:47] - (. - .) - [8.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageList[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.07 Ko] - C:\WINDOWS\System32\restore[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [22/07/2017 12:00:49] - (. - .) - [17.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\roboot64.exe[MD5.F85C8899860241F78D7107C7581AA2F1] - |A| - [22/07/2017 16:00:39] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x64.) - [314.17 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DAA64.dll[MD5.BA3C19EF06BA9B0E316D702C31E6DBA6] - |A| - [22/07/2017 16:00:42] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x64.) - [314.17 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DHT64.dll[MD5.166CDCF1CA92579C051BCA8C5C13C3FB] - |A| - [27/04/2017 15:49:32] - (.Copyright (c) 2000 - 2015 Advanced Messaging Systems LLC - Outlook Redemption COM library.) - [12500.1 Ko] - (5.10.0.4312) - C:\WINDOWS\System32\rsror64.dll[MD5.F7BAB6656AA3851FB90D3E1699F9B946] - |A| - [27/04/2017 15:49:32] - (.Copyright (c) 2000 - 2015 Advanced Messaging Systems LLC - Outlook Redemption COM library.) - [3793.1 Ko] - (5.10.0.4312) - C:\WINDOWS\System32\rsrorx64.dll[MD5.D7CFCE6811519582690065C21088E9A5] - |A| - [21/07/2017 11:24:16] - (.Copyright (C) 2014 - RtCRX.) - [82.5 Ko] - (1.11.9600.0) - C:\WINDOWS\System32\RtCRX64.dll[MD5.8CF627BC89548ABC9DB4DE7912834DE7] - |A| - [22/07/2017 16:01:00] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x64.) - [209.79 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEED64A.dll[MD5.92C9AF448C11908A907A7EF92B338000] - |A| - [22/07/2017 16:00:59] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x64.) - [86.27 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEG64A.dll[MD5.A3DFE60ECBBEDE0E2BAAE2444B881994] - |A| - [22/07/2017 16:00:58] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x64.) - [108.38 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEL64A.dll[MD5.97382543BC45FEF210414DAEABF2C040] - |A| - [22/07/2017 16:01:04] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x64.) - [378.23 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEP64A.dll[MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |AC| - [18/03/2017 22:59:52] - (. - .) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScavengeSpace.xml[MD5.697DBE44CB6516ECAE92552CBBCD8752] - |A| - [21/07/2017 11:12:32] - (.Copyright (C) 2014 - GeneStor co-installer .) - [129.09 Ko] - (1.0.0.1) - C:\WINDOWS\System32\SET8311.tmp[MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |AC| - [18/03/2017 22:58:03] - (. - .) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\settings.dat[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [253 Ko] - C:\WINDOWS\System32\sk-SK[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [249 Ko] - C:\WINDOWS\System32\sl-SI[MD5.2354FCDB540A378A657866DF39D87573] - |A| - [22/07/2017 16:07:54] - (.Copyright (C) 2016 DTS, Inc. - DTS Universal APO DLL.) - [961.83 Ko] - (3.5.14.0) - C:\WINDOWS\System32\sl3apo64.dll[MD5.D52E47DC28B44901CFC8ED3C5CF3BE14] - |A| - [22/07/2017 16:08:05] - (.Copyright (C) 2016 DTS, Inc. - DTS APO Controller DLL.) - [3330.89 Ko] - (3.5.14.0) - C:\WINDOWS\System32\slcnt64.dll[MD5.00000000000000000000000000000000] - |D| - [26/04/2017 18:47:17] - [23587.74 Ko] - C:\WINDOWS\System32\SleepStudy[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [52.14 Ko] - C:\WINDOWS\System32\slmgr[MD5.649CBCA4755E2AD7EDC371D849447681] - |A| - [22/07/2017 16:08:02] - (.TODO: (c) . All rights reserved. - TODO: .) - [252.79 Ko] - (1.0.0.1) - C:\WINDOWS\System32\slprp64.dll[MD5.6C1A08D54D1E2E40C95641A2296F4540] - |A| - [22/07/2017 16:08:34] - (.Copyright (C) 2016 DTS, Inc. - DTS APO Technology DLL.) - [3049.47 Ko] - (3.5.14.0) - C:\WINDOWS\System32\sltech64.dll[MD5.1C6F12AA3D178A0A953E8005B3CD4CDE] - |AC| - [18/03/2017 22:57:05] - (. - .) - [68.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SmallRoom.bin[MD5.D57880A3F9F22D67974EF0EB8B67021C] - |A| - [22/07/2017 12:11:34] - (.Copyright © 2005-2013 - SmartDefrag.) - [35.96 Ko] - (2.0.0.0) - C:\WINDOWS\System32\SmartDefragBootTime.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [13385.02 Ko] - C:\WINDOWS\System32\SMI[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [22/07/2017 12:18:26] - (. - .) - [20 Ko] - (0.0.0.0) - C:\WINDOWS\System32\smpnative64.exe[MD5.76F8BDA4D4AA4AA4C4D84C2E2660E6FF] - |AC| - [18/03/2017 22:57:05] - (. - .) - [36.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpectrumSyncClient.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [7504.91 Ko] - C:\WINDOWS\System32\Speech[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [11620.23 Ko] - C:\WINDOWS\System32\Speech_OneCore[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [190791.71 Ko] - C:\WINDOWS\System32\spool[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [5985.3 Ko] - C:\WINDOWS\System32\spp[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [31.88 Ko] - C:\WINDOWS\System32\sppui[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 09:22:35] - [0 Ko] - C:\WINDOWS\System32\sr-Latn-CS[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [251.5 Ko] - C:\WINDOWS\System32\sr-Latn-RS[MD5.2198474472474C48169F532553207419] - |A| - [22/07/2017 16:07:30] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRAPO.DLL.) - [456.2 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRAPO64.dll[MD5.826C0C7F0AA01D30809795A3B37FC338] - |A| - [22/07/2017 16:07:51] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [333.15 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM.dll[MD5.028CA8FC7B630E7E3A5696EAA7C07E4F] - |A| - [22/07/2017 16:07:34] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [372.47 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM64.dll[MD5.5128BC123224124D67397A1BE698431C] - |AC| - [18/03/2017 22:57:16] - (. - .) - [56.63 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms.dat[MD5.F27491D59709E7E047FD9B51738A5738] - |A| - [22/07/2017 16:07:38] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRRPTR.DLL.) - [1401.5 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRRPTR64.dll[MD5.284606226D06EF38393C8CFE4A7ACA96] - |A| - [22/07/2017 15:59:38] - (.(c) 2007 SRS Labs, Inc. All rights reserved. - COM object implementing SRS Headphone 360.) - [204.62 Ko] - (1.1.0.0) - C:\WINDOWS\System32\SRSHP64.dll[MD5.00000000000000000000000000000000] - |D| - [26/04/2017 18:50:57] - [2255.97 Ko] - C:\WINDOWS\System32\SRSLabs[MD5.A701A35E1492887D7FB220D18C9201F3] - |A| - [22/07/2017 15:59:36] - (.Copyright (c) 2006 SRS Labs, Inc.. All rights reserved. - TruSurround HD and HD4 COM object for Windows.) - [216.76 Ko] - (1.1.4.0) - C:\WINDOWS\System32\SRSTSH64.dll[MD5.636F6AE756E2E57426EBEEF517D83FF1] - |A| - [22/07/2017 15:59:30] - (.Copyright 2002 SRS Labs, Inc. All Rights Reserved. - TruSurroundXT Module.) - [519.9 Ko] - (3.2.0.0) - C:\WINDOWS\System32\SRSTSX64.dll[MD5.177A57DA2987C03ED941376215B0DE4A] - |A| - [22/07/2017 15:59:34] - (.(c) 2006 SRS Labs, Inc. All rights reserved. - WOW HD COM object for Windows.) - [162.3 Ko] - (1.1.3.0) - C:\WINDOWS\System32\SRSWOW64.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [9048 Ko] - C:\WINDOWS\System32\sru[MD5.E042A078EDE878E1F489D08F045D2205] - |AC| - [18/03/2017 22:57:05] - (. - .) - [368.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ssdm.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [296 Ko] - C:\WINDOWS\System32\sv-SE[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:22] - [1590.75 Ko] - C:\WINDOWS\System32\Sysprep[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [906.28 Ko] - C:\WINDOWS\System32\SystemResetPlatform[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [641.1 Ko] - C:\WINDOWS\System32\Tasks[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 09:22:35] - [536.56 Ko] - C:\WINDOWS\System32\Tasks_Migrated[MD5.D602CA245CC6774A0981B607F0675609] - |AC| - [18/03/2017 22:58:24] - (. - .) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\tcpmon.ini[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [234 Ko] - C:\WINDOWS\System32\th-TH[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [293 Ko] - C:\WINDOWS\System32\tr-TR[MD5.B88B8D017386A00D7724519F475317A0] - |AC| - [18/03/2017 22:58:18] - (. - .) - [10.33 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlan.xslt[MD5.2F05390B798363D51EBE65D6320CD45E] - |AC| - [18/03/2017 22:58:18] - (. - .) - [1.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlanCredentials.xslt[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [247 Ko] - C:\WINDOWS\System32\uk-UA[MD5.501A55E569661CB34D75E772420F3B58] - |A| - [25/04/2017 14:22:22] - (. - .) - [793.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Vim.RWBlock.dll[MD5.EE36699DE2B2C89E57AA0F900A805407] - |A| - [25/04/2017 14:22:24] - (. - .) - [140.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vimbase.dll[MD5.18C0AA13EE6ED19F70759D8A29C0AC51] - |A| - [25/04/2017 14:22:26] - (. - .) - [2198.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vimsdk.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [84800.56 Ko] - C:\WINDOWS\System32\wbem[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [0 Ko] - C:\WINDOWS\System32\WCN[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [69037.51 Ko] - C:\WINDOWS\System32\WDI[MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |AC| - [18/03/2017 22:57:19] - (. - .) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WdsUnattendTemplate.xml[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1.12 Ko] - C:\WINDOWS\System32\WinBioDatabase[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [76166.44 Ko] - C:\WINDOWS\System32\WinBioPlugIns[MD5.558D9282D5CEA82B2253B88017552F33] - |AC| - [18/03/2017 22:58:18] - (. - .) - [96 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsDefaultHeatProcessor.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [9339.55 Ko] - C:\WINDOWS\System32\WindowsPowerShell[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [162948 Ko] - C:\WINDOWS\System32\winevt[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4744.09 Ko] - C:\WINDOWS\System32\WinMetadata[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [107.53 Ko] - C:\WINDOWS\System32\winrm[MD5.C30C621748C66CE751B19B2788559A3E] - |AC| - [18/03/2017 22:58:17] - (. - .) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcmon.png[MD5.B6B479B04C64AF5EF36C24EBDF278302] - |AC| - [18/03/2017 22:58:01] - (. - .) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpr.config.xml[MD5.549347BCD4AACD63243D78E8F869DBB1] - |A| - [09/07/2017 09:01:45] - (.Copyright © 2008 - OpenAL32.) - [455.52 Ko] - (2.2.0.5) - C:\WINDOWS\System32\wrap_oal.dll[MD5.19820EEC2D1A4D264F051B789F79D51A] - |AC| - [06/07/2017 18:34:52] - (. - .) - [84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xboxgipsynthetic.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [208 Ko] - C:\WINDOWS\System32\zh-CN[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 09:22:36] - [3 Ko] - C:\WINDOWS\System32\zh-HK[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [203 Ko] - C:\WINDOWS\System32\zh-TW[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [0 Ko] - C:\WINDOWS\SysWOW64\0409[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 11:45:54] - [328.34 Ko] - C:\WINDOWS\SysWOW64\1033[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 14:36:58] - [113.39 Ko] - C:\WINDOWS\SysWOW64\1036[MD5.82C37C3E27020AF6C2E018E944284676] - |AC| - [18/03/2017 22:58:44] - (. - .) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AudioToastIcon.png[MD5.495C1F072039B434827A5FE0D9761E4D] - |AC| - [18/03/2017 22:58:54] - (. - .) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@EnrollmentToastIcon.png[MD5.1622DE67156496C78D6B7BE9B471645B] - |AC| - [18/03/2017 22:58:51] - (. - .) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@VpnToastIcon.png[MD5.13FA039C5E464F3BF0C6D01E00581CAA] - |A| - [01/05/2017 17:03:26] - (.Copyright © 2010 by fccHandler - AC-3 ACM Codec.) - [148 Ko] - (1.5.0.0) - C:\WINDOWS\SysWOW64\ac3acm.acm[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:24] - [1998.91 Ko] - C:\WINDOWS\SysWOW64\AdvancedInstallers[MD5.7D4761FD5A02353C9BD70C1F5B15AA4F] - |A| - [21/10/2015 03:14:42] - (. - .) - [193.98 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\amdgfxinfo32.dll[MD5.F12467373381C72FAE9CA7C08ED6C919] - |A| - [21/10/2015 03:14:42] - (. - .) - [128.98 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\amdhdl32.dll[MD5.87882BCCDF63B74B675ECCE6B6609DC2] - |A| - [21/10/2015 03:14:42] - (.Advanced Micro Devices, Inc. Copyright (C) 2015 - LiquidVR SDK 1.0.) - [511.98 Ko] - (1.0.3.8) - C:\WINDOWS\SysWOW64\amdlvr32.dll[MD5.8F2144D05F41DD27308548B5D9D19101] - |A| - [21/10/2015 03:14:42] - (.Copyright (C) 2013 AMD Inc. - Mantle driver, support for SI family and above.) - [5093.98 Ko] - (9.1.10.83) - C:\WINDOWS\SysWOW64\amdmantle32.dll[MD5.F9F99EA40AF48C716C2E823F2B6FD2D8] - |A| - [21/10/2015 03:14:42] - (.Copyright (c) 2013 Advanced Micro Devices, Inc. - Radeon MMOCL Universal Driver.) - [46.98 Ko] - (1.6.0.0) - C:\WINDOWS\SysWOW64\amdmmcl.dll[MD5.E30B1D883DC886016C38FDEE6755CCC6] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OpenCL 2.0 Runtime.) - [38790.48 Ko] - (10.0.1800.11) - C:\WINDOWS\SysWOW64\amdocl.dll[MD5.5F0F6073A243FC8C4C190E3F06D1247E] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2011 Advanced Micro Devices Inc. - AMD COMPILER OpenCL 1.1 Compiler.) - [21803.98 Ko] - (0.8.0.0) - C:\WINDOWS\SysWOW64\amdocl12cl.dll[MD5.40A2E4C2933EB5DE99C06F00A9E2C589] - |A| - [21/10/2015 03:14:44] - (. - .) - [980.49 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\amdocl_as32.exe[MD5.985589A3C4BB14ED23A15D9477475F7B] - |A| - [21/10/2015 03:14:42] - (. - .) - [788.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\amdocl_ld32.exe[MD5.170EA2F4A32130BBF7EABD2D94B235AE] - |A| - [21/10/2015 03:14:54] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [79.26 Ko] - (8.14.10.23) - C:\WINDOWS\SysWOW64\amdpcom32.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\AppLocker[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [255 Ko] - C:\WINDOWS\SysWOW64\ar-SA[MD5.546E937838E7D9FD945D6505529F2209] - |A| - [21/10/2015 03:14:44] - (.Copyright (C) 2008-2014 Advanced Micro Devices, Inc. - ADL.) - [913.48 Ko] - (7.15.20.1301) - C:\WINDOWS\SysWOW64\atiadlxx.dll[MD5.546E937838E7D9FD945D6505529F2209] - |A| - [21/10/2015 03:14:44] - (.Copyright (C) 2008-2014 Advanced Micro Devices, Inc. - ADL.) - [913.48 Ko] - (7.15.20.1301) - C:\WINDOWS\SysWOW64\atiadlxy.dll[MD5.53650482B8E621276DC55E50C9FB2FEE] - |A| - [22/08/2015 02:53:34] - (. - .) - [646.87 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\atiapfxx.blb[MD5.4A8BC73F07C13E602B573BE723BFB360] - |A| - [21/10/2015 03:14:44] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL compiler runtime.) - [56.48 Ko] - (6.14.10.1848) - C:\WINDOWS\SysWOW64\aticalcl.dll[MD5.64E261847856C53DE5A3007682707290] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL DD.) - [13975.48 Ko] - (6.14.10.1848) - C:\WINDOWS\SysWOW64\aticaldd.dll[MD5.F1E925DE8ECC7BE99BCC380BBA3F477E] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2008 Advanced Micro Devices Inc. - ATI CAL runtime.) - [59.48 Ko] - (6.14.10.1848) - C:\WINDOWS\SysWOW64\aticalrt.dll[MD5.DCE2F09D2DF45938DB476B287D6F560B] - |A| - [21/10/2015 03:14:54] - (.Copyright (C) 1998-2012 AMD Inc. - aticfx32.dll.) - [1194.88 Ko] - (8.17.10.1404) - C:\WINDOWS\SysWOW64\aticfx32.dll[MD5.194B36603ED7BB93290F4A3C73B94764] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 1998-2011 AMD Inc. - atidxx32.dll.) - [9971.7 Ko] - (8.17.10.625) - C:\WINDOWS\SysWOW64\atidxx32.dll[MD5.B84EF06D0D8192F33EE5BC12B2BA3702] - |A| - [21/10/2015 03:14:46] - (. - .) - [148.98 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\atieah32.exe[MD5.B728F7B42DA61395F43C86BDDE5196E5] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atigktxx.dll.) - [146.98 Ko] - (8.14.1.6463) - C:\WINDOWS\SysWOW64\atigktxx.dll[MD5.0C3156664885AF41100B63853EBCE037] - |A| - [21/10/2015 03:14:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiglpxx.dll.) - [76.48 Ko] - (8.14.1.6463) - C:\WINDOWS\SysWOW64\atiglpxx.dll[MD5.B344A7D717211B7DF53E369FC58290DF] - |A| - [21/10/2015 03:14:54] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [79.26 Ko] - (8.14.10.23) - C:\WINDOWS\SysWOW64\atimpc32.dll[MD5.6557A2BB671495C8F7E127FCD23FAF3E] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 1998-2011 Advanced Micro Devices, Inc. - AMD OpenGL driver.) - [24726.98 Ko] - (6.14.10.13399) - C:\WINDOWS\SysWOW64\atioglxx.dll[MD5.E183E40B75E742A6E597A922168C2405] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiu9pag.dll.) - [109.73 Ko] - (8.14.1.6463) - C:\WINDOWS\SysWOW64\atiu9pag.dll[MD5.E638384DCD47CEA8F0DF2B6BAFB11F57] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 1998-2011 AMD Inc. - atiumdag.dll.) - [7307.19 Ko] - (9.14.10.1128) - C:\WINDOWS\SysWOW64\atiumdag.dll[MD5.A98DA23A524803615B083CFCED1CE362] - |A| - [22/08/2015 02:50:46] - (. - .) - [3390.02 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\atiumdva.cap[MD5.34438A391DADBD03940AF0760E2932CB] - |A| - [21/10/2015 03:14:56] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon Video Acceleration Universal Driver.) - [7821.64 Ko] - (8.14.10.513) - C:\WINDOWS\SysWOW64\atiumdva.dll[MD5.C62336798199A3705424A6708445DD11] - |A| - [21/10/2015 03:14:56] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atiuxpag.dll.) - [139.7 Ko] - (8.14.1.6463) - C:\WINDOWS\SysWOW64\atiuxpag.dll[MD5.7C163EDE63854539828F5B2C1BC529FD] - |A| - [22/08/2015 02:54:10] - (. - .) - [153.46 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ativvsva.dat[MD5.219D7091DD1D93728392337FE9C7ADD6] - |A| - [22/08/2015 02:54:10] - (. - .) - [200.15 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ativvsvl.dat[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [234 Ko] - C:\WINDOWS\SysWOW64\bg-BG[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.93 Ko] - C:\WINDOWS\SysWOW64\Bthprops[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot[MD5.28B0CBD160AD694EE8C1D463077E438C] - |A| - [08/06/2017 04:41:18] - (.2005-2017 COMODO. All rights reserved. - COMODO Internet Security.) - [355.19 Ko] - (10.0.1.6258) - C:\WINDOWS\SysWOW64\cmdvrt32.dll[MD5.00000000000000000000000000000000] - |D| - [07/07/2017 14:17:14] - [788.5 Ko] - C:\WINDOWS\SysWOW64\Codecs[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [314 Ko] - C:\WINDOWS\SysWOW64\Com[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1423.99 Ko] - C:\WINDOWS\SysWOW64\config[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [51.27 Ko] - C:\WINDOWS\SysWOW64\Configuration[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [279.5 Ko] - C:\WINDOWS\SysWOW64\cs-CZ[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [21/07/2017 10:56:07] - (. - .) - [270.31 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\D3DX8Wrapper.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [275 Ko] - C:\WINDOWS\SysWOW64\da-DK[MD5.848BF7577E0EC99DE1F79BD692EE9DDA] - |A| - [07/07/2017 14:10:15] - (.©2000 Dart Communications - PowerTCP© Certificate Controls.) - [229 Ko] - (2.10.5.0) - C:\WINDOWS\SysWOW64\DartCertificate.dll[MD5.889C4A742EA54F1524C9016AFA5DA433] - |A| - [07/07/2017 14:10:15] - (.©2000 Dart Communications - PowerTCP© Secure Controls.) - [377.5 Ko] - (2.1.5.0) - C:\WINDOWS\SysWOW64\DartSecure2.dll[MD5.DA2C86B559173699976273924590850C] - |A| - [07/07/2017 14:10:15] - (.©2000 Dart Communications - PowerTCP© Winsock Controls.) - [415.5 Ko] - (2.10.2.1) - C:\WINDOWS\SysWOW64\DartSock.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [311 Ko] - C:\WINDOWS\SysWOW64\de-DE[MD5.B227DF8720C51EE0A80CB23CCCEF1EC6] - |A| - [26/10/2012 17:42:24] - (. - .) - [328.35 Ko] - (13.80.853.0) - C:\WINDOWS\SysWOW64\DevManagerCore.dll[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [201.5 Ko] - C:\WINDOWS\SysWOW64\DiagSvcs[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [5929.02 Ko] - C:\WINDOWS\SysWOW64\Dism[MD5.F42E95BFB193754E9148DB6434D2E88E] - |A| - [19/02/2010 21:27:36] - (.Copyright © 2000-2009 DivX, Inc. All rights reserved. - DivX.) - [703.5 Ko] - (6.9.2.26) - C:\WINDOWS\SysWOW64\DivX.dll[MD5.24581F00D3EBBEB42BE1CFC28EF2D23D] - |A| - [01/05/2017 22:06:00] - (.2017 DivX, LLC. All rights reserved. DivX and associated logos are trademarks of DivX, LLC or its affiliates. - DivX Control Panel Applet.) - [355.46 Ko] - (10.5.0.80) - C:\WINDOWS\SysWOW64\DivXControlPanelApplet.cpl[MD5.A266D3E430E9FF97E9D659E5F087EF99] - |A| - [19/02/2010 21:27:16] - (.Copyright © 2001-2008 DivX, Inc. All rights reserved. - DivX.) - [836 Ko] - (6.9.2.26) - C:\WINDOWS\SysWOW64\divx_xx07.dll[MD5.0DADCB1C15AB04A655F7B386FE625B35] - |A| - [19/02/2010 21:27:16] - (.Copyright © 2001-2008 DivX, Inc. All rights reserved. - DivX.) - [828 Ko] - (6.9.2.26) - C:\WINDOWS\SysWOW64\divx_xx0a.dll[MD5.725C556795DFC534660E784F9324515C] - |A| - [19/02/2010 21:27:16] - (.Copyright © 2001-2008 DivX, Inc. All rights reserved. - DivX.) - [836 Ko] - (6.9.2.26) - C:\WINDOWS\SysWOW64\divx_xx0c.dll[MD5.E1F94DFDC350BB8CE14655F5DB567149] - |A| - [19/02/2010 21:27:16] - (.Copyright ? 2001-2008 DivX, Inc. All rights reserved. - DivX.) - [820 Ko] - (6.9.2.26) - C:\WINDOWS\SysWOW64\divx_xx11.dll[MD5.AD8E4393EAD5A8A71378BEEE95C59FDA] - |A| - [19/02/2010 21:27:16] - (.Copyright © 2001-2008 DivX, Inc. All rights reserved. - DivX.) - [824 Ko] - (6.9.2.26) - C:\WINDOWS\SysWOW64\divx_xx16.dll[MD5.0902754B4F3041FD31673CB63B34012D] - |A| - [21/07/2017 17:18:00] - (. - .) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\dllhost.exe.config[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1077.55 Ko] - C:\WINDOWS\SysWOW64\downlevel[MD5.90C7F5E71EEFE13F762CFE7B42C7157A] - |A| - [02/06/2011 19:53:02] - (.Copyright © 2005-2006 - dpl100.) - [92 Ko] - (1.3.0.25) - C:\WINDOWS\SysWOW64\dpl100.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [3422.56 Ko] - C:\WINDOWS\SysWOW64\drivers[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\DriverStore[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [21/07/2017 10:56:07] - (. - .) - [223.81 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\EasyHook32.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [306.5 Ko] - C:\WINDOWS\SysWOW64\el-GR[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [0 Ko] - C:\WINDOWS\SysWOW64\en[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [223 Ko] - C:\WINDOWS\SysWOW64\en-GB[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1547.03 Ko] - C:\WINDOWS\SysWOW64\en-US[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [300 Ko] - C:\WINDOWS\SysWOW64\es-ES[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [244.5 Ko] - C:\WINDOWS\SysWOW64\es-MX[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [220 Ko] - C:\WINDOWS\SysWOW64\et-EE[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [24159.66 Ko] - C:\WINDOWS\SysWOW64\F12[MD5.657FE95F272CB8E8CC737D7B1352214D] - |A| - [18/03/2017 22:58:39] - (. - .) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\fcc.dll[MD5.C58947149D01B615E478D7201DD0CFA4] - |A| - [01/05/2017 17:03:22] - (. - .) - [79 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ff_vfw.dll[MD5.3B5BB4DA93EBCB6ECBAC48C66F4B28A4] - |A| - [01/05/2017 17:03:23] - (. - .) - [0.58 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ff_vfw.dll.manifest[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [279.5 Ko] - C:\WINDOWS\SysWOW64\fi-FI[MD5.5C8874EE321F4623FFF7A1315039DDBC] - |A| - [11/07/2017 08:00:52] - (.Copyright (C) 2005, Fox Magic Software - FM Screen Capture Codec (VFW).) - [76 Ko] - (1.0.0.0) - C:\WINDOWS\SysWOW64\fmcodec.DLL[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:27] - [3149 Ko] - C:\WINDOWS\SysWOW64\fr[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [250.5 Ko] - C:\WINDOWS\SysWOW64\fr-CA[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [37328.29 Ko] - C:\WINDOWS\SysWOW64\fr-FR[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\FxsTmp[MD5.CC8206C9288EA409781DE1D7FC754A39] - |A| - [29/04/2017 21:39:17] - (.2005-2013 - Generic Service.) - [478.72 Ko] - (2.4.4.0) - C:\WINDOWS\SysWOW64\GSService.exe[MD5.313F0F8F9A33F438A36BDB107EDBF803] - |A| - [08/06/2017 04:45:44] - (.2005-2017 COMODO. All rights reserved. - COMODO Internet Security.) - [715.77 Ko] - (10.0.1.6258) - C:\WINDOWS\SysWOW64\guard32.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [243 Ko] - C:\WINDOWS\SysWOW64\he-IL[MD5.2927ADFC93821B344BA524BCF9889A51] - |AC| - [18/03/2017 22:58:54] - (. - .) - [109.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\HeatCore.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [229 Ko] - C:\WINDOWS\SysWOW64\hr-HR[MD5.506C5BE8B184615F7F35A85C00A16E76] - |A| - [21/10/2015 03:14:48] - (. - .) - [108.48 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\hsa-thunk.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [283 Ko] - C:\WINDOWS\SysWOW64\hu-HU[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [36.27 Ko] - C:\WINDOWS\SysWOW64\icsxml[MD5.24E1434E899B3EC4E3CD4CA56AA63BC6] - |AC| - [18/03/2017 22:58:54] - (. - .) - [114.09 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\InputHost.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [221.5 Ko] - C:\WINDOWS\SysWOW64\InputMethod[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1160 Ko] - C:\WINDOWS\SysWOW64\InstallShield[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\Ipmi[MD5.CADC1F6669EC3F9143A33D1342C2410E] - |A| - [28/04/2017 14:48:55] - (. - .) - [209.5 Ko] - (1.0.0.110) - C:\WINDOWS\SysWOW64\ISCM32.dll[MD5.ED5D4435EC628F9EBB6AEC8A1D3FA41D] - |A| - [28/04/2017 14:48:56] - (. - .) - [704.36 Ko] - (1.0.0.2) - C:\WINDOWS\SysWOW64\ISCM64.dll[MD5.260A7E98E23B77C9C64AB37AC8868AB1] - |A| - [11/07/2017 11:02:04] - (.2005-2017 COMODO. All rights reserved. - Internet Security Essentials.) - [200.72 Ko] - (1.2.28809.92) - C:\WINDOWS\SysWOW64\iseguard32.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [305 Ko] - C:\WINDOWS\SysWOW64\it-IT[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [222.5 Ko] - C:\WINDOWS\SysWOW64\ja-JP[MD5.5ACD11DF2AA5F3E3F30F785589B70347] - |A| - [13/11/2005 20:07:12] - (. - .) - [6.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\kc.exe[MD5.00000000000000000000000000000000] - |D| - [05/05/2017 12:29:51] - [24125.03 Ko] - C:\WINDOWS\SysWOW64\KDirectShow[MD5.6315AB54B0156C7B5B1B6E499601C171] - |A| - [29/10/2006 17:36:54] - (.Killer{R} - .) - [1158 Ko] - (2.8.4.0) - C:\WINDOWS\SysWOW64\killcopy.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [220.5 Ko] - C:\WINDOWS\SysWOW64\ko-KR[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [79.18 Ko] - C:\WINDOWS\SysWOW64\Licenses[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\LogFiles[MD5.B65E8E52916A527F88486875EE291AA8] - |A| - [26/10/2012 17:42:22] - (. - .) - [10663.85 Ko] - (13.80.853.0) - C:\WINDOWS\SysWOW64\LogiDPP.dll[MD5.24764C249F769991079F6D4B14B822AF] - |A| - [26/10/2012 17:42:22] - (. - .) - [100.85 Ko] - (13.80.853.0) - C:\WINDOWS\SysWOW64\LogiDPPApp.exe[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [224.5 Ko] - C:\WINDOWS\SysWOW64\lt-LT[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [226.5 Ko] - C:\WINDOWS\SysWOW64\lv-LV[MD5.BDC67729D0A4940C525654FF869C5289] - |A| - [26/10/2012 17:42:22] - (.(c) 1996-2012 Logitech. All rights reserved. - Video Codec.) - [297.85 Ko] - (13.80.853.0) - C:\WINDOWS\SysWOW64\lvcodec2.dll[MD5.E8C604C7E16CE90C0D4564EC06B118E8] - |A| - [26/10/2012 17:42:22] - (.(c) 1996-2012 Logitech. All rights reserved. - Logitech Camera Property Pages.) - [529.85 Ko] - (13.80.853.0) - C:\WINDOWS\SysWOW64\LVUI2.dll[MD5.F13DA78D0873B2025556D65DB5E3210D] - |A| - [26/10/2012 17:42:24] - (.(c) 1996-2012 Logitech. All rights reserved. - Logitech Camera Property Pages.) - [525.85 Ko] - (13.80.853.0) - C:\WINDOWS\SysWOW64\LVUI2RC.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [24342.29 Ko] - C:\WINDOWS\SysWOW64\Macromed[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [32.68 Ko] - C:\WINDOWS\SysWOW64\MailContactsCalendarSync[MD5.39CE334A6E1CBED62462A0CCCC080A5C] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 2013 AMD Inc. - Mantle loader.) - [119.48 Ko] - (9.1.10.83) - C:\WINDOWS\SysWOW64\mantle32.dll[MD5.890CD0E80FA4CA7728FF49E372D789F2] - |A| - [21/10/2015 03:14:48] - (.Copyright (C) 2013 AMD Inc. - Mantle extension library.) - [94.48 Ko] - (9.1.10.83) - C:\WINDOWS\SysWOW64\mantleaxl32.dll[MD5.00000000000000000000000000000000] - |SD| - [11/07/2017 11:32:13] - [0 Ko] - C:\WINDOWS\SysWOW64\Microsoft[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2978.39 Ko] - C:\WINDOWS\SysWOW64\migration[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [814.41 Ko] - C:\WINDOWS\SysWOW64\migwiz[MD5.23D4907D662E248E09872E5A32E71570] - |A| - [01/05/2017 17:03:27] - (.Copyright © 2004 Fraunhofer IIS - MPEG Audio Layer-3 Codec for MSACM.) - [227 Ko] - (3.4.0.0) - C:\WINDOWS\SysWOW64\mp3fhg.acm[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [45.5 Ko] - C:\WINDOWS\SysWOW64\MSDRM[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [52.28 Ko] - C:\WINDOWS\SysWOW64\MsDtc[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [19.15 Ko] - C:\WINDOWS\SysWOW64\MUI[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [271 Ko] - C:\WINDOWS\SysWOW64\nb-NO[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\NDF[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [51 Ko] - C:\WINDOWS\SysWOW64\networklist[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [290 Ko] - C:\WINDOWS\SysWOW64\nl-NL[MD5.7AEA4DF1CA68FD45DD4BBE1F0243CE7F] - |A| - [28/04/2017 13:59:56] - (. - .) - [69.43 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\NMSAccessU.exe[MD5.00000000000000000000000000000000] - |D| - [08/07/2017 14:36:23] - [643.31 Ko] - C:\WINDOWS\SysWOW64\Npcap[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [3781.5 Ko] - C:\WINDOWS\SysWOW64\Nui[MD5.50B0B2122AAABD76A64CDD52AFFF83C8] - |A| - [22/07/2017 15:34:37] - (. - .) - [4.06 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ocsvc.ini[MD5.26C812B50D31694461513EF308D30222] - |A| - [22/07/2017 15:34:38] - (. - .) - [12.27 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ocsvcOff.ini[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [635.23 Ko] - C:\WINDOWS\SysWOW64\oobe[MD5.235355A8DD26903E75D5E812ECF50E53] - |A| - [09/07/2017 09:01:45] - (.Copyright (C) 2000-2006 - Standard OpenAL(TM) Implementation.) - [106.52 Ko] - (6.14.357.24) - C:\WINDOWS\SysWOW64\OpenAL32.dll[MD5.A03878583E9A9CD28C418B3E37CE0021] - |A| - [26/04/2017 18:52:03] - (. - .) - [1931.66 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PerfStringBackup.INI[MD5.C7A1F603619B96503674D15BF4FFE637] - |A| - [24/04/2017 10:29:12] - (.Copyright (C) ArcSoft Inc. 2001 - ArcSoft Screen Saver.) - [160 Ko] - (1.0.0.1) - C:\WINDOWS\SysWOW64\PhotoImpression Screen Saver.scr[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [288 Ko] - C:\WINDOWS\SysWOW64\pl-PL[MD5.00000000000000000000000000000000] - |D| - [28/04/2017 13:58:48] - [29.74 Ko] - C:\WINDOWS\SysWOW64\PolicyDefinitions[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:28] - [420.42 Ko] - C:\WINDOWS\SysWOW64\Printing_Admin_Scripts[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [290.5 Ko] - C:\WINDOWS\SysWOW64\pt-BR[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [285.5 Ko] - C:\WINDOWS\SysWOW64\pt-PT[MD5.F318E151801F7EB505894718E03BC438] - |A| - [24/04/2017 09:27:30] - (. - .) - [5.54 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\quartz.vxd[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [23.75 Ko] - C:\WINDOWS\SysWOW64\ras[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\RasToast[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.82 Ko] - C:\WINDOWS\SysWOW64\Recovery[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\restore[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [230.5 Ko] - C:\WINDOWS\SysWOW64\ro-RO[MD5.F5C5B3A75783BEFF7257EABA026783CA] - |A| - [27/04/2017 15:49:49] - (.Copyright (c) 2000 - 2015 Advanced Messaging Systems LLC - Outlook Redemption COM library.) - [7776.6 Ko] - (5.10.0.4312) - C:\WINDOWS\SysWOW64\rsror32.dll[MD5.3FE1177C731A499D875FFD2555C0EED1] - |A| - [27/04/2017 15:50:02] - (.Copyright (c) 2000 - 2015 Advanced Messaging Systems LLC - Outlook Redemption COM library.) - [2393.6 Ko] - (5.10.0.4312) - C:\WINDOWS\SysWOW64\rsrorx32.dll[MD5.00000000000000000000000000000000] - |D| - [26/04/2017 18:50:33] - [2198.22 Ko] - C:\WINDOWS\SysWOW64\RTCOM[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [283.5 Ko] - C:\WINDOWS\SysWOW64\ru-RU[MD5.00000000000000000000000000000000] - |D| - [21/07/2017 11:15:42] - [131 Ko] - C:\WINDOWS\SysWOW64\sda[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [231 Ko] - C:\WINDOWS\SysWOW64\sk-SK[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [228.5 Ko] - C:\WINDOWS\SysWOW64\sl-SI[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:28] - [52.14 Ko] - C:\WINDOWS\SysWOW64\slmgr[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\SMI[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4128.41 Ko] - C:\WINDOWS\SysWOW64\Speech[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [8209.1 Ko] - C:\WINDOWS\SysWOW64\Speech_OneCore[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1271.66 Ko] - C:\WINDOWS\SysWOW64\spp[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [31.88 Ko] - C:\WINDOWS\SysWOW64\sppui[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 09:22:36] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-CS[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [231.5 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-RS[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\sru[MD5.1291A61F0F4A49E5F4C869E677F67C57] - |AC| - [18/03/2017 22:58:39] - (. - .) - [300 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ssdm.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [276.5 Ko] - C:\WINDOWS\SysWOW64\sv-SE[MD5.B71EDD2C82F513AACCD3059635F483EA] - |A| - [28/04/2017 13:58:53] - (. - .) - [676 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\SyncBackPro.dll[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:28] - [0 Ko] - C:\WINDOWS\SysWOW64\sysprep[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\WINDOWS\SysWOW64\Tasks[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [215 Ko] - C:\WINDOWS\SysWOW64\th-TH[MD5.0087F6F680BEFDA997B357BD55BE991C] - |A| - [01/05/2017 17:03:37] - (. - .) - [161.5 Ko] - (3.93.100.73) - C:\WINDOWS\SysWOW64\unrar.dll[MD5.6FBC8680275BD9B0871CF2A0A7BBAABA] - |A| - [10/07/2017 20:41:35] - (.MoonLight Software Inc. - copy protection software.) - [734 Ko] - (4.2.3.25) - C:\WINDOWS\SysWOW64\VBOLock.ocx[MD5.A40EFB7B05D727D9D0B5D7ED9C8B87C4] - |A| - [10/07/2017 20:41:35] - (. - .) - [1.04 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vbrun60.inf[MD5.550BA20DF6C08E628CA9ABD0F6E917B8] - |A| - [24/04/2017 09:27:31] - (. - .) - [10 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vidx16.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [15582.66 Ko] - C:\WINDOWS\SysWOW64\wbem[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:28] - [0 Ko] - C:\WINDOWS\SysWOW64\WCN[MD5.D676BC75BD566BC91BFEC3D4EDA42655] - |AC| - [18/03/2017 22:58:54] - (. - .) - [84.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [7507.12 Ko] - C:\WINDOWS\SysWOW64\WindowsPowerShell[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4744.1 Ko] - C:\WINDOWS\SysWOW64\WinMetadata[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 07:10:28] - [107.53 Ko] - C:\WINDOWS\SysWOW64\winrm[MD5.D494267BC169604FAC5E3679B9A97FED] - |A| - [09/07/2017 09:01:45] - (.Copyright © 2008 - OpenAL32.) - [434.52 Ko] - (2.2.0.5) - C:\WINDOWS\SysWOW64\wrap_oal.dll[MD5.B6F89F4C37052969C0E5A8CF47C103D5] - |AC| - [06/07/2017 18:37:15] - (. - .) - [58.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll[MD5.00000000000000000000000000000000] - |D| - [26/04/2017 19:18:54] - [10.16 Ko] - C:\WINDOWS\SysWOW64\XPSViewer[MD5.214BF440424F4B02151D977223008E4B] - |A| - [21/07/2017 19:53:35] - (. - .) - [76 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvid.ax[MD5.2448E711931D8827B53F891CCC845C57] - |A| - [01/05/2017 17:03:24] - (. - .) - [796 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvidcore.dll[MD5.37F6747C36BE24A9BFE63F6F041095C8] - |A| - [01/05/2017 17:03:24] - (. - .) - [176 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvidvfw.dll[MD5.C52757F1EA2812847EB65B72A8371794] - |A| - [01/05/2017 17:03:25] - (.www.helixcommunity.org - Helix YV12 YUV Codec.) - [232 Ko] - (1.3.0.0) - C:\WINDOWS\SysWOW64\yv12vfw.dll[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [197.5 Ko] - C:\WINDOWS\SysWOW64\zh-CN[MD5.00000000000000000000000000000000] - |D| - [12/11/2016 09:22:36] - [0 Ko] - C:\WINDOWS\SysWOW64\zh-HK[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [192 Ko] - C:\WINDOWS\SysWOW64\zh-TW ---------- | Shell Folders [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]"!Do not use this registry key"=Use the SHGetFolderPath or SHGetKnownFolderPath function instead "AppData"=C:\Users\Jean-Marie\AppData\Roaming [26/04/2017 18:53:29]"Local AppData"=C:\Users\Jean-Marie\AppData\Local [26/04/2017 18:53:29]"{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Libraries [12/11/2016 10:02:24]"My Video"=C:\Users\Jean-Marie\Videos [10/11/2016 15:52:02]"My Pictures"=C:\Users\Jean-Marie\Pictures [10/11/2016 15:52:02]"Desktop"=C:\Users\Jean-Marie\Desktop [10/11/2016 15:52:04]"History"=C:\Users\Jean-Marie\AppData\Local\Microsoft\Windows\History [12/11/2016 09:57:56]"NetHood"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Network Shortcuts [26/04/2017 18:53:29]"{56784854-C6CB-462B-8169-88E350ACB882}"=C:\Users\Jean-Marie\Contacts [10/11/2016 15:54:29]"{00BCFC5A-ED94-4E48-96A1-3F6217F21990}"=C:\Users\Jean-Marie\AppData\Local\Microsoft\Windows\RoamingTiles [12/11/2016 10:09:10]"Cookies"=C:\Users\Jean-Marie\AppData\Local\Microsoft\Windows\INetCookies [12/11/2016 09:57:56]"Favorites"=C:\Users\Jean-Marie\Favorites [10/11/2016 15:52:02]"SendTo"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\SendTo [12/11/2016 09:57:55]"Start Menu"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu [12/11/2016 09:57:55]"My Music"=C:\Users\Jean-Marie\Music [10/11/2016 15:52:02]"Programs"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [12/11/2016 09:57:55]"Recent"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Recent [12/11/2016 09:57:55]"CD Burning"=C:\Users\Jean-Marie\AppData\Local\Microsoft\Windows\Burn\Burn1 [26/04/2017 20:51:23]"PrintHood"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Printer Shortcuts [26/04/2017 18:53:29]"{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}"=C:\Users\Jean-Marie\Searches [12/11/2016 10:09:10]"{374DE290-123F-4565-9164-39C4925E467B}"=C:\Users\Jean-Marie\Downloads [10/11/2016 15:52:02]"{A520A1A4-1780-4FF6-BD18-167343C5AF16}"=C:\Users\Jean-Marie\AppData\LocalLow [10/11/2016 15:52:15]"Startup"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [12/11/2016 10:09:10]"Administrative Tools"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [12/11/2016 10:09:10]"Personal"=C:\Users\Jean-Marie\Documents [10/11/2016 15:52:02]"{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}"=C:\Users\Jean-Marie\Links [10/11/2016 15:52:02]"Cache"=C:\Users\Jean-Marie\AppData\Local\Microsoft\Windows\INetCache [06/07/2017 07:46:54]"Templates"=C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Templates [26/04/2017 18:53:29]"{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}"=C:\Users\Jean-Marie\Saved Games [10/11/2016 15:52:02]"Fonts"=C:\WINDOWS\Fonts [18/03/2017 23:03:29] [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]"AppData"=%USERPROFILE%\AppData\Roaming "Cache"=%USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache "Cookies"=%USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies "Desktop"=%USERPROFILE%\Desktop "Favorites"=%USERPROFILE%\Favorites "History"=%USERPROFILE%\AppData\Local\Microsoft\Windows\History "Local AppData"=%USERPROFILE%\AppData\Local "My Music"=%USERPROFILE%\Music "My Pictures"=%USERPROFILE%\Pictures "My Video"=%USERPROFILE%\Videos "NetHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts "Personal"=%USERPROFILE%\Documents "PrintHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts "Programs"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs "Recent"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent "SendTo"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo "Start Menu"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu "Startup"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup "Templates"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates "{374DE290-123F-4565-9164-39C4925E467B}"=%USERPROFILE%\Downloads "CD Burning"=%USERPROFILE%\AppData\Local\Microsoft\Windows\Burn\Burn1 [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]"Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [18/03/2017 23:03:29]"Common AppData"=C:\ProgramData [18/03/2017 23:03:29]"Common Desktop"=C:\Users\Public\Desktop [26/07/2012 10:12:59]"Common Documents"=C:\Users\Public\Documents [26/07/2012 10:12:59]"Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [18/03/2017 23:03:29]"Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [18/03/2017 23:03:29]"Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [18/03/2017 23:03:29]"Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [26/07/2012 10:12:59]"CommonMusic"=C:\Users\Public\Music [26/07/2012 10:12:59]"CommonPictures"=C:\Users\Public\Pictures [26/07/2012 10:12:59]"CommonVideo"=C:\Users\Public\Videos [26/07/2012 10:12:59]"OEM Links"=C:\ProgramData\OEM\Links [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]"Common AppData"=%ProgramData% "Common Desktop"=%PUBLIC%\Desktop "Common Documents"=%PUBLIC%\Documents "Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs "Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu "Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup "Common Templates"=%ProgramData%\Microsoft\Windows\Templates "CommonMusic"=%PUBLIC%\Music "CommonPictures"=%PUBLIC%\Pictures "CommonVideo"=%PUBLIC%\Videos "{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]"Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [18/03/2017 23:03:29]"Common AppData"=C:\ProgramData [18/03/2017 23:03:29]"Common Desktop"=C:\Users\Public\Desktop [26/07/2012 10:12:59]"Common Documents"=C:\Users\Public\Documents [26/07/2012 10:12:59]"Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [18/03/2017 23:03:29]"Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [18/03/2017 23:03:29]"Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [18/03/2017 23:03:29]"Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [26/07/2012 10:12:59]"CommonMusic"=C:\Users\Public\Music [26/07/2012 10:12:59]"CommonPictures"=C:\Users\Public\Pictures [26/07/2012 10:12:59]"CommonVideo"=C:\Users\Public\Videos [26/07/2012 10:12:59]"OEM Links"=C:\ProgramData\OEM\Links [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]"Common AppData"=%ProgramData% "Common Desktop"=%PUBLIC%\Desktop "Common Documents"=%PUBLIC%\Documents "Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs "Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu "Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup "Common Templates"=%ProgramData%\Microsoft\Windows\Templates "CommonMusic"=%PUBLIC%\Music "CommonPictures"=%PUBLIC%\Pictures "CommonVideo"=%PUBLIC%\Videos "{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads ---------- | [Jean-Marie] [26/04/2017 18:53:29] - |D| - [3234213893] - C:\Users\Jean-Marie\AppData\Local[10/11/2016 15:52:15] - |D| - [377634511] - C:\Users\Jean-Marie\AppData\LocalLow[26/04/2017 18:53:29] - |D| - [984740631] - C:\Users\Jean-Marie\AppData\Roaming[07/07/2017 15:02:43] - |D| - [0] - C:\Users\Jean-Marie\AppData\RoamingStartup Manager[28/04/2017 13:57:21] - |D| - [2914] - C:\Users\Jean-Marie\AppData\Local\2BrightSparks[07/07/2017 20:48:44] - |D| - [1234] - C:\Users\Jean-Marie\AppData\Local\68cd1c0899494f3ebe64f4d7218bb21b[06/07/2017 15:36:04] - |D| - [1234] - C:\Users\Jean-Marie\AppData\Local\7446686657b8429f8aeac9a2e298e45a[27/04/2017 11:28:14] - |D| - [688496] - C:\Users\Jean-Marie\AppData\Local\AdAwareDesktop[23/04/2017 20:15:36] - |D| - [688496] - C:\Users\Jean-Marie\AppData\Local\AdAwareUpdater[06/07/2017 15:20:56] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Adobe[28/04/2017 12:23:22] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Aiseesoft Studio[21/07/2017 18:03:46] - |D| - [135040404] - C:\Users\Jean-Marie\AppData\Local\Amazon Music[12/11/2016 10:15:07] - |D| - [102055] - C:\Users\Jean-Marie\AppData\Local\AMD[12/11/2016 16:27:22] - |D| - [1953204] - C:\Users\Jean-Marie\AppData\Local\Apowersoft[26/04/2017 18:53:30] - |SHD| - [32831818831] - C:\Users\Jean-Marie\AppData\Local\Application Data[28/04/2017 13:25:59] - |D| - [140214271] - C:\Users\Jean-Marie\AppData\Local\Apps[01/05/2017 20:50:15] - |D| - [366178] - C:\Users\Jean-Marie\AppData\Local\ashampoo[12/11/2016 10:14:29] - |D| - [66104] - C:\Users\Jean-Marie\AppData\Local\ATI[02/05/2017 13:22:19] - |D| - [2885001] - C:\Users\Jean-Marie\AppData\Local\Avanquest[15/07/2017 14:42:32] - |D| - [453] - C:\Users\Jean-Marie\AppData\Local\Black Bird Cleaner Software[01/05/2017 23:30:40] - |D| - [446149] - C:\Users\Jean-Marie\AppData\Local\CEF[28/04/2017 13:28:57] - |D| - [99] - C:\Users\Jean-Marie\AppData\Local\ChemTable Software[12/11/2016 10:51:55] - |D| - [26959876] - C:\Users\Jean-Marie\AppData\Local\Comms[10/07/2017 23:08:55] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Comodo[12/11/2016 10:08:51] - |D| - [235679] - C:\Users\Jean-Marie\AppData\Local\ConnectedDevicesPlatform[29/04/2017 09:47:01] - |D| - [138] - C:\Users\Jean-Marie\AppData\Local\Copy Handler[25/04/2017 15:09:02] - |D| - [10995500] - C:\Users\Jean-Marie\AppData\Local\CrashDumps[19/07/2017 18:58:37] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\CrashRpt[23/04/2017 11:18:15] - |D| - [190831] - C:\Users\Jean-Marie\AppData\Local\CyberGhost[14/11/2016 19:14:54] - |D| - [3209915] - C:\Users\Jean-Marie\AppData\Local\CyberLink[06/07/2017 17:00:23] - |D| - [1234] - C:\Users\Jean-Marie\AppData\Local\d0bc93ac1fa14d4da183e0d1a213e056[26/04/2017 20:49:14] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\DBG[28/04/2017 13:25:59] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Deployment[27/04/2017 15:24:14] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Diagnostics[12/11/2016 11:52:06] - |D| - [962560] - C:\Users\Jean-Marie\AppData\Local\Downloaded Installations[28/04/2017 13:44:38] - |D| - [2836618] - C:\Users\Jean-Marie\AppData\Local\DownloadFileOpener[12/05/2017 07:14:37] - |D| - [869] - C:\Users\Jean-Marie\AppData\Local\Fast HTML Checker[23/04/2017 11:35:50] - |D| - [40] - C:\Users\Jean-Marie\AppData\Local\Google[21/07/2017 18:26:34] - |D| - [113245140] - C:\Users\Jean-Marie\AppData\Local\Grabilla[29/04/2017 09:25:18] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Greenshot[26/04/2017 18:53:30] - |SHD| - [130] - C:\Users\Jean-Marie\AppData\Local\Historique[22/07/2017 20:03:25] - |D| - [130] - C:\Users\Jean-Marie\AppData\Local\History[28/04/2017 14:01:24] - |D| - [124732467] - C:\Users\Jean-Marie\AppData\Local\Innovative Solutions[28/04/2017 14:56:51] - |D| - [82] - C:\Users\Jean-Marie\AppData\Local\iSkysoft[30/04/2017 18:30:29] - |D| - [5427136] - C:\Users\Jean-Marie\AppData\Local\Kotobee Author[30/04/2017 18:30:12] - |D| - [5401856] - C:\Users\Jean-Marie\AppData\Local\Kotobee Reader[28/04/2017 13:45:45] - |D| - [586] - C:\Users\Jean-Marie\AppData\Local\LabPixels[14/11/2016 20:17:30] - |D| - [2914129] - C:\Users\Jean-Marie\AppData\Local\Logitech® Webcam Software[26/04/2017 18:53:29] - |D| - [408697532] - C:\Users\Jean-Marie\AppData\Local\Microsoft[12/11/2016 10:25:42] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\MicrosoftEdge[12/11/2016 14:05:55] - |D| - [312761309] - C:\Users\Jean-Marie\AppData\Local\Moonchild Productions[22/07/2017 18:00:19] - |D| - [1671798] - C:\Users\Jean-Marie\AppData\Local\Mozilla[21/07/2017 18:19:37] - |D| - [178251] - C:\Users\Jean-Marie\AppData\Local\NOS[01/05/2017 17:02:08] - |D| - [57102] - C:\Users\Jean-Marie\AppData\Local\Online Video Recorder[09/07/2017 09:20:45] - |D| - [7878397] - C:\Users\Jean-Marie\AppData\Local\Opera Software[12/11/2016 10:09:01] - |D| - [197630112] - C:\Users\Jean-Marie\AppData\Local\Packages[07/07/2017 13:49:45] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Paragon[09/07/2017 09:44:17] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\PDFCreator[15/11/2016 10:50:51] - |D| - [40960] - C:\Users\Jean-Marie\AppData\Local\Power2Go11[12/11/2016 16:27:11] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Programs[09/07/2017 09:06:27] - |D| - [72269] - C:\Users\Jean-Marie\AppData\Local\Protect[12/11/2016 10:11:36] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Publishers[03/05/2017 14:57:48] - |D| - [7554] - C:\Users\Jean-Marie\AppData\Local\Recovery[29/04/2017 08:06:41] - |D| - [14122] - C:\Users\Jean-Marie\AppData\Local\Seed4Me[22/07/2017 15:51:34] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\SelfExtractible[22/07/2017 15:51:33] - |A| - [9276713] - C:\Users\Jean-Marie\AppData\Local\SelfExtractible.zip[27/04/2017 16:15:04] - |D| - [22510] - C:\Users\Jean-Marie\AppData\Local\SIB[28/04/2017 14:10:22] - |D| - [1470604] - C:\Users\Jean-Marie\AppData\Local\StartIsBack[09/07/2017 09:19:25] - |AD| - [3369563] - C:\Users\Jean-Marie\AppData\Local\SterJo Key Finder[24/04/2017 10:18:01] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\TeamViewer[29/04/2017 09:29:15] - |D| - [1810510] - C:\Users\Jean-Marie\AppData\Local\TechSmith[06/07/2017 07:46:39] - |D| - [1252368530] - C:\Users\Jean-Marie\AppData\Local\Temp[26/04/2017 18:53:30] - |SHD| - [91337112] - C:\Users\Jean-Marie\AppData\Local\Temporary Internet Files[22/07/2017 08:21:15] - |A| - [0] - C:\Users\Jean-Marie\AppData\Local\Temprad94669.tmp[27/04/2017 13:41:47] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\Thinstall[12/11/2016 10:08:57] - |D| - [19161088] - C:\Users\Jean-Marie\AppData\Local\TileDataLayer[21/07/2017 17:01:15] - |D| - [4769] - C:\Users\Jean-Marie\AppData\Local\TriSun_Software_Limited[07/07/2017 13:22:52] - |D| - [370] - C:\Users\Jean-Marie\AppData\Local\Turbo View & Convert[29/04/2017 10:45:55] - |D| - [0] - C:\Users\Jean-Marie\AppData\Local\VDownloader[12/11/2016 10:09:05] - |D| - [4337614] - C:\Users\Jean-Marie\AppData\Local\VirtualStore[29/04/2017 10:09:12] - |D| - [22310139] - C:\Users\Jean-Marie\AppData\Local\Vision[22/07/2017 17:00:14] - |D| - [194094387] - C:\Users\Jean-Marie\AppData\Local\VS Revo Group[11/07/2017 08:58:16] - |D| - [8856407] - C:\Users\Jean-Marie\AppData\Local\WallpaperAnime[12/11/2016 12:05:34] - |D| - [46182785] - C:\Users\Jean-Marie\AppData\Local\WinZip[28/04/2017 13:08:23] - |D| - [82] - C:\Users\Jean-Marie\AppData\Local\Wondershare[14/11/2016 10:04:35] - |D| - [70174033] - C:\Users\Jean-Marie\AppData\Local\Zemana[25/04/2017 09:09:12] - |D| - [162404] - C:\Users\Jean-Marie\AppData\Local\ZHP[25/04/2017 18:19:29] - |D| - [693764] - C:\Users\Jean-Marie\AppData\Local\{C7C5F199-E36D-9D21-8EF5-B8C9AA9D4451}[06/07/2017 15:24:11] - |D| - [107] - C:\Users\Jean-Marie\AppData\LocalLow\iFunSoft[27/04/2017 15:00:38] - |D| - [369807522] - C:\Users\Jean-Marie\AppData\LocalLow\IObit[10/11/2016 15:52:30] - |SD| - [7037465] - C:\Users\Jean-Marie\AppData\LocalLow\Microsoft[26/04/2017 14:20:25] - |D| - [223] - C:\Users\Jean-Marie\AppData\LocalLow\Mozilla[11/07/2017 07:42:21] - |D| - [756426] - C:\Users\Jean-Marie\AppData\LocalLow\Sun[22/07/2017 14:27:01] - |D| - [0] - C:\Users\Jean-Marie\AppData\LocalLow\Temp[11/07/2017 08:20:07] - |D| - [32768] - C:\Users\Jean-Marie\AppData\LocalLow\uTorrent[12/05/2017 04:41:00] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Acronis[27/04/2017 11:28:55] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\adaware[12/11/2016 10:09:01] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Adobe[24/04/2017 16:00:44] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\AmazingPartitionManager[12/11/2016 16:27:31] - |D| - [87] - C:\Users\Jean-Marie\AppData\Roaming\Apowersoft[01/05/2017 20:50:33] - |D| - [689751] - C:\Users\Jean-Marie\AppData\Roaming\Ashampoo[12/11/2016 10:14:29] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\ATI[07/07/2017 09:59:38] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Avanquest[02/05/2017 13:22:18] - |D| - [2562912] - C:\Users\Jean-Marie\AppData\Roaming\Avanquest Software[06/07/2017 16:01:47] - |D| - [26] - C:\Users\Jean-Marie\AppData\Roaming\Avant Downloader[06/07/2017 16:01:43] - |D| - [28941894] - C:\Users\Jean-Marie\AppData\Roaming\Avant Profiles[01/05/2017 23:30:42] - |D| - [221] - C:\Users\Jean-Marie\AppData\Roaming\AVAST Software[12/05/2017 05:56:47] - |D| - [247825901] - C:\Users\Jean-Marie\AppData\Roaming\Azureus[02/05/2017 11:32:29] - |A| - [83] - C:\Users\Jean-Marie\AppData\Roaming\Camdata.ini[02/05/2017 11:32:29] - |A| - [408] - C:\Users\Jean-Marie\AppData\Roaming\CamLayout.ini[02/05/2017 11:32:29] - |A| - [408] - C:\Users\Jean-Marie\AppData\Roaming\CamShapes.ini[02/05/2017 11:32:29] - |A| - [4547] - C:\Users\Jean-Marie\AppData\Roaming\CamStudio.cfg[28/04/2017 13:38:24] - |D| - [89629] - C:\Users\Jean-Marie\AppData\Roaming\ChemTable Software[07/07/2017 09:39:12] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLAngularJS[07/07/2017 09:39:12] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLBackboneJS[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLCakePHP[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLCodeIgniter[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLDrupal[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLEmberJS[25/04/2017 10:21:23] - |D| - [1761937] - C:\Users\Jean-Marie\AppData\Roaming\Clipdiary[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLJoomla[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLJQuery[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLLaravel[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLMagento[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLMeteorJS[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLPhalcon[07/07/2017 09:39:14] - |D| - [1102] - C:\Users\Jean-Marie\AppData\Roaming\ClPhpEd[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLSmarty[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLSMySQL[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLSymfony[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLWordPress[07/07/2017 09:39:13] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\CLYii[10/07/2017 20:52:51] - |A| - [701] - C:\Users\Jean-Marie\AppData\Roaming\codec.dll[11/07/2017 08:52:00] - |D| - [387657] - C:\Users\Jean-Marie\AppData\Roaming\Comodo[21/07/2017 18:34:04] - |D| - [1842048] - C:\Users\Jean-Marie\AppData\Roaming\concept design[15/11/2016 10:52:05] - |D| - [142803] - C:\Users\Jean-Marie\AppData\Roaming\CyberLink[28/04/2017 14:05:10] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\DAEMON Tools Lite[14/11/2016 10:27:11] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\DAEMON Tools Pro[22/07/2017 12:21:57] - |D| - [360518] - C:\Users\Jean-Marie\AppData\Roaming\DesktopIconAmazon[10/07/2017 21:27:31] - |D| - [98534] - C:\Users\Jean-Marie\AppData\Roaming\DesktopIconCALLofWAR[21/07/2017 17:27:21] - |D| - [26] - C:\Users\Jean-Marie\AppData\Roaming\Digiarty[23/04/2017 11:52:30] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\DiskDefrag[02/05/2017 10:10:48] - |D| - [140094] - C:\Users\Jean-Marie\AppData\Roaming\DivX[28/04/2017 13:44:42] - |D| - [27] - C:\Users\Jean-Marie\AppData\Roaming\DownloadFileOpener[23/04/2017 14:05:11] - |D| - [384] - C:\Users\Jean-Marie\AppData\Roaming\EASEUS[22/07/2017 15:12:40] - |D| - [206524651] - C:\Users\Jean-Marie\AppData\Roaming\Easeware[12/05/2017 07:10:42] - |D| - [82100] - C:\Users\Jean-Marie\AppData\Roaming\Encrypt4all Software[22/07/2017 12:44:56] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Enigma Software Group[13/11/2016 19:26:19] - |D| - [6777] - C:\Users\Jean-Marie\AppData\Roaming\Epson[23/04/2017 10:38:02] - |D| - [8406311] - C:\Users\Jean-Marie\AppData\Roaming\eufsc[10/07/2017 21:54:40] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\extensions[04/05/2017 18:08:04] - |D| - [12] - C:\Users\Jean-Marie\AppData\Roaming\Foxit AgentInformation[04/05/2017 18:07:39] - |D| - [4756444] - C:\Users\Jean-Marie\AppData\Roaming\Foxit Software[24/04/2017 20:31:12] - |D| - [9479] - C:\Users\Jean-Marie\AppData\Roaming\FreeFileSync[22/07/2017 12:03:46] - |D| - [8659] - C:\Users\Jean-Marie\AppData\Roaming\Genie9[21/07/2017 18:19:37] - |D| - [959336] - C:\Users\Jean-Marie\AppData\Roaming\get2Clouds[23/04/2017 11:52:28] - |D| - [97383] - C:\Users\Jean-Marie\AppData\Roaming\GlarySoft[11/07/2017 08:03:19] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\GoodSync[29/04/2017 09:25:18] - |D| - [15688] - C:\Users\Jean-Marie\AppData\Roaming\Greenshot[15/07/2017 10:26:51] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\IceDragon[06/07/2017 15:22:54] - |D| - [3172] - C:\Users\Jean-Marie\AppData\Roaming\iFunSoft[28/04/2017 13:57:07] - |D| - [38017235] - C:\Users\Jean-Marie\AppData\Roaming\Innovative Solutions[27/04/2017 14:47:37] - |D| - [6398747] - C:\Users\Jean-Marie\AppData\Roaming\IObit[25/04/2017 11:18:12] - |D| - [307280] - C:\Users\Jean-Marie\AppData\Roaming\JAM Software[04/05/2017 11:09:07] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\java[07/07/2017 10:51:16] - |D| - [48] - C:\Users\Jean-Marie\AppData\Roaming\KastorAllVideoDownloader[23/04/2017 11:29:55] - |D| - [20] - C:\Users\Jean-Marie\AppData\Roaming\KastorFreeVimeoDownloader[23/04/2017 11:27:09] - |D| - [22] - C:\Users\Jean-Marie\AppData\Roaming\KastorStreamRecorder[23/04/2017 11:27:37] - |D| - [383] - C:\Users\Jean-Marie\AppData\Roaming\KastorTubeToMp3[29/04/2017 11:31:00] - |D| - [233] - C:\Users\Jean-Marie\AppData\Roaming\KastorVideoConverter[30/04/2017 18:36:09] - |D| - [22242029] - C:\Users\Jean-Marie\AppData\Roaming\KotobeePublisher[12/11/2016 10:26:25] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Lavasoft[12/11/2016 10:25:39] - |D| - [737] - C:\Users\Jean-Marie\AppData\Roaming\LavasoftStatistics[14/11/2016 19:39:48] - |D| - [345] - C:\Users\Jean-Marie\AppData\Roaming\Leadertech[13/11/2016 20:28:03] - |D| - [291] - C:\Users\Jean-Marie\AppData\Roaming\Macromedia[02/05/2017 13:58:19] - |D| - [74] - C:\Users\Jean-Marie\AppData\Roaming\Media Player Classic[26/04/2017 18:53:29] - |SD| - [4208789] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft[12/11/2016 11:46:14] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Modules[12/11/2016 14:05:55] - |D| - [16648414] - C:\Users\Jean-Marie\AppData\Roaming\Moonchild Productions[12/11/2016 10:29:20] - |D| - [50256115] - C:\Users\Jean-Marie\AppData\Roaming\Mozilla[19/07/2017 13:11:18] - |D| - [39366] - C:\Users\Jean-Marie\AppData\Roaming\MultiCommander[21/07/2017 17:07:18] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Nico Mak Computing[21/07/2017 18:56:22] - |D| - [2022105] - C:\Users\Jean-Marie\AppData\Roaming\Notepad++[24/04/2017 18:53:52] - |HD| - [576] - C:\Users\Jean-Marie\AppData\Roaming\Obsidium[21/07/2017 18:38:41] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\OpenBoxLab[09/07/2017 09:20:21] - |D| - [13159262] - C:\Users\Jean-Marie\AppData\Roaming\Opera Software[21/07/2017 18:37:50] - |D| - [14339] - C:\Users\Jean-Marie\AppData\Roaming\PeaZip[27/04/2017 15:56:01] - |AD| - [23488372] - C:\Users\Jean-Marie\AppData\Roaming\PhrozenWinja[29/04/2017 18:19:48] - |D| - [5180173] - C:\Users\Jean-Marie\AppData\Roaming\proDAD[07/07/2017 11:48:31] - |D| - [27896] - C:\Users\Jean-Marie\AppData\Roaming\ProductData[27/04/2017 15:51:26] - |D| - [100536941] - C:\Users\Jean-Marie\AppData\Roaming\Remo[07/07/2017 14:21:43] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Remo MORE[07/07/2017 20:53:03] - |D| - [978] - C:\Users\Jean-Marie\AppData\Roaming\Roxio[08/07/2017 07:18:59] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Roxio Burn[07/07/2017 10:10:04] - |D| - [2915] - C:\Users\Jean-Marie\AppData\Roaming\Roxio Log Files[11/07/2017 09:37:09] - |D| - [661] - C:\Users\Jean-Marie\AppData\Roaming\SDO[22/07/2017 12:18:44] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\SimpleStar[12/11/2016 10:32:54] - |D| - [77] - C:\Users\Jean-Marie\AppData\Roaming\Skype[29/04/2017 10:37:58] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\SoftCDN[02/05/2017 13:13:40] - |D| - [974514] - C:\Users\Jean-Marie\AppData\Roaming\StartMenuX[10/07/2017 21:54:29] - |D| - [2825486] - C:\Users\Jean-Marie\AppData\Roaming\Steganos[10/07/2017 21:55:28] - |D| - [18808504] - C:\Users\Jean-Marie\AppData\Roaming\Steganos Updates[10/07/2017 21:54:37] - |D| - [346958] - C:\Users\Jean-Marie\AppData\Roaming\Steganos VPN[21/07/2017 10:56:02] - |D| - [143558] - C:\Users\Jean-Marie\AppData\Roaming\SuperBoost[05/05/2017 12:43:11] - |D| - [36111557] - C:\Users\Jean-Marie\AppData\Roaming\SyncDroid[05/05/2017 12:43:12] - |D| - [3108] - C:\Users\Jean-Marie\AppData\Roaming\Syncios[05/05/2017 12:43:11] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Syncios Data Transfer[09/07/2017 09:06:33] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\syscn[24/04/2017 09:52:03] - |D| - [28378] - C:\Users\Jean-Marie\AppData\Roaming\TeamViewer[24/04/2017 18:52:30] - |D| - [46006652] - C:\Users\Jean-Marie\AppData\Roaming\TeraCopy[27/04/2017 13:41:47] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Thinstall[21/07/2017 17:01:16] - |D| - [30954] - C:\Users\Jean-Marie\AppData\Roaming\TSS[12/11/2016 11:46:04] - |AD| - [15345563] - C:\Users\Jean-Marie\AppData\Roaming\UsbFix[02/05/2017 10:10:23] - |A| - [96] - C:\Users\Jean-Marie\AppData\Roaming\version2.xml[27/04/2017 16:06:25] - |D| - [21068] - C:\Users\Jean-Marie\AppData\Roaming\Viv[23/04/2017 13:17:25] - |D| - [28002517] - C:\Users\Jean-Marie\AppData\Roaming\VOS[11/07/2017 10:30:43] - |D| - [191040] - C:\Users\Jean-Marie\AppData\Roaming\WarThunder[24/04/2017 09:52:27] - |D| - [13] - C:\Users\Jean-Marie\AppData\Roaming\WinParam[25/04/2017 18:59:54] - |D| - [12] - C:\Users\Jean-Marie\AppData\Roaming\WinRAR[06/07/2017 15:31:27] - |D| - [303] - C:\Users\Jean-Marie\AppData\Roaming\Wise Duplicate Finder[07/07/2017 09:57:05] - |D| - [239] - C:\Users\Jean-Marie\AppData\Roaming\Wise Folder Hider[06/07/2017 15:31:26] - |D| - [366] - C:\Users\Jean-Marie\AppData\Roaming\Wise Hotkey[08/07/2017 13:51:38] - |D| - [597] - C:\Users\Jean-Marie\AppData\Roaming\Wise Registry Cleaner[21/07/2017 16:48:06] - |D| - [9074344] - C:\Users\Jean-Marie\AppData\Roaming\Wondershare[29/04/2017 09:37:52] - |D| - [15870] - C:\Users\Jean-Marie\AppData\Roaming\Xilisoft[02/05/2017 13:48:25] - |D| - [2239492] - C:\Users\Jean-Marie\AppData\Roaming\XYplorerFree[12/11/2016 12:17:58] - |D| - [37976453] - C:\Users\Jean-Marie\AppData\Roaming\ZHP[12/11/2016 10:09:10] - |ASH| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini[21/07/2017 19:51:40] - |A| - [2024] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\File Arranger.lnk[26/04/2017 18:53:30] - |SHD| - [218331] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes[12/11/2016 09:57:55] - |RD| - [218331] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs[26/04/2017 18:53:29] - |RD| - [3888] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility[26/04/2017 18:53:29] - |RD| - [2709] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories[12/11/2016 10:09:10] - |RD| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools[21/07/2017 18:03:59] - |D| - [3525] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon Music[11/07/2017 08:13:38] - |D| - [4769] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Android Data Recovery[11/07/2017 08:14:34] - |D| - [3425] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Any Data Recovery Pro[22/07/2017 15:13:23] - |D| - [8180] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AoaoPhoto Digital Studio[22/07/2017 06:58:48] - |D| - [5794] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Avanquest[11/07/2017 08:15:03] - |D| - [4686] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Card Data Recovery[11/07/2017 10:00:48] - |D| - [2258] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Charity Engine[24/04/2017 17:02:01] - |D| - [2183] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CHM Editor[07/07/2017 09:38:08] - |D| - [2713] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Codelobster Software[21/07/2017 18:34:04] - |D| - [6505] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\concept design[23/04/2017 11:18:42] - |A| - [2077] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberGhost 6.lnk[11/07/2017 08:15:25] - |D| - [4303] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Data Wipe[29/04/2017 09:24:03] - |D| - [4156] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Debugmode[26/04/2017 20:46:44] - |ASH| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini[28/04/2017 13:44:42] - |D| - [1199] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DownloadFileOpener[05/05/2017 13:17:33] - |D| - [1606] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Easy File Locker[21/07/2017 18:33:41] - |D| - [509] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Etwok LLC[12/05/2017 07:14:11] - |D| - [1598] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fast HTML Checker[21/07/2017 19:51:40] - |D| - [4186] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Arranger[21/07/2017 19:51:40] - |A| - [2030] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Arranger.lnk[30/04/2017 19:13:56] - |A| - [2123] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileHippo App Manager.lnk[11/07/2017 08:15:38] - |D| - [3487] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Any Data Recovery[26/04/2017 11:58:38] - |D| - [3613] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freeraser[21/07/2017 18:19:41] - |D| - [2358] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\get2Clouds[21/07/2017 18:27:11] - |D| - [1160] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grabilla[27/04/2017 15:52:56] - |D| - [12651] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iGetting Audio[15/07/2017 10:33:38] - |D| - [2882] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IM-Magic Partition Resizer Free[24/04/2017 18:45:14] - |D| - [6022] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KillCopy[11/07/2017 10:50:11] - |D| - [2981] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrorit Data Wiper Free[11/07/2017 10:48:00] - |D| - [3176] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrorit Disk Partition Expert Free[11/07/2017 10:49:26] - |D| - [3006] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrorit Disk Scanner Free[11/07/2017 10:48:38] - |D| - [3242] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrorit NTFS To FAT32 Converter[11/07/2017 10:40:09] - |D| - [3164] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrorit Partition Extender Free[26/04/2017 18:53:29] - |D| - [170] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance[05/05/2017 13:27:54] - |D| - [3413] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\muCommander[28/04/2017 13:25:07] - |D| - [2379] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Multi Install 2.4.5[12/11/2016 10:31:58] - |A| - [2428] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk[06/07/2017 15:29:17] - |D| - [2644] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF Files Text Extractor v2.0[29/04/2017 21:26:54] - |D| - [2260] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF-to-Word[29/04/2017 09:44:54] - |D| - [4714] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PerigeeCopy[28/04/2017 14:38:34] - |D| - [3483] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QEMU[14/11/2016 08:54:58] - |D| - [5250] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegSeeker[11/07/2017 08:19:12] - |D| - [4769] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung Data Recovery[12/11/2016 10:09:10] - |RD| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup[01/05/2017 22:06:26] - |D| - [1154] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Supercopier[05/05/2017 12:41:46] - |D| - [3950] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Syncios[26/04/2017 18:53:29] - |RD| - [3496] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools[30/04/2017 18:15:42] - |D| - [3912] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z[11/07/2017 08:18:53] - |D| - [5046] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tenorshare Partition Manager[11/07/2017 08:16:01] - |D| - [5371] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tenorshare Video Converter Standard[05/05/2017 13:26:53] - |D| - [4623] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\trolCommander[23/04/2017 10:38:38] - |D| - [1706] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultracopier[23/04/2017 10:45:04] - |D| - [3540] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker[06/07/2017 15:21:52] - |D| - [8057] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\USB Safely Remove[10/07/2017 20:53:34] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Joiner[29/04/2017 10:09:16] - |D| - [2363] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vision[12/05/2017 05:56:46] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vuze Leap[11/07/2017 08:58:18] - |D| - [2176] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WallpaperAnime[11/07/2017 10:30:43] - |D| - [0] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder[07/07/2017 13:54:29] - |D| - [412] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 10 IoT Core[09/07/2017 08:34:33] - |D| - [3618] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Boot Genius[26/04/2017 18:53:29] - |RD| - [7238] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell[25/04/2017 09:06:02] - |D| - [3318] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR[22/07/2017 15:17:18] - |D| - [4155] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WonderFox Soft[12/11/2016 10:09:10] - |ASH| - [174] - C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [MSSQL$ADK] [26/04/2017 18:53:28] - |D| - [11136487] - C:\Users\MSSQL$ADK\AppData\Local[11/11/2016 10:12:03] - |D| - [0] - C:\Users\MSSQL$ADK\AppData\LocalLow[26/04/2017 18:53:28] - |D| - [44151] - C:\Users\MSSQL$ADK\AppData\Roaming[26/04/2017 18:53:28] - |SHD| - [124754157] - C:\Users\MSSQL$ADK\AppData\Local\Application Data[26/04/2017 18:53:28] - |SHD| - [0] - C:\Users\MSSQL$ADK\AppData\Local\Historique[22/07/2017 20:03:46] - |D| - [0] - C:\Users\MSSQL$ADK\AppData\Local\History[26/04/2017 18:53:28] - |D| - [2395623] - C:\Users\MSSQL$ADK\AppData\Local\Microsoft[06/07/2017 07:30:38] - |D| - [0] - C:\Users\MSSQL$ADK\AppData\Local\Temp[26/04/2017 18:53:28] - |SHD| - [0] - C:\Users\MSSQL$ADK\AppData\Local\Temporary Internet Files[12/07/2017 18:32:03] - |D| - [8740864] - C:\Users\MSSQL$ADK\AppData\Local\TileDataLayer[26/04/2017 18:53:28] - |SD| - [44151] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft[26/04/2017 18:53:28] - |SHD| - [17357] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes[12/11/2016 09:57:53] - |D| - [17357] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs[26/04/2017 18:53:28] - |RD| - [3888] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility[26/04/2017 18:53:28] - |RD| - [2565] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories[26/04/2017 18:53:28] - |D| - [170] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance[26/04/2017 18:53:28] - |RD| - [3496] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools[26/04/2017 18:53:28] - |RD| - [7238] - C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | [Public] ---------- | C:\ProgramData [21/07/2017 16:37:56] - |D| - [906056] - C:\ProgramData\1500647876_00000000_base[28/04/2017 13:54:51] - |D| - [12288] - C:\ProgramData\2BrightSparks[22/07/2017 17:10:52] - |D| - [0] - C:\ProgramData\360safe[06/07/2017 15:35:56] - |D| - [1234] - C:\ProgramData\491d6f83da194b9ba83cd731f362fb98[07/07/2017 14:34:27] - |D| - [1234] - C:\ProgramData\8b65273228e94e319fb363944a28e77d[29/04/2017 11:38:26] - |D| - [271152] - C:\ProgramData\A-PDF[11/07/2017 10:50:28] - |D| - [113] - C:\ProgramData\ABBYY[12/05/2017 04:38:47] - |AD| - [93195] - C:\ProgramData\Acronis[23/04/2017 20:06:22] - |D| - [455511978] - C:\ProgramData\adaware[12/05/2017 03:47:00] - |D| - [1875968] - C:\ProgramData\Admin Arsenal[08/07/2017 13:39:20] - |A| - [56277] - C:\ProgramData\agent.1499513555.bdinstall.bin[11/07/2017 11:35:27] - |A| - [21616] - C:\ProgramData\agent.uninstall.1499765722.bdinstall.bin[28/04/2017 12:22:17] - |D| - [0] - C:\ProgramData\Aiseesoft Studio[26/04/2017 18:52:24] - |D| - [456] - C:\ProgramData\AMD[22/07/2017 15:48:54] - |D| - [7563269] - C:\ProgramData\Animation Editor[21/07/2017 19:48:24] - |D| - [0] - C:\ProgramData\AnyMP4 Studio[26/04/2017 20:18:25] - |SHD| - [142106503915] - C:\ProgramData\Application Data[10/07/2017 11:05:51] - |D| - [186] - C:\ProgramData\ATI[22/07/2017 12:08:37] - |D| - [2143027] - C:\ProgramData\Auslogics[02/05/2017 13:22:01] - |D| - [4942067] - C:\ProgramData\Avanquest[01/05/2017 22:19:18] - |D| - [23338764] - C:\ProgramData\AVAST Software[07/07/2017 14:34:17] - |D| - [1234] - C:\ProgramData\b9021bd426174a9d86efee979576486b[07/07/2017 10:17:14] - |D| - [0] - C:\ProgramData\BDLogging[12/11/2016 10:42:16] - |D| - [2171] - C:\ProgramData\BitDefender[08/07/2017 14:24:42] - |D| - [0] - C:\ProgramData\Bitdefender Home Scanner[11/07/2017 10:00:27] - |D| - [49611] - C:\ProgramData\BOINC[12/11/2016 10:06:06] - |SHD| - [12396] - C:\ProgramData\Bureau[07/07/2017 13:15:05] - |D| - [1234] - C:\ProgramData\c38a54086e05480b80afe510b168cdcc[25/04/2017 19:42:07] - |D| - [19597116] - C:\ProgramData\Caphyon[28/04/2017 13:31:50] - |D| - [0] - C:\ProgramData\Chemtable Software[25/04/2017 09:06:38] - |D| - [1275] - C:\ProgramData\clp[15/11/2016 11:29:55] - |D| - [1345] - C:\ProgramData\CLSK[12/11/2016 09:22:34] - |D| - [0] - C:\ProgramData\Comms[10/07/2017 22:23:02] - |D| - [416407649] - C:\ProgramData\Comodo[10/07/2017 22:23:03] - |D| - [284046577] - C:\ProgramData\Comodo Downloader[02/05/2017 13:18:20] - |D| - [1943] - C:\ProgramData\Configuration[12/11/2016 10:21:20] - |D| - [2812896] - C:\ProgramData\CyberLink[28/04/2017 14:02:44] - |D| - [3382] - C:\ProgramData\DAEMON Tools Lite[14/11/2016 10:26:06] - |D| - [2874] - C:\ProgramData\DAEMON Tools Pro[15/11/2016 10:51:07] - |D| - [0] - C:\ProgramData\dbg[22/07/2017 20:02:59] - |D| - [12396] - C:\ProgramData\Desktop[23/04/2017 10:56:06] - |D| - [0] - C:\ProgramData\DigitalWave.ApplicationUpdater_files[15/11/2016 11:52:05] - |D| - [12722539] - C:\ProgramData\DivX[09/07/2017 07:42:43] - |A| - [20534] - C:\ProgramData\dm.1499578963.2636.bin[09/07/2017 07:42:50] - |A| - [1216] - C:\ProgramData\dm.1499578963.3624.bin[09/07/2017 07:42:50] - |A| - [14310] - C:\ProgramData\dm.1499578963.9172.bin[26/04/2017 20:18:25] - |SHD| - [318134355] - C:\ProgramData\Documents[07/07/2017 13:15:03] - |D| - [1234] - C:\ProgramData\ef023532563846dca758f250d3136483[26/04/2017 18:51:20] - |D| - [11076615] - C:\ProgramData\EPSON[07/07/2017 19:27:18] - |AD| - [360580] - C:\ProgramData\eSellerate[21/07/2017 18:34:25] - |D| - [0] - C:\ProgramData\Etwok Software[07/07/2017 19:19:33] - |D| - [3712212] - C:\ProgramData\FLEXnet[29/04/2017 11:24:41] - |D| - [0] - C:\ProgramData\flipBook[28/04/2017 13:49:53] - |D| - [31532685] - C:\ProgramData\Folderico[04/05/2017 18:08:04] - |D| - [29] - C:\ProgramData\Foxit ContentPlatform[04/05/2017 18:10:06] - |D| - [0] - C:\ProgramData\Foxit Software[22/07/2017 15:48:52] - |D| - [123070] - C:\ProgramData\fpr[21/07/2017 13:41:28] - |D| - [0] - C:\ProgramData\GenesysLogic[23/04/2017 11:50:51] - |D| - [32995447] - C:\ProgramData\GlarySoft[11/07/2017 08:04:04] - |D| - [2961] - C:\ProgramData\GoodSync[08/07/2017 14:31:04] - |A| - [89584] - C:\ProgramData\hva.1499514926.bdinstall.bin[06/07/2017 15:23:59] - |D| - [127] - C:\ProgramData\iFunSoft[01/05/2017 22:32:03] - |D| - [531] - C:\ProgramData\Informer Technologies, Inc[28/04/2017 14:10:35] - |D| - [111067818] - C:\ProgramData\Innovative Solutions[12/11/2016 10:23:59] - |D| - [269656078] - C:\ProgramData\install_backup[12/11/2016 10:23:59] - |D| - [276450] - C:\ProgramData\install_clap[27/04/2017 14:47:10] - |D| - [1997918290] - C:\ProgramData\IObit[28/04/2017 14:41:21] - |D| - [3238710] - C:\ProgramData\iSkysoft[28/04/2017 14:43:54] - |D| - [4759] - C:\ProgramData\iSkysoft iMedia Converter Deluxe[08/07/2017 09:42:14] - |D| - [204] - C:\ProgramData\Kingsoft[12/11/2016 10:21:23] - |D| - [320470996] - C:\ProgramData\Lavasoft[30/04/2017 18:05:58] - |D| - [153] - C:\ProgramData\Licenses[14/11/2016 19:55:53] - |D| - [289] - C:\ProgramData\LogiShrd[07/07/2017 13:29:15] - |D| - [0] - C:\ProgramData\LopeSoft[14/11/2016 10:31:20] - |D| - [1630] - C:\ProgramData\Macrium[07/07/2017 18:56:34] - |D| - [4440231] - C:\ProgramData\Macrovision[25/04/2017 15:41:36] - |D| - [314628166] - C:\ProgramData\Malwarebytes[11/07/2017 08:52:58] - |D| - [0] - C:\ProgramData\McAfee[12/11/2016 10:06:06] - |SHD| - [2181169] - C:\ProgramData\Menu Démarrer[18/03/2017 23:03:29] - |SD| - [1097317785] - C:\ProgramData\Microsoft[12/11/2016 17:25:09] - |D| - [0] - C:\ProgramData\Microsoft DNX[26/04/2017 20:50:32] - |D| - [0] - C:\ProgramData\Microsoft OneDrive[21/07/2017 21:08:10] - |D| - [288129] - C:\ProgramData\MindGems[12/11/2016 10:06:06] - |SHD| - [0] - C:\ProgramData\Modèles[11/07/2017 07:45:29] - |AD| - [998076] - C:\ProgramData\Nero[25/04/2017 09:06:25] - |D| - [518786] - C:\ProgramData\NETC[21/07/2017 17:04:51] - |D| - [0] - C:\ProgramData\Nico Mak Computing[07/07/2017 13:17:54] - |RASH| - [8] - C:\ProgramData\ntuser.pol[12/11/2016 15:44:11] - |D| - [468] - C:\ProgramData\NuGet[12/05/2017 05:56:10] - |D| - [127] - C:\ProgramData\Oracle[26/04/2017 18:51:16] - |D| - [6538201890] - C:\ProgramData\Package Cache[06/07/2017 12:00:32] - |D| - [0] - C:\ProgramData\Paragon[07/07/2017 13:50:58] - |D| - [0] - C:\ProgramData\Paragon Software[15/11/2016 12:03:44] - |D| - [36] - C:\ProgramData\PDVD[10/07/2017 20:41:32] - |D| - [653722] - C:\ProgramData\Photopus[12/11/2016 17:59:51] - |D| - [3906573] - C:\ProgramData\PreEmptive Solutions[29/04/2017 18:19:32] - |D| - [627812562] - C:\ProgramData\proDAD[05/05/2017 13:02:50] - |D| - [2209] - C:\ProgramData\ProductData[15/11/2016 22:52:53] - |D| - [100887490] - C:\ProgramData\Rebit[15/11/2016 23:03:25] - |D| - [0] - C:\ProgramData\Rebit 5[27/04/2017 15:39:31] - |D| - [1666] - C:\ProgramData\regid.2003-04.com.caphyon[11/07/2017 10:46:29] - |D| - [0] - C:\ProgramData\ReviverSoft[25/04/2017 15:13:30] - |D| - [38973618] - C:\ProgramData\RogueKiller[28/04/2017 13:48:49] - |D| - [1800] - C:\ProgramData\RogueKillerPE[07/07/2017 18:57:21] - |AD| - [22600458] - C:\ProgramData\Roxio[10/07/2017 22:23:02] - |D| - [0] - C:\ProgramData\Shared Space[07/07/2017 09:29:01] - |D| - [1008816] - C:\ProgramData\SharewareOnSale Notifier[22/07/2017 12:04:12] - |D| - [1957808] - C:\ProgramData\SimpleStar[28/04/2017 13:36:20] - |D| - [145161337] - C:\ProgramData\Simply Super Software[07/07/2017 18:10:20] - |D| - [421764188] - C:\ProgramData\SmartSound Software Inc[18/03/2017 23:03:29] - |D| - [0] - C:\ProgramData\SoftwareDistribution[07/07/2017 19:18:22] - |D| - [572] - C:\ProgramData\Sonic[13/11/2016 19:35:40] - |D| - [645] - C:\ProgramData\Sony Corporation[22/07/2017 20:02:59] - |D| - [2181169] - C:\ProgramData\Start Menu[02/05/2017 13:13:40] - |D| - [1193] - C:\ProgramData\StartMenuX[21/07/2017 10:56:54] - |D| - [88] - C:\ProgramData\SuperBoost[12/11/2016 10:23:59] - |D| - [36344401] - C:\ProgramData\SUPPORTDIR[14/11/2016 08:20:03] - |D| - [126840] - C:\ProgramData\Temp[22/07/2017 20:02:59] - |D| - [0] - C:\ProgramData\Templates[05/05/2017 13:19:35] - |D| - [751203] - C:\ProgramData\Teorex[03/05/2017 11:25:48] - |D| - [2208] - C:\ProgramData\UCheck[13/11/2016 19:36:35] - |D| - [4680] - C:\ProgramData\UDL[12/11/2016 12:06:19] - |D| - [294] - C:\ProgramData\UniqueId[06/07/2017 15:21:53] - |D| - [7654] - C:\ProgramData\USBSRService[18/03/2017 23:03:29] - |D| - [5992] - C:\ProgramData\USOPrivate[26/04/2017 18:58:41] - |D| - [1888256] - C:\ProgramData\USOShared[25/04/2017 09:06:21] - |D| - [528] - C:\ProgramData\UTILILAB[22/07/2017 16:59:56] - |D| - [1754] - C:\ProgramData\VS Revo Group[20/03/2017 07:11:49] - |D| - [0] - C:\ProgramData\WindowsHolographicDevices[12/11/2016 12:05:13] - |AD| - [411] - C:\ProgramData\WinZip[28/04/2017 13:06:30] - |D| - [99578] - C:\ProgramData\Wondershare[28/04/2017 13:08:55] - |D| - [131828867] - C:\ProgramData\Wondershare Video Editor[29/04/2017 09:31:18] - |D| - [24576] - C:\ProgramData\Xilisoft[07/07/2017 14:10:59] - |HDC| - [9582543] - C:\ProgramData\{4C13979D-F8C4-41F2-B4D5-07A2A4FB8F6B}[27/04/2017 15:01:58] - |D| - [0] - C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A}[07/07/2017 10:14:48] - |D| - [65] - C:\ProgramData\{ACBCD40A-42A8-4FF9-BD42-ABCD14998CBA}[22/07/2017 17:59:48] - |D| - [0] - C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}[07/07/2017 10:14:53] - |D| - [63] - C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}[06/07/2017 16:10:41] - |D| - [67] - C:\ProgramData\{EAAB5A83-3809-4B0E-83A6-E4B0DBF2157E} ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [06/07/2017 15:22:33] - |A| - [1998] - C:\ProgramData\Microsoft\Windows\Start Menu\Avant Browser.lnk[18/03/2017 23:03:33] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini[21/07/2017 18:04:57] - |A| - [2006] - C:\ProgramData\Microsoft\Windows\Start Menu\File Arranger.lnk[12/11/2016 12:05:45] - |A| - [2200] - C:\ProgramData\Microsoft\Windows\Start Menu\Notifications de Mises à jour.lnk[12/11/2016 12:05:45] - |A| - [2161] - C:\ProgramData\Microsoft\Windows\Start Menu\Outils d’arrière-plan WinZip.lnk[12/11/2016 10:06:06] - |SHD| - [1083849] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes[18/03/2017 23:03:29] - |RD| - [1083849] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs[23/04/2017 10:40:33] - |A| - [1727] - C:\ProgramData\Microsoft\Windows\Start Menu\TeraCopy.lnk[25/04/2017 16:22:17] - |A| - [1072] - C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk[12/11/2016 12:05:45] - |A| - [2133] - C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [28/04/2017 13:59:52] - |D| - [4037] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2BrightSparks[09/07/2017 08:49:36] - |D| - [1991] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip[06/07/2017 15:16:55] - |D| - [5689] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A-PDF to Video[18/03/2017 23:03:29] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility[18/03/2017 23:03:29] - |RD| - [14299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories[12/05/2017 04:38:52] - |D| - [24977] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis[12/05/2017 04:38:52] - |A| - [1288] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis True Image WD Edition.lnk[11/07/2017 08:14:43] - |D| - [1140] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Browser[27/04/2017 10:53:13] - |D| - [2600] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\adaware[18/03/2017 23:03:29] - |RD| - [20488] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools[27/04/2017 15:39:31] - |D| - [9720] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Installer 13.8.1[29/04/2017 10:48:13] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Windows Service Manager[29/04/2017 11:25:29] - |D| - [20214] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazing[11/07/2017 07:55:08] - |D| - [22751] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazing Studio[24/04/2017 15:30:12] - |D| - [14583] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazing-Share[09/07/2017 20:30:22] - |D| - [4373] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center[28/04/2017 13:34:34] - |D| - [2439] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anti-Locky[29/04/2017 21:43:42] - |D| - [2344] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyMedia Player[21/07/2017 19:48:39] - |D| - [10221] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyMP4[24/04/2017 10:29:16] - |D| - [6595] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft PhotoImpression 4[24/04/2017 09:40:57] - |D| - [8927] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft VideoImpression 1.6[14/11/2016 08:11:06] - |D| - [11851] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo[06/07/2017 15:16:27] - |D| - [1329] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher[22/07/2017 12:07:48] - |D| - [1479] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics[12/11/2016 16:30:11] - |D| - [14835] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3[29/04/2017 10:43:20] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autorun File Remover[22/07/2017 07:11:10] - |D| - [4814] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avanquest[06/07/2017 15:22:33] - |D| - [5194] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avant Browser[27/04/2017 11:08:03] - |D| - [3593] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Batch Picture Resizer[10/07/2017 21:29:10] - |D| - [1761] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BCUninstaller[09/07/2017 09:15:01] - |A| - [2211] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk[12/11/2016 13:55:14] - |D| - [1608] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing Bureau[08/07/2017 14:24:56] - |D| - [2095] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Home Scanner[12/11/2016 15:06:45] - |A| - [1500] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blend for Visual Studio 2015.lnk[09/07/2017 09:01:54] - |D| - [4381] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management[29/04/2017 09:26:49] - |D| - [1866] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7[23/04/2017 11:39:12] - |D| - [1826] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner[21/07/2017 19:10:16] - |D| - [1447] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clear ThemePack[25/04/2017 10:21:16] - |D| - [2276] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clipdiary[22/07/2017 16:18:03] - |D| - [914] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CloseAll[11/07/2017 08:48:52] - |D| - [7255] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo[29/04/2017 09:46:57] - |D| - [2814] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Copy Handler[23/04/2017 11:14:37] - |D| - [2690] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6[22/07/2017 12:00:06] - |D| - [2103] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Advisor[14/11/2016 08:54:07] - |RD| - [1524] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Application Manager[29/04/2017 14:03:44] - |A| - [2126] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink AudioDirector 7 (64-bit).lnk[29/04/2017 11:58:08] - |A| - [2122] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink ColorDirector 5 (64-bit).lnk[11/07/2017 08:41:30] - |A| - [2157] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink MakeupDirector 2 (64-bit).lnk[15/11/2016 11:34:51] - |RD| - [16547] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite[02/05/2017 11:28:40] - |A| - [2280] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go 11.lnk[29/04/2017 18:15:08] - |A| - [2067] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 15 (64-bit).lnk[29/04/2017 11:13:38] - |A| - [2375] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 17.lnk[22/07/2017 12:34:38] - |A| - [2450] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PresenterLink+.lnk[29/04/2017 18:15:14] - |A| - [2150] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Screen Recorder 15.lnk[29/04/2017 18:41:36] - |RD| - [2404] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink WaveEditor 2[10/07/2017 23:03:54] - |D| - [946] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite[22/07/2017 15:50:02] - |D| - [1830] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro[23/04/2017 11:40:32] - |D| - [1869] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler[21/07/2017 18:23:46] - |D| - [604] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Degoo[07/07/2017 13:03:56] - |ASH| - [2806] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini[21/07/2017 17:27:49] - |D| - [2775] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digiarty[21/07/2017 19:53:13] - |A| - [1460] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digital Media Converter 4.1.lnk[08/07/2017 06:50:44] - |D| - [6218] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX[28/04/2017 13:34:10] - |D| - [8256] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DIY DataRecovery CHK-Mate[22/07/2017 15:18:08] - |D| - [2751] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Do Your Data Recovery 5.7[10/07/2017 20:53:26] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Doc Scrubber[27/04/2017 15:06:02] - |D| - [2755] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4[21/07/2017 10:00:12] - |D| - [2825] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 5 Beta[22/07/2017 15:12:19] - |D| - [1974] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy[28/04/2017 14:01:19] - |D| - [4082] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverMax[21/07/2017 18:24:13] - |D| - [2453] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriveTheLife[29/04/2017 10:30:21] - |D| - [2177] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Carte Bleue Caisse d'Epargne[23/04/2017 14:03:50] - |D| - [2838] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS EverySync 3.0[14/11/2016 09:36:46] - |D| - [2694] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup Free 8.6[10/07/2017 20:41:19] - |D| - [1922] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eassos Recovery[10/07/2017 20:41:36] - |D| - [1920] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eassos System Restore[12/05/2017 07:10:42] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Encrypt4all Software[13/11/2016 19:26:51] - |D| - [3212] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON[13/11/2016 18:59:18] - |D| - [7080] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software[28/04/2017 15:36:50] - |D| - [2324] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eyes Relaxing And Focusing[21/07/2017 18:14:55] - |D| - [5481] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZ-Agile Project Management [Community][29/04/2017 09:45:39] - |D| - [2556] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fast File Copy by Daanav.com[28/04/2017 14:21:43] - |AD| - [2753] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FF Copy[21/07/2017 18:04:57] - |D| - [4150] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Arranger[21/07/2017 18:04:57] - |A| - [2012] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Arranger.lnk[12/05/2017 07:09:06] - |D| - [2310] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileVoyager[12/05/2017 07:21:40] - |D| - [4300] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flip HTML5[29/04/2017 11:38:10] - |D| - [4204] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flip PDF Professional[21/07/2017 21:08:10] - |D| - [4977] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Folder Size[28/04/2017 13:49:52] - |D| - [2257] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Folderico[12/05/2017 07:16:36] - |D| - [7717] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FolderViewer[04/05/2017 19:37:08] - |D| - [4210] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF[08/07/2017 07:18:56] - |D| - [2875] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader[11/07/2017 09:04:39] - |D| - [2970] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Any Android Data Recovery[11/07/2017 08:21:21] - |D| - [2598] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Any Data Encryption[11/07/2017 08:45:10] - |D| - [2560] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Any Data Recovery[11/07/2017 08:51:09] - |D| - [2579] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Any Photo Recovery[11/07/2017 08:13:13] - |D| - [2780] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen Recorder[23/04/2017 11:27:46] - |D| - [2345] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Tube To Mp3[29/04/2017 09:42:13] - |D| - [3314] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free-video-splitter[24/04/2017 20:30:59] - |A| - [961] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk[21/07/2017 17:20:33] - |D| - [10418] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GiliSoft[23/04/2017 11:50:51] - |A| - [1312] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Undelete.lnk[23/04/2017 11:52:58] - |D| - [1224] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5[23/04/2017 11:52:58] - |A| - [1167] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk[23/04/2017 11:50:50] - |D| - [4142] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glarysoft[12/05/2017 07:09:24] - |D| - [3931] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glorylogic[29/04/2017 10:51:54] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Ad Blocker[02/05/2017 10:09:47] - |D| - [3591] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Greenshot[28/04/2017 13:41:21] - |D| - [975] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Anti-Ransomware[07/07/2017 19:46:42] - |D| - [2932] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDR Express[21/07/2017 21:11:11] - |D| - [1314] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IconPack[06/07/2017 15:23:55] - |D| - [2738] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iFun Video Converter[18/03/2017 22:59:54] - |RASC| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk[02/05/2017 13:23:50] - |D| - [2427] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InPixio[21/07/2017 19:10:30] - |D| - [2509] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit MBR Guard[07/07/2017 15:15:23] - |D| - [2740] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller[29/04/2017 09:43:18] - |D| - [2529] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Unlocker[21/07/2017 18:36:23] - |A| - [1390] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IP Camera Viewer 3.lnk[28/04/2017 14:55:21] - |D| - [1215] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft[15/11/2016 18:24:12] - |D| - [2148] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB[01/05/2017 17:03:42] - |D| - [51445] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack[07/07/2017 10:51:24] - |D| - [2471] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kastor All Video Downloader[29/04/2017 11:31:11] - |D| - [2496] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kastor Free Video Converter[23/04/2017 11:29:58] - |D| - [2580] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kastor Free Vimeo Downloader[23/04/2017 11:27:18] - |D| - [2471] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kastor Stream Recorder[09/07/2017 09:15:21] - |D| - [3402] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder Plus[30/04/2017 18:28:04] - |D| - [2363] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kotobee Author[23/04/2017 12:06:44] - |D| - [2420] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kotobee Publisher[23/04/2017 10:37:41] - |D| - [2363] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kotobee Reader[12/11/2016 13:52:46] - |D| - [4391] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Laplink PCmover Professional[07/07/2017 14:10:37] - |D| - [9127] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft[11/07/2017 07:38:43] - |D| - [1890] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiteManager Pro - Server[11/07/2017 07:40:02] - |D| - [6203] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiteManager Pro - Viewer[14/11/2016 19:26:01] - |D| - [1733] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech[27/04/2017 15:42:08] - |D| - [1948] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LopeSoft[01/05/2017 13:52:55] - |D| - [2032] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium[18/03/2017 23:03:29] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance[01/05/2017 21:57:50] - |D| - [10149] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Majorgeeks.com[01/05/2017 21:53:41] - |A| - [1305] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Hunter.lnk[25/04/2017 15:42:19] - |D| - [3888] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes[11/07/2017 09:07:09] - |D| - [5250] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware[12/11/2016 15:24:14] - |D| - [1775] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression[15/11/2016 10:47:33] - |D| - [2340] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight[12/11/2016 13:23:20] - |D| - [1475] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008[12/11/2016 13:19:26] - |D| - [4007] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2012[02/05/2017 17:38:46] - |D| - [1124] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniCopier[18/03/2017 22:57:42] - |RASC| - [2219] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk[09/07/2017 09:34:53] - |A| - [1194] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk[09/07/2017 09:48:58] - |A| - [1284] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk[10/07/2017 20:53:23] - |D| - [2198] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MRU-Blaster[28/04/2017 14:14:11] - |D| - [7630] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MultiCommander[09/07/2017 09:20:17] - |A| - [1198] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigateur Opera.lnk[28/04/2017 14:10:25] - |D| - [2790] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSetup Updater[11/07/2017 07:46:56] - |D| - [13089] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero[11/07/2017 07:50:04] - |D| - [17469] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2016[29/04/2017 18:17:24] - |D| - [9643] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue[21/07/2017 18:56:30] - |D| - [845] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++[10/07/2017 21:54:42] - |D| - [1166] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom[29/04/2017 21:40:51] - |D| - [1321] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Video Recorder[12/11/2016 13:59:03] - |A| - [968] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pale Moon.lnk[28/04/2017 14:09:27] - |D| - [2326] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security[07/07/2017 13:45:55] - |D| - [1438] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Backup & Recovery™ 16[06/07/2017 12:00:33] - |D| - [2659] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon ExtFS for Windows[10/07/2017 20:41:02] - |D| - [1889] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartitionGuru[11/07/2017 07:37:57] - |D| - [2368] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PasswordConfidential[09/07/2017 09:43:52] - |D| - [7561] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator[10/07/2017 20:52:52] - |D| - [60] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFPasswordRemover[05/05/2017 13:28:41] - |D| - [2184] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDQ Deploy[05/05/2017 13:33:15] - |D| - [2220] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDQ Inventory[21/07/2017 18:37:43] - |D| - [3108] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip[21/07/2017 18:38:30] - |D| - [5391] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photopus[10/07/2017 20:41:37] - |D| - [5731] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photopus Pro[28/04/2017 13:42:51] - |D| - [54] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStitcher[18/03/2017 22:58:04] - |RASC| - [2199] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk[05/05/2017 12:29:54] - |D| - [2745] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\proDAD[30/04/2017 18:13:06] - |D| - [2567] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Folder[24/04/2017 18:17:49] - |A| - [1293] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quick Search.lnk[21/07/2017 16:24:15] - |D| - [2663] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Random Password Generator[24/04/2017 20:30:59] - |A| - [931] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealTimeSync.lnk[15/11/2016 22:58:31] - |D| - [1153] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rebit Pro[09/07/2017 09:14:51] - |D| - [2540] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recover Keys[23/04/2017 11:38:12] - |D| - [3502] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva[28/04/2017 13:31:29] - |D| - [3862] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Organizer[27/04/2017 15:50:09] - |D| - [3888] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Convert OST to PST[27/04/2017 16:06:27] - |D| - [4672] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Drive Defrag[27/04/2017 15:55:24] - |D| - [4626] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Drive Wipe[05/05/2017 13:24:32] - |D| - [4794] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo File Eraser 2.0[07/07/2017 14:21:27] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo MORE[27/04/2017 15:55:32] - |D| - [5070] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Outlook Backup & Migrate[05/05/2017 13:26:13] - |D| - [4766] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Privacy Cleaner[07/07/2017 11:01:29] - |D| - [4108] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Recover for Android[07/07/2017 12:16:51] - |D| - [4072] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Recover FREE Edition[07/07/2017 12:08:18] - |D| - [5021] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Recover Outlook Express[27/04/2017 15:58:07] - |D| - [3848] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair MOV[07/07/2017 11:43:32] - |D| - [4008] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair Outlook [PST][27/04/2017 16:13:49] - |D| - [4952] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair PowerPoint[27/04/2017 16:13:51] - |D| - [4481] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair RAR[27/04/2017 16:11:43] - |D| - [3918] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair Registry[07/07/2017 10:39:05] - |D| - [4824] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair Word[27/04/2017 16:12:56] - |D| - [4461] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair ZIP[11/07/2017 10:54:29] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReviverSoft[22/07/2017 16:59:59] - |D| - [3421] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro[28/04/2017 14:08:41] - |D| - [1123] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roadkil.Net[25/04/2017 15:12:48] - |D| - [879] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller[28/04/2017 14:00:21] - |D| - [943] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKillerPE[07/07/2017 19:22:44] - |D| - [4436] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio[07/07/2017 18:12:01] - |D| - [28459] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012[28/04/2017 14:09:05] - |D| - [1213] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software[28/04/2017 13:42:17] - |D| - [991] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Securely File Shredder[28/04/2017 13:35:29] - |D| - [2061] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer[27/04/2017 14:43:59] - |D| - [1009] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Silent Install Builder 5[22/07/2017 12:04:43] - |D| - [3878] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimpleStar[21/07/2017 21:15:42] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkinPack[21/07/2017 16:51:33] - |D| - [2149] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkinPack Creator[22/07/2017 12:11:29] - |D| - [2479] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag[07/07/2017 19:45:16] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartSound[21/07/2017 09:49:20] - |D| - [2402] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftOrbits Photo Retoucher[01/05/2017 22:24:53] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software Informer[07/07/2017 09:57:15] - |D| - [937] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy[27/04/2017 15:52:34] - |D| - [2611] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speed Install[29/04/2017 10:53:37] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy BHO Remover[28/04/2017 13:59:14] - |D| - [1190] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot Anti-Beacon[06/07/2017 15:20:53] - |D| - [3453] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron[06/07/2017 16:10:58] - |D| - [2450] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8[02/05/2017 13:19:22] - |D| - [2792] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu X[18/03/2017 23:03:29] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup[09/07/2017 09:19:26] - |D| - [2551] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SterJo Key Finder[22/07/2017 07:22:22] - |D| - [1214] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio V5[21/07/2017 16:57:21] - |D| - [2229] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Password[29/04/2017 10:57:35] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX Antivirus Kit[29/04/2017 11:00:13] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX Blocker Suite[29/04/2017 11:03:33] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX Network Suite[29/04/2017 11:07:51] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX System Suite[29/04/2017 11:11:12] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX WiFi Security Suite[18/03/2017 23:03:29] - |RD| - [1458] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools[22/07/2017 15:27:49] - |A| - [1078] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk[29/04/2017 09:28:54] - |D| - [2647] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith[28/04/2017 14:01:09] - |D| - [4095] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy[25/04/2017 11:18:48] - |D| - [12138] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize[25/04/2017 11:18:07] - |D| - [3972] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free[28/04/2017 13:38:41] - |D| - [3684] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover[21/07/2017 16:57:05] - |D| - [2339] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSS[09/07/2017 09:13:48] - |D| - [1316] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Turbo View & Convert[22/07/2017 16:56:50] - |D| - [10009] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com[03/05/2017 11:25:26] - |D| - [857] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UCheck[12/05/2017 06:12:02] - |D| - [734] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unreal Commander[28/04/2017 14:35:05] - |D| - [2599] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Key Vaccine 2016[25/04/2017 09:06:21] - |D| - [846] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UTILILAB[29/04/2017 10:45:45] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDownloader[25/04/2017 19:42:59] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirusTotal Scanner[12/11/2016 14:26:25] - |D| - [7395] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015[12/11/2016 11:44:52] - |A| - [1509] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015.lnk[27/04/2017 15:53:39] - |D| - [2389] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VivPDF Editor[22/07/2017 16:49:29] - |D| - [867] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed[07/07/2017 14:18:58] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 - Codec Pack[07/07/2017 14:17:57] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack[12/11/2016 12:51:10] - |D| - [23993] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits[26/04/2017 19:53:38] - |A| - [1576] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk[22/07/2017 15:16:25] - |D| - [2396] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windscribe[27/04/2017 15:56:07] - |D| - [1066] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winja[02/05/2017 17:37:27] - |D| - [3180] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinMend[25/04/2017 09:06:06] - |D| - [3264] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR[28/04/2017 14:43:49] - |D| - [1890] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinToHDD[12/11/2016 12:05:01] - |D| - [2145] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 21.0[22/07/2017 15:17:00] - |D| - [1213] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Care 365[06/07/2017 15:30:37] - |D| - [1289] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Driver Care[28/04/2017 14:42:57] - |D| - [1349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Duplicate Finder[07/07/2017 09:50:31] - |D| - [1315] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Folder Hider[28/04/2017 14:41:19] - |D| - [1329] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Folder Hider Pro[28/04/2017 14:44:53] - |D| - [1007] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Hotkey[24/04/2017 18:01:48] - |D| - [1270] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise JetSearch[14/11/2016 09:05:44] - |D| - [1344] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Memory Optimizer[06/07/2017 15:30:45] - |D| - [1285] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Plugin Manager[08/07/2017 13:00:04] - |D| - [1324] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner[14/11/2016 09:05:17] - |D| - [1324] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Video Downloader[28/04/2017 13:07:11] - |D| - [22307] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare[29/04/2017 09:36:50] - |D| - [23016] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilisoft[26/04/2017 15:08:40] - |D| - [6720] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\xplorer2 lite[26/04/2017 14:50:15] - |D| - [5317] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\xplorer2 ult x64[21/07/2017 19:53:36] - |D| - [17829] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid[01/05/2017 22:10:37] - |D| - [3460] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XYplorerFree[25/04/2017 19:42:02] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Video Ad Blocker[22/04/2017 17:57:27] - |D| - [1170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiLogger[22/07/2017 12:03:22] - |D| - [2645] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoolz ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [18/03/2017 23:03:33] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini[21/07/2017 10:22:45] - |A| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\errorlog.txt ---------- | C:\Program Files (x86) [28/04/2017 13:54:51] - |D| - [112311487] - C:\Program Files (x86)\2BrightSparks[09/07/2017 08:49:36] - |AD| - [3622824] - C:\Program Files (x86)\7-Zip[06/07/2017 15:16:49] - |AD| - [23488557] - C:\Program Files (x86)\A-PDF to Video[12/05/2017 04:38:34] - |AD| - [351953644] - C:\Program Files (x86)\Acronis[11/07/2017 08:13:54] - |D| - [100843310] - C:\Program Files (x86)\Ad-Aware Browser[05/05/2017 13:28:37] - |D| - [50551896] - C:\Program Files (x86)\Admin Arsenal[29/04/2017 11:25:01] - |D| - [156432683] - C:\Program Files (x86)\Amazing[11/07/2017 07:53:55] - |D| - [914894562] - C:\Program Files (x86)\Amazing Studio[24/04/2017 15:30:06] - |D| - [115722235] - C:\Program Files (x86)\Amazing-Share[11/07/2017 08:13:38] - |D| - [44559946] - C:\Program Files (x86)\Android Data Recovery[05/05/2017 12:41:19] - |D| - [227104879] - C:\Program Files (x86)\Anvsoft[11/07/2017 08:14:33] - |D| - [20841628] - C:\Program Files (x86)\Any Data Recovery Pro[29/04/2017 21:43:06] - |AD| - [38079796] - C:\Program Files (x86)\AnyMedia Player[21/07/2017 19:48:24] - |D| - [220633593] - C:\Program Files (x86)\AnyMP4 Studio[22/07/2017 15:13:10] - |D| - [75712097] - C:\Program Files (x86)\AoaoPhoto Digital Studio[12/11/2016 20:50:18] - |D| - [6219076] - C:\Program Files (x86)\AppInsights[24/04/2017 09:23:20] - |D| - [302926347] - C:\Program Files (x86)\ArcSoft[14/11/2016 08:08:16] - |D| - [539409749] - C:\Program Files (x86)\Ashampoo[09/07/2017 20:26:26] - |AD| - [106367910] - C:\Program Files (x86)\ATI Technologies[22/07/2017 12:07:44] - |D| - [18242564] - C:\Program Files (x86)\Auslogics[12/11/2016 16:28:00] - |D| - [30538491] - C:\Program Files (x86)\AutoIt3[07/07/2017 09:57:06] - |AD| - [902835198] - C:\Program Files (x86)\Avanquest[06/07/2017 15:22:22] - |AD| - [17019810] - C:\Program Files (x86)\Avant Browser[28/04/2017 13:34:26] - |D| - [4226065] - C:\Program Files (x86)\AxBx[27/04/2017 11:07:18] - |AD| - [25914225] - C:\Program Files (x86)\Batch Picture Resizer[09/07/2017 09:15:01] - |D| - [5864575] - C:\Program Files (x86)\Belarc[11/07/2017 10:00:25] - |AD| - [15428702] - C:\Program Files (x86)\BOINC[09/07/2017 09:01:54] - |AD| - [172197537] - C:\Program Files (x86)\Calibre2[27/04/2017 15:39:30] - |D| - [214671427] - C:\Program Files (x86)\Caphyon[11/07/2017 08:15:02] - |D| - [17466465] - C:\Program Files (x86)\Card Data Recovery[25/04/2017 10:18:30] - |D| - [16458889] - C:\Program Files (x86)\Clipdiary[07/07/2017 09:38:04] - |D| - [146113898] - C:\Program Files (x86)\Codelobster Software[26/04/2017 11:58:35] - |D| - [2922805] - C:\Program Files (x86)\Codyssey[18/03/2017 23:03:28] - |D| - [1227091128] - C:\Program Files (x86)\Common Files[11/07/2017 08:46:33] - |D| - [287600924] - C:\Program Files (x86)\Comodo[21/07/2017 18:34:03] - |D| - [5920516] - C:\Program Files (x86)\concept design[12/11/2016 11:24:24] - |AD| - [3758304963] - C:\Program Files (x86)\CyberLink[11/07/2017 08:15:25] - |D| - [2820738] - C:\Program Files (x86)\Data Wipe[29/04/2017 09:23:45] - |D| - [9846959] - C:\Program Files (x86)\DebugMode[21/07/2017 18:36:05] - |D| - [108300976] - C:\Program Files (x86)\Deskshare[18/03/2017 23:03:33] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini[21/07/2017 17:27:21] - |D| - [113965483] - C:\Program Files (x86)\Digiarty[15/11/2016 11:52:10] - |D| - [229209912] - C:\Program Files (x86)\DivX[28/04/2017 13:33:39] - |AD| - [2334545] - C:\Program Files (x86)\DIY DataRecovery CHK-Mate[22/07/2017 15:18:04] - |D| - [21884969] - C:\Program Files (x86)\DoYourData[06/07/2017 15:16:17] - |D| - [74852168] - C:\Program Files (x86)\DsNET Corp[21/07/2017 18:24:03] - |D| - [26594453] - C:\Program Files (x86)\DTLSoft[12/11/2016 11:53:42] - |D| - [349448] - C:\Program Files (x86)\e-Carte Bleue[14/11/2016 09:09:31] - |D| - [511713675] - C:\Program Files (x86)\EaseUS[13/11/2016 19:23:46] - |D| - [17239263] - C:\Program Files (x86)\EPSON[13/11/2016 18:59:13] - |AD| - [224517519] - C:\Program Files (x86)\EPSON Software[28/04/2017 15:36:47] - |AD| - [2398128] - C:\Program Files (x86)\Eyes Relaxing And Focusing 3.0[21/07/2017 18:14:33] - |D| - [53192328] - C:\Program Files (x86)\EZ-Agile Project Management [Community][29/04/2017 09:45:37] - |AD| - [5333935] - C:\Program Files (x86)\Fast File Copy by Daanav.com[28/04/2017 14:21:40] - |AD| - [195006] - C:\Program Files (x86)\FF Copy[21/07/2017 18:04:56] - |D| - [9234501] - C:\Program Files (x86)\File Arranger[07/07/2017 11:57:39] - |AD| - [1775875] - C:\Program Files (x86)\File Identifier[30/04/2017 19:13:52] - |D| - [10955385] - C:\Program Files (x86)\FileHippo.com[12/05/2017 07:08:39] - |AD| - [118053460] - C:\Program Files (x86)\FileVoyager[12/05/2017 07:17:09] - |AD| - [320696554] - C:\Program Files (x86)\Flip HTML5[29/04/2017 11:24:41] - |AD| - [256140708] - C:\Program Files (x86)\Flip PDF Professional[07/07/2017 09:49:37] - |AD| - [5939143] - C:\Program Files (x86)\Folder Size[28/04/2017 13:49:40] - |D| - [2045655] - C:\Program Files (x86)\Folderico[12/05/2017 07:16:25] - |AD| - [66501819] - C:\Program Files (x86)\FolderViewer[04/05/2017 18:05:51] - |D| - [904837433] - C:\Program Files (x86)\Foxit Software[11/07/2017 08:21:18] - |AD| - [5024997] - C:\Program Files (x86)\Free Any Data Encryption[10/07/2017 23:04:45] - |AD| - [24908441] - C:\Program Files (x86)\Free Any Data Recovery[11/07/2017 08:51:04] - |AD| - [13812287] - C:\Program Files (x86)\Free Any Photo Recovery[29/04/2017 09:42:10] - |D| - [23870839] - C:\Program Files (x86)\free-video-splitter[23/04/2017 10:51:49] - |D| - [20641460] - C:\Program Files (x86)\FreeCodecPack[21/07/2017 11:15:37] - |D| - [0] - C:\Program Files (x86)\Genesys Logic[21/07/2017 17:19:05] - |D| - [330514010] - C:\Program Files (x86)\GiliSoft[23/04/2017 11:47:42] - |D| - [45252246] - C:\Program Files (x86)\Glary Utilities 5[23/04/2017 11:50:24] - |D| - [279720920] - C:\Program Files (x86)\Glarysoft[12/05/2017 07:09:22] - |D| - [9090356] - C:\Program Files (x86)\Glorylogic[23/04/2017 11:35:30] - |D| - [0] - C:\Program Files (x86)\Google[30/04/2017 18:15:33] - |D| - [3272674] - C:\Program Files (x86)\GPU-Z[24/04/2017 17:01:48] - |D| - [32148397] - C:\Program Files (x86)\Gridinsoft[06/07/2017 15:23:41] - |D| - [79556408] - C:\Program Files (x86)\iFunSoft[27/04/2017 15:52:13] - |D| - [253490806] - C:\Program Files (x86)\iGetting Audio[12/11/2016 15:38:32] - |D| - [1182443] - C:\Program Files (x86)\IIS[12/11/2016 16:12:48] - |AD| - [18253524] - C:\Program Files (x86)\IIS Express[07/07/2017 11:49:16] - |D| - [149018801] - C:\Program Files (x86)\IMSIDesign[28/04/2017 14:00:14] - |D| - [32067564] - C:\Program Files (x86)\Innovative Solutions[02/05/2017 13:22:02] - |D| - [127816194] - C:\Program Files (x86)\InPixio[12/11/2016 11:38:25] - |HD| - [216557313] - C:\Program Files (x86)\InstallShield Installation Information[18/03/2017 23:03:28] - |D| - [2017907] - C:\Program Files (x86)\Internet Explorer[27/04/2017 14:47:37] - |D| - [352506503] - C:\Program Files (x86)\IObit[28/04/2017 14:41:21] - |D| - [187845814] - C:\Program Files (x86)\iSkysoft[15/11/2016 18:24:06] - |AD| - [5540312] - C:\Program Files (x86)\ISO to USB[25/04/2017 11:17:30] - |D| - [7618959] - C:\Program Files (x86)\JAM Software[01/05/2017 17:03:11] - |AD| - [49397790] - C:\Program Files (x86)\K-Lite Codec Pack[07/07/2017 10:51:16] - |AD| - [38774426] - C:\Program Files (x86)\Kastor All Video Downloader[29/04/2017 11:31:00] - |AD| - [19924816] - C:\Program Files (x86)\Kastor Free Video Converter[23/04/2017 11:29:55] - |AD| - [11210079] - C:\Program Files (x86)\Kastor Free Vimeo Downloader[23/04/2017 11:27:09] - |AD| - [35219250] - C:\Program Files (x86)\Kastor Stream Recorder[23/04/2017 11:27:37] - |AD| - [36862078] - C:\Program Files (x86)\Kastor Tube To Mp3[14/11/2016 10:05:26] - |D| - [197494] - C:\Program Files (x86)\KeyCryptSDK[24/04/2017 18:45:07] - |D| - [1104403] - C:\Program Files (x86)\KillSoft[30/04/2017 18:26:02] - |AD| - [127448005] - C:\Program Files (x86)\Kotobee Author[23/04/2017 12:05:00] - |AD| - [106802982] - C:\Program Files (x86)\Kotobee Publisher[23/04/2017 10:37:15] - |AD| - [78151430] - C:\Program Files (x86)\Kotobee Reader[12/11/2016 13:52:46] - |D| - [63221631] - C:\Program Files (x86)\Laplink[21/07/2017 18:58:34] - |D| - [0] - C:\Program Files (x86)\LimeWire[11/07/2017 07:38:40] - |AD| - [21194263] - C:\Program Files (x86)\LiteManager Pro - Server[11/07/2017 07:39:57] - |AD| - [35574977] - C:\Program Files (x86)\LiteManager Pro - Viewer[14/11/2016 19:25:20] - |D| - [38884251] - C:\Program Files (x86)\Logitech[01/05/2017 21:57:45] - |D| - [4763746] - C:\Program Files (x86)\Majorgeeks.com[11/07/2017 09:07:00] - |AD| - [59499560] - C:\Program Files (x86)\Malwarebytes Anti-Malware[11/07/2017 09:06:12] - |D| - [921100] - C:\Program Files (x86)\marmiton-install.exe 0.0.0.0[12/11/2016 13:54:51] - |D| - [28382294] - C:\Program Files (x86)\Microsoft[12/11/2016 17:48:11] - |D| - [389907090] - C:\Program Files (x86)\Microsoft ASP.NET[12/11/2016 14:22:52] - |D| - [12587472] - C:\Program Files (x86)\Microsoft Help Viewer[12/11/2016 16:01:02] - |D| - [19600882] - C:\Program Files (x86)\Microsoft Office365 Tools[12/11/2016 11:03:13] - |AD| - [776131163] - C:\Program Files (x86)\Microsoft SDKs[15/11/2016 10:40:56] - |AD| - [42892246] - C:\Program Files (x86)\Microsoft Silverlight[12/11/2016 11:45:14] - |AD| - [1590776592] - C:\Program Files (x86)\Microsoft SQL Server[12/11/2016 18:16:31] - |D| - [9475628] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition[12/11/2016 13:25:14] - |D| - [4850] - C:\Program Files (x86)\Microsoft Visual Studio 10.0[12/11/2016 19:27:28] - |D| - [78646] - C:\Program Files (x86)\Microsoft Visual Studio 11.0[12/11/2016 14:55:08] - |D| - [1067854] - C:\Program Files (x86)\Microsoft Visual Studio 12.0[12/11/2016 11:10:02] - |AD| - [1910219652] - C:\Program Files (x86)\Microsoft Visual Studio 14.0[12/11/2016 15:42:56] - |D| - [46749807] - C:\Program Files (x86)\Microsoft WCF Data Services[12/11/2016 16:42:48] - |AD| - [924999892] - C:\Program Files (x86)\Microsoft Web Tools[18/03/2017 23:03:28] - |D| - [31762827] - C:\Program Files (x86)\Microsoft.NET[02/05/2017 17:37:54] - |AD| - [91566481] - C:\Program Files (x86)\MiniCopier[22/07/2017 17:44:55] - |D| - [94045922] - C:\Program Files (x86)\Mozilla Firefox[09/07/2017 09:34:51] - |D| - [442253] - C:\Program Files (x86)\Mozilla Maintenance Service[09/07/2017 09:48:28] - |AD| - [88483823] - C:\Program Files (x86)\Mozilla Thunderbird[10/07/2017 20:53:23] - |AD| - [1981739] - C:\Program Files (x86)\MRU-Blaster[26/04/2017 19:18:50] - |AD| - [82582292] - C:\Program Files (x86)\MSBuild[05/05/2017 13:27:52] - |D| - [11260780] - C:\Program Files (x86)\muCommander[28/04/2017 13:23:34] - |D| - [5773515] - C:\Program Files (x86)\Multi Install 2.4.5[21/07/2017 16:52:00] - |D| - [16159124] - C:\Program Files (x86)\MultiCommander[11/07/2017 07:46:52] - |AD| - [2313046120] - C:\Program Files (x86)\Nero[29/04/2017 18:16:06] - |D| - [421501100] - C:\Program Files (x86)\NewBlue[12/11/2016 11:38:23] - |D| - [61352650] - C:\Program Files (x86)\NSIS Uninstall Information[12/11/2016 15:44:12] - |D| - [6746308] - C:\Program Files (x86)\NuGet[11/07/2017 08:22:49] - |AD| - [46550478] - C:\Program Files (x86)\OkayFreedom[29/04/2017 21:38:53] - |AD| - [86732975] - C:\Program Files (x86)\Online Video Recorder[09/07/2017 09:01:45] - |D| - [809496] - C:\Program Files (x86)\OpenAL[09/07/2017 09:19:50] - |AD| - [315569257] - C:\Program Files (x86)\Opera[28/04/2017 13:50:55] - |D| - [0] - C:\Program Files (x86)\OSTotoSoft[28/04/2017 14:08:46] - |AD| - [2159865] - C:\Program Files (x86)\Panda USB Vaccine[06/07/2017 12:00:32] - |D| - [133854619] - C:\Program Files (x86)\Paragon Software[29/04/2017 21:26:39] - |D| - [807597] - C:\Program Files (x86)\PDF-to-Word[21/07/2017 18:37:38] - |D| - [29041407] - C:\Program Files (x86)\PeaZip[21/07/2017 18:38:25] - |D| - [22314723] - C:\Program Files (x86)\Photopus[10/07/2017 20:41:31] - |AD| - [22886767] - C:\Program Files (x86)\Photopus Pro[05/05/2017 12:29:50] - |AD| - [24456071] - C:\Program Files (x86)\proDAD[08/07/2017 14:40:46] - |D| - [519080824] - C:\Program Files (x86)\Realtek[09/07/2017 09:14:47] - |AD| - [24697864] - C:\Program Files (x86)\Recover Keys[26/04/2017 19:18:50] - |D| - [1070586837] - C:\Program Files (x86)\Reference Assemblies[28/04/2017 13:29:14] - |AD| - [35098700] - C:\Program Files (x86)\Reg Organizer[14/11/2016 08:54:57] - |D| - [959392] - C:\Program Files (x86)\RegSeeker[27/04/2017 16:06:02] - |AD| - [22830513] - C:\Program Files (x86)\Remo Drive Defrag[27/04/2017 15:54:59] - |AD| - [31137415] - C:\Program Files (x86)\Remo Drive Wipe[05/05/2017 13:23:46] - |AD| - [42399274] - C:\Program Files (x86)\Remo File Eraser 2.0[27/04/2017 15:55:05] - |AD| - [31322107] - C:\Program Files (x86)\Remo Outlook Backup & Migrate[05/05/2017 13:23:34] - |AD| - [29099854] - C:\Program Files (x86)\Remo Privacy Cleaner[07/07/2017 12:07:46] - |AD| - [25547914] - C:\Program Files (x86)\Remo Recover Outlook Express[27/04/2017 16:13:28] - |AD| - [21641487] - C:\Program Files (x86)\Remo Repair PowerPoint 2.0[27/04/2017 16:13:34] - |AD| - [21179175] - C:\Program Files (x86)\Remo Repair RAR 2.0[07/07/2017 10:38:51] - |AD| - [21350931] - C:\Program Files (x86)\Remo Repair Word 2.0[27/04/2017 16:12:45] - |AD| - [21278082] - C:\Program Files (x86)\Remo Repair ZIP 2.0[28/04/2017 14:08:36] - |AD| - [845978] - C:\Program Files (x86)\Roadkil.Net[07/07/2017 19:22:32] - |D| - [525850646] - C:\Program Files (x86)\Roxio[07/07/2017 12:21:43] - |AD| - [2273384605] - C:\Program Files (x86)\Roxio 2012[28/04/2017 14:08:19] - |D| - [2993216] - C:\Program Files (x86)\Runtime Software[11/07/2017 08:19:07] - |D| - [44263902] - C:\Program Files (x86)\Samsung Data Recovery[28/04/2017 13:35:02] - |AD| - [2253541] - C:\Program Files (x86)\ShadowExplorer[12/11/2016 17:58:51] - |D| - [180542] - C:\Program Files (x86)\ShellDir[27/04/2017 14:43:59] - |AD| - [23467386] - C:\Program Files (x86)\Silent Install Builder 5[21/07/2017 09:49:09] - |D| - [83053707] - C:\Program Files (x86)\SoftOrbits Photo Retoucher[28/04/2017 13:57:28] - |AD| - [6235212] - C:\Program Files (x86)\Spybot Anti-Beacon[06/07/2017 15:20:11] - |AD| - [174160344] - C:\Program Files (x86)\SRWare Iron[28/04/2017 14:05:30] - |AD| - [4266790] - C:\Program Files (x86)\StartIsBack[22/07/2017 06:58:53] - |D| - [707214282] - C:\Program Files (x86)\Studio V5[21/07/2017 16:57:19] - |D| - [4206814] - C:\Program Files (x86)\Super Password[21/07/2017 10:56:02] - |D| - [2711132] - C:\Program Files (x86)\SuperBoost[28/04/2017 13:53:44] - |D| - [23697267] - C:\Program Files (x86)\Supercopier[24/04/2017 09:45:49] - |AD| - [88880332] - C:\Program Files (x86)\TeamViewer[29/04/2017 09:28:52] - |D| - [11373214] - C:\Program Files (x86)\TechSmith[08/07/2017 14:01:23] - |HD| - [0] - C:\Program Files (x86)\Temp[11/07/2017 08:18:52] - |D| - [4385602] - C:\Program Files (x86)\Tenorshare Partition Manager[11/07/2017 08:15:54] - |D| - [64598071] - C:\Program Files (x86)\Tenorshare Video Converter Standard[09/07/2017 09:15:21] - |AD| - [2023813] - C:\Program Files (x86)\Top Password[28/04/2017 13:36:20] - |AD| - [20968214] - C:\Program Files (x86)\Trojan Remover[05/05/2017 13:26:49] - |D| - [36830654] - C:\Program Files (x86)\trolCommander[21/07/2017 16:57:05] - |D| - [2038393] - C:\Program Files (x86)\TSS[22/07/2017 16:56:21] - |D| - [48844775] - C:\Program Files (x86)\Tweaking.com[06/07/2017 15:21:46] - |AD| - [16914250] - C:\Program Files (x86)\USB Safely Remove[27/04/2017 15:53:18] - |AD| - [32319556] - C:\Program Files (x86)\VivPDF Editor[09/07/2017 08:34:30] - |D| - [285030907] - C:\Program Files (x86)\Windows Boot Genius[18/03/2017 23:03:28] - |D| - [2001344] - C:\Program Files (x86)\Windows Defender[12/11/2016 11:03:18] - |D| - [4089801557] - C:\Program Files (x86)\Windows Kits[18/03/2017 23:03:28] - |D| - [5924864] - C:\Program Files (x86)\Windows Mail[20/03/2017 07:10:55] - |D| - [3364265] - C:\Program Files (x86)\Windows Media Player[18/03/2017 23:03:28] - |D| - [42960] - C:\Program Files (x86)\Windows Multimedia Platform[18/03/2017 23:03:28] - |D| - [7569090] - C:\Program Files (x86)\Windows NT[18/03/2017 23:03:28] - |D| - [5365568] - C:\Program Files (x86)\Windows Photo Viewer[18/03/2017 23:03:28] - |D| - [42960] - C:\Program Files (x86)\Windows Portable Devices[18/03/2017 23:03:28] - |SHD| - [0] - C:\Program Files (x86)\Windows Sidebar[18/03/2017 23:03:28] - |D| - [2184102] - C:\Program Files (x86)\WindowsPowerShell[22/07/2017 15:14:24] - |D| - [49585269] - C:\Program Files (x86)\Windscribe[02/05/2017 17:37:09] - |D| - [14769381] - C:\Program Files (x86)\WinMend[14/11/2016 09:01:25] - |D| - [117182903] - C:\Program Files (x86)\Wise[22/07/2017 15:17:09] - |D| - [36545075] - C:\Program Files (x86)\WonderFox Soft[28/04/2017 13:06:30] - |D| - [85146822] - C:\Program Files (x86)\Wondershare[29/04/2017 09:31:18] - |D| - [251443354] - C:\Program Files (x86)\Xilisoft[21/07/2017 19:53:35] - |D| - [770769] - C:\Program Files (x86)\Xvid[01/05/2017 22:10:23] - |AD| - [8547622] - C:\Program Files (x86)\XYplorerFree[26/04/2017 15:08:18] - |D| - [2811950] - C:\Program Files (x86)\zabkat[14/11/2016 10:05:20] - |AD| - [17338136] - C:\Program Files (x86)\Zemana AntiLogger ---------- | C:\Program Files [27/04/2017 10:38:51] - |D| - [805151981] - C:\Program Files\adaware[26/04/2017 18:50:11] - |D| - [96636696] - C:\Program Files\AMD[09/07/2017 20:29:42] - |AD| - [5595872] - C:\Program Files\ATI Technologies[10/07/2017 21:29:08] - |AD| - [9285253] - C:\Program Files\BCUninstaller[08/07/2017 14:04:47] - |AD| - [125053614] - C:\Program Files\Bitdefender Home Scanner[29/04/2017 09:26:36] - |AD| - [41623061] - C:\Program Files\CamStudio 2.7[23/04/2017 11:38:43] - |AD| - [15563696] - C:\Program Files\CCleaner[09/07/2017 08:49:16] - |AD| - [3284890] - C:\Program Files\CloseAll[18/03/2017 23:03:28] - |D| - [413074500] - C:\Program Files\Common Files[11/07/2017 08:46:21] - |D| - [457866367] - C:\Program Files\COMODO[29/04/2017 09:46:48] - |AD| - [19889964] - C:\Program Files\Copy Handler[23/04/2017 11:11:14] - |AD| - [65042094] - C:\Program Files\CyberGhost 6[14/11/2016 19:36:58] - |D| - [2203112426] - C:\Program Files\CyberLink[10/07/2017 23:03:33] - |D| - [42186575] - C:\Program Files\DAEMON Tools Lite[22/07/2017 15:49:03] - |D| - [56669509] - C:\Program Files\DAEMON Tools Pro[23/04/2017 11:40:27] - |AD| - [13522136] - C:\Program Files\Defraggler[18/03/2017 23:03:33] - |ASH| - [174] - C:\Program Files\desktop.ini[08/07/2017 10:20:50] - |D| - [1048872] - C:\Program Files\DIFX[15/11/2016 11:52:45] - |D| - [0] - C:\Program Files\DivX[22/07/2017 15:12:17] - |D| - [12699930] - C:\Program Files\Easeware[10/07/2017 20:41:06] - |AD| - [25122441] - C:\Program Files\Eassos Recovery[10/07/2017 20:41:23] - |AD| - [43115540] - C:\Program Files\Eassos System Restore[05/05/2017 13:17:31] - |D| - [812116] - C:\Program Files\Easy File Locker[28/04/2017 13:44:10] - |D| - [0] - C:\Program Files\FastCopy[12/11/2016 10:06:06] - |SHD| - [413074500] - C:\Program Files\Fichiers communs[05/05/2017 13:19:30] - |AD| - [13713757] - C:\Program Files\FolderIco[07/07/2017 09:50:21] - |AD| - [576000] - C:\Program Files\FolderSize[24/04/2017 20:30:41] - |AD| - [48626041] - C:\Program Files\FreeFileSync[22/07/2017 12:03:19] - |D| - [37031588] - C:\Program Files\Genie9[02/05/2017 10:09:31] - |AD| - [5045802] - C:\Program Files\Greenshot[28/04/2017 13:38:58] - |AD| - [9290598] - C:\Program Files\GridinSoft Anti-Ransomware[12/11/2016 15:38:34] - |AD| - [5477059] - C:\Program Files\IIS[12/11/2016 16:12:48] - |AD| - [18839453] - C:\Program Files\IIS Express[15/07/2017 10:33:32] - |D| - [14883387] - C:\Program Files\IM-Magic[18/03/2017 23:03:28] - |D| - [2644574] - C:\Program Files\Internet Explorer[25/04/2017 11:18:38] - |D| - [46934160] - C:\Program Files\JAM Software[12/11/2016 10:23:11] - |D| - [686023344] - C:\Program Files\Lavasoft[27/04/2017 15:42:03] - |D| - [35942964] - C:\Program Files\LopeSoft[01/05/2017 13:52:51] - |AD| - [92552380] - C:\Program Files\Macrium[29/04/2017 11:15:56] - |D| - [72728451] - C:\Program Files\Macrorit[25/04/2017 15:41:36] - |D| - [230397920] - C:\Program Files\Malwarebytes[12/11/2016 17:25:09] - |D| - [80313] - C:\Program Files\Microsoft DNX[28/04/2017 13:49:03] - |AD| - [0] - C:\Program Files\Microsoft Office[21/07/2017 17:52:15] - |D| - [0] - C:\Program Files\Microsoft Office 15[15/11/2016 10:40:56] - |AD| - [55725526] - C:\Program Files\Microsoft Silverlight[12/11/2016 11:45:13] - |AD| - [269490383] - C:\Program Files\Microsoft SQL Server[12/11/2016 18:16:56] - |AD| - [10086444] - C:\Program Files\Microsoft SQL Server Compact Edition[12/11/2016 14:55:19] - |D| - [1125536] - C:\Program Files\Microsoft Visual Studio 12.0[12/11/2016 11:11:15] - |D| - [64760] - C:\Program Files\Microsoft Visual Studio 14.0[26/04/2017 19:18:50] - |D| - [25757] - C:\Program Files\MSBuild[28/04/2017 14:13:46] - |D| - [20649897] - C:\Program Files\MultiCommander (x64)[29/04/2017 18:17:24] - |D| - [521722715] - C:\Program Files\NewBlue[21/07/2017 18:56:22] - |D| - [7575858] - C:\Program Files\Notepad++[08/07/2017 14:36:14] - |D| - [566160] - C:\Program Files\Npcap[22/07/2017 07:08:01] - |D| - [93542327] - C:\Program Files\Pale Moon[07/07/2017 13:45:50] - |D| - [94277266] - C:\Program Files\Paragon Software[10/07/2017 20:40:50] - |AD| - [33286483] - C:\Program Files\PartitionGuru[09/07/2017 09:43:40] - |D| - [34745704] - C:\Program Files\PDFCreator[29/04/2017 09:44:53] - |AD| - [1286657] - C:\Program Files\PerigeeCopy[29/04/2017 18:19:26] - |AD| - [185835809] - C:\Program Files\proDAD[28/04/2017 14:25:56] - |D| - [416136727] - C:\Program Files\qemu[09/07/2017 10:55:11] - |D| - [51612488] - C:\Program Files\Realtek[15/11/2016 22:58:17] - |D| - [67605555] - C:\Program Files\Rebit[23/04/2017 11:38:03] - |AD| - [11000272] - C:\Program Files\Recuva[26/04/2017 19:18:50] - |D| - [36854953] - C:\Program Files\Reference Assemblies[27/04/2017 15:49:21] - |AD| - [82521227] - C:\Program Files\Remo Convert OST to PST[07/07/2017 10:58:26] - |AD| - [68193373] - C:\Program Files\Remo Recover for Android 2.0[07/07/2017 12:15:52] - |AD| - [64994941] - C:\Program Files\Remo Recover FREE Edition[27/04/2017 15:57:52] - |AD| - [22063315] - C:\Program Files\Remo Repair MOV 2.0[07/07/2017 11:42:08] - |AD| - [92288916] - C:\Program Files\Remo Repair Outlook [PST][27/04/2017 16:11:18] - |AD| - [56565680] - C:\Program Files\Remo Repair Registry[25/04/2017 15:12:15] - |AD| - [80080460] - C:\Program Files\RogueKiller[28/04/2017 13:58:52] - |AD| - [64766970] - C:\Program Files\RogueKillerPE[07/07/2017 18:13:27] - |D| - [785392] - C:\Program Files\Roxio[07/07/2017 12:20:21] - |AD| - [148464] - C:\Program Files\Roxio 2012[28/04/2017 13:42:08] - |D| - [721401] - C:\Program Files\Securely File Shredder[11/07/2017 08:03:02] - |D| - [90021943] - C:\Program Files\Siber Systems[22/07/2017 12:04:12] - |D| - [36626444] - C:\Program Files\Simple Driver Updater[21/07/2017 18:57:32] - |D| - [35343809] - C:\Program Files\Simple Registry Cleaner[07/07/2017 09:57:11] - |AD| - [14853672] - C:\Program Files\Speccy[02/05/2017 13:18:01] - |AD| - [28277595] - C:\Program Files\Start Menu X[23/04/2017 11:16:04] - |D| - [272409] - C:\Program Files\TAP-Windows[18/03/2017 23:03:28] - |D| - [120] - C:\Program Files\TaskLogic ZN-165C[23/04/2017 10:40:21] - |AD| - [16342576] - C:\Program Files\TeraCopy[03/05/2017 11:25:14] - |AD| - [62139543] - C:\Program Files\UCheck[07/07/2017 19:46:11] - |D| - [32354894] - C:\Program Files\UCT[23/04/2017 10:38:37] - |D| - [23334781] - C:\Program Files\Ultracopier[12/11/2016 09:47:56] - |HD| - [0] - C:\Program Files\Uninstall Information[23/04/2017 10:45:03] - |D| - [266699] - C:\Program Files\Unlocker[22/07/2017 16:59:50] - |D| - [42003378] - C:\Program Files\VS Revo Group[22/07/2017 16:49:26] - |D| - [13365476] - C:\Program Files\WhoCrashed[18/03/2017 23:03:28] - |RD| - [16330682] - C:\Program Files\Windows Defender[18/03/2017 23:03:28] - |D| - [6145536] - C:\Program Files\Windows Mail[20/03/2017 07:10:55] - |D| - [4781757] - C:\Program Files\Windows Media Player[18/03/2017 23:03:28] - |D| - [49688] - C:\Program Files\Windows Multimedia Platform[18/03/2017 23:03:28] - |D| - [7835330] - C:\Program Files\Windows NT[18/03/2017 23:03:28] - |D| - [6169408] - C:\Program Files\Windows Photo Viewer[18/03/2017 23:03:28] - |D| - [49696] - C:\Program Files\Windows Portable Devices[18/03/2017 23:03:28] - |D| - [95352] - C:\Program Files\Windows Security[18/03/2017 23:03:28] - |SHD| - [0] - C:\Program Files\Windows Sidebar[18/03/2017 23:03:28] - |HD| - [1860421135] - C:\Program Files\WindowsApps[18/03/2017 23:03:28] - |D| - [2433872] - C:\Program Files\WindowsPowerShell[25/04/2017 09:05:44] - |AD| - [6369989] - C:\Program Files\WinRAR[28/04/2017 14:43:02] - |AD| - [34446262] - C:\Program Files\WinToHDD[12/11/2016 12:05:01] - |AD| - [293425904] - C:\Program Files\WinZip[28/04/2017 14:44:24] - |D| - [8422138] - C:\Program Files\Wise[28/04/2017 13:08:53] - |D| - [552737547] - C:\Program Files\Wondershare[26/04/2017 14:50:09] - |D| - [4184607] - C:\Program Files\zabkat ---------- | C:\Program Files (x86)\Common Files [12/05/2017 04:38:34] - |AD| - [489577111] - C:\Program Files (x86)\Common Files\Acronis[07/07/2017 09:58:25] - |AD| - [83102013] - C:\Program Files (x86)\Common Files\AntiVirus[01/05/2017 23:16:22] - |D| - [818407] - C:\Program Files (x86)\Common Files\AV[12/05/2017 07:08:02] - |D| - [70] - C:\Program Files (x86)\Common Files\Clover[12/11/2016 11:38:08] - |D| - [133400] - C:\Program Files (x86)\Common Files\CyberLink[12/11/2016 14:23:11] - |AD| - [25256] - C:\Program Files (x86)\Common Files\Designer[21/07/2017 19:53:12] - |D| - [3089098] - C:\Program Files (x86)\Common Files\DeskShare Shared[15/11/2016 11:52:29] - |D| - [116029335] - C:\Program Files (x86)\Common Files\DivX Shared[14/11/2016 10:50:40] - |D| - [2341589] - C:\Program Files (x86)\Common Files\InstallShield[27/04/2017 14:55:18] - |D| - [1310] - C:\Program Files (x86)\Common Files\IObit[28/04/2017 14:56:36] - |D| - [6927597] - C:\Program Files (x86)\Common Files\iSkysoft[26/04/2017 18:51:35] - |AD| - [90449906] - C:\Program Files (x86)\Common Files\logishrd[11/07/2017 08:58:37] - |D| - [883169] - C:\Program Files (x86)\Common Files\McAfee[12/11/2016 11:42:30] - |D| - [0] - C:\Program Files (x86)\Common Files\Merge Modules[18/03/2017 23:03:28] - |AD| - [96457982] - C:\Program Files (x86)\Common Files\Microsoft Shared[11/07/2017 07:47:56] - |D| - [72779000] - C:\Program Files (x86)\Common Files\Nero[29/04/2017 18:17:20] - |D| - [286720] - C:\Program Files (x86)\Common Files\NewBlue[11/07/2017 08:41:51] - |D| - [1488873] - C:\Program Files (x86)\Common Files\Nikon[07/07/2017 18:11:32] - |AD| - [4856608] - C:\Program Files (x86)\Common Files\PX Storage Engine[07/07/2017 18:11:41] - |AD| - [228198429] - C:\Program Files (x86)\Common Files\Roxio Shared[18/03/2017 23:03:28] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services[07/07/2017 18:11:34] - |AD| - [13116719] - C:\Program Files (x86)\Common Files\Sonic Shared[10/07/2017 21:54:27] - |D| - [1115] - C:\Program Files (x86)\Common Files\Steganos[18/03/2017 23:03:28] - |D| - [9596811] - C:\Program Files (x86)\Common Files\System[28/04/2017 13:18:04] - |D| - [6927908] - C:\Program Files (x86)\Common Files\Wondershare ---------- | C:\Program Files\Common files [23/04/2017 20:10:56] - |D| - [188282884] - C:\Program Files\Common files\adaware[01/05/2017 23:16:22] - |D| - [818407] - C:\Program Files\Common files\AV[07/07/2017 04:37:14] - |AD| - [23240] - C:\Program Files\Common files\DESIGNER[26/04/2017 18:51:25] - |D| - [152640] - C:\Program Files\Common files\EPSON[07/07/2017 14:10:38] - |D| - [19864616] - C:\Program Files\Common files\Lavasoft[26/04/2017 18:51:31] - |D| - [22858487] - C:\Program Files\Common files\logishrd[18/03/2017 23:03:28] - |AD| - [156420189] - C:\Program Files\Common files\microsoft shared[29/04/2017 18:18:17] - |D| - [352768] - C:\Program Files\Common files\NewBlue[18/03/2017 23:03:28] - |D| - [2702] - C:\Program Files\Common files\Services[18/03/2017 23:03:28] - |D| - [10317707] - C:\Program Files\Common files\System[07/07/2017 19:46:15] - |D| - [7869161] - C:\Program Files\Common files\UCT[28/04/2017 13:08:03] - |D| - [6111699] - C:\Program Files\Common files\Wondershare ---------- | Tasks [MD5.D1119C0881B9BB90F60F3BC1A4330C60] - [09/07/2017 09:18:46] - |AH| - [430] - C:\WINDOWS\Tasks\AdapterUpdater.job[MD5.88A79F2E688B6D0094F602403915AEFF] - [11/07/2017 09:10:17] - |A| - [306] - C:\WINDOWS\Tasks\Advanced-PC-Care_Logon.job[MD5.90B4A5CA359DDD7D28849DC8D89F6C44] - [07/07/2017 19:10:24] - |A| - [564] - C:\WINDOWS\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job[MD5.30A1FDB9205A72B8FD7C37BC5E8D5BAF] - [07/07/2017 13:18:09] - |A| - [334] - C:\WINDOWS\Tasks\B3A986DC-C2DD-40A0-8C0C-FEF66B783511.job[MD5.3853BE23413DA750B4D7B8EA8558008C] - [21/07/2017 17:25:35] - |A| - [368] - C:\WINDOWS\Tasks\ByteFence Scan.job[MD5.23155868A9CE15FD74C55910F189FC1F] - [15/07/2017 14:17:28] - |A| - [214] - C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job[MD5.2C86633A627EA95A94B79EF7F9CE37D5] - [22/07/2017 12:12:18] - |A| - [354] - C:\WINDOWS\Tasks\Driver Booster Beta Scheduler.job[MD5.B84D54E96A5BA9400E78CE76BD280901] - [22/07/2017 12:12:18] - |A| - [310] - C:\WINDOWS\Tasks\Driver Booster Beta SkipUAC (Jean-Marie).job[MD5.846BA6B40B50D854EB700739E929EDC0] - [22/07/2017 15:12:36] - |A| - [446] - C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job[MD5.0E4067E031E850B22F4F4794F71C0DB7] - [07/07/2017 19:11:03] - |A| - [490] - C:\WINDOWS\Tasks\DriverMaxWelcome.job[MD5.9825F9CACB4C88D29EC13533F6E23532] - [12/11/2016 10:02:14] - |A| - [763] - C:\WINDOWS\Tasks\EPSON XP-710 Series Invitation {68953606-62A7-4B6A-87A7-1CF73FEC7E9A}.job[MD5.919B72D35F92534504C2CA1C33147687] - [12/11/2016 09:51:55] - |A| - [763] - C:\WINDOWS\Tasks\EPSON XP-710 Series Invitation {69791235-D3B3-45B7-A134-218554EE5C76}.job[MD5.9AC58A48DDFC87CC86423D9DDF383B1E] - [26/04/2017 19:59:48] - |A| - [763] - C:\WINDOWS\Tasks\EPSON XP-710 Series Invitation {AE5780A0-0AF2-4E57-8021-42C010C39E40}.job[MD5.845036415BB68F444D73F6B7748C3A8C] - [26/04/2017 18:51:26] - |A| - [763] - C:\WINDOWS\Tasks\EPSON XP-710 Series Invitation {FC6094E7-B8B4-44EE-9D76-76624B51979F}.job[MD5.C719B70C7B9E51C104719EA63DB0CCA7] - [12/11/2016 10:02:13] - |A| - [949] - C:\WINDOWS\Tasks\EPSON XP-710 Series Update {68953606-62A7-4B6A-87A7-1CF73FEC7E9A}.job[MD5.DCCE293F9177CBC8ACA9C3FD3372BF48] - [12/11/2016 09:51:55] - |A| - [949] - C:\WINDOWS\Tasks\EPSON XP-710 Series Update {69791235-D3B3-45B7-A134-218554EE5C76}.job[MD5.FDCDC7C7EE0492AB3EE765ADC787AD65] - [26/04/2017 19:59:48] - |A| - [949] - C:\WINDOWS\Tasks\EPSON XP-710 Series Update {AE5780A0-0AF2-4E57-8021-42C010C39E40}.job[MD5.21537D58831A31A2551244454285F7EB] - [26/04/2017 18:51:26] - |A| - [949] - C:\WINDOWS\Tasks\EPSON XP-710 Series Update {FC6094E7-B8B4-44EE-9D76-76624B51979F}.job[MD5.76B1FA875007F2A86A8A7AC1C5B279B1] - [07/07/2017 19:12:48] - |A| - [348] - C:\WINDOWS\Tasks\GlaryInitialize 5.job[MD5.59C3C46F611A38152CD3CEE71EDDE9BA] - [07/07/2017 19:12:49] - |A| - [250] - C:\WINDOWS\Tasks\GU5SkipUAC.job[MD5.00000000000000000000000000000000] - [27/04/2017 14:55:19] - |D| - [0] - C:\WINDOWS\Tasks\ImCleanDisabled[MD5.B13D7F65132432CE64B8E67DEC9A2DD8] - [11/07/2017 08:51:49] - |A| - [248] - C:\WINDOWS\Tasks\MakeupDirector2.exe_20170711_085147_0871.job[MD5.7C9D1C0E70F4E8A8AA89887DCE516BB3] - [09/07/2017 09:20:19] - |A| - [460] - C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1499584801.job[MD5.CCACCE73621B986ED6883F42CA66F976] - [21/07/2017 17:04:21] - |A| - [460] - C:\WINDOWS\Tasks\PC TuneUp Maestro Disk Defrag Analysis.job[MD5.45253AF35C762916230965444C791310] - [21/07/2017 17:01:45] - |A| - [448] - C:\WINDOWS\Tasks\PC TuneUp Maestro Scan FirstTime.job[MD5.E3253CD5DB5F5EA773C28A0B6E6084D4] - [21/07/2017 17:02:22] - |A| - [448] - C:\WINDOWS\Tasks\PC TuneUp Maestro Scan SecondTime.job[MD5.23C02D907305D6DC9768E559C10455D0] - [21/07/2017 17:01:06] - |A| - [448] - C:\WINDOWS\Tasks\PC TuneUp Maestro Scan.job[MD5.ED2EE367BB082DF063F572111153D3A3] - [11/07/2017 10:10:45] - |A| - [268] - C:\WINDOWS\Tasks\PresenterLinkPlus.exe_20170711_101040_0036.job[MD5.7EC6E0EA4841DBD4B2BEA2C2235AA443] - [22/07/2017 12:35:00] - |A| - [268] - C:\WINDOWS\Tasks\PresenterLinkPlus.exe_20170722_123500_0103.job[MD5.708EA029F398E51E2AEBBD0AD5E5CA73] - [26/04/2017 20:06:59] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT[MD5.5FBD6BA1A09C356B4C95D8323A1B427A] - [22/07/2017 12:04:42] - |A| - [316] - C:\WINDOWS\Tasks\Start Simple Driver Updater for LFSULTRA-WIDEN@Jean-Marie(logon).job[MD5.35C9E9C7E45D4153DA5EB1A8EF6461D9] - [22/07/2017 12:04:42] - |A| - [300] - C:\WINDOWS\Tasks\Start Simple Driver Updater Schedule.job[MD5.8553BDA28A21C43742095CE284B00A74] - [22/07/2017 12:04:42] - |A| - [306] - C:\WINDOWS\Tasks\Start Simple Driver Updater Update.job[MD5.DD9C52A2E98BF20BB0EB146DC7A72234] - [11/07/2017 10:56:41] - |A| - [338] - C:\WINDOWS\Tasks\Start Simple PC Optimizer for LFSULTRA-WIDEN@Jean-Marie(logon).job[MD5.3B4EF1CFF7731282206A68FD343311B1] - [11/07/2017 10:56:41] - |A| - [296] - C:\WINDOWS\Tasks\Start Simple PC Optimizer Schedule.job[MD5.8AA98446A7D756C1F89481DCC3B7F2E5] - [11/07/2017 10:56:41] - |A| - [302] - C:\WINDOWS\Tasks\Start Simple PC Optimizer Update.job[MD5.04CB379D1EA070DDE1873BE42737CFC5] - [21/07/2017 18:57:57] - |A| - [364] - C:\WINDOWS\Tasks\Start Simple Registry Cleaner for LFSULTRA-WIDEN@Jean-Marie(logon).job[MD5.C26F36A0B551104D28D0FF697F96B191] - [22/07/2017 12:05:43] - |A| - [308] - C:\WINDOWS\Tasks\Start Simple Registry Cleaner Schedule.job[MD5.935A484EA64CEC9B04648131EEAE95FB] - [22/07/2017 12:05:43] - |A| - [314] - C:\WINDOWS\Tasks\Start Simple Registry Cleaner Update.job[MD5.B77C84C777FD69077A7AFB026C903004] - [06/07/2017 16:10:56] - |A| - [266] - C:\WINDOWS\Tasks\StartMenu8_Start.job[MD5.5624D0E832A10BE4D796372AC1F5F6C5] - [06/07/2017 15:52:28] - |A| - [1546] - C:\WINDOWS\Tasks\TaskLogic ZN-165C.job[MD5.0012E01E883DA806B1DE07B438F49C65] - [22/07/2017 16:57:50] - |A| - [574] - C:\WINDOWS\Tasks\Tweaking.com - Windows Repair Tray Icon.job[MD5.157663C8D93939814AAFA94BB9C64157] - [07/07/2017 10:02:57] - |A| - [318] - C:\WINDOWS\Tasks\Uninstaller_SkipUac_Jean-Marie.job[MD5.C498CA28840F086DF8354DFD9B802415] - [11/07/2017 10:30:44] - |A| - [574] - C:\WINDOWS\Tasks\WarThunder0.job[MD5.989FCF10AB0A21C2712501FF3437685F] - [11/07/2017 10:30:45] - |A| - [574] - C:\WINDOWS\Tasks\WarThunder1.job[MD5.5C0EEF45DA14F8AD7F611D50FECDCB4C] - [11/07/2017 10:30:45] - |A| - [574] - C:\WINDOWS\Tasks\WarThunder2.job[MD5.CC1EE8A83FE9A081D90F885E17714AE7] - [11/07/2017 10:30:45] - |A| - [574] - C:\WINDOWS\Tasks\WarThunder3.job[MD5.B69334F6ECBD1C429C3399B366D3A8E4] - [06/07/2017 15:31:27] - |A| - [388] - C:\WINDOWS\Tasks\Wise Hotkey.job[MD5.98D65F7D0790019A0FDF9D34A3FF61D4] - [02/05/2017 08:37:05] - |A| - [3674] - C:\WINDOWS\System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c : C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe[MD5.068CA4F4FCE9AD3E4660227ADA272324] - [07/07/2017 12:24:20] - |A| - [3152] - C:\WINDOWS\System32\Tasks\ASCU10_PerformanceMonitor : C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe[MD5.AD2401901FFF92BCD57FD0966C719EDA] - [07/07/2017 12:18:33] - |A| - [2492] - C:\WINDOWS\System32\Tasks\ASCU10_SkipUac_Jean-Marie : C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASC.exe[MD5.AF3C737EFC96AA2377025907EB78CD68] - [01/05/2017 23:14:28] - |A| - [4268] - C:\WINDOWS\System32\Tasks\Avast Emergency Update : C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe[MD5.00000000000000000000000000000000] - [01/05/2017 23:16:41] - |D| - [3968] - C:\WINDOWS\System32\Tasks\AVAST Software[MD5.357954AD3A05760A2AD777C682FAAA28] - [07/07/2017 13:18:10] - |A| - [2696] - C:\WINDOWS\System32\Tasks\B3A986DC-C2DD-40A0-8C0C-FEF66B783511 : rundll32[MD5.8FA3024D98BF443B9989F7E459D9EC89] - [07/07/2017 13:18:17] - |A| - [2912] - C:\WINDOWS\System32\Tasks\B3A986DC-C2DD-40A0-8C0C-FEF66B7835112 : rundll32[MD5.624908DAF8465DCAEEF97143F897DCEB] - [08/07/2017 13:42:14] - |A| - [3798] - C:\WINDOWS\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 : C:\Program Files\Bitdefender Agent\WatchDog.exe[MD5.FDB30E1A31464894C4117B8F10CCCD98] - [08/07/2017 14:30:48] - |A| - [3384] - C:\WINDOWS\System32\Tasks\Bitdefender AgentTask_6F2980EE6088481484E6D8285516CD07 : C:\Program Files\Bitdefender Home Scanner\hvaag.exe[MD5.B52D1C667598A10B042153A55E4E6A55] - [26/04/2017 20:06:56] - |A| - [2220] - C:\WINDOWS\System32\Tasks\CCleanerSkipUAC : "C:\Program Files\CCleaner\CCleaner.exe"[MD5.00000000000000000000000000000000] - [11/07/2017 13:40:11] - |D| - [22170] - C:\WINDOWS\System32\Tasks\COMODO[MD5.04042C072592CE7B83EC6CFE2350FDB6] - [03/05/2017 19:22:36] - |A| - [3664] - C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask : C:\WINDOWS\explorer.exe[MD5.B1D52EBE2AC8CC9262CEDBF947C50259] - [26/04/2017 20:06:56] - |A| - [2548] - C:\WINDOWS\System32\Tasks\DeviceDetector7.5 : C:\Program Files (x86)\CyberLink\MediaEspresso7.5\DeviceDetector\DeviceDetector7.5.exe[MD5.EBD791D6261DACF59A04006DCC3FB231] - [08/07/2017 07:00:28] - |A| - [3708] - C:\WINDOWS\System32\Tasks\DivXUpdate : C:\Program Files (x86)\Common Files\DivX Shared\DivX Update\DivXUpdate.exe[MD5.4BEC392BE960F94FBCCED568DE3997CB] - [21/07/2017 10:01:06] - |A| - [3422] - C:\WINDOWS\System32\Tasks\Driver Booster Beta Scheduler : C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\Scheduler.exe[MD5.BC6BF2EB2E14CBE1D6D55EFDA6B121AA] - [21/07/2017 10:01:10] - |A| - [3076] - C:\WINDOWS\System32\Tasks\Driver Booster Beta SkipUAC (Jean-Marie) : C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\DriverBooster.exe[MD5.1EDFE5A5749654143FA3331449B5576A] - [17/07/2017 14:08:44] - |A| - [3056] - C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Jean-Marie) : C:\Program Files (x86)\IObit\Driver Booster\4.4.0\DriverBooster.exe[MD5.6158F2A1BF6F1330090D3C3DDF79707D] - [26/04/2017 20:06:56] - |A| - [3382] - C:\WINDOWS\System32\Tasks\EPSON XP-710 Series Invitation {68953606-62A7-4B6A-87A7-1CF73FEC7E9A} : C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLPE.EXE[MD5.EA6F97DD84F6FB92022801755ED2C3B2] - [26/04/2017 20:06:56] - |A| - [3382] - C:\WINDOWS\System32\Tasks\EPSON XP-710 Series Invitation {69791235-D3B3-45B7-A134-218554EE5C76} : C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLPE.EXE[MD5.70F8482DE74EDAB7E556006E135CD168] - [26/04/2017 20:06:56] - |A| - [3560] - C:\WINDOWS\System32\Tasks\EPSON XP-710 Series Update {68953606-62A7-4B6A-87A7-1CF73FEC7E9A} : C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLPE.EXE[MD5.EE2AA2F24F166AB7E539516593DAC09C] - [26/04/2017 20:06:56] - |A| - [3560] - C:\WINDOWS\System32\Tasks\EPSON XP-710 Series Update {69791235-D3B3-45B7-A134-218554EE5C76} : C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLPE.EXE[MD5.53A57E6E60CE88FA8D8C9F0F1B92C9F0] - [06/07/2017 12:00:34] - |A| - [3474] - C:\WINDOWS\System32\Tasks\ExtFS GUI : C:\Program Files (x86)\Paragon Software\ExtFS for Windows\Paragon ExtFS for Windows.exe[MD5.6622C190305164DE6DCF22A331BC6B8E] - [06/07/2017 12:00:34] - |A| - [3670] - C:\WINDOWS\System32\Tasks\ExtFS Updater : C:\Program Files (x86)\Paragon Software\ExtFS for Windows\Updater.exe[MD5.CF9ED368C6F2725FBDF43740AF30FE1B] - [01/05/2017 21:50:45] - |A| - [2578] - C:\WINDOWS\System32\Tasks\GlaryInitialize 5 : C:\Program Files (x86)\Glary Utilities 5\Initialize.exe[MD5.A0A76DD409029CC6FAAAB722C1E629B9] - [01/05/2017 21:53:38] - |A| - [2306] - C:\WINDOWS\System32\Tasks\GMHSkipUAC : C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe[MD5.041C041E864647FA56F8E07A21E12B4E] - [26/04/2017 20:06:56] - |A| - [3350] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[MD5.011C25E8CB3FEDD93D724AB700D8A216] - [26/04/2017 20:06:56] - |A| - [3574] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[MD5.467CD9434776B676D167C1F9CBF3E683] - [02/05/2017 17:26:03] - |A| - [3302] - C:\WINDOWS\System32\Tasks\GridinSoft Anti-Ransomware : "C:\Program Files\GridinSoft Anti-Ransomware\gsar.exe"[MD5.75FB1BB49BB281AFFAAE2DBB1F37E0D2] - [01/05/2017 21:50:45] - |A| - [2286] - C:\WINDOWS\System32\Tasks\GU5SkipUAC : C:\Program Files (x86)\Glary Utilities 5\Integrator.exe[MD5.00000000000000000000000000000000] - [18/03/2017 23:03:29] - |D| - [524600] - C:\WINDOWS\System32\Tasks\Microsoft[MD5.540CD5AC4BA9F136DC0F39E3D3393EC8] - [28/04/2017 14:09:34] - |A| - [3294] - C:\WINDOWS\System32\Tasks\PandaUSBVaccine : "C:\Program Files (x86)\Panda USB Vaccine\RunInteractiveWin.exe"[MD5.00000000000000000000000000000000] - [28/04/2017 13:59:50] - |D| - [3640] - C:\WINDOWS\System32\Tasks\Safer-Networking[MD5.BC85A763428382F269E3F0609830E223] - [21/07/2017 10:57:04] - |A| - [3404] - C:\WINDOWS\System32\Tasks\SuperbGameBoost : C:\Program Files (x86)\SuperBoost\Superb Game Boost\SuperbGameBoostMain.exe[MD5.43544D4FE91955B758155C9919B821A0] - [07/07/2017 13:18:17] - |A| - [3250] - C:\WINDOWS\System32\Tasks\U2_B3A986DC-C2DD-40A0-8C0C-FEF66B783511 : rundll32[MD5.D8A5CD27EEE1F2B8170A3BD3AC4EE364] - [07/07/2017 10:02:59] - |A| - [2524] - C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_Jean-Marie : C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe[MD5.E0074FFD809CE08872D576AA434E4ABF] - [13/07/2017 14:10:12] - |A| - [3140] - C:\WINDOWS\System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} : C:\Program Files\COMODO\COMODO Internet Security\cistray.exe[MD5.00000000000000000000000000000000] - [18/03/2017 23:03:29] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules]"MDNS-Out-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|LPort=5353|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37305|Desc=@%SystemRoot%\system32\firewallapi.dll,-37306|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302|"MDNS-In-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort2_24=mDNS|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37303|Desc=@%SystemRoot%\system32\firewallapi.dll,-37304|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302|"WirelessDisplay-Infra-In-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100|"WirelessDisplay-Out-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay|"WirelessDisplay-Out-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay|"WirelessDisplay-In-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay|"Netlogon-TCP-RPC-In"=v2.27|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010|"Netlogon-NamedPipe-In"=v2.27|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010|"DeliveryOptimization-UDP-In"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE|"DeliveryOptimization-TCP-In"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE|"WiFiDirect-KM-Driver-Out-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=System|Name=@wlansvc.dll,-37381|Desc=@wlansvc.dll,-37893|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|"WiFiDirect-KM-Driver-In-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=System|Name=@wlansvc.dll,-37380|Desc=@wlansvc.dll,-37892|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|"WiFiDirect-KM-Driver-Out-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=System|Name=@wlansvc.dll,-37379|Desc=@wlansvc.dll,-37891|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|"WiFiDirect-KM-Driver-In-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=System|Name=@wlansvc.dll,-37378|Desc=@wlansvc.dll,-37890|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|"Wininit-Shutdown-In-Rule-TCP-RPC-EPMapper"=v2.27|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC-EPMap|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36755|Desc=@firewallapi.dll,-36756|EmbedCtxt=@firewallapi.dll,-36751|"Wininit-Shutdown-In-Rule-TCP-RPC"=v2.27|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36753|Desc=@firewallapi.dll,-36754|EmbedCtxt=@firewallapi.dll,-36751|"{866F1EA1-E022-4898-AFC2-7DF12C47B786}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\DriverBooster.exe|Name=Driver Booster - DriverBooster.exe|EmbedCtxt=IObit|"{22125EF4-BDDE-4018-8692-C45B5FC2CF0F}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\DriverBooster.exe|Name=Driver Booster - DriverBooster.exe|EmbedCtxt=IObit|"{1F68D0AC-01A7-409D-92C2-74CCAC6E4888}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\DBDownloader.exe|Name=Driver Booster - DBDownloader.exe|EmbedCtxt=IObit|"{C29AAEA8-7A34-477E-A1A3-0AB3848C6E43}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\DBDownloader.exe|Name=Driver Booster - DBDownloader.exe|EmbedCtxt=IObit|"{913E1AA3-8D5A-44CA-968D-AE97A49BEB8F}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\AutoUpdate.exe|Name=Driver Booster - AutoUpdate.exe|EmbedCtxt=IObit|"{3E0BF103-D3DD-4FC4-A81A-56CDFDC7FD66}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\AutoUpdate.exe|Name=Driver Booster - AutoUpdate.exe|EmbedCtxt=IObit|"{0D1B6A4E-C8E6-46F1-B68D-176CF4556673}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files\Easeware\DriverEasy\DriverEasy.exe|Name=Driver Easy|Desc=Allow Driver Easy Access Internet to Scan and Download Drivers.|"{B00B16BE-73FD-4F9A-9230-8D399728B935}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\TeamViewer\TeamViewer.exe|Name=Teamviewer Remote Control Application|"{41CF5C04-B0AE-43D5-B0E8-CDA33929604A}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\TeamViewer\TeamViewer.exe|Name=Teamviewer Remote Control Application|"{6619BB6A-7144-45A0-AD5E-AC8B2E1F02C1}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe|Name=Teamviewer Remote Control Service|"{313E671C-726D-4F6C-A2B3-527FEB7D9E17}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe|Name=Teamviewer Remote Control Service|"TCP Query User{A9DF99A2-5071-44B2-93C0-EDDF2034C004}C:\programdata\a-pdf\flip html5\previewflash\previewhtmlserver.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\programdata\a-pdf\flip html5\previewflash\previewhtmlserver.exe|Name=previewhtmlserver|Desc=previewhtmlserver|Defer=User|"UDP Query User{3CF37235-B1F9-4D40-B5FD-87C2771703FF}C:\programdata\a-pdf\flip html5\previewflash\previewhtmlserver.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\programdata\a-pdf\flip html5\previewflash\previewhtmlserver.exe|Name=previewhtmlserver|Desc=previewhtmlserver|Defer=User|"{D67E4B2B-528B-4C29-AEE1-08E86B4B02E8}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Mozilla Firefox\firefox.exe|Name=Firefox (C:\Program Files (x86)\Mozilla Firefox)|"{109651EE-6B7B-4A2D-A69D-98105A2A3498}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Mozilla Firefox\firefox.exe|Name=Firefox (C:\Program Files (x86)\Mozilla Firefox)| [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\standardprofile\authorizedapplications\list]"C:\Users\Jean-Marie\Desktop\adsfix_4_29.04.17.1.exe"=C:\Users\Jean-Marie\Desktop\adsfix_4_29.04.17.1.exe:*:Enabled:adsfix_4_29.04.17.1 [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\domainprofile\authorizedapplications\list]"C:\Users\Jean-Marie\Desktop\adsfix_4_29.04.17.1.exe"=C:\Users\Jean-Marie\Desktop\adsfix_4_29.04.17.1.exe:*:Enabled:adsfix_4_29.04.17.1 ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals[HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device[HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{19837c5c-96f5-45e0-9a2d-c6bb26e1b12b}] : (UIM) [] -> @oem5.inf,%UimClassName%;Universal Image Mounter[HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues[HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026[HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (Security Accelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators[HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader[HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025[HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300[HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023[HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @%SystemRoot%\System32\DispCI.dll,-3100[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4fc9541c-0fe6-4480-a4f6-9495a0d17cd2}] : (HidLineDisplay) [] -> @c_linedisplay.inf,%ClassName%;POS Line Display[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000[HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028[HKLM\SYSTEM\CurrentControlSet\Control\Class\{54f3637b-4777-4f96-970c-6bfa5477b542}] : (ParagonBlockDevice) [] -> @oem7.inf,%ClassName%;User-mode block device[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs)[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5aea001d-9372-4ed7-97f3-b79bf15a53c5}] : (OposLegacyDevice) [] -> @oposdrv.inf,%ClassName%;OPOS Legacy Device[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{645ad99b-1344-4316-837a-08a3e73db222}] : (PerceptionSimulation) [] -> @PerceptionSimulationSixDof.inf,%ClassName%;Perception Simulation Controllers[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes[HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611[HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101[HKLM\SYSTEM\CurrentControlSet\Control\Class\{76F9ABD8-2CB5-4D55-B2DD-1082752E0D32}] : (uxstyle) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer[HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019[HKLM\SYSTEM\CurrentControlSet\Control\Class\{81C87465-DE07-4EFC-9D93-61E891D52FD2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8496e87e-c0a1-4102-9d8d-bd9a9b8b07a9}] : (WDC_SAM) [] -> @oem21.inf,%WDC_SAM_ClassName%;WD Drive Management devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{87ef9ad1-8f70-49ee-b215-ab1fcadcbe3c}] : (NetDriver) [] -> @c_netdriver.inf,%ClassDesc%;Universal Network Drivers[HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029[HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003[HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031[HKLM\SYSTEM\CurrentControlSet\Control\Class\{9d6d66a6-0b0c-4563-9077-a0e9a7955ae4}] : (Ramdisk) [] -> @ramdisk.inf,%ClassName%;RAM Disk drives[HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012[HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer[HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d612553d-06b1-49ca-8938-e39ef80eb16f}] : (Holographic) [] -> @c_holographic.inf,%ClassName%;Mixed Reality devices[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020[HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032[HKLM\SYSTEM\CurrentControlSet\Control\Class\{E004269C-D387-4461-B955-25A64CFE23CE}] : (amdkmdag) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001[HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions[HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters[HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation. All rights reserved.)[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation. All rights reserved.)[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation. All rights reserved.) ---------- | Loaded modules (whitelist) [18/03/2017 22:56:23] - (7.13.65.105) - (QLogic Corporation - QLogic 10 GigE VBD) - C:\WINDOWS\System32\drivers\evbda.sys[18/03/2017 22:56:25] - (10.6.0.23) - (NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver) - C:\WINDOWS\System32\drivers\nvraid.sys[18/03/2017 22:56:23] - (7.12.31.105) - (QLogic Corporation - QLogic Gigabit Ethernet VBD) - C:\WINDOWS\System32\drivers\bxvbda.sys[18/03/2017 22:56:25] - (5.1.0.51) - (LSI - LSI 3ware SCSI Storport Driver) - C:\WINDOWS\System32\drivers\3ware.sys[18/03/2017 22:56:25] - (3.7.1540.43) - (AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform) - C:\WINDOWS\System32\drivers\amdsbs.sys[18/03/2017 22:56:25] - (7.5.0.32048) - (PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver) - C:\WINDOWS\System32\drivers\arcsas.sys[18/03/2017 22:56:25] - (1.34.3.83) - (LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sas.sys[18/03/2017 22:56:25] - (2.0.79.81) - (LSI Corporation - LSI SAS Gen2 Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sas2i.sys[18/03/2017 22:56:25] - (2.51.12.81) - (Avago Technologies - Avago SAS Gen3 Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sas3i.sys[18/03/2017 22:56:25] - (2.10.61.81) - (LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort)) - C:\WINDOWS\System32\drivers\lsi_sss.sys[18/03/2017 22:56:25] - (6.706.6.0) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\megasas.sys[18/03/2017 22:56:25] - (6.711.10.11) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\MegaSas2i.sys[18/03/2017 22:56:25] - (15.2.2013.129) - (LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver) - C:\WINDOWS\System32\drivers\megasr.sys[18/03/2017 22:56:25] - (1.0.5.1016) - (Marvell Semiconductor, Inc. - Marvell Flash Controller Driver) - C:\WINDOWS\System32\drivers\mvumis.sys[18/03/2017 22:56:25] - (10.6.0.23) - (NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver) - C:\WINDOWS\System32\drivers\nvstor.sys[18/03/2017 22:56:25] - (6.805.3.0) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\percsas2i.sys[18/03/2017 22:56:25] - (6.603.6.0) - (Avago Technologies - MEGASAS RAID Controller Driver for Windows) - C:\WINDOWS\System32\drivers\percsas3i.sys[18/03/2017 22:56:25] - (5.1.1039.2600) - (Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver) - C:\WINDOWS\System32\drivers\SiSRaid2.sys[18/03/2017 22:56:25] - (5.1.1039.3600) - (Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver) - C:\WINDOWS\System32\drivers\sisraid4.sys[18/03/2017 22:56:25] - (5.1.0.10) - (Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64) - C:\WINDOWS\System32\drivers\stexstor.sys[18/03/2017 22:56:25] - (7.0.9600.6352) - (VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64) - C:\WINDOWS\System32\drivers\vsmraid.sys[18/03/2017 22:56:25] - (8.0.9200.8110) - (VIA Corporation - VIA StorX RAID Controller Driver) - C:\WINDOWS\System32\drivers\vstxraid.sys[18/03/2017 22:56:25] - (1.3.0.10769) - (PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller) - C:\WINDOWS\System32\drivers\ADP80XX.SYS[18/03/2017 22:56:25] - (8.0.4.0) - (Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver) - C:\WINDOWS\System32\drivers\HpSAMD.sys[23/05/2010 19:47:08] - (1.0.0.1) - (Sonic Solutions - BackOnTrack Component) - C:\WINDOWS\system32\drivers\syscowad64v.sys[12/05/2017 04:39:39] - (1.1.0.2305) - (Acronis International GmbH - File tracker minifilter driver) - C:\WINDOWS\system32\DRIVERS\file_tracker.sys[12/05/2017 04:39:14] - (1.3.0.2227) - (Acronis International GmbH - Acronis Storage Filter Management Driver) - C:\WINDOWS\system32\DRIVERS\fltsrv.sys[12/05/2017 04:39:21] - (1.0.0.1132) - (Acronis International GmbH - Acronis Backup Archive Explorer) - C:\WINDOWS\system32\DRIVERS\tib.sys[07/07/2017 18:11:52] - (3.0.95.0) - (Rovi Corporation - Px Engine Device Driver for 64-bit Windows) - C:\WINDOWS\System32\Drivers\PxHlpa64.sys[07/07/2017 19:23:59] - (2.0.37.0) - (Sonic Solutions - Disk Filter Driver) - C:\WINDOWS\System32\Drivers\Sahdad64.sys[07/07/2017 19:23:59] - (2.0.37.0) - (Sonic Solutions - Disk Filter Driver) - C:\WINDOWS\System32\Drivers\Saibad64.sys[22/07/2017 12:11:34] - (2.0.2.0) - (IObit - SmartDefrag Driver) - C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys[14/11/2016 09:36:55] - (0.0.0.0) - ( - ) - C:\WINDOWS\system32\drivers\EUBKMON.sys[14/11/2016 09:37:07] - (1.0.1.0) - (CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Driver) - C:\WINDOWS\system32\drivers\eubakup.sys[02/06/2017 03:48:34] - (10.0.1.6241) - (COMODO - COMODO Internet Security Eradication Driver) - C:\WINDOWS\System32\DRIVERS\cmderd.sys[16/02/2016 17:52:38] - (7.0.0.12) - (BitDefender LLC - BitDefender Firewall NDIS6 Filter Driver) - C:\WINDOWS\system32\DRIVERS\bdfndisf6.sys[16/02/2016 17:52:38] - (7.0.0.8) - (BitDefender LLC - BitDefender Firewall WFP Filter Driver) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.1.0\Drivers\bdfwfpf.sys[02/06/2017 03:48:58] - (10.0.1.6241) - (COMODO - COMODO Internet Security Helper Driver) - C:\WINDOWS\system32\DRIVERS\cmdhlp.sys[01/05/2017 22:58:44] - (1.5.2.1) - (Windows (R) Win 7 DDK provider - NetFilter SDK WFP Driver (WPP)) - C:\WINDOWS\system32\drivers\cgnetfilter1521.sys[13/06/2017 00:11:42] - (5.0.92.612) - (Insecure.Com LLC. - npcap.sys (NT6 AMD64) Kernel Filter Driver) - C:\WINDOWS\system32\DRIVERS\npcap.sys[07/06/2017 21:47:54] - (10.0.1.6245) - (COMODO - COMODO Internet Security Firewall Driver) - C:\WINDOWS\system32\DRIVERS\inspect.sys[21/07/2017 11:24:17] - (10.0.14393.31233) - (Realsil Semiconductor Corporation - RTS USB READER Driver) - C:\WINDOWS\system32\Drivers\RtsUer.sys[21/07/2017 11:13:05] - (2.1.0.17) - (Qualcomm Atheros, Inc. - Killer e2200 PCI-E Gigabit Ethernet Controller) - C:\WINDOWS\System32\drivers\L1C63x64.sys[28/04/2017 14:08:47] - (3.4.0.0) - (Disc Soft Ltd - DAEMON Tools Lite Virtual USB Bus Driver) - C:\WINDOWS\System32\drivers\dtliteusbbus.sys[05/01/2016 14:45:28] - (3.11.12293.6311) - (BitDefender - BitDefender AntiVirus Active Virus Control Hypervisor driver) - C:\WINDOWS\system32\DRIVERS\avchv.sys[10/11/2016 19:52:59] - (2.0.0.3505) - (CyberLink - CyberLink Virtual CDROM Bus Enumerator) - C:\WINDOWS\System32\drivers\CLVirtualBus01.sys[28/04/2017 14:05:39] - (5.28.0.0) - (Disc Soft Ltd - DAEMON Tools Lite Virtual SCSI Bus Driver) - C:\WINDOWS\System32\drivers\dtlitescsibus.sys[14/11/2016 10:05:31] - (1.8.2.328) - (Zemana Ltd. - Zemana AntiLogger Free) - C:\WINDOWS\system32\DRIVERS\KeyCrypt64.sys[22/07/2017 15:14:31] - (9.0.0.21) - (The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6.0)) - C:\WINDOWS\System32\drivers\tapwindscribe0901.sys[24/04/2017 09:48:03] - (9.0.0.3) - (TeamViewer GmbH - TeamViewerVPN Network Adapter) - C:\WINDOWS\System32\drivers\teamviewervpn.sys[22/07/2017 15:35:58] - (2.0.0.0) - (NordNet - WFP driver) - C:\WINDOWS\system32\Drivers\cpwfpnd64.sys[14/11/2016 10:27:16] - (5.28.0.0) - (Disc Soft Ltd - DAEMON Tools Pro Virtual SCSI Bus Driver) - C:\WINDOWS\System32\drivers\dtproscsibus.sys[21/07/2017 11:14:56] - (4.5.1.0) - (Genesys logic - GeneStor) - C:\WINDOWS\system32\DRIVERS\GeneStor.sys ---------- | LoadOrderGroup Name: System Reserved - DriverEnabled: True - GroupOrder: 1 - Status: OKName: EMS - DriverEnabled: True - GroupOrder: 2 - Status: OKName: WdfLoadGroup - DriverEnabled: True - GroupOrder: 3 - Status: OKName: Boot Bus Extender - DriverEnabled: True - GroupOrder: 4 - Status: OKName: System Bus Extender - DriverEnabled: True - GroupOrder: 5 - Status: OKName: SCSI miniport - DriverEnabled: True - GroupOrder: 6 - Status: OKName: Port - DriverEnabled: True - GroupOrder: 7 - Status: OKName: Primary Disk - DriverEnabled: True - GroupOrder: 8 - Status: OKName: SCSI Class - DriverEnabled: True - GroupOrder: 9 - Status: OKName: SCSI CDROM Class - DriverEnabled: True - GroupOrder: 10 - Status: OKName: FSFilter Infrastructure - DriverEnabled: True - GroupOrder: 11 - Status: OKName: FSFilter System - DriverEnabled: True - GroupOrder: 12 - Status: OKName: FSFilter Bottom - DriverEnabled: True - GroupOrder: 13 - Status: OKName: FSFilter Copy Protection - DriverEnabled: True - GroupOrder: 14 - Status: OKName: FSFilter Security Enhancer - DriverEnabled: True - GroupOrder: 15 - Status: OKName: FSFilter Open File - DriverEnabled: True - GroupOrder: 16 - Status: OKName: FSFilter Physical Quota Management - DriverEnabled: True - GroupOrder: 17 - Status: OKName: FSFilter Virtualization - DriverEnabled: True - GroupOrder: 18 - Status: OKName: FSFilter Encryption - DriverEnabled: True - GroupOrder: 19 - Status: OKName: FSFilter Compression - DriverEnabled: True - GroupOrder: 20 - Status: OKName: FSFilter Imaging - DriverEnabled: True - GroupOrder: 21 - Status: OKName: FSFilter HSM - DriverEnabled: True - GroupOrder: 22 - Status: OKName: FSFilter Cluster File System - DriverEnabled: True - GroupOrder: 23 - Status: OKName: FSFilter System Recovery - DriverEnabled: True - GroupOrder: 24 - Status: OKName: FSFilter Quota Management - DriverEnabled: True - GroupOrder: 25 - Status: OKName: FSFilter Content Screener - DriverEnabled: True - GroupOrder: 26 - Status: OKName: FSFilter Continuous Backup - DriverEnabled: True - GroupOrder: 27 - Status: OKName: FSFilter Replication - DriverEnabled: True - GroupOrder: 28 - Status: OKName: FSFilter Anti-Virus - DriverEnabled: True - GroupOrder: 29 - Status: OKName: FSFilter Undelete - DriverEnabled: True - GroupOrder: 30 - Status: OKName: FSFilter Activity Monitor - DriverEnabled: True - GroupOrder: 31 - Status: OKName: FSFilter Top - DriverEnabled: True - GroupOrder: 32 - Status: OKName: Filter - DriverEnabled: True - GroupOrder: 33 - Status: OKName: Boot File System - DriverEnabled: True - GroupOrder: 34 - Status: OKName: Base - DriverEnabled: True - GroupOrder: 35 - Status: OKName: Pointer Port - DriverEnabled: True - GroupOrder: 36 - Status: OKName: Keyboard Port - DriverEnabled: True - GroupOrder: 37 - Status: OKName: Pointer Class - DriverEnabled: True - GroupOrder: 38 - Status: OKName: Keyboard Class - DriverEnabled: True - GroupOrder: 39 - Status: OKName: Video Init - DriverEnabled: True - GroupOrder: 40 - Status: OKName: Video - DriverEnabled: True - GroupOrder: 41 - Status: OKName: Video Save - DriverEnabled: True - GroupOrder: 42 - Status: OKName: File System - DriverEnabled: True - GroupOrder: 43 - Status: OKName: Streams Drivers - DriverEnabled: True - GroupOrder: 44 - Status: OKName: NDIS Wrapper - DriverEnabled: True - GroupOrder: 45 - Status: OKName: COM Infrastructure - DriverEnabled: True - GroupOrder: 46 - Status: OKName: Event Log - DriverEnabled: True - GroupOrder: 47 - Status: OKName: ProfSvc_Group - DriverEnabled: True - GroupOrder: 48 - Status: OKName: AudioGroup - DriverEnabled: True - GroupOrder: 49 - Status: OKName: UIGroup - DriverEnabled: True - GroupOrder: 50 - Status: OKName: MS_WindowsLocalValidation - DriverEnabled: True - GroupOrder: 51 - Status: OKName: PlugPlay - DriverEnabled: True - GroupOrder: 52 - Status: OKName: Cryptography - DriverEnabled: True - GroupOrder: 53 - Status: OKName: PNP_TDI - DriverEnabled: True - GroupOrder: 54 - Status: OKName: NDIS - DriverEnabled: True - GroupOrder: 55 - Status: OKName: TDI - DriverEnabled: True - GroupOrder: 56 - Status: OKName: iSCSI - DriverEnabled: True - GroupOrder: 57 - Status: OKName: NetBIOSGroup - DriverEnabled: True - GroupOrder: 58 - Status: OKName: ShellSvcGroup - DriverEnabled: True - GroupOrder: 59 - Status: OKName: SchedulerGroup - DriverEnabled: True - GroupOrder: 60 - Status: OKName: SpoolerGroup - DriverEnabled: True - GroupOrder: 61 - Status: OKName: SmartCardGroup - DriverEnabled: True - GroupOrder: 62 - Status: OKName: NetworkProvider - DriverEnabled: True - GroupOrder: 63 - Status: OKName: MS_WindowsRemoteValidation - DriverEnabled: True - GroupOrder: 64 - Status: OKName: NetDDEGroup - DriverEnabled: True - GroupOrder: 65 - Status: OKName: Parallel arbitrator - DriverEnabled: True - GroupOrder: 66 - Status: OKName: Extended Base - DriverEnabled: True - GroupOrder: 67 - Status: OKName: PCI Configuration - DriverEnabled: True - GroupOrder: 68 - Status: OKName: MS Transactions - DriverEnabled: True - GroupOrder: 69 - Status: OKName: Core - DriverEnabled: False - GroupOrder: 70 - Status: OKName: Network - DriverEnabled: False - GroupOrder: 71 - Status: OKName: extendedbase - DriverEnabled: False - GroupOrder: 72 - Status: OKName: PnP Filter - DriverEnabled: False - GroupOrder: 73 - Status: OKName: GSARS Anti-Virus - DriverEnabled: False - GroupOrder: 74 - Status: OKName: Core Security Extensions - DriverEnabled: False - GroupOrder: 75 - Status: OKName: NetworkService - DriverEnabled: False - GroupOrder: 76 - Status: OKName: _Early-Launch - DriverEnabled: False - GroupOrder: 77 - Status: OKName: LocalService - DriverEnabled: False - GroupOrder: 78 - Status: OK ---------- | LoadOrderGroupServiceDependencies LoadOrderGroup.Name="NetBIOSGroup" - Service.Name="RemoteAccess"LoadOrderGroup.Name="SCSI CDROM Class" - SystemDriver.Name="cdfs" ---------- | LoadOrderGroupServiceMembers LoadOrderGroup.Name="Event log" - Service.Name="AMD External Events Utility"LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="AppIDSvc"LoadOrderGroup.Name="AudioGroup" - Service.Name="AudioEndpointBuilder"LoadOrderGroup.Name="AudioGroup" - Service.Name="Audiosrv"LoadOrderGroup.Name="NetworkProvider" - Service.Name="BFE"LoadOrderGroup.Name="Event Log" - Service.Name="BOTService"LoadOrderGroup.Name="COM Infrastructure" - Service.Name="BrokerInfrastructure"LoadOrderGroup.Name="NetworkProvider" - Service.Name="Browser"LoadOrderGroup.Name="Core" - Service.Name="CmdAgent"LoadOrderGroup.Name="COM Infrastructure" - Service.Name="DcomLaunch"LoadOrderGroup.Name="PlugPlay" - Service.Name="DeviceInstall"LoadOrderGroup.Name="TDI" - Service.Name="Dhcp"LoadOrderGroup.Name="TDI" - Service.Name="Dnscache"LoadOrderGroup.Name="TDI" - Service.Name="dot3svc"LoadOrderGroup.Name="TDI" - Service.Name="DusmSvc"LoadOrderGroup.Name="Event Log" - Service.Name="EventLog"LoadOrderGroup.Name="AudioGroup" - Service.Name="FontCache"LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="gpsvc"LoadOrderGroup.Name="TDI" - Service.Name="icssvc"LoadOrderGroup.Name="TDI" - Service.Name="irmon"LoadOrderGroup.Name="NetworkProvider" - Service.Name="LanmanWorkstation"LoadOrderGroup.Name="TDI" - Service.Name="lmhosts"LoadOrderGroup.Name="COM Infrastructure" - Service.Name="LSM"LoadOrderGroup.Name="NetworkService" - Service.Name="MapsBroker"LoadOrderGroup.Name="NetworkProvider" - Service.Name="MpsSvc"LoadOrderGroup.Name="iSCSI" - Service.Name="MSiSCSI"LoadOrderGroup.Name="MS_WindowsRemoteValidation" - Service.Name="Netlogon"LoadOrderGroup.Name="Cryptography" - Service.Name="NgcCtnrSvc"LoadOrderGroup.Name="Cryptography" - Service.Name="NgcSvc"LoadOrderGroup.Name="PlugPlay" - Service.Name="PlugPlay"LoadOrderGroup.Name="Plugplay" - Service.Name="Power"LoadOrderGroup.Name="profsvc_group" - Service.Name="ProfSvc"LoadOrderGroup.Name="COM Infrastructure" - Service.Name="RpcEptMapper"LoadOrderGroup.Name="COM Infrastructure" - Service.Name="RpcSs"LoadOrderGroup.Name="PlugPlay" - Service.Name="RtkAudioService"LoadOrderGroup.Name="MS_WindowsLocalValidation" - Service.Name="SamSs"LoadOrderGroup.Name="SmartCardGroup" - Service.Name="SCardSvr"LoadOrderGroup.Name="SchedulerGroup" - Service.Name="Schedule"LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="SENS"LoadOrderGroup.Name="ShellSvcGroup" - Service.Name="ShellHWDetection"LoadOrderGroup.Name="SpoolerGroup" - Service.Name="Spooler"LoadOrderGroup.Name="PlugPlay" - Service.Name="TabletInputService"LoadOrderGroup.Name="System Reserved" - Service.Name="TeraCopyService"LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="Themes"LoadOrderGroup.Name="ProfSvc_Group" - Service.Name="TrustedInstaller"LoadOrderGroup.Name="Base" - Service.Name="USBSafelyRemoveService"LoadOrderGroup.Name="SmartCardGroup" - Service.Name="WbioSrvc"LoadOrderGroup.Name="TDI" - Service.Name="Wcmsvc"LoadOrderGroup.Name="NetworkProvider" - Service.Name="WebClient"LoadOrderGroup.Name="TDI" - Service.Name="WlanSvc"LoadOrderGroup.Name="TDI" - Service.Name="wlpasvc"LoadOrderGroup.Name="LocalService" - Service.Name="workfolderssvc"LoadOrderGroup.Name="PlugPlay" - Service.Name="wudfsvc"LoadOrderGroup.Name="TDI" - Service.Name="WwanSvc"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="360AvFlt"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="3ware"LoadOrderGroup.Name="Core" - SystemDriver.Name="ACPI"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AcpiDev"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="acpiex"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="acpitime"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="ADP80XX"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="AFD"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AmdK8"LoadOrderGroup.Name="Video" - SystemDriver.Name="amdkmdag"LoadOrderGroup.Name="Video" - SystemDriver.Name="amdkmdap"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="AmdPPM"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdsata"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdsbs"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amdxata"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="arcsas"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="atapi"LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="avc3"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="avchv"LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="avckf"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="b06bdrv"LoadOrderGroup.Name="Video" - SystemDriver.Name="BasicDisplay"LoadOrderGroup.Name="Video" - SystemDriver.Name="BasicRender"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="bcmfn2"LoadOrderGroup.Name="NDIS Wrapper" - SystemDriver.Name="BdfNdisf"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="bdfwfpf"LoadOrderGroup.Name="Base" - SystemDriver.Name="Beep"LoadOrderGroup.Name="Network" - SystemDriver.Name="bowser"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="BthAvrcpTg"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="BthHFEnum"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="cdfs"LoadOrderGroup.Name="SCSI CDROM Class" - SystemDriver.Name="cdrom"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="cgnetfilter1521"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="cht4iscsi"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="cht4vbd"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="circlass"LoadOrderGroup.Name="FSFilter HSM" - SystemDriver.Name="CldFlt"LoadOrderGroup.Name="Filter" - SystemDriver.Name="CLFS"LoadOrderGroup.Name="base" - SystemDriver.Name="clreg"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="CLVirtualBus01"LoadOrderGroup.Name="Primary Disk" - SystemDriver.Name="cmderd"LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="cmdGuard"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="cmdhlp"LoadOrderGroup.Name="Core" - SystemDriver.Name="CNG"LoadOrderGroup.Name="Base" - SystemDriver.Name="cnghwassist"LoadOrderGroup.Name="extendedbase" - SystemDriver.Name="CompFilter64"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="CompositeBus"LoadOrderGroup.Name="Base" - SystemDriver.Name="condrv"LoadOrderGroup.Name="Network" - SystemDriver.Name="Dfsc"LoadOrderGroup.Name="File System" - SystemDriver.Name="Dokan"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="DtlDrvProtect"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="dtlitescsibus"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="dtliteusbbus"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="dtproscsibus"LoadOrderGroup.Name="Video Init" - SystemDriver.Name="DXGKrnl"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="ebdrv"LoadOrderGroup.Name="SCSI Class" - SystemDriver.Name="EhStorClass"LoadOrderGroup.Name="SCSI Class" - SystemDriver.Name="EhStorTcgDrv"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="ErrDev"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="exfat"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="fastfat"LoadOrderGroup.Name="FSFilter Encryption" - SystemDriver.Name="FileCrypt"LoadOrderGroup.Name="FSFilter Bottom" - SystemDriver.Name="FileInfo"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="Filetrace"LoadOrderGroup.Name="FSFilter Continuous Backup" - SystemDriver.Name="file_tracker"LoadOrderGroup.Name="FSFilter Infrastructure" - SystemDriver.Name="FltMgr"LoadOrderGroup.Name="Filter" - SystemDriver.Name="fltsrv"LoadOrderGroup.Name="FSFilter Top" - SystemDriver.Name="FsDepends"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="fvevol"LoadOrderGroup.Name="Base" - SystemDriver.Name="genericusbfn"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="GPIOClx0101"LoadOrderGroup.Name="GSARS Anti-Virus" - SystemDriver.Name="GridinSoftAntiRansomwareDriver"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="HDAudBus"LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidBth"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hidi2c"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hidinterrupt"LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidIr"LoadOrderGroup.Name="extended base" - SystemDriver.Name="HidUsb"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="HpSAMD"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hvservice"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="hyperkbd"LoadOrderGroup.Name="Keyboard Port" - SystemDriver.Name="i8042prt"LoadOrderGroup.Name="Base" - SystemDriver.Name="iai2c"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iaLPSS2i_GPIO2"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iaLPSS2i_GPIO2_BXT_P"LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSS2i_I2C"LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSS2i_I2C_BXT_P"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="iaLPSSi_GPIO"LoadOrderGroup.Name="Base" - SystemDriver.Name="iaLPSSi_I2C"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="iaStorAV"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="iaStorV"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="ibbus"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="ignis"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="IMFMBRProtect"LoadOrderGroup.Name="Base" - SystemDriver.Name="IndirectKmd"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="inspect"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="intelide"LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="intelpep"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="intelppm"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="iorate"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="irda"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="isapnp"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="IUFileFilter"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="kdnic"LoadOrderGroup.Name="Keyboard Class" - SystemDriver.Name="keycrypt"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="kmloop"LoadOrderGroup.Name="Base" - SystemDriver.Name="KSecDD"LoadOrderGroup.Name="Cryptography" - SystemDriver.Name="KSecPkg"LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="ksthunk"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="L1C"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="lltdio"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS2i"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SAS3i"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="LSI_SSS"LoadOrderGroup.Name="FSFilter Virtualization" - SystemDriver.Name="luafv"LoadOrderGroup.Name="Base" - SystemDriver.Name="mausbhost"LoadOrderGroup.Name="Base" - SystemDriver.Name="mausbip"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="MBAMChameleon"LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="MBAMProtection"LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="MBAMProtector"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="MBAMSwissArmy"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasas"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasas2i"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="megasr"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="mlx4_bus"LoadOrderGroup.Name="Extended base" - SystemDriver.Name="Modem"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="mountmgr"LoadOrderGroup.Name="network" - SystemDriver.Name="mpsdrv"LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb"LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb10"LoadOrderGroup.Name="Network" - SystemDriver.Name="mrxsmb20"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="MsBridge"LoadOrderGroup.Name="File system" - SystemDriver.Name="Msfs"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="msgpiowin32"LoadOrderGroup.Name="Base" - SystemDriver.Name="mshidkmdf"LoadOrderGroup.Name="Base" - SystemDriver.Name="mshidumdf"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="msisadrv"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSKSSRV"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="MsLldp"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSPCLOCK"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSPQM"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MSTEE"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="MTConfig"LoadOrderGroup.Name="Network" - SystemDriver.Name="Mup"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="mvumis"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NativeWifiP"LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="ndfltr"LoadOrderGroup.Name="NDIS Wrapper" - SystemDriver.Name="NDIS"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NdisCap"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="NdisTapi"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="Ndisuio"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="ndiswanlegacy"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="ndproxy"LoadOrderGroup.Name="NetBIOSGroup" - SystemDriver.Name="NetBIOS"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="NetBT"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="netcontroller"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="netvsc"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="npcap"LoadOrderGroup.Name="File system" - SystemDriver.Name="Npfs"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="NTFS"LoadOrderGroup.Name="Base" - SystemDriver.Name="Null"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="nvraid"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="nvstor"LoadOrderGroup.Name="Parallel arbitrator" - SystemDriver.Name="Parport"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="partmgr"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="pci"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="pciide"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="pcmcia"LoadOrderGroup.Name="System Reserved" - SystemDriver.Name="pcw"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="pdc"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="percsas2i"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="percsas3i"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="PfFilter"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="Processor"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="Psched"LoadOrderGroup.Name="Filter" - SystemDriver.Name="PxHlpa64"LoadOrderGroup.Name="Streams Drivers" - SystemDriver.Name="RasAcd"LoadOrderGroup.Name="Network" - SystemDriver.Name="rdbss"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="rdyboost"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="ReFS"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="ReFSv1"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="rspndr"LoadOrderGroup.Name="Video" - SystemDriver.Name="s3cap"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="Sahdad64"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="Saibad64"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="scfilter"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="sdbus"LoadOrderGroup.Name="Base" - SystemDriver.Name="SensorsSimulatorDriver"LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="Serenum"LoadOrderGroup.Name="Extended base" - SystemDriver.Name="Serial"LoadOrderGroup.Name="Pointer Port" - SystemDriver.Name="sermouse"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="SiSRaid2"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="SiSRaid4"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="spaceport"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="SpatialGraphFilter"LoadOrderGroup.Name="Network" - SystemDriver.Name="srv"LoadOrderGroup.Name="Network" - SystemDriver.Name="srv2"LoadOrderGroup.Name="Network" - SystemDriver.Name="srvnet"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="stexstor"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="storahci"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="storflt"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="stornvme"LoadOrderGroup.Name="FSFilter Quota Management" - SystemDriver.Name="storqosflt"LoadOrderGroup.Name="Base" - SystemDriver.Name="storvsc"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="swenum"LoadOrderGroup.Name="Video Init" - SystemDriver.Name="Synth3dVsc"LoadOrderGroup.Name="FSFilter System Recovery" - SystemDriver.Name="SysCow"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="tap0901"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="Tcpip"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="tdx"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="teamviewervpn"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="terminpt"LoadOrderGroup.Name="Filter" - SystemDriver.Name="tib"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="tnd"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="TPM"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="TsUsbGD"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UcmCx0101"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UcmTcpciCx0101"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="Ucx01000"LoadOrderGroup.Name="Boot File System" - SystemDriver.Name="udfs"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="Ufx01000"LoadOrderGroup.Name="Base" - SystemDriver.Name="UfxChipidea"LoadOrderGroup.Name="Base" - SystemDriver.Name="ufxsynopsys"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="umbus"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="UmPass"LoadOrderGroup.Name="Base" - SystemDriver.Name="UrsChipidea"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="UrsCx01000"LoadOrderGroup.Name="Base" - SystemDriver.Name="UrsSynopsys"LoadOrderGroup.Name="Base" - SystemDriver.Name="usbccgp"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="usbcir"LoadOrderGroup.Name="Base" - SystemDriver.Name="usbehci"LoadOrderGroup.Name="Base" - SystemDriver.Name="usbhub"LoadOrderGroup.Name="Base" - SystemDriver.Name="USBHUB3"LoadOrderGroup.Name="Base" - SystemDriver.Name="usbohci"LoadOrderGroup.Name="extended base" - SystemDriver.Name="usbprint"LoadOrderGroup.Name="Base" - SystemDriver.Name="usbscan"LoadOrderGroup.Name="Base" - SystemDriver.Name="usbuhci"LoadOrderGroup.Name="File System" - SystemDriver.Name="uxstyle"LoadOrderGroup.Name="Boot Bus Extender" - SystemDriver.Name="vdrvroot"LoadOrderGroup.Name="WdfLoadGroup" - SystemDriver.Name="VerifierExt"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="vhdmp"LoadOrderGroup.Name="Base" - SystemDriver.Name="vhf"LoadOrderGroup.Name="Filter" - SystemDriver.Name="virtual_file"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="vmbus"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="VMBusHID"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="volmgr"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="volmgrx"LoadOrderGroup.Name="System Bus Extender" - SystemDriver.Name="vpci"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="vsmraid"LoadOrderGroup.Name="SCSI Miniport" - SystemDriver.Name="VSTXRAID"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="vwififlt"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WacomPen"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wanarp"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="wanarpv6"LoadOrderGroup.Name="FSFilter Virtualization" - SystemDriver.Name="wcifs"LoadOrderGroup.Name="FSFilter Top" - SystemDriver.Name="wcnfs"LoadOrderGroup.Name="_Early-Launch" - SystemDriver.Name="WdBoot"LoadOrderGroup.Name="WdfLoadGroup" - SystemDriver.Name="Wdf01000"LoadOrderGroup.Name="FSFilter Anti-Virus" - SystemDriver.Name="WdFilter"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="WFPLWFS"LoadOrderGroup.Name="FSFilter Infrastructure" - SystemDriver.Name="WIMMount"LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="WindowsTrustedRT"LoadOrderGroup.Name="Core Security Extensions" - SystemDriver.Name="WindowsTrustedRTProxy"LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="WinMad"LoadOrderGroup.Name="PNP Filter" - SystemDriver.Name="WinVerbs"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WmiAcpi"LoadOrderGroup.Name="FSFilter Compression" - SystemDriver.Name="Wof"LoadOrderGroup.Name="PnP Filter" - SystemDriver.Name="WpdUpFltr"LoadOrderGroup.Name="PNP_TDI" - SystemDriver.Name="ws2ifsl"LoadOrderGroup.Name="Extended Base" - SystemDriver.Name="WSDPrintDevice"LoadOrderGroup.Name="Base" - SystemDriver.Name="WSDScan"LoadOrderGroup.Name="base" - SystemDriver.Name="WudfPf"LoadOrderGroup.Name="base" - SystemDriver.Name="WUDFRd"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="xboxgip"LoadOrderGroup.Name="Base" - SystemDriver.Name="xinputhid"LoadOrderGroup.Name="FSFilter Content Screener" - SystemDriver.Name="xlkfs"LoadOrderGroup.Name="NDIS" - SystemDriver.Name="tapwindscribe0901"LoadOrderGroup.Name="networkprovider" - SystemDriver.Name="cpwfpnd"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amd_sata"LoadOrderGroup.Name="SCSI miniport" - SystemDriver.Name="amd_xata"LoadOrderGroup.Name="FSFilter Activity Monitor" - SystemDriver.Name="Revoflt" ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service R0 - [Kernel Driver] - 3ware () -> System32\drivers\3ware.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - ADP80XX () -> System32\drivers\ADP80XX.SYS - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - amdsata () -> System32\drivers\amdsata.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - amdsbs () -> System32\drivers\amdsbs.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - amdxata () -> System32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD) -> System32\drivers\bxvbda.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - Disk (@disk.inf,%disk_ServiceDesc%;Disk Driver) -> System32\drivers\disk.sys - AcceptPause: False - AcceptStop: TrueS0 - [File System Driver] - DtlDrvProtect (DtlDrvProtect) -> system32\drivers\DtlDrvProtect64.sys - AcceptPause: False - AcceptStop: FalseR0 - [Kernel Driver] - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys - AcceptPause: False - AcceptStop: TrueS0 - [Kernel Driver] - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys - AcceptPause: False - AcceptStop: FalseR0 - [Kernel Driver] - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - EUBAKUP (EUBAKUP) -> system32\drivers\eubakup.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - EUBKMON (EUBKMON) -> system32\drivers\EUBKMON.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - file_tracker (file_tracker) -> system32\DRIVERS\file_tracker.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - fltsrv (Acronis Storage Filter Management) -> system32\DRIVERS\fltsrv.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - HpSAMD () -> System32\drivers\HpSAMD.sys - AcceptPause: False - AcceptStop: TrueS0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: FalseR0 - [Kernel Driver] - iaStorAV (@iastorav.inf,%iaStorAV.DeviceDesc%;Intel(R) SATA RAID Controller Windows) -> System32\drivers\iaStorAV.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys - AcceptPause: False - AcceptStop: TrueS0 - [Kernel Driver] - ignis (ignis Service) -> system32\drivers\ignis.sys - AcceptPause: False - AcceptStop: FalseR0 - [Kernel Driver] - intelide () -> System32\drivers\intelide.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - iorate (@%SystemRoot%\system32\drivers\iorate.sys,-101) -> system32\drivers\iorate.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - isapnp () -> System32\drivers\isapnp.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - LSI_SAS () -> System32\drivers\lsi_sas.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - LSI_SSS () -> System32\drivers\lsi_sss.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - MBAMChameleon (MBAMChameleon) -> system32\drivers\MBAMChameleon.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - megasas () -> System32\drivers\megasas.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - megasas2i () -> System32\drivers\MegaSas2i.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - megasr () -> System32\drivers\megasr.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - msisadrv () -> System32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - mvumis () -> System32\drivers\mvumis.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - nvraid () -> System32\drivers\nvraid.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - nvstor () -> System32\drivers\nvstor.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - pci (@pci.inf,%pci_svcdesc%;PCI Bus Driver) -> System32\drivers\pci.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - pciide () -> System32\drivers\pciide.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - pcmcia () -> System32\drivers\pcmcia.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - percsas2i () -> System32\drivers\percsas2i.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - percsas3i () -> System32\drivers\percsas3i.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - PxHlpa64 (PxHlpa64) -> System32\Drivers\PxHlpa64.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - Sahdad64 (HDD Filter Driver) -> System32\Drivers\Sahdad64.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - Saibad64 (Volume Filter Driver) -> System32\Drivers\Saibad64.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - scmbus (@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver) -> System32\drivers\scmbus.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - SiSRaid2 () -> System32\drivers\SiSRaid2.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - SiSRaid4 () -> System32\drivers\sisraid4.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - SmartDefragDriver (SmartDefragDriver) -> System32\Drivers\SmartDefragDriver.sys - AcceptPause: False - AcceptStop: TrueS0 - [Kernel Driver] - snapman (Acronis Snapshots Manager) -> system32\DRIVERS\snapman.sys - AcceptPause: False - AcceptStop: FalseR0 - [Kernel Driver] - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - stexstor () -> System32\drivers\stexstor.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - storvsc () -> System32\drivers\storvsc.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - SysCow (SysCow) -> system32\drivers\syscowad64v.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\drivers\tcpip.sys,-10001) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - tib (Acronis TIB Manager) -> system32\DRIVERS\tib.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - volsnap (@%SystemRoot%\system32\drivers\volsnap.sys,-100) -> System32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - volume (@volume.inf,%VolumeServiceDesc%;Volume driver) -> System32\drivers\volume.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - vsmraid () -> System32\drivers\vsmraid.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys - AcceptPause: False - AcceptStop: TrueR0 - [Kernel Driver] - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys - AcceptPause: False - AcceptStop: TrueR0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> (?) - AcceptPause: False - AcceptStop: TrueS0 - [Kernel Driver] - amd_sata () -> System32\drivers\amd_sata.sys - AcceptPause: False - AcceptStop: FalseS0 - [Kernel Driver] - amd_xata () -> System32\drivers\amd_xata.sys - AcceptPause: False - AcceptStop: FalseR1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - BasicDisplay () -> \SystemRoot\System32\drivers\BasicDisplay.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - BasicRender () -> \SystemRoot\System32\drivers\BasicRender.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - BdfNdisf (@oem4.inf,%BdfNdisf_Desc%;BitDefender Firewall NDIS 6 Filter Driver) -> \SystemRoot\system32\DRIVERS\bdfndisf6.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - bdfwfpf (bdfwfpf) -> \??\C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.1.0\Drivers\bdfwfpf.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - cgnetfilter1521 (cgnetfilter1521) -> system32\drivers\cgnetfilter1521.sys - AcceptPause: False - AcceptStop: TrueR1 - [File System Driver] - cmderd (COMODO Internet Security Eradication Driver) -> System32\DRIVERS\cmderd.sys - AcceptPause: False - AcceptStop: TrueS1 - [File System Driver] - cmdGuard (COMODO Internet Security Sandbox Driver) -> system32\DRIVERS\cmdguard.sys - AcceptPause: False - AcceptStop: FalseR1 - [Kernel Driver] - cmdhlp (COMODO Internet Security Helper Driver) -> \SystemRoot\system32\DRIVERS\cmdhlp.sys - AcceptPause: False - AcceptStop: TrueS1 - [Kernel Driver] - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys - AcceptPause: False - AcceptStop: FalseR1 - [File System Driver] - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: TrueS1 - [Kernel Driver] - ElRawDisk (ElRawDisk) -> \??\C:\WINDOWS\system32\drivers\rsdrvx64.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - ESProtectionDriver (Malwarebytes Anti-Exploit) -> \??\C:\WINDOWS\system32\drivers\mbae64.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - EUDSKACS (EUDSKACS) -> \??\C:\WINDOWS\system32\drivers\eudskacs.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - EUFDDISK (EUFDDISK) -> \??\C:\WINDOWS\system32\drivers\EuFdDisk.sys - AcceptPause: False - AcceptStop: FalseS1 - [File System Driver] - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - GUBootStartup (GUBootStartup) -> \??\C:\WINDOWS\System32\drivers\GUBootStartup.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - GUSBootStartup (GUSBootStartup) -> \??\C:\WINDOWS\System32\drivers\GUSBootStartup.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - HWiNFO32 (HWiNFO32/64 Kernel Driver) -> \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS - AcceptPause: False - AcceptStop: FalseS1 - [File System Driver] - IMFMBRProtect (IMFMBRProtect) -> \??\C:\Program Files (x86)\IObit\IObit MBR Guard\drivers\win10_amd64\IMFMBRProtect.sys - AcceptPause: False - AcceptStop: FalseR1 - [Kernel Driver] - inspect (@oem25.inf,%inspect_Desc%;COMODO Internet Security Firewall Driver) -> \SystemRoot\system32\DRIVERS\inspect.sys - AcceptPause: False - AcceptStop: TrueS1 - [Kernel Driver] - isedrv (Internet Security Essentials) -> \SystemRoot\system32\drivers\isedrv.sys - AcceptPause: False - AcceptStop: FalseR1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys - AcceptPause: False - AcceptStop: TrueR1 - [File System Driver] - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - npcap (@oem12.inf,%NPF_Desc_Standard%;Npcap Packet Driver (NPCAP)) -> \SystemRoot\system32\DRIVERS\npcap.sys - AcceptPause: False - AcceptStop: TrueR1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: TrueS1 - [Kernel Driver] - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys - AcceptPause: False - AcceptStop: FalseR1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: TrueR1 - [Kernel Driver] - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys - AcceptPause: False - AcceptStop: TrueR1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: TrueS1 - [Kernel Driver] - SaibVdAd64 (Virtual Disk Driver) -> System32\Drivers\SaibVdAd64.sys - AcceptPause: False - AcceptStop: FalseR1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: TrueS1 - [Kernel Driver] - UimBus (@oem4.inf,%UIMDeviceDesc%;UIM Bus Controller) -> \SystemRoot\System32\drivers\uimbus.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - Uim_DEVIM (@oem5.inf,%UIMDeviceDesc%;UIM Direct Device Image Plugin) -> \SystemRoot\System32\drivers\uimdevim.sys - AcceptPause: False - AcceptStop: FalseR1 - [Kernel Driver] - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys - AcceptPause: False - AcceptStop: TrueS1 - [File System Driver] - xlkfs (xlkfs) -> system32\DRIVERS\xlkfs.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - ZAM (ZAM Helper Driver) -> \??\C:\WINDOWS\System32\drivers\zam64.sys - AcceptPause: False - AcceptStop: FalseS1 - [Kernel Driver] - ZAM_Guard (ZAM Guard Driver) -> \??\C:\WINDOWS\System32\drivers\zamguard64.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - CldFlt (Windows Cloud Files Filter Driver) -> system32\drivers\cldflt.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - clreg (@%SystemRoot%\system32\drivers\registry.sys,-100) -> \SystemRoot\System32\drivers\registry.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - Dokan (Dokan File System Driver) -> system32\DRIVERS\dokan.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys - AcceptPause: False - AcceptStop: FalseR2 - [File System Driver] - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys - AcceptPause: False - AcceptStop: TrueS2 - [Kernel Driver] - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - PfFilter (PfFilter) -> \??\C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - tib_mounter (Acronis TIB Mounter) -> \SystemRoot\system32\DRIVERS\tib_mounter.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - uxstyle (uxstyle) -> \??\C:\WINDOWS\system32\Drivers\elytsxu.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - virtual_file (Acronis Virtual File Driver) -> system32\DRIVERS\virtual_file.sys - AcceptPause: False - AcceptStop: FalseS2 - [File System Driver] - wcifs (@%systemroot%\system32\drivers\wcifs.sys,-100) -> \SystemRoot\system32\drivers\wcifs.sys - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - {41E8078B-96D9-42DC-8789-A1CF102CD880} (Power Control [2016/11/15 11:05:37]) -> \??\C:\Program Files (x86)\CyberLink\PowerDVD16\Common\NavFilter\000.fcl - AcceptPause: False - AcceptStop: FalseS2 - [Kernel Driver] - {A14A8EF6-B11D-4356-9ECC-4B937E6CC626} (Power Control [2017/04/29 11:35:52]) -> \??\C:\Program Files (x86)\CyberLink\PowerDVD17\Common\NavFilter\000.fcl - AcceptPause: False - AcceptStop: FalseR2 - [Kernel Driver] - cpwfpnd (cpwfpnd) -> \??\C:\WINDOWS\system32\Drivers\cpwfpnd64.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - 1394ohci (@1394.inf,%PCI\CC_0C0010.DeviceDesc%;1394 OHCI Compliant Host Controller) -> \SystemRoot\System32\drivers\1394ohci.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - AcpiDev (@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver) -> \SystemRoot\System32\drivers\AcpiDev.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - acpipagr (@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver) -> \SystemRoot\System32\drivers\acpipagr.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - AcpiPmi (@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver) -> \SystemRoot\System32\drivers\acpipmi.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - acpitime (@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver) -> \SystemRoot\System32\drivers\acpitime.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - AmdK8 (@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver) -> \SystemRoot\System32\drivers\amdk8.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - amdkmdag () -> \SystemRoot\system32\DRIVERS\atikmdag.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - amdkmdap () -> \SystemRoot\system32\DRIVERS\atikmpag.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - AmdPPM (@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver) -> \SystemRoot\System32\drivers\amdppm.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - AppID (@%systemroot%\system32\srpapi.dll,-100) -> system32\drivers\appid.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - applockerfltr (@%systemroot%\system32\srpapi.dll,-102) -> system32\drivers\applockerfltr.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - AsyncMac (@%systemroot%\system32\mprmsg.dll,-32000) -> \SystemRoot\System32\drivers\asyncmac.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - avc3 (avc3) -> system32\DRIVERS\avc3.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - avchv (@oem0.inf,%ServiceDesc%;avchv Function Driver) -> \SystemRoot\system32\DRIVERS\avchv.sys - AcceptPause: False - AcceptStop: TrueS3 - [File System Driver] - avckf (avckf) -> system32\DRIVERS\avckf.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - bcmfn2 (@bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service) -> \SystemRoot\System32\drivers\bcmfn2.sys - AcceptPause: False - AcceptStop: FalseR3 - [File System Driver] - bowser (@%systemroot%\system32\browser.dll,-102) -> system32\DRIVERS\bowser.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - BthAvrcpTg (@bthaudhid.inf,%BthAvrcpTg_SvcDesc%;Bluetooth Audio/Video Remote Control HID) -> \SystemRoot\System32\drivers\BthAvrcpTg.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - BthHFEnum (@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio and Call Control HID Enumerator) -> \SystemRoot\System32\drivers\bthhfenum.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - bthhfhid (@bthaudhid.inf,%BthAudioHFHid.SVCDESC%;Bluetooth Hands-Free Call Control HID) -> \SystemRoot\System32\drivers\BthHFHid.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - BTHMODEM (@mdmbtmdm.inf,%BthModem.DisplayName%;Bluetooth Modem Communications Driver) -> \SystemRoot\System32\drivers\bthmodem.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - buttonconverter (@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices) -> \SystemRoot\System32\drivers\buttonconverter.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - CAD (@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver) -> \SystemRoot\System32\drivers\CAD.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - CapImg (@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen) -> \SystemRoot\System32\drivers\capimg.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - cht4iscsi () -> System32\drivers\cht4sx64.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - cht4vbd (@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver) -> \SystemRoot\System32\drivers\cht4vx64.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - circlass (@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices) -> \SystemRoot\System32\drivers\circlass.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - clvad () -> \SystemRoot\system32\drivers\clvad.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - CLVirtualBus01 (@oem1.inf,%CLVirtualBus01.SVCDESC%;CyberLink Virtual CDROM Bus Enumerator) -> \SystemRoot\System32\drivers\CLVirtualBus01.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - clwvdVM (@oem13.inf,%clwvd.DeviceDesc% Service;Camera for VideoMeeting+/PresenterLink+ Service) -> \SystemRoot\system32\DRIVERS\clwvdVM.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - CmBatt (@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver) -> \SystemRoot\System32\drivers\CmBatt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - CompFilter64 (UVCCompositeFilter) -> \SystemRoot\System32\drivers\lvbflt64.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - CompositeBus (@compositebus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver) -> \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - condrv (Console Driver) -> System32\drivers\condrv.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - dmvsc () -> \SystemRoot\System32\drivers\dmvsc.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - drmkaud (@wdmaudio.inf,%drmkaud.SvcDesc%;Microsoft Trusted Audio Drivers) -> \SystemRoot\System32\drivers\drmkaud.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - dtlitescsibus (@oem14.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus) -> \SystemRoot\System32\drivers\dtlitescsibus.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - dtliteusbbus (@oem76.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus) -> \SystemRoot\System32\drivers\dtliteusbbus.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - dtproscsibus (@oem3.inf,%DTPROSCSIBUS.DeviceDesc%;DAEMON Tools Pro Virtual SCSI Bus) -> \SystemRoot\System32\drivers\dtproscsibus.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - DXGKrnl (LDDM Graphics Subsystem) -> \SystemRoot\System32\drivers\dxgkrnl.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - ErrDev (@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver) -> \SystemRoot\System32\drivers\errdev.sys - AcceptPause: False - AcceptStop: FalseR3 - [File System Driver] - exfat (exFAT File System Driver) -> (?) - AcceptPause: False - AcceptStop: TrueR3 - [File System Driver] - fastfat (FAT12/16/32 File System Driver) -> (?) - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - fdc (@fdc.inf,%fdc_ServiceDesc%;Floppy Disk Controller Driver) -> \SystemRoot\System32\drivers\fdc.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - Filetrace (@%SystemRoot%\system32\drivers\filetrace.sys,-10001) -> system32\drivers\filetrace.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - flpydisk (@flpydisk.inf,%floppy_ServiceDesc%;Floppy Disk Driver) -> \SystemRoot\System32\drivers\flpydisk.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - FsDepends (@%SystemRoot%\system32\drivers\fsdepends.sys,-10001) -> System32\drivers\FsDepends.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - gencounter (@wgencounter.inf,%GenCounter.SVCDESC%;Microsoft Hyper-V Generation Counter) -> \SystemRoot\System32\drivers\vmgencounter.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - genericusbfn (@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class) -> \SystemRoot\System32\drivers\genericusbfn.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - GeneStor (@oem36.inf,%GeneStor.SvcDesc%;Genesys Logic Storage Driver) -> \SystemRoot\system32\DRIVERS\GeneStor.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - GPIOClx0101 (Microsoft GPIO Class Extension Driver) -> System32\Drivers\msgpioclx.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - GridinSoftAntiRansomwareDriver (GridinSoft AntiRansomware) -> system32\DRIVERS\gsars.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - GridinSoftTrafficInspectDriver (GridinSoftTrafficInspectDriver) -> \SystemRoot\system32\DRIVERS\gsinspect.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - GUMHFilters (GUMHFilters) -> \??\C:\Program Files (x86)\Glarysoft\Malware Hunter\Native\winxp_x64\GUMHFilter.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - HdAudAddService (@hdaudio.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Microsoft 1.1 UAA Function Driver for High Definition Audio Service) -> \SystemRoot\System32\drivers\HdAudio.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - HDAudBus (@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio) -> \SystemRoot\System32\drivers\HDAudBus.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - HidBatt (@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver) -> \SystemRoot\System32\drivers\HidBatt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - HidBth (@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport) -> \SystemRoot\System32\drivers\hidbth.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - hidi2c (@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver) -> \SystemRoot\System32\drivers\hidi2c.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - hidinterrupt (@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts) -> \SystemRoot\System32\drivers\hidinterrupt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - HidIr (@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver) -> \SystemRoot\System32\drivers\hidir.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - HidUsb (@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver) -> \SystemRoot\System32\drivers\hidusb.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - HTTP (@%SystemRoot%\system32\drivers\http.sys,-1) -> system32\drivers\HTTP.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - hvservice (@%SystemRoot%\system32\drivers\hvservice.sys,-16) -> system32\drivers\hvservice.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - hyperkbd () -> \SystemRoot\System32\drivers\hyperkbd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - i8042prt (@msmouse.inf,%i8042prt.SvcDesc%;PS/2 Keyboard and Mouse Port Driver) -> \SystemRoot\System32\drivers\i8042prt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iagpio (@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver) -> \SystemRoot\System32\drivers\iagpio.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iai2c (@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller) -> \SystemRoot\System32\drivers\iai2c.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iaLPSS2i_GPIO2 (@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iaLPSS2i_GPIO2_BXT_P (@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iaLPSS2i_I2C (@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_I2C.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iaLPSS2i_I2C_BXT_P (@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2) -> \SystemRoot\System32\drivers\iaLPSS2i_I2C_BXT_P.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iaLPSSi_GPIO (@ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Controller Driver) -> \SystemRoot\System32\drivers\iaLPSSi_GPIO.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iaLPSSi_I2C (@ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel(R) Serial IO I2C Controller Driver) -> \SystemRoot\System32\drivers\iaLPSSi_I2C.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - ibbus (@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver)) -> \SystemRoot\System32\drivers\ibbus.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IndirectKmd (@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100) -> \SystemRoot\System32\drivers\IndirectKmd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IntcAzAudAddService (Service for Realtek HD Audio (WDM)) -> \SystemRoot\system32\drivers\RTKVHD64.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - intelppm (@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver) -> \SystemRoot\System32\drivers\intelppm.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IpFilterDriver (@%systemroot%\system32\mprmsg.dll,-32013) -> system32\DRIVERS\ipfltdrv.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IPMIDRV () -> \SystemRoot\System32\drivers\IPMIDrv.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IPNAT (IP Network Address Translator) -> System32\drivers\ipnat.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - irda (IrDA) -> \SystemRoot\system32\drivers\irda.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IRENUM (@%SystemRoot%\system32\drivers\irenum.sys,-100) -> system32\drivers\irenum.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - iScsiPrt (@iscsi.inf,%iScsiPortName%;iScsiPort Driver) -> \SystemRoot\System32\drivers\msiscsi.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - IUFileFilter (IUFileFilter) -> \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - IURegProcessFilter (IURegProcessFilter) -> \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegProcessFilter.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - kbdclass (@keyboard.inf,%kbdclass.SvcDesc%;Keyboard Class Driver) -> \SystemRoot\System32\drivers\kbdclass.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - kbdhid (@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver) -> \SystemRoot\System32\drivers\kbdhid.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - kdnic (@kdnic.inf,%KdNic.Service.DispName%;Microsoft Kernel Debug Network Miniport (NDIS 6.20)) -> \SystemRoot\System32\drivers\kdnic.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - keycrypt (keycrypt) -> system32\DRIVERS\KeyCrypt64.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - kmloop (@netloop.inf,%kmloop.Service.DispName%;Microsoft KM-TEST Loopback Adapter Driver) -> \SystemRoot\System32\drivers\loop.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - ksthunk (Kernel Streaming Thunks) -> \SystemRoot\system32\drivers\ksthunk.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - L1C (@oem28.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller) -> \SystemRoot\System32\drivers\L1C63x64.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - lvrs64 (@oem22.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver) -> \SystemRoot\system32\DRIVERS\lvrs64.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - LVUVC64 (@oem20.inf,%PID_081B_DD%(UVC);Logitech HD Webcam C310(UVC)) -> \SystemRoot\system32\DRIVERS\lvuvc64.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - mausbhost (@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver) -> \SystemRoot\System32\drivers\mausbhost.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - mausbip (@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver) -> \SystemRoot\System32\drivers\mausbip.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - MBAMProtection () -> \??\C:\WINDOWS\system32\drivers\mbam.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - MBAMProtector () -> \??\C:\WINDOWS\system32\drivers\mbam.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - MBAMSwissArmy (MBAMSwissArmy) -> \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - MBAMWebAccessControl () -> \??\C:\WINDOWS\system32\drivers\mwac.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - MBAMWebProtection () -> \??\C:\WINDOWS\system32\drivers\mwac.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MDA_NTDRV (MDA_NTDRV) -> \??\C:\WINDOWS\system32\MDA_NTDRV.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - mlx4_bus (@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator) -> \SystemRoot\System32\drivers\mlx4_bus.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MMPDrv (MMPDrv) -> \??\C:\WINDOWS\System32\drivers\MMPDrv.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Modem () -> system32\drivers\modem.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - monitor (@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service) -> \SystemRoot\System32\drivers\monitor.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - mouclass (@msmouse.inf,%mouclass.SvcDesc%;Mouse Class Driver) -> \SystemRoot\System32\drivers\mouclass.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - mouhid (@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver) -> \SystemRoot\System32\drivers\mouhid.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - mpsdrv (@%SystemRoot%\system32\drivers\mpsdrv.sys,-23092) -> System32\drivers\mpsdrv.sys - AcceptPause: False - AcceptStop: TrueS3 - [File System Driver] - MRxDAV (@%systemroot%\system32\webclnt.dll,-104) -> \SystemRoot\system32\drivers\mrxdav.sys - AcceptPause: False - AcceptStop: FalseR3 - [File System Driver] - mrxsmb (@%systemroot%\system32\wkssvc.dll,-1002) -> system32\DRIVERS\mrxsmb.sys - AcceptPause: False - AcceptStop: TrueR3 - [File System Driver] - mrxsmb20 (@%systemroot%\system32\wkssvc.dll,-1006) -> system32\DRIVERS\mrxsmb20.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - MsBridge (@%SystemRoot%\system32\bridgeres.dll,-1) -> System32\drivers\bridge.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - msgpiowin32 (@msgpiowin32.inf,%GPIO.SvcDesc%;Common Driver for Buttons, DockMode and Laptop/Slate Indicator) -> \SystemRoot\System32\drivers\msgpiowin32.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - mshidkmdf (@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100) -> \SystemRoot\System32\drivers\mshidkmdf.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - mshidumdf (@%SystemRoot%\system32\drivers\mshidumdf.sys,-100) -> \SystemRoot\System32\drivers\mshidumdf.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MSKSSRV (@ksfilter.inf,%MSKSSRV.DeviceDesc%;Proxy de service de répartition Microsoft) -> \SystemRoot\system32\DRIVERS\MSKSSRV.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MSPCLOCK (@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Proxy d’horloge de répartition Microsoft) -> \SystemRoot\system32\DRIVERS\MSPCLOCK.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MSPQM (@ksfilter.inf,%MSPQM.DeviceDesc%;Proxy de gestion de qualité de répartition Microsoft) -> \SystemRoot\system32\DRIVERS\MSPQM.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MsRPC () -> (?) - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MSTEE (@ksfilter.inf,%MSTEE.DeviceDesc%;Convertisseur en T/site-à-site de répartition Microsoft) -> \SystemRoot\system32\DRIVERS\MSTEE.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - MTConfig (@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver) -> \SystemRoot\System32\drivers\MTConfig.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - NativeWifiP (@%SystemRoot%\System32\drivers\nwifi.sys,-101) -> system32\DRIVERS\nwifi.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - ndfltr (@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service) -> \SystemRoot\System32\drivers\ndfltr.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - NdisCap (@%SystemRoot%\System32\drivers\ndiscap.sys,-5000) -> System32\drivers\ndiscap.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - NdisImPlatform (@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501) -> System32\drivers\NdisImPlatform.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - NdisTapi (@%systemroot%\system32\mprmsg.dll,-32001) -> System32\DRIVERS\ndistapi.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - Ndisuio (NDIS Usermode I/O Protocol) -> system32\drivers\ndisuio.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - NdisVirtualBus (@%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200) -> \SystemRoot\System32\drivers\NdisVirtualBus.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - NdisWan (@%systemroot%\system32\mprmsg.dll,-32002) -> \SystemRoot\System32\drivers\ndiswan.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - ndiswanlegacy (@%systemroot%\system32\mprmsg.dll,-32014) -> System32\DRIVERS\ndiswan.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - ndproxy (@%SystemRoot%\system32\drivers\todo.sys,-101;NDIS Proxy) -> System32\DRIVERS\NDProxy.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - NetAdapterCx (Network Adapter Wdf Class Extension Library) -> system32\drivers\NetAdapterCx.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - netvsc () -> \SystemRoot\System32\drivers\netvsc.sys - AcceptPause: False - AcceptStop: FalseR3 - [File System Driver] - NTFS () -> (?) - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - nvdimmn (@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver) -> \SystemRoot\System32\drivers\nvdimmn.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Parport (@msports.inf,%Parport.SVCDESC%;Parallel port driver) -> \SystemRoot\System32\drivers\parport.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - pmem (@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver) -> \SystemRoot\System32\drivers\pmem.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - PptpMiniport (@%systemroot%\system32\mprmsg.dll,-32006) -> \SystemRoot\System32\drivers\raspptp.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Processor (@cpu.inf,%Processor.SvcDesc%;Processor Driver) -> \SystemRoot\System32\drivers\processr.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - QWAVEdrv (@%SystemRoot%\system32\drivers\qwavedrv.sys,-1) -> \SystemRoot\system32\drivers\qwavedrv.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - RasAcd (Remote Access Auto Connection Driver) -> System32\DRIVERS\rasacd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - RasAgileVpn (@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2)) -> \SystemRoot\System32\drivers\AgileVpn.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Rasl2tp (@%systemroot%\system32\mprmsg.dll,-32005) -> \SystemRoot\System32\drivers\rasl2tp.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - RasPppoe (@%systemroot%\system32\mprmsg.dll,-32007) -> System32\DRIVERS\raspppoe.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - RasSstp (@%systemroot%\system32\sstpsvc.dll,-202) -> \SystemRoot\System32\drivers\rassstp.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - rdpbus (@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver) -> \SystemRoot\System32\drivers\rdpbus.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - RDPDR (@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100) -> System32\drivers\rdpdr.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - RdpVideoMiniport (Remote Desktop Video Miniport Driver) -> System32\drivers\rdpvideominiport.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - ReFS () -> (?) - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - ReFSv1 () -> (?) - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - RTSUER (@oem31.inf,%RtsUER%;Realtek USB Card Reader - UER) -> \SystemRoot\system32\Drivers\RtsUer.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - s3cap () -> \SystemRoot\System32\drivers\vms3cap.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - scfilter (@%SystemRoot%\System32\drivers\scfilter.sys,-11) -> System32\DRIVERS\scfilter.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - sdbus () -> \SystemRoot\System32\drivers\sdbus.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - SDFRd (@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector) -> \SystemRoot\System32\drivers\SDFRd.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - sdstor (@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver) -> \SystemRoot\System32\drivers\sdstor.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - SensorsSimulatorDriver (@oem19.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver) -> \SystemRoot\System32\drivers\WUDFRd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - SerCx (Serial UART Support Library) -> system32\drivers\SerCx.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - SerCx2 (Serial UART Support Library) -> system32\drivers\SerCx2.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Serenum (@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver) -> \SystemRoot\System32\drivers\serenum.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Serial (@msports.inf,%Serial.SVCDESC%;Serial port driver) -> \SystemRoot\System32\drivers\serial.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - sermouse (@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver) -> \SystemRoot\System32\drivers\sermouse.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - sfloppy (@flpydisk.inf,%sfloppy_devdesc%;High-Capacity Floppy Disk Drive) -> \SystemRoot\System32\drivers\sfloppy.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - SpatialGraphFilter (Holographic Spatial Graph Filter) -> System32\drivers\SpatialGraphFilter.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - SpbCx (Simple Peripheral Bus Support Library) -> system32\drivers\SpbCx.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - srv2 (@%systemroot%\system32\srvsvc.dll,-104) -> System32\DRIVERS\srv2.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - srvnet () -> System32\DRIVERS\srvnet.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - swenum (@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver) -> \SystemRoot\System32\drivers\swenum.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - Synth3dVsc () -> \SystemRoot\System32\drivers\Synth3dVsc.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - tap0901 (@oem9.inf,%DeviceDescription%;TAP-Windows Adapter V9) -> \SystemRoot\System32\drivers\tap0901.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Tcpip6 (@todo.dll,-100;Microsoft IPv6 Protocol Driver) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - teamviewervpn (@oem33.inf,%DeviceDescription%;TeamViewer VPN Adapter) -> \SystemRoot\System32\drivers\teamviewervpn.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - terminpt (@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver) -> \SystemRoot\System32\drivers\terminpt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - tnd (Acronis Try&Decide filter) -> \SystemRoot\system32\DRIVERS\tnd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - TPM (@tpm.inf,%TPM%;TPM) -> \SystemRoot\System32\drivers\tpm.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - TsUsbFlt (@%SystemRoot%\system32\drivers\tsusbflt.sys,-1000) -> system32\drivers\tsusbflt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - TsUsbGD (@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device) -> \SystemRoot\System32\drivers\TsUsbGD.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - UASPStor (@uaspstor.inf,%UASPortName%;USB Attached SCSI (UAS) Driver) -> \SystemRoot\System32\drivers\uaspstor.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - UcmCx0101 (USB Connector Manager KMDF Class Extension) -> System32\Drivers\UcmCx.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - UcmTcpciCx0101 (UCM-TCPCI KMDF Class Extension) -> System32\Drivers\UcmTcpciCx.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - UcmUcsi (@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client) -> \SystemRoot\System32\drivers\UcmUcsi.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - Ucx01000 (USB Host Support Library) -> system32\drivers\ucx01000.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - UdeCx (USB Device Emulation Support Library) -> system32\drivers\udecx.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - UEFI (@uefi.inf,%UEFI.SvcDesc%;Microsoft UEFI Driver) -> \SystemRoot\System32\drivers\UEFI.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - Ufx01000 (USB Function Class Extension) -> system32\drivers\ufx01000.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - UfxChipidea (@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller) -> \SystemRoot\System32\drivers\UfxChipidea.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - ufxsynopsys (@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller) -> \SystemRoot\System32\drivers\ufxsynopsys.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - umbus (@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver) -> \SystemRoot\System32\drivers\umbus.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - UmPass (@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver) -> \SystemRoot\System32\drivers\umpass.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - UrsChipidea (@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver) -> \SystemRoot\System32\drivers\urschipidea.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - UrsCx01000 (USB Role-Switch Support Library) -> system32\drivers\urscx01000.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - UrsSynopsys (@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver) -> \SystemRoot\System32\drivers\urssynopsys.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - usbaudio (@wdma_usb.inf,%USBAudio.SvcDesc%;Pilote USB audio (WDM)) -> \SystemRoot\system32\drivers\usbaudio.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - usbccgp (@usb.inf,%GenericParent.SvcDesc%;Pilote parent générique USB Microsoft) -> \SystemRoot\System32\drivers\usbccgp.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - usbcir (@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR)) -> \SystemRoot\System32\drivers\usbcir.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - usbehci (@usbport.inf,%EHCIMP.SvcDesc%;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbehci.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - usbhub (@usbport.inf,%ROOTHUB.SvcDesc%;Microsoft USB Standard Hub Driver) -> \SystemRoot\System32\drivers\usbhub.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - USBHUB3 (@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub) -> \SystemRoot\System32\drivers\UsbHub3.sys - AcceptPause: False - AcceptStop: TrueR3 - [Kernel Driver] - usbohci (@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbohci.sys - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - usbprint (@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class) -> \SystemRoot\System32\drivers\usbprint.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - usbscan (@sti.inf,%usbscan.SvcDesc%;Pilote de scanneur USB) -> \SystemRoot\system32\DRIVERS\usbscan.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - usbser (@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver) -> \SystemRoot\System32\drivers\usbser.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - USBSTOR (@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver) -> \SystemRoot\System32\drivers\USBSTOR.SYS - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - usbuhci (@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver) -> \SystemRoot\System32\drivers\usbuhci.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - USBXHCI (@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller) -> \SystemRoot\System32\drivers\USBXHCI.SYS - AcceptPause: False - AcceptStop: TrueS3 - [Kernel Driver] - VerifierExt (@%SystemRoot%\system32\drivers\VerifierExt.sys,-1000) -> system32\drivers\VerifierExt.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - vhdmp () -> \SystemRoot\System32\drivers\vhdmp.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - vhf (@%SystemRoot%\system32\drivers\vhf.sys,-100) -> \SystemRoot\System32\drivers\vhf.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - VMBusHID () -> \SystemRoot\System32\drivers\VMBusHID.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - vmgid (@wvmgid.inf,%VmGid.SVCDESC%;Microsoft Hyper-V Guest Infrastructure Driver) -> \SystemRoot\System32\drivers\vmgid.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - vpci (@wvpci.inf,%vpci.SVCDESC%;Microsoft Hyper-V Virtual PCI Bus) -> \SystemRoot\System32\drivers\vpci.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - vwifibus (@%SystemRoot%\System32\drivers\vwifibus.sys,-257) -> \SystemRoot\System32\drivers\vwifibus.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WacomPen (@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver) -> \SystemRoot\System32\drivers\wacompen.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - wanarp (@%systemroot%\system32\mprmsg.dll,-32011) -> System32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - wanarpv6 (@%systemroot%\system32\mprmsg.dll,-32012) -> System32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - wcnfs (@%systemroot%\system32\drivers\wcnfs.sys,-100) -> \SystemRoot\system32\drivers\wcnfs.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WdBoot (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390) -> \SystemRoot\system32\drivers\WdBoot.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WDC_SAM (@oem21.inf,%WDC_SAM_ServiceName%;WD SCSI Pass Thru driver) -> \SystemRoot\System32\drivers\wdcsam64.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - WdFilter (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330) -> \SystemRoot\system32\drivers\WdFilter.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - wdiwifi (WDI Driver Framework) -> system32\DRIVERS\wdiwifi.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WdNisDrv (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-370) -> system32\Drivers\WdNisDrv.sys - AcceptPause: False - AcceptStop: FalseS3 - [File System Driver] - WIMMount (@%SystemRoot%\system32\drivers\wimmount.sys,-101) -> system32\drivers\wimmount.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WinMad (@mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service) -> \SystemRoot\System32\drivers\winmad.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WinNat (@%SystemRoot%\system32\drivers\winnat.sys,-10001) -> system32\drivers\winnat.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WINUSB (@winusb.inf,%WINUSB_SvcDesc%;WinUsb Driver) -> \SystemRoot\System32\drivers\WinUSB.SYS - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WinVerbs (@mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service) -> \SystemRoot\System32\drivers\winverbs.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WmiAcpi (@wmiacpi.inf,%WMIMAP.SvcDesc%;Microsoft Windows Management Interface for ACPI) -> \SystemRoot\System32\drivers\wmiacpi.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WpdUpFltr (@%systemroot%\System32\drivers\WpdUpFltr.sys,-100) -> System32\drivers\WpdUpFltr.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WSDPrintDevice (@wsdprint.inf,%WSDPrintDevice.SVCDESC%;WSD Print Support) -> \SystemRoot\System32\drivers\WSDPrint.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WSDScan (@sti.inf,%WSDScan.SvcDesc%;Prise en charge de la numérisation WSD) -> \SystemRoot\system32\DRIVERS\WSDScan.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WudfPf (@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000) -> system32\drivers\WudfPf.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WUDFRd (@%SystemRoot%\system32\drivers\WudfRd.sys,-1000) -> \SystemRoot\System32\drivers\WUDFRd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - WUDFWpdFs () -> \SystemRoot\system32\DRIVERS\WUDFRd.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - xboxgip (@xboxgip.inf,%XBOXGIP_Desc%;Xbox Game Input Protocol Driver) -> \SystemRoot\System32\drivers\xboxgip.sys - AcceptPause: False - AcceptStop: FalseS3 - [Kernel Driver] - xinputhid (@xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver) -> \SystemRoot\System32\drivers\xinputhid.sys - AcceptPause: False - AcceptStop: FalseR3 - [Kernel Driver] - tapwindscribe0901 (@oem32.inf,%DeviceDescription%;Windscribe VPN) -> \SystemRoot\System32\drivers\tapwindscribe0901.sys - AcceptPause: False - AcceptStop: TrueS3 - [File System Driver] - Revoflt (Revoflt) -> system32\DRIVERS\revoflt.sys - AcceptPause: False - AcceptStop: FalseR4 - [File System Driver] - cdfs (CD/DVD File System Reader) -> system32\DRIVERS\cdfs.sys - AcceptPause: False - AcceptStop: TrueS4 - [Kernel Driver] - cnghwassist (@%SystemRoot%\system32\drivers\cnghwassist.sys,-100) -> System32\DRIVERS\cnghwassist.sys - AcceptPause: False - AcceptStop: FalseS4 - [File System Driver] - udfs (udfs) -> system32\DRIVERS\udfs.sys - AcceptPause: False - AcceptStop: FalseS4 - [Kernel Driver] - ws2ifsl (@%systemroot%\System32\drivers\ws2ifsl.sys,-1000) -> \SystemRoot\system32\drivers\ws2ifsl.sys - AcceptPause: False - AcceptStop: False ---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted) [MD5.EF558A02D734A1403583E95CCEEC2487] - [27/04/2017 15:06:30] - (.Copyright (c)1999-2015 Martin Malík - REALiX - HWiNFO AMD64 Kernel Driver.) - [26.91 Ko] - (8.98.0.0) - C:\WINDOWS\Syswow64\Drivers\HWiNFO64A.SYS ---------- | Uninstall [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\2c4529525b7e166a] : (Windows 10 IoT Core Dashboard.-.Windows 10 IoT Core) -> rundll32.exe dfshim.dll,ShArpMaintain Windows10IoTCoreDashboard.application, Culture=neutral, PublicKeyToken=c3bce3770c238a49, processorArchitecture=msil[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\a6e43da6e76c5494] : (NetSpot.-.Etwok LLC) -> rundll32.exe dfshim.dll,ShArpMaintain NetSpot.application, Culture=neutral, PublicKeyToken=4bf38b5aa6c013ee, processorArchitecture=msil[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Amazon Amazon Music] : (Amazon Music.-.Amazon Services LLC) -> C:\Users\Jean-Marie\AppData\Local\Amazon Music\Uninstall.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CEB9F3E9BD4E4FF1ACEB2370E55A36AC1] : (.-.) -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DownloadFileOpener] : (DownloadFileOpener.-.DownloadFileOpener.com) -> C:\Users\Jean-Marie\AppData\Local\DownloadFileOpener\uninstall.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\fdd5afeb1c26219962a43ddc726e1dbe] : (.-.) -> [HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Grabilla] : (Grabilla.-.Grabilla.com) -> C:\Users\Jean-Marie\AppData\Local\Grabilla\uninst.exe[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Pale Moon 27.3.0 (x64 en-US)] : (Pale Moon 27.3.0 (x64 en-US).-.Moonchild Productions) -> "C:\Program Files\Pale Moon\uninstall\helper.exe"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SharewareOnSale Notifier] : (SharewareOnSale Notifier.-.SharewareOnSale) -> "C:\ProgramData\SharewareOnSale Notifier\SharewareOnSale Notifier.exe" /u[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WallpaperAnime] : (WallpaperAnime.-.WallpaperAnime) -> "C:\Users\Jean-Marie\AppData\Local\WallpaperAnime\uninstall.exe" /S[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{20573C69-4A68-4BEF-A23D-365CB66924CE}] : (Avanquest Message.-.Avanquest Software) -> "C:\Users\Jean-Marie\AppData\Roaming\Avanquest Software\SetupAQ\{20573C69-4A68-4BEF-A23D-365CB66924CE}\Setup.exe" /UNINST[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1] : (Apowersoft Online Launcher version 1.4.5.-.APOWERSOFT LIMITED) -> "C:\Users\Jean-Marie\AppData\Local\Apowersoft\Apowersoft Online Launcher\unins000.exe"[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E6ADCBB4-97D5-4891-9955-026A20E2A3A7}] : (get2Clouds(R) Transfer Manager.-.NOS Microsystems Ltd.) -> "C:\Users\Jean-Marie\AppData\Roaming\get2Clouds\bin\get2Clouds.exe" /Get1[HKU\S-1-5-21-1766228302-1366166313-1596766668-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{EF0B188B-6C1F-4573-8979-DAB1C66266CD}] : (eXpert PDF démo.-.Avanquest) -> C:\Users\Jean-Marie\AppData\Roaming\Avanquest Software\SetupAQ\{EF0B188B-6C1F-4573-8979-DAB1C66266CD}\SetupAQ.exe /UNINST[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\8B3D7924-ED89-486B-8322-E8594065D5CB_is1] : (RogueKiller version 12.-.Adlice Software) -> "C:\Program Files\RogueKiller\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\94A5CE8ED7633ED77531B6CB14CEB1927C5CAE1F] : (Package de pilotes Windows - TAP-Windows Provider V9 (tap0901) Net (04/21/2016 9.00.00.21).-.TAP-Windows Provider V9) -> C:\PROGRA~1\DIFX\B4C372DECF8ED599\DPInst64.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\oemvista.inf_amd64_a572b7f20c402d28\oemvista.inf[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\BEC55C5D-D6D0-4A41-B82C-264EC5EE8052_is1] : (RogueKillerPE version 1.32.0.0.-.Adlice Software) -> "C:\Program Files\RogueKillerPE\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Bitdefender Home Scanner] : (Bitdefender Home Scanner.-.Bitdefender) -> "C:\Program Files\Bitdefender Home Scanner\installer\installer.exe" /uninstall[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\C4E7EE54-826F-41C4-BE3C-375CC70DC1D8_is1] : (UCheck version 2.0.0.0.-.Adlice Software) -> "C:\Program Files\UCheck\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CCleaner] : (CCleaner.-.Piriform) -> "C:\Program Files\CCleaner\uninst.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CEB9F3E9BD4E4FF1ACEB2370E55A36AC0] : (.-.) -> [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\COMODO Internet Security] : (COMODO Internet Security Pro.-.COMODO Security Solutions Inc.) -> "C:\Program Files\COMODO\COMODO Internet Security\cmdinstall.exe" -type local -uninstall -theme lycia -log##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CyberGhost 6_is1] : (CyberGhost 6.-.CyberGhost S.R.L.) -> "C:\Program Files\CyberGhost 6\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DAEMON Tools Lite] : (DAEMON Tools Lite.-.Disc Soft Ltd) -> C:\Program Files\DAEMON Tools Lite\uninst.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DAEMON Tools Pro] : (DAEMON Tools Pro.-.Disc Soft Ltd) -> C:\Program Files\DAEMON Tools Pro\uninst.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Defraggler] : (Defraggler.-.Piriform) -> "C:\Program Files\Defraggler\uninst.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DivX Setup] : (Configuration DivX.-.DivX, LLC) -> C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DriverEasy_is1] : (Driver Easy 5.5.2.-.Easeware) -> "C:\Program Files\Easeware\DriverEasy\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\EPSON XP-710 Series] : (EPSON XP-710 Series Printer Uninstall.-.SEIKO EPSON Corporation) -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IINSLPE.EXE /R /APD /P:"EPSON XP-710 Series"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\FileMenu Tools_is1] : (FileMenu Tools.-.LopeSoft) -> "C:\Program Files\LopeSoft\FileMenu Tools\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Greenshot_is1] : (Greenshot 1.2.9.129.-.Greenshot) -> "C:\Program Files\Greenshot\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MacriumReflect] : (Macrium Reflect Free Edition.-.Paramount Software (UK) Ltd.) -> C:\Program Files\Macrium\Reflect\xReflect.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MozillaMaintenanceService] : (Mozilla Maintenance Service.-.Mozilla) -> "C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MultiCommander x64] : (MultiCommander (x64).-.Mathias Svensson) -> C:\Program Files\MultiCommander (x64)\Uninstall MultiCommander.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Notepad++] : (Notepad++ (64-bit x64).-.Notepad++ Team) -> C:\Program Files\Notepad++\uninstall.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Pale Moon 26.5.0 (x64 en-US)] : (Pale Moon 26.5.0 (x64 en-US).-.Moonchild Productions) -> "C:\Program Files\Pale Moon\uninstall\helper.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\PerigeeCopy] : (PerigeeCopy 1.7.-.Jeremy Stanley) -> C:\Program Files\PerigeeCopy\uninst.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\proDAD-Adorage-3.0] : (proDAD Adorage 3.0 (64bit).-.proDAD GmbH) -> "C:\Program Files\proDAD\Adorage-3.0\uninstall.exe" uninstall spcp PATHVERSION "3.0" MAINNAME "Adorage"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\proDAD-Vitascene-2.0] : (proDAD Vitascene 2.0 (64bit).-.proDAD GmbH) -> "C:\Program Files\proDAD\Vitascene-2.0\uninstall.exe" uninstall spcp PATHVERSION "2.0" MAINNAME "Vitascene"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\QEMU] : (QEMU.-.) -> "C:\Program Files\qemu\qemu-uninstall.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Recuva] : (Recuva.-.Piriform) -> "C:\Program Files\Recuva\uninst.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Seed4.Me VPN] : (Seed4.Me VPN 1.0.9.-.Seed4.me) -> C:\Program Files\Seed4.Me VPN\Uninstall.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Simple Driver Updater] : (Simple Driver Updater.-.Corel Corporation) -> C:\Program Files\Simple Driver Updater\Uninstall.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Simple Registry Cleaner] : (Simple Registry Cleaner.-.Corel Corporation) -> C:\Program Files\Simple Registry Cleaner\Uninstall.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Speccy] : (Speccy.-.Piriform) -> "C:\Program Files\Speccy\uninst.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\TAP-Windows] : (TAP-Windows 9.21.2.-.) -> C:\Program Files\TAP-Windows\Uninstall.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\TeraCopy_is1] : (TeraCopy version 3.0.8.-.Code Sector) -> "C:\Program Files\TeraCopy\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\TreeSize_is1] : (TreeSize V6.3.6 (64 bit).-.JAM Software) -> "C:\Program Files\JAM Software\TreeSize\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Unlocker] : (Unlocker 1.9.2.-.Cedrick Collomb) -> C:\Program Files\Unlocker\uninst.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\UpdateStar Product Key Finder_is1] : (UpdateStar Product Key Finder.-.UpdateStar) -> "C:\Program Files\UpdateStar\Product Key Finder\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WhoCrashed_is1] : (WhoCrashed 5.54.-.Resplendence Software Projects Sp.) -> "C:\Program Files\WhoCrashed\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WinRAR archiver] : (WinRAR 5.40 (64-bit).-.win.rar GmbH) -> C:\Program Files\WinRAR\uninstall.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WinToHDD_is1] : (WinToHDD version 2.3 Beta.-.The EasyUEFI Development Team.) -> "C:\Program Files\WinToHDD\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Wise Hotkey_is1] : (Wise Hotkey 1.18.-.WiseCleaner.com, Inc.) -> "C:\Program Files\Wise\Wise Hotkey\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Wondershare Filmora_is1] : (Wondershare Filmora(Build 8.2.2).-.Wondershare Software) -> "C:\Program Files\Wondershare\Filmora\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\xplorer2p64_u] : (xplorer² Ultimate 64 bit.-.Zabkat) -> "C:\Program Files\zabkat\xplorer2_ult\Uninstall.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Zoolz2] : (.-.) -> [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}] : (PDFCreator.-.pdfforge GmbH) -> C:\Program Files\PDFCreator\unins000.exe[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{04B83666-3A62-452B-85D3-70F8117F2329}_is1] : (CamStudio 2.7.4.-.CamStudio Open Source) -> "C:\Program Files\CamStudio 2.7\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{0517F875-BBB2-4812-A63E-733B33CEF215}] : (Roxio System Rollback.-.Roxio) -> MsiExec.exe /I{0517F875-BBB2-4812-A63E-733B33CEF215}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}] : (ccc-utility64.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{06D33B93-9458-4E28-BDEA-F5ECB2C3C30E}] : (AntimalwareEngine.-.adaware) -> MsiExec.exe /I{06D33B93-9458-4E28-BDEA-F5ECB2C3C30E}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{17520B79-9D56-4107-891F-5207F2B5B4D8}_is1] : (Remo Convert OST to PST.-.Remo Software) -> "C:\Program Files\Remo Convert OST to PST\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{22C37D82-6137-40BF-8625-7A846ED65F3A}_is1] : (FolderIco 5.1.-.teorex) -> "C:\Program Files\FolderIco\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{26F31E12-3722-45FD-903B-49012286BB4C}] : (OnlineThreatsEngine.-.adaware) -> MsiExec.exe /I{26F31E12-3722-45FD-903B-49012286BB4C}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{28A17CCB-77BB-49C9-847B-60E076DC43D1}] : (UxStyle.-.The Within Network, LLC) -> MsiExec.exe /I{28A17CCB-77BB-49C9-847B-60E076DC43D1}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{299EB32D-0525-4482-A8B5-1F30725AB6F1}_is1] : (PhotoStitcher 2.0.-.Teorex) -> "C:\Program Files\PhotoStitcher\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2B75557A-B66B-4C26-8AFD-F1B752C1D4CB}] : (Fast HTML Checker.-.WebTweakTools.com) -> MsiExec.exe /I{2B75557A-B66B-4C26-8AFD-F1B752C1D4CB}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1] : (Malwarebytes version 3.1.2.1733.-.Malwarebytes) -> "C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{36036827-FA38-4A74-8333-26BC4EEC9308}_AdAwareUpdater] : (.-.) -> [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{37E567C7-EB03-4349-B068-1FD0A2CD55FE}_is1] : (Eassos System Restore 2.0.2.-.Eassos Co., Ltd.) -> "C:\Program Files\Eassos System Restore\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3BAE1213-33F0-4482-A6F5-7360F9CD73E1}_is1] : (Encrypt4all Professional Edition version 6.0.0.183.-.Encrypt4all Software) -> "C:\Program Files\Encrypt4all Software\Encrypt4all Professional\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3BF6B4CF-E6A1-45B3-9BC5-67213D146CB6}_is1] : (Remo Recover for Android.-.Remo Software) -> "C:\Program Files\Remo Recover for Android 2.0\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3E494002-985C-4908-B72C-5B4DD15BE090}_is1] : (Start Menu X version 6.02.-.OrdinarySoft) -> "C:\Program Files\Start Menu X\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3E5BEF30-3962-4B47-AECA-937B6CBB0A68}] : (AvcEngine.-.adaware) -> MsiExec.exe /I{3E5BEF30-3962-4B47-AECA-937B6CBB0A68}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{56EECD69-F428-41C4-ADF6-6CDEE14DDF3F}] : (Paragon UIM.-.Paragon Software) -> MsiExec.exe /I{56EECD69-F428-41C4-ADF6-6CDEE14DDF3F}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}] : (Macrium Reflect Free Edition.-.Paramount Software (UK) Ltd.) -> MsiExec.exe /I{595B8A7B-253D-4A4E-95C2-A823EDDD5496}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1] : (Revo Uninstaller Pro 3.1.9.-.VS Revo Group, Ltd.) -> "C:\Program Files\VS Revo Group\Revo Uninstaller Pro\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{76C8F882-DBFC-43FB-9483-E5DE5D7D5FFA}_is1] : (Remo Privacy Cleaner.-.Remo Software) -> "C:\Program Files (x86)\Remo Privacy Cleaner\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{77BE1F2C-552C-438E-8E6B-4C0816BDEC5D}] : (Rebit Pro (64-bit).-.Rebit, Inc.) -> MsiExec.exe /I{77BE1F2C-552C-438E-8E6B-4C0816BDEC5D}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{7DE129E5-BB4A-4517-A6CD-C69EEB346781}] : (AntispamEngine.-.adaware) -> MsiExec.exe /I{7DE129E5-BB4A-4517-A6CD-C69EEB346781}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{7F7C8AE0-961B-4AED-B99A-D9BE29C0F24C}] : (AdAwareProxyEngine.-.adaware) -> MsiExec.exe /I{7F7C8AE0-961B-4AED-B99A-D9BE29C0F24C}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{8DD5B1BF-E1BB-43DB-965C-DC6180A19518}_is1] : (Remo Repair MOV.-.Remo Software) -> "C:\Program Files\Remo Repair MOV 2.0\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{97B648DA-2BBF-47EE-864E-EF029C23A425}_is1] : (Eassos Recovery V4.2.1.-.Eassos Co., Ltd.) -> "C:\Program Files\Eassos Recovery\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9CF6A157-F0E8-4216-B229-C0CA8204BE2C}_is1] : (Copy Handler 1.44.-.Józef Starosczyk) -> "C:\Program Files\Copy Handler\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}] : (RBVirtualFolder64Inst.-.Roxio, Inc.) -> MsiExec.exe /I{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9F198151-82C8-4AE0-9290-4248B416BDF4}_is1] : (Remo Repair Outlook [PST].-.Remo Software) -> "C:\Program Files\Remo Repair Outlook [PST]\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A1E718A7-BB83-41B8-BA96-BC219C322B8E}] : (COMODO Internet Security Pro.-.COMODO Security Solutions Inc.) -> MsiExec.exe /I{A1E718A7-BB83-41B8-BA96-BC219C322B8E} [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A6CD3589-2B65-44D1-B68D-E0E6C79EE639}_is1] : (Remo Recover FREE Edition 1.0.-.Remo Software) -> "C:\Program Files\Remo Recover FREE Edition\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{AAF4B2C1-2E27-46EF-9B9E-2B2130F056F3}] : (FirewallEngine.-.adaware) -> MsiExec.exe /I{AAF4B2C1-2E27-46EF-9B9E-2B2130F056F3}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B07BBB6E-6753-41B0-B4B9-1E9FE4AF5C18}] : (Lavasoft Privacy Toolbox.-.Lavasoft) -> [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}] : (GoodSync.-.Siber Systems) -> "C:\Program Files\Siber Systems\GoodSync\GoodSync-v10.exe" /stop-remove-services[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B8D1E97B-3C79-47A4-ADB7-09625917A2FB}_is1] : (Remo Repair Registry.-.Remo Software) -> "C:\Program Files\Remo Repair Registry\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{BECD7155-DC57-4F89-B1A8-A90B033C6209}] : (AdAwareUpdater.-.adaware) -> MsiExec.exe /I{BECD7155-DC57-4F89-B1A8-A90B033C6209}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{BECD7155-DC57-4F89-B1A8-A90B033C6209}_AdAwareUpdater] : (adaware antivirus.-.adaware) -> "C:\Program Files\Common Files\adaware\adaware antivirus\updater\12.0.649.11190\AdAwareUpdater.exe" --uninstall[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410B}] : (WinZip 21.0.-.WinZip Computing, S.L. ) -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C2410B}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{D78E5094-F665-4F98-A552-43AE08C6C105}_is1] : (Remo File Eraser 2.0.-.Remo Software) -> "C:\Program Files (x86)\Remo File Eraser 2.0\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{D7BF2029-EB2D-4523-AFA0-95CE605E696E}] : (AdAwareInstaller.-.adaware) -> MsiExec.exe /I{D7BF2029-EB2D-4523-AFA0-95CE605E696E}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}] : (VD64Inst.-.Roxio, Inc.) -> MsiExec.exe /I{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E7366CA8-7179-77AE-E712-BA18D70A0A07}] : (AMD Fuel.-.Advanced Micro Devices, Inc.) -> [HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F008F551-A58D-4257-9FB6-2F750860A0DE}_is1] : (GridinSoft Anti-Ransomware 0.9.1.-.GridinSoft, LLC.) -> "C:\Program Files\GridinSoft Anti-Ransomware\unins000.exe"[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F24FF688-7138-4CCF-A83F-71E9FB01170E}] : (Folder Size (64-bit).-.Brio) -> MsiExec.exe /X{F24FF688-7138-4CCF-A83F-71E9FB01170E}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{f4fef76c-1aa9-441c-af7e-d27f58d898d1}_is1] : (BCUninstaller.-.Marcin Szeniak) -> "C:\Program Files\BCUninstaller\unins000.exe"##########[{Hidden}][HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{FA02F344-8F3D-4EDC-97DA-A7B4469EC72E}] : (Paragon Backup & Recovery™ 16.-.Paragon Software) -> MsiExec.exe /X{FA02F344-8F3D-4EDC-97DA-A7B4469EC72E}[HKLM64\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{FC4FF5F4-2265-4E18-8BBC-12CBA9794388}_is1] : (Eassos PartitionGuru 4.9.3.-.Eassos Co., Ltd.) -> "C:\Program Files\PartitionGuru\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\2a2f52d72f79860f] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\7-Zip] : (7-Zip 16.02.-.Igor Pavlov) -> C:\Program Files (x86)\7-Zip\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\A-PDF to Video_is1] : (A-PDF to Video.-.A-PDF Solution) -> "C:\Program Files (x86)\A-PDF to Video\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Advanced Windows Service Manager 6.0] : (Advanced Windows Service Manager.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}\Setup_AdvancedWinServiceManager.exe /i {E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Android Data Recovery] : (Android Data Recovery .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Android Data Recovery\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Anti-Locky_is1] : (Anti-Locky.-.AxBx) -> "C:\Program Files (x86)\AxBx\Anti-Locky\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Any Data Recovery Pro] : (Any Data Recovery Pro .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Any Data Recovery Pro\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Ashampoo Photo Converter_is1] : (Ashampoo Photo Converter v.1.0.1.-.Ashampoo GmbH & Co. KG) -> "C:\Program Files (x86)\Ashampoo\Ashampoo Photo Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Ashampoo StartUp Tuner 2_is1] : (Ashampoo StartUp Tuner 2.00.-.ashampoo GmbH & Co. KG) -> "C:\Program Files (x86)\Ashampoo\Ashampoo StartUp Tuner 2\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AutoItv3] : (AutoIt v3.3.14.2.-.AutoIt Team) -> C:\Program Files (x86)\AutoIt3\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Autorun File Remover 5.0] : (Autorun File Remover.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}\Setup_AutorunFileRemover.exe /i {8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AvantBrowser] : (Avant Browser (remove only).-.Avant Force) -> "C:\Program Files (x86)\Avant Browser\uninst.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Batch Picture Resizer_is1] : (Batch Picture Resizer 7.3.-.SoftOrbits) -> "C:\Program Files (x86)\Batch Picture Resizer\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Belarc Advisor] : (Belarc Advisor 8.5c.-.Belarc Inc.) -> "C:\Program Files (x86)\Belarc\BelarcAdvisor\Uninstall.exe" "C:\Program Files (x86)\Belarc\BelarcAdvisor\INSTALL.LOG"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Card Data Recovery] : (Card Data Recovery .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Card Data Recovery\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\CHK-Mate_is1] : (DIY DataRecovery CHK-Mate.-.DIY DataRecovery.nl) -> "C:\Program Files (x86)\DIY DataRecovery CHK-Mate\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\CHM Editor] : (CHM Editor.-.) -> C:\Program Files (x86)\Gridinsoft\CHMEditor\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Clear ThemePack] : (Clear ThemePack.-.mythemepack) -> C:\Clear ThemePack\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Clipdiary] : (Clipdiary 5.0.-.Tiushkov Nikolay) -> C:\Program Files (x86)\Clipdiary\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\CloseAll] : (CloseAll.-.NTWind Software) -> C:\Program Files\CloseAll\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ClPhpEd] : (ClPhpEd(remove only).-.) -> "C:\Program Files (x86)\Codelobster Software\CodelobsterPHPEdition\uninst.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Comodo Dragon] : (Comodo Dragon.-.Comodo) -> "C:\Program Files (x86)\Comodo\Dragon\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Comodo IceDragon] : (Comodo IceDragon.-.COMODO) -> "C:\Program Files (x86)\Comodo\IceDragon\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ComodoIse] : (Internet Security Essentials.-.Comodo) -> C:\ProgramData\COMODO\ISE\ise_installer.exe##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DailymotionVideoAdBlocker] : (DailymotionVideoAdBlocker v1.5.-.SecurityXploded) -> "C:\Program Files (x86)\SecurityXploded\DailymotionVideoAdBlocker\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Data Wipe] : (Data Wipe .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Data Wipe\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DebugMode Wink] : (DebugMode Wink.-.) -> "C:\Program Files (x86)\DebugMode\Wink\uninst.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Digital Media Converter 4.0_is1] : (Digital Media Converter 4.1.-.Deskshare Inc.) -> "C:\Program Files (x86)\Deskshare\Digital Media Converter 4\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DivX Setup.divx.com] : (Configuration DivX.-.DivX, LLC) -> C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DMX5_is1] : (DriverMax 9.-.Innovative Solutions) -> "C:\Program Files (x86)\Innovative Solutions\DriverMax\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Do Your Data Recovery Trial 5.5_is1] : (Do Your Data Recovery Trial 5.7.-.DoYourData) -> "C:\Program Files (x86)\DoYourData\Do Your Data Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Doc Scrubber_is1] : (Doc Scrubber v1.2.-.BrightFort LLC) -> "C:\Program Files (x86)\Doc Scrubber\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Driver Booster Beta_is1] : (Driver Booster 5 Beta.-.IObit) -> "C:\Program Files (x86)\IObit\Driver Booster Beta\5.0.0\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Driver Booster_is1] : (Driver Booster 4.4.-.IObit) -> "C:\Program Files (x86)\IObit\Driver Booster\4.4.0\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EaseUS EverySync_is1] : (EaseUS EverySync 3.0.-.EaseUS) -> "C:\Program Files (x86)\EaseUS\EaseUS EverySync\unins001.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EaseUS Todo Backup_is1] : (EaseUS Todo Backup Free 8.6 .-.CHENGDU YIWO Tech Development Co., Ltd) -> "C:\Program Files (x86)\EaseUS\Todo Backup\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Easy File Locker] : (Easy File Locker 2.2.-.XOSLAB.COM) -> C:\Program Files\Easy File Locker\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\EPSON Scanner] : (EPSON Scan.-.Seiko Epson Corporation) -> C:\Program Files (x86)\epson\escndv\setup\setup.exe /r[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\File Arranger1.0] : (File Arranger.-.File Arranger) -> "C:\Program Files (x86)\File Arranger\uninstall.exe" "/U:C:\Program Files (x86)\File Arranger\Uninstall\uninstall.xml"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FileHippo.com] : (FileHippo App Manager.-.FileHippo.com) -> "C:\Program Files (x86)\FileHippo.com\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Flip HTML5_is1] : (Flip HTML5.-.eflippdfforipad Solution) -> "C:\Program Files (x86)\Flip HTML5\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Flip PDF Professional_is1] : (Flip PDF Professional.-.FlipBuilder Solution) -> "C:\Program Files (x86)\Flip PDF Professional\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Folderico] : (Folderico 4.0 RC12.-.Shedko ( www.softq.org )) -> C:\Program Files (x86)\Folderico\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FolderViewer] : (FolderViewer.-.MatirSoft) -> "C:\Program Files (x86)\FolderViewer\Uninstall\Uninstall.exe" /u:"FolderViewer"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Foxit Reader_is1] : (Foxit Reader.-.Foxit Software Inc.) -> "C:\Program Files (x86)\Foxit Software\Foxit Reader\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Any Blu-ray Ripper_is1] : (Free Any Blu-ray Ripper version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Any Blu-ray Ripper\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Any Data Recovery] : (Free Any Data Recovery .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Free Any Data Recovery\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Any DVD Ripper_is1] : (Free Any DVD Ripper version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Any DVD Ripper\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Any MP3 Converter_is1] : (Free Any MP3 Converter version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Any MP3 Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Any MP4 Converter_is1] : (Free Any MP4 Converter version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Any MP4 Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Any Video Converter_is1] : (Free Any Video Converter version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Any Video Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Blu-ray Player_is1] : (Free Blu-ray Player version 1.7.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Blu-ray Player\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Flash Gallery Maker_is1] : (Free Flash Gallery Maker (1.8.4.0).-.Amazing Studio) -> "C:\Program Files (x86)\Amazing\Free Flash Gallery Maker\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free GIF to AVI Converter_is1] : (Free GIF to AVI Converter (1.3.0.0).-.Amazing Studio) -> "C:\Program Files (x86)\Amazing\Free GIF to AVI Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free GIF to Video Converter_is1] : (Free GIF to Video Converter (1.3.0.0).-.Amazing Studio) -> "C:\Program Files (x86)\Amazing\Free GIF to Video Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free HD Video Converter_is1] : (Free HD Video Converter version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free HD Video Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Slideshow Maker_is1] : (Free Slideshow Maker (3.5.8.0).-.Amazing Studio) -> "C:\Program Files (x86)\Amazing\Free Slideshow Maker\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Studio_is1] : (Free Studio.-.Digital Wave Ltd) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Video Converter Ultimate_is1] : (Free Video Converter Ultimate version 1.6.-.Amazing Studio) -> "C:\Program Files (x86)\Amazing Studio\Free Video Converter Ultimate\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Video Converter_is1] : (Free Video Converter V 2.3.-.Kastor Soft) -> "C:\Program Files (x86)\Kastor Free Video Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Video Splitter] : (Free Video Splitter 4.0.1.-.Free Video Splitter Team) -> C:\Program Files (x86)\free-video-splitter\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free Video to GIF Converter_is1] : (Free Video to GIF Converter (1.6.0.0).-.Amazing Studio) -> "C:\Program Files (x86)\Amazing\Free Video to GIF Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free YouTube Download_is1] : (Free YouTube Download.-.Digital Wave Ltd) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FreeFileSync_is1] : (FreeFileSync 9.1 [Donation Edition].-.www.FreeFileSync.org) -> "C:\Program Files\FreeFileSync\Uninstall\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Freeraser] : (Freeraser.-.Codyssey.com) -> C:\Program Files (x86)\Codyssey\Freeraser\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Glary Undelete] : (Glary Undelete 5.0.1.19.-.Glarysoft Ltd) -> C:\Program Files (x86)\Glarysoft\Glary Undelete 5\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Glary Utilities 5] : (Glary Utilities 5.79.-.Glarysoft Ltd) -> C:\Program Files (x86)\Glary Utilities 5\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Google Ad Blocker 6.5] : (Google Ad Blocker.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{DD3D64A7-3165-458D-96D4-06FBC609C22A}\Setup_GoogleAdBlocker.exe /i {DD3D64A7-3165-458D-96D4-06FBC609C22A}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\HDR Express] : (HDR Express.-.UCT) -> C:\Program Files\UCT\HDR Express\uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IconPack] : (IconPack Gradiente Biohazard.-.SkinPack) -> C:\IconPack\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\iFun Video Converter_is1] : (iFun Video Converter 1.0.-.iFunSoft) -> "C:\Program Files (x86)\iFunSoft\iFun Video Converter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\iGetting Audio] : (iGetting Audio .-.Tenorshare, Inc.) -> C:\Program Files (x86)\iGetting Audio\driver_signed\win7_64\driver_signed\win7_64\driver_signed\win7_64\driver_signed\win7_64\driver_signed\win7_64\driver_signed\win7_64\driver_signed\win7_64\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IM_Magic_PR] : (IM-Magic Partition Resizer Free 2017.-.IM-Magic Inc.) -> C:\Program Files\IM-Magic\Partition Resizer\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{1D273D91-D7D5-4036-8B84-EB4615FF5F81}] : (SmartSound Sonicfire Pro 5.-.SmartSound Software Inc.) -> "C:\Program Files (x86)\InstallShield Installation Information\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}\setup.exe" -runfromtemp -l0x0409 -removeonly[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}] : (SmartSound Quicktracks 5.-.SmartSound Software Inc.) -> "C:\Program Files (x86)\InstallShield Installation Information\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}\setup.exe" -runfromtemp -l0x0409 -removeonly[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}] : (CyberLink Media Suite 14.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}\setup.exe" /z-uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\Setup.exe" /z-uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{ADD5DB49-72CF-11D8-9D75-000129760D75}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\Setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}] : (SmartSound Common Data.-.SmartSound Software Inc.) -> "C:\Program Files (x86)\InstallShield Installation Information\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}\setup.exe" -runfromtemp -l0x0409 -removeonly##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{D25D3E15-CABD-420c-B62C-70C1C5EE63FD}] : (CyberLink Application Manager.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D25D3E15-CABD-420c-B62C-70C1C5EE63FD}\setup.exe" /z-uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\Setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObit Unlocker_is1] : (IObit Unlocker.-.IObit) -> "C:\Program Files (x86)\IObit\IObit Unlocker\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObitMBRGuard_is1] : (IObit MBR Guard 1.0 beta.-.IObit) -> "C:\Program Files (x86)\IObit\IObit MBR Guard\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObitUninstall] : (IObit Uninstaller.-.IObit) -> "C:\Program Files (x86)\IObit\IObit Uninstaller\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObit_StartMenu8_is1] : (Start Menu 8.-.IObit) -> "C:\Program Files (x86)\IObit\Classic Start\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IP Camera Viewer_is1] : (IP Camera Viewer 3.-.DeskShare Inc.) -> "C:\Program Files (x86)\Deskshare\IP Camera Viewer 3\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\iSkysoft iMedia Converter Deluxe_is1] : (iSkysoft iMedia Converter Deluxe(Build 9.0.0.1).-.iSkysoft Software) -> "C:\Program Files (x86)\iSkysoft\VCU\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ISO Workshop_is1] : (ISO Workshop 7.5.-.Glorylogic) -> "C:\Program Files (x86)\Glorylogic\ISO Workshop\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Kastor Free Vimeo Downloader_is1] : (Kastor Free Vimeo Downloader V 2.0.-.KastorSoft) -> "C:\Program Files (x86)\Kastor Free Vimeo Downloader\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\KeyFinder Plus_is1] : (KeyFinder Plus 1.9.-.Top Password Software, Inc.) -> "C:\Program Files (x86)\Top Password\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\KLiteCodecPack_is1] : (K-Lite Mega Codec Pack 7.0.0.-.) -> "C:\Program Files (x86)\K-Lite Codec Pack\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Lavasoft Privacy Toolbox] : (Lavasoft Privacy Toolbox.-.Lavasoft) -> "C:\ProgramData\{4C13979D-F8C4-41F2-B4D5-07A2A4FB8F6B}\LavasoftPrivacyToolbox.exe" REMOVE=TRUE MODIFY=FALSE[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\LogoMaker_is1] : (LogoMaker 4.0.-.Avanquest) -> "C:\Program Files (x86)\Studio V5\LogoMaker\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Macrorit] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Macrorit_extender] : (Macrorit Partition Extender Free 2017.-.Macrorit Inc.) -> C:\Program Files\Macrorit\Partition Extender\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Macrorit_MDE] : (Macrorit Disk Partition Expert Free 2017.-.Macrorit Inc.) -> C:\Program Files\Macrorit\Disk Partition Expert\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MACRORIT_MDS] : (Macrorit Disk Scanner Free 2017.-.Macrorit Inc.) -> C:\Program Files\Macrorit\Disk Scanner\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Macrorit_MDW] : (Macrorit Data Wiper Free 2017.-.Macrorit Inc.) -> C:\Program Files\Macrorit\Data Wiper\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Majorgeeks.com Software Updates and News] : (Majorgeeks.com Software Updates and News.-.Majorgeeks.com) -> "C:\Program Files (x86)\Majorgeeks.com\Software Updates and News\uninstall.exe" "/U:C:\Program Files (x86)\Majorgeeks.com\Software Updates and News\Uninstall\uninstall.xml"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Malware Hunter] : (Malware Hunter 1.34.0.59.-.Glarysoft Ltd) -> C:\Program Files (x86)\Glarysoft\Malware Hunter\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1] : (Malwarebytes Anti-Malware version 2.2.1.1043.-.Malwarebytes) -> "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Microsoft SQL Server 11] : (Microsoft SQL Server 2012.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Mozilla Firefox 54.0.1 (x86 fr)] : (Mozilla Firefox 54.0.1 (x86 fr).-.Mozilla) -> "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Mozilla Thunderbird 45.3.0 (x86 fr)] : (Mozilla Thunderbird 45.3.0 (x86 fr).-.Mozilla) -> C:\Program Files (x86)\Mozilla Thunderbird\uninstall\helper.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MRU-Blaster_is1] : (MRU-Blaster v1.5 (Database 3.28.04).-.BrightFort LLC) -> "C:\Program Files (x86)\MRU-Blaster\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Multi Install 2.4.5] : (Multi Install 2.4.5.-.) -> C:\Program Files (x86)\Multi Install 2.4.5\Uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MultiCommander Win32] : (MultiCommander (Win32).-.Mathias Svensson) -> C:\Program Files (x86)\MultiCommander\Uninstall MultiCommander.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MyEpson Portal] : (MyEpson Portal.-.SEIKO EPSON Corporation) -> MsiExec.exe /I{3361D415-BA35-4143-B301-661991BA6219}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Paint Effects for Windows] : (NewBlue Paint Effects for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Paint Effects for Windows\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Titler Pro for Windows] : (NewBlue Titler Pro for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Titler Pro for Windows\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Video Essentials for Windows] : (NewBlue Video Essentials for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Video Essentials for Windows\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Video Essentials V for Windows] : (NewBlue Video Essentials V for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Video Essentials V for Windows\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Video Essentials VI for Windows] : (NewBlue Video Essentials VI for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Video Essentials VI for Windows\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NewBlue Video Essentials VII for Windows] : (NewBlue Video Essentials VII for Windows.-.NewBlue) -> "C:\Program Files (x86)\NewBlue\Video Essentials VII for Windows\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NpcapInst] : (Npcap 0.92.-.Nmap Project) -> "C:\Program Files\Npcap\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\OpenAL] : (OpenAL.-.) -> "C:\Program Files (x86)\OpenAL\oalinst.exe" /U[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Opera 46.0.2597.39] : (Opera Stable 46.0.2597.39.-.Opera Software) -> "C:\Program Files (x86)\Opera\Launcher.exe" /uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PDF-to-Excel 1.5 Demo] : (PDF-to-Excel 1.5 Demo.-.) -> C:\PROGRA~2\Avanquest\demos\UNWISE.EXE /U C:\PROGRA~2\Avanquest\demos\pdf2xls.log[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PDF-to-HTML 1.1 Demo] : (PDF-to-HTML 1.1 Demo.-.) -> C:\PROGRA~2\Avanquest\demos\UNWISE.EXE /U C:\PROGRA~2\Avanquest\demos\pdf2htm.log[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PDF-to-Word 3.1 Demo] : (PDF-to-Word 3.1 Demo.-.) -> C:\PROGRA~2\PDF-TO~1\demos\UNWISE.EXE /U C:\PROGRA~2\PDF-TO~1\demos\pdf2word.log[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PDFPasswordRemover_is1] : (PDFPasswordRemover 1.6.2.-.PDFPasswordRemover) -> "c:\PDFPasswordRemover\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Photopus Pro_is1] : (Photopus Pro 1.4.-.) -> "C:\Program Files (x86)\Photopus Pro\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Photopus_is1] : (Photopus 1.4.-.) -> "C:\Program Files (x86)\Photopus\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\proDAD-MercalliEasy-2.0] : (proDAD Mercalli Easy Video Stabilizer 2.0.-.proDAD GmbH) -> "C:\Program Files (x86)\proDAD\MercalliEasy-2.0\uninstall.exe" uninstall spcp PATHVERSION "2.0" MAINNAME "MercalliEasy"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Protected Folder_is1] : (Protected Folder.-.IObit) -> "C:\Program Files (x86)\IObit\Protected Folder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Quick Search] : (Quick Search 5.28.1.91.-.Glarysoft Ltd) -> C:\Program Files (x86)\Glarysoft\Quick Search 5\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Random Password Generator_is1] : (Random Password Generator.-.IObit) -> "C:\Program Files (x86)\IObit\Random Password Generator\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Recover Keys_is1] : (Recover Keys.-.Recover Keys) -> "C:\Program Files (x86)\Recover Keys\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\RegSeeker] : (RegSeeker.-.HoverDesk) -> C:\Program Files (x86)\RegSeeker\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\RPD_is1] : (NeoSetup Updater.-.Innovative Solutions) -> "C:\Program Files (x86)\Innovative Solutions\NeoSetup Updater\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Samsung Data Recovery] : (Samsung Data Recovery .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Samsung Data Recovery\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Securely File Shredder] : (Securely File Shredder.-.Reason Company Software Inc.) -> "C:\Program Files\Securely File Shredder\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ShadowExplorer_is1] : (ShadowExplorer 0.9.-.ShadowExplorer.com) -> "C:\Program Files (x86)\ShadowExplorer\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SkinPack] : (SkinPack Noble.-.SkinPack) -> C:\SkinPack\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SkinPack Creator] : (SkinPack Creator 10.0.-.SkinPack) -> C:\SkinPack Creator\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Smart Defrag_is1] : (Smart Defrag 5.-.IObit) -> "C:\Program Files (x86)\IObit\Smart Defrag\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SoftOrbits Photo Retoucher_is1] : (SoftOrbits Photo Retoucher 4.0.-.SoftOrbits) -> "C:\Program Files (x86)\SoftOrbits Photo Retoucher\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SoundCloud Download_is1] : (SoundCloud Download.-.Digital Wave Ltd) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Speed Install_is1] : (Speed Install 2.0.2.1738.-.Almeza Company) -> "C:\Users\Jean-Marie\Documents\Speed Install\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Spy BHO Remover 7.0] : (Spy BHO Remover.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{5DD7489B-EC46-47AF-BB68-22F47253228B}\Setup_SpyBHORemover.exe /i {5DD7489B-EC46-47AF-BB68-22F47253228B}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\StartIsBack] : (StartIsBack++.-.startisback.com) -> C:\Program Files (x86)\StartIsBack\StartIsBackCfg.exe /uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Supercopier] : (Supercopier 1.2.3.5.-.Supercopier) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SX Antivirus Kit 4.0] : (SX Antivirus Kit.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{BBD54A11-C598-4789-8F12-AA189B3374C2}\Setup_SXAntivirusKit.exe /i {BBD54A11-C598-4789-8F12-AA189B3374C2}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SX Blocker Suite 3.0] : (SX Blocker Suite.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{35AB7D6C-C217-4470-B2D7-021291708FF4}\Setup_SXBlockerSuite.exe /i {35AB7D6C-C217-4470-B2D7-021291708FF4}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SX Network Suite 5.0] : (SX Network Suite.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}\Setup_SXNetworkSuite.exe /i {9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SX System Suite 3.0] : (SX System Suite.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}\Setup_SXSystemSuite.exe /i {D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SX WiFi Security Suite 6.0] : (SX WiFi Security Suite.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}\Setup_SXWiFiSecuritySuite.exe /i {F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SyncBackFree_is1] : (SyncBackFree.-.2BrightSparks) -> "C:\Program Files (x86)\2BrightSparks\SyncBackFree\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SyncBackPro_is1] : (SyncBackPro.-.2BrightSparks) -> "C:\Program Files (x86)\2BrightSparks\SyncBackPro\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SyncBackTouch_is1] : (SyncBackTouch.-.2BrightSparks) -> "C:\Program Files (x86)\2BrightSparks\SyncBackTouch\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Syncios] : (Syncios 6.1.2.-.Anvsoft) -> C:\Program Files (x86)\Anvsoft\Syncios\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\TeamViewer] : (TeamViewer 12.-.TeamViewer) -> "C:\Program Files (x86)\TeamViewer\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\TechPowerUp GPU-Z] : (TechPowerUp GPU-Z.-.TechPowerUp) -> "C:\Program Files (x86)\GPU-Z\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Tenorshare Partition Manager] : (Tenorshare Partition Manager .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Tenorshare Partition Manager\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Tenorshare Video Converter Standard] : (Tenorshare Video Converter Standard .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Tenorshare Video Converter Standard\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\TreeSize Free_is1] : (TreeSize Free V4.0.1.-.JAM Software) -> "C:\Program Files (x86)\JAM Software\TreeSize Free\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Trojan Remover_is1] : (Trojan Remover.-.Simply Super Software) -> "C:\Program Files (x86)\Trojan Remover\unins001.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\trolCommander] : (trolCommander (remove only).-.) -> "C:\Program Files (x86)\trolCommander\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Tweaking.com - Windows Repair] : (Tweaking.com - Windows Repair.-.Tweaking.com) -> "C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\uninstall.exe" "/U:C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Uninstall\uninstall.xml"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Ultracopier] : (Ultracopier 1.2.3.5.-.Ultracopier) -> C:\Program Files\Ultracopier\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\UnrealCommander_is1] : (Unreal Commander v3.57.-.Max Diesel) -> "c:\Unreal Commander\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\USB Key Vaccine 2016_is1] : (USB Key Vaccine 2016.-.AxBx) -> "C:\Program Files (x86)\AxBx\USB Key Vaccine 2016\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\USB Safely Remove_is1] : (USB Safely Remove 6.0.-.SafelyRemove.com) -> "C:\Program Files (x86)\USB Safely Remove\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Usbfix] : (UsbFix Premium 2016.-.SOSVirus (SOSVirus.Net)) -> C:\Users\Jean-Marie\AppData\Roaming\UsbFix\Un-UsbFix.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Video Joiner] : (Video Joiner .-.Adoreshare, Inc.) -> C:\Program Files (x86)\Video Joiner\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Video Watermark Pro] : (Video Watermark Pro 5.3.-.AoaoPhoto Digital Studio.) -> C:\Program Files (x86)\AoaoPhoto Digital Studio\Video Watermark Pro\unins000.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Vimeo Download_is1] : (Vimeo Download.-.Digital Wave Ltd) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VirusTotal Scanner 6.5] : (VirusTotal Scanner.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{43C5B500-38EB-456F-8C71-CE7B1F7F9976}\Setup_VirusTotalScanner.exe /i {43C5B500-38EB-456F-8C71-CE7B1F7F9976}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VisualInstaller] : (SkinPack extras.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VivPDFEditor_is1] : (VivPDF Editor.-.) -> "C:\Program Files (x86)\VivPDF Editor\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Watermark Software] : (Watermark Software 8.3.-.watermark-software.com) -> C:\Program Files (x86)\AoaoPhoto Digital Studio\Watermark Software\unins000.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Windows 10 - Codec Pack] : (Windows 10 Codec Pack 2.0.8.-.Windows 10 Codec Pack) -> C:\WINDOWS\SysWOW64\Codecs\Uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Windows 7 - Codec Pack] : (Windows 7 Codec Pack 4.1.7.-.Windows 7 Codec Pack) -> C:\WINDOWS\SysWOW64\Codecs\Uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Windows Boot Genius] : (Windows Boot Genius .-.Tenorshare, Inc.) -> C:\Program Files (x86)\Windows Boot Genius\uninst.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WinExt_is1] : (WinExt 2.1.-.TriSun Software Limited) -> "C:\Program Files (x86)\TSS\WinExt\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Winja_is1] : (Winja version 3.0.3.-.Phrozen SAS) -> "C:\Users\Jean-Marie\AppData\Roaming\PhrozenWinja\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WinMend File Copy_is1] : (WinMend File Copy 2.3.0.-.WinMend.com) -> "C:\Program Files (x86)\WinMend\File Copy\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WinX DVD Ripper Platinum_is1] : (WinX DVD Ripper Platinum 8.5.0.-.Digiarty Software, Inc.) -> "C:\Program Files (x86)\Digiarty\WinX_DVD_Ripper_Platinum\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Care 365_is1] : (Wise Care 365 4.6.7.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Care 365\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Driver Care_is1] : (Wise Driver Care 1.0.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Driver Care\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Duplicate Finder_is1] : (Wise Duplicate Finder 1.21.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Duplicate Finder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Folder Hider Pro_is1] : (Wise Folder Hider Pro.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Folder Hider Pro\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Folder Hider_is1] : (Wise Folder Hider.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Folder Hider\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise JetSearch_is1] : (Wise JetSearch 2.31.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise JetSearch\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Memory Optimizer_is1] : (Wise Memory Optimizer 3.51.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Memory Optimizer\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise PC 1stAid_is1] : (Wise PC 1stAid 1.48.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise PC 1stAid\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Plugin Manager_is1] : (Wise Plugin Manager 1.28.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Plugin Manager\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1] : (Wise Registry Cleaner 9.45.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Registry Cleaner\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wise Video Downloader_is1] : (Wise Video Downloader 2.53.-.WiseCleaner.com, Inc.) -> "C:\Program Files (x86)\Wise\Wise Video Downloader\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WonderFox DVD Ripper Pro] : (WonderFox DVD Ripper Pro 8.6.-.WonderFox Soft, Inc.) -> C:\Program Files (x86)\WonderFox Soft\WonderFox DVD Ripper\unins000.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Wondershare TidyMyMusic_is1] : (Wondershare TidyMyMusic(Build 1.5.0.1).-.Wondershare Software) -> "C:\Program Files (x86)\Wondershare\TidyMyMusic\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WUCCCApp] : (AMD Catalyst Control Center.-.AMD) -> "C:\AMD\WU-CCC2\ccc2_install\WULaunchApp.exe" -uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Xilisoft Video Cutter 2] : (Xilisoft Video Cutter 2.-.Xilisoft) -> C:\Program Files (x86)\Xilisoft\Video Cutter 2\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Xilisoft Video Editor 2] : (Xilisoft Video Editor 2.-.Xilisoft) -> C:\Program Files (x86)\Xilisoft\Video Editor 2\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Xilisoft Video Splitter 2] : (Xilisoft Video Splitter 2.-.Xilisoft) -> C:\Program Files (x86)\Xilisoft\Video Splitter 2\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\xplorer2l] : (xplorer² lite 32 bit.-.Zabkat) -> "C:\Program Files (x86)\zabkat\xplorer2_lite\Uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Xvid_is1] : (Xvid 1.2.1 final uninstall.-.Xvid team (Koepi)) -> "C:\Program Files (x86)\Xvid\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\XYplorerFree] : (XYplorerFree 17.40.-.Donald Lessau, Cologne Code Company) -> C:\Program Files (x86)\XYplorerFree\Uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\YouTube Video Ad Blocker 3.0] : (YouTube Video Ad Blocker.-.SecurityXploded) -> C:\ProgramData\Caphyon\Advanced Installer\{07CF5846-FAEA-4A01-8B70-9014216AA707}\Setup_YouTubeVideoAdBlocker.exe /i {07CF5846-FAEA-4A01-8B70-9014216AA707}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Zoolz2] : (Zoolz2.-.Genie9) -> "C:\Program Files\Genie9\Zoolz2\uninstall.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}] : (Nero 2016 Content Pack.-.Nero AG) -> MsiExec.exe /I{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{05C6B128-1B40-4495-9CB9-090B368BFA0A}] : (Nero Video Samples.-.Nero AG) -> MsiExec.exe /X{05C6B128-1B40-4495-9CB9-090B368BFA0A}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{06A965CC-D8A3-4A33-AA9A-78292E9DBBC8}] : (Video Explosion Ultimate.-.Avanquest Software) -> "C:\Program Files (x86)\InstallShield Installation Information\{06A965CC-D8A3-4A33-AA9A-78292E9DBBC8}\setup.exe" -runfromtemp -l0x040c -removeonly##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{07326A3E-02B3-1078-25D7-B8666BA8FE15}] : (CCC Help Korean.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{07AA1C7F-E8CA-4FDC-B975-BC9EBC22B6DE}] : (Epson Easy Photo Print 2.-.SEIKO EPSON CORPORATION) -> "C:\Program Files (x86)\InstallShield Installation Information\{07AA1C7F-E8CA-4FDC-B975-BC9EBC22B6DE}\setup.exe" -runfromtemp -l0x040c UNINST -removeonly##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{07CF5846-FAEA-4A01-8B70-9014216AA707}] : (YouTube Video Ad Blocker.-.SecurityXploded) -> MsiExec.exe /I{07CF5846-FAEA-4A01-8B70-9014216AA707}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}] : (CCC Help Finnish.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{08610298-29AE-445B-B37D-EFBE05802967}] : (LWS Pictures And Video.-.Logitech) -> MsiExec.exe /I{08610298-29AE-445B-B37D-EFBE05802967}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{08C03D14-B619-4CD6-938F-C2BB569364E0}] : (FF Copy.-.FF Projects) -> MsiExec.exe /I{08C03D14-B619-4CD6-938F-C2BB569364E0}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0A11EA01-7909-E272-BFA6-BC39E55F240A}_is1] : (Ashampoo Snap 10.-.Ashampoo GmbH & Co. KG) -> "C:\Program Files (x86)\Ashampoo\Ashampoo Snap 10\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0B11329E-1DDE-448A-95E6-AA003C63A6A7}_is1] : (MiniCopier.-.Adrian Courreges) -> "C:\Program Files (x86)\MiniCopier\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0B456D24-DD76-4163-8175-4F720E6F3C92}] : (calibre.-.Kovid Goyal) -> MsiExec.exe /I{0B456D24-DD76-4163-8175-4F720E6F3C92}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{11087D24-567D-7D88-69C6-D7A08B5F4C47}] : (Catalyst Control Center - Branding.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /I{11087D24-567D-7D88-69C6-D7A08B5F4C47}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{117CE366-3EED-48C5-BF6A-E0F47A0E68A4}] : (ShadowCopy.-.Runtime Software) -> "C:\Program Files (x86)\Runtime Software\ShadowCopy\Uninstall.exe" "C:\Program Files (x86)\Runtime Software\ShadowCopy\install.log" -u[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{11FC9C17-17FF-4F2B-9D5A-4DE097629F00}}_is1] : (Kotobee Reader version 1.1.1.-.Vijua, Inc.) -> "C:\Program Files (x86)\Kotobee Reader\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{11FC9C17-17FF-4F2B-9D5A-4DE097629F21}}_is1] : (Kotobee Author version 1.3.2.-.Vijua, Inc.) -> "C:\Program Files (x86)\Kotobee Author\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{150D88F1-40AF-4678-A39D-BCE2332F34E5}] : (Nero Abstract Themes.-.Nero AG) -> MsiExec.exe /X{150D88F1-40AF-4678-A39D-BCE2332F34E5}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{15634701-BACE-4449-8B25-1567DA8C9FD3}] : (CameraHelperMsi.-.Logitech) -> MsiExec.exe /I{15634701-BACE-4449-8B25-1567DA8C9FD3}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1651216E-E7AD-4250-92A1-FB8ED61391C9}] : (LWS Help_main.-.Logitech) -> MsiExec.exe /I{1651216E-E7AD-4250-92A1-FB8ED61391C9}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{174A3B31-4C43-43DD-866F-73C9DB887B48}] : (LWS Twitter.-.Logitech) -> MsiExec.exe /I{174A3B31-4C43-43DD-866F-73C9DB887B48}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{18C5824A-FD59-453D-9DC1-5D86FA034357}] : (CyberLink AudioDirector 7.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{18C5824A-FD59-453D-9DC1-5D86FA034357}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{18C5824A-FD59-453D-9DC1-5D86FA034357}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1959CCD2-1227-4de4-97E7-04F29D526762}_is1] : (AnyMedia Player 3.4.4.-.cyan soft ltd) -> "C:\Program Files (x86)\AnyMedia Player\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1AD99E77-37CC-744E-39CA-67F6FD34565A}] : (Catalyst Control Center Localization All.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1B6F5E51-575E-4693-BCA2-7543570D076D}] : (Nero Kwik Themes Basic.-.Nero AG) -> MsiExec.exe /X{1B6F5E51-575E-4693-BCA2-7543570D076D}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}] : (CCC Help English.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1C63279A-BF36-4852-9924-B1978D6585A6}] : (Nero Device Updates.-.Nero AG) -> MsiExec.exe /X{1C63279A-BF36-4852-9924-B1978D6585A6}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}] : (SmartSound Sonicfire Pro 5.-.SmartSound Software Inc.) -> MsiExec.exe /I{1D273D91-D7D5-4036-8B84-EB4615FF5F81}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}] : (CCC Help French.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}] : (CyberLink Media Suite 14.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{203FFCF4-6F3D-43C4-ACC9-80F5DB25841C}_is1] : (Remo Recover Outlook Express 2.0.1.-.Remo Software) -> "C:\Program Files (x86)\Remo Recover Outlook Express\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}] : (LWS YouTube Plugin.-.Logitech) -> MsiExec.exe /I{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}] : (Nero Video Transitions 1.-.Nero AG) -> MsiExec.exe /X{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{23036C0D-54B5-46A6-A9ED-0B96B1301C78}] : (CyberLink MakeupDirector 2.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{23036C0D-54B5-46A6-A9ED-0B96B1301C78}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{23036C0D-54B5-46A6-A9ED-0B96B1301C78}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{233A5BF0-8F61-460F-9635-2AF5499DADBC}_is1] : (EZ-Agile Project Management [Community] version 2017 SP1.-.ADVENCYS LLC.) -> "C:\Program Files (x86)\EZ-Agile Project Management [Community]\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2432E589-6256-4513-B0BF-EFA8E325D5F0}] : (Nero SharedVideoCodecs.-.Nero AG) -> MsiExec.exe /X{2432E589-6256-4513-B0BF-EFA8E325D5F0}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2452C59D-5040-4A9A-A97F-B925390619E1}] : (Silent Install Builder 5.-.Aprel Tech, LLC) -> MsiExec.exe /X{2452C59D-5040-4A9A-A97F-B925390619E1}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}] : (CCC Help Russian.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26adfabf-dec5-4140-9f85-795f483836f3}_is1] : (GiliSoft Video Splitter 7.1.0.-.GiliSoft International LLC.) -> "C:\Program Files (x86)\GiliSoft\Video Splitter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{293B15F9-91A8-44D4-ACBB-E13E8E2EC97D}] : (CyberLink ColorDirector 5.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{293B15F9-91A8-44D4-ACBB-E13E8E2EC97D}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{293B15F9-91A8-44D4-ACBB-E13E8E2EC97D}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}] : (Nero Cliparts.-.Nero AG) -> MsiExec.exe /X{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{29F67D84-3A70-456E-806A-52301B02070B}] : (Nero Effects Basic.-.Nero AG) -> MsiExec.exe /X{29F67D84-3A70-456E-806A-52301B02070B}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{29FE44D7-BC89-4188-8B0E-F6BA073C15A5}_is1] : (DriveTheLife.-.???????????????) -> C:\Program Files (x86)\DTLSoft\DriveTheLife\Uninstall.exe##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2B682751-E749-441C-A4B3-1F538E26E56E}] : (Roxio System Rollback Recovery Disk.-.Roxio) -> MsiExec.exe /I{2B682751-E749-441C-A4B3-1F538E26E56E}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}] : (CCC Help Hungarian.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}] : (CyberLink Ultra HD Blu-ray Advisor.-.CyberLink Corp.) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}\Setup.exe" -uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2DDBB2E7-CB4E-4E65-A6B9-B9C95ED77D42}] : (Triple Scoop Music.-.Roxio) -> MsiExec.exe /X{2DDBB2E7-CB4E-4E65-A6B9-B9C95ED77D42}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2DFA85ED-588F-4CE3-A175-29E52C3804A8}_is1] : (Folder Size 3.4.0.0.-.MindGems, Inc.) -> "C:\Program Files (x86)\Folder Size\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}] : (SmartSound Quicktracks 5.-.SmartSound Software Inc.) -> MsiExec.exe /I{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{302763FD-5CEA-4DFF-80C8-9B41414C4822}] : (Roxio CinePlayer.-.Roxio) -> MsiExec.exe /I{302763FD-5CEA-4DFF-80C8-9B41414C4822}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}] : (CyberLink WaveEditor 2.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3361D415-BA35-4143-B301-661991BA6219}] : (MyEpson Portal.-.SEIKO EPSON CORPORATION) -> MsiExec.exe /I{3361D415-BA35-4143-B301-661991BA6219}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}] : (CCC Help Spanish.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}] : (CCC Help Chinese Standard.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{35AB7D6C-C217-4470-B2D7-021291708FF4}] : (SX Blocker Suite.-.SecurityXploded) -> MsiExec.exe /I{35AB7D6C-C217-4470-B2D7-021291708FF4}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{35B8CC58-F128-4169-82EB-0E6CB0C3AFE6}] : (ArcSoft PhotoImpression.-.) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{35B8CC58-F128-4169-82EB-0E6CB0C3AFE6}\setup.exe" -l0x40c -uninst [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{38FFFD17-81AD-49EE-80F0-12DF92162DD2}_is1] : (EyesRelaxingAndFocusing 3.0.-.Aledensoft, Inc.) -> "C:\Program Files (x86)\Eyes Relaxing And Focusing 3.0\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3908B421-EF03-4389-A38C-DBAF6252E312}_is1] : (GiliSoft Video Editor 8.1.0.-.GiliSoft International LLC.) -> "C:\Program Files (x86)\Gilisoft\Video Editor\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3908B421-EF03-4389-A38C-DBAF6252E312}_is2] : (.-.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3A9527CF-4E91-4683-A03F-F1AD022126E5}] : (DirectX 9 Runtime.-.Sonic Solutions) -> MsiExec.exe /I{3A9527CF-4E91-4683-A03F-F1AD022126E5}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}] : (erLT.-.Logitech, Inc.) -> MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3F3FB10C-7175-4D38-9335-3488B89C12AF}] : (OkayFreedom.-.Steganos Software GmbH) -> C:\Program Files (x86)\OkayFreedom\uninstall.exe[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{419A7FCF-93E1-474D-BFE9-987CF3F90C88}_is1] : (Spybot Anti-Beacon.-.Safer-Networking Ltd.) -> "C:\Program Files (x86)\Spybot Anti-Beacon\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{423643C0-9315-4349-B1D3-9B3E7D2CBD37}_is1] : (concept/design onlineTV 12.-.concept/design GmbH) -> "C:\Program Files (x86)\concept design\onlineTV 12\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}] : (PreEmptive Analytics Visual Studio Components.-.PreEmptive Solutions) -> MsiExec.exe /X{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{43C5B500-38EB-456F-8C71-CE7B1F7F9976}] : (VirusTotal Scanner.-.SecurityXploded) -> MsiExec.exe /I{43C5B500-38EB-456F-8C71-CE7B1F7F9976}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{46E9BE31-70DC-4797-A24B-CB7FF0BB68BB}] : (FileOpen.-.Foxit Software Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{48F22622-1CC2-4A83-9C1E-644DD96F832D}] : (.-.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4B45B12B-CD31-4235-9D44-03A368510635}] : (.-.Avanquest Software) -> MsiExec.exe /X{4B45B12B-CD31-4235-9D44-03A368510635}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4D25D881-7183-462F-95C8-990CA1944E0B}] : (Nero PiP Effects 1.-.Nero AG) -> MsiExec.exe /X{4D25D881-7183-462F-95C8-990CA1944E0B}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}] : (Nero Holiday and Sports Themes.-.Nero AG) -> MsiExec.exe /X{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1] : (Wondershare Helper Compact 2.5.2.-.Wondershare) -> "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1] : (Panda USB Vaccine 1.0.1.4.-.Panda Security) -> "C:\Program Files (x86)\Panda USB Vaccine\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{55B464FA-16DE-4127-A7B8-D49CD2768E63}_is1] : (Turbo View & Convert.-.IMSI/Design, LLC) -> "C:\Program Files (x86)\IMSIDesign\Turbo View & Convert\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5686E484-7136-4674-A4B2-508C7B26DCA4}] : (LiteManager Pro - Viewer.-.LiteManagerTeam) -> MsiExec.exe /I{5686E484-7136-4674-A4B2-508C7B26DCA4}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{56E39D98-4569-4977-BB04-43D658F28807}] : (Roxio Creator 2012 Pro Disc 2.-.Roxio) -> C:\ProgramData\Uninstall\{56E39D98-4569-4977-BB04-43D658F28807}\setup.exe /x {56E39D98-4569-4977-BB04-43D658F28807} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{581697C8-33DC-44BA-A7C3-992B5D29C011}] : (Advanced Installer 13.8.1.-.Caphyon) -> MsiExec.exe /I{581697C8-33DC-44BA-A7C3-992B5D29C011}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{58BD86F8-895F-4ACE-9535-7E961AF9A321}_is1] : (SterJo Key Finder.-.SterJo Software) -> "C:\Users\Jean-Marie\AppData\Local\SterJo Key Finder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1] : (PeaZip 6.3.1.-.Giorgio Tani) -> "C:\Program Files (x86)\PeaZip\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}] : (Realtek Card Reader.-.Realtek Semiconductor Corp.) -> C:\WINDOWS\RtCRU64.exe /u[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5BD113FE-B8D8-4E7A-9BA1-17C649432B3E}] : (PDQ Deploy.-.Admin Arsenal) -> MsiExec.exe /X{5BD113FE-B8D8-4E7A-9BA1-17C649432B3E}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5DD7489B-EC46-47AF-BB68-22F47253228B}] : (Spy BHO Remover.-.SecurityXploded) -> MsiExec.exe /I{5DD7489B-EC46-47AF-BB68-22F47253228B}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}] : (Prerequisite installer.-.Nero AG) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60018889-9E0F-43E8-9B89-29E8C828B40A}] : (Dotfuscator and Analytics Community Edition 5.22.0.-.PreEmptive Solutions) -> MsiExec.exe /X{60018889-9E0F-43E8-9B89-29E8C828B40A}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60251665-84B4-41D6-84BF-6D50CE68DD08}] : (Nero Express.-.Nero AG) -> MsiExec.exe /X{60251665-84B4-41D6-84BF-6D50CE68DD08}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{64AB8FE0-0627-4FE2-A136-2DAB4B0AF087}_is1] : (Kotobee Publisher version 2.14.-.Vijua, Inc.) -> "C:\Program Files (x86)\Kotobee Publisher\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{64D5A142-BD50-726E-ED9E-D2508D2A17E2}] : (Catalyst Control Center InstallProxy.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}] : (Nero Update.-.Nero AG) -> MsiExec.exe /X{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{665680CE-EABF-4678-94AA-F3253AD70B0A}_is1] : (Remo Repair RAR.-.Remo Software) -> "C:\Program Files (x86)\Remo Repair RAR 2.0\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6861C1AD-9829-4DE4-8647-4785ECEA421A}] : (Nero Video.-.Nero AG) -> MsiExec.exe /X{6861C1AD-9829-4DE4-8647-4785ECEA421A}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6bf90d91-c5db-454e-a7b4-81bc6cbbe13f}] : (UxStyle.-.The Within Network, LLC) -> "C:\ProgramData\Package Cache\{6bf90d91-c5db-454e-a7b4-81bc6cbbe13f}\UxStyle_Bundle.exe" /uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6C4F538B-A66F-444E-9615-A2EBC202EFC5}_is1] : (Remo Drive Defrag.-.Remo Software) -> "C:\Program Files (x86)\Remo Drive Defrag\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6D74EB04-2E10-4266-A435-C5012FC68A36}_is1] : (Remo Outlook Backup & Migrate 1.0.0.-.Remo Software) -> "C:\Program Files (x86)\Remo Outlook Backup & Migrate\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}] : (LWS Gallery.-.Logitech) -> MsiExec.exe /I{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}] : (CCC Help German.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{71E66D3F-A009-44AB-8784-75E2819BA4BA}] : (LWS Motion Detection.-.Logitech) -> MsiExec.exe /I{71E66D3F-A009-44AB-8784-75E2819BA4BA}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{71FFA475-24D5-44FB-A51F-39B699E3D82C}] : (LiteManager Pro - Server.-.LiteManagerTeam) -> MsiExec.exe /I{71FFA475-24D5-44FB-A51F-39B699E3D82C}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{729B89D0-946A-407E-A121-343BD3320C40}] : (Roxio BackOnTrack.-.Roxio) -> MsiExec.exe /I{729B89D0-946A-407E-A121-343BD3320C40}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7309D717-F38D-436D-9537-066AA0AC7639}] : (Charity Engine.-.Charity Engine) -> MsiExec.exe /X{7309D717-F38D-436D-9537-066AA0AC7639}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{77CDA026-3860-4C95-8233-34F3CEF121FB}] : (Roxio Creator 2012 Pro.-.Roxio) -> MsiExec.exe /I{77CDA026-3860-4C95-8233-34F3CEF121FB}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{789E7816-C3DD-4392-B486-7C913C26FEDA}_is1] : (Remo Repair PowerPoint.-.Remo Software) -> "C:\Program Files (x86)\Remo Repair PowerPoint 2.0\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}] : (CCC Help Chinese Traditional.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7A3F32E0-D8E1-40C1-8E1B-1F5693F2ADE0}] : (CyberLink Power2Go 11.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{7A3F32E0-D8E1-40C1-8E1B-1F5693F2ADE0}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{7A3F32E0-D8E1-40C1-8E1B-1F5693F2ADE0}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7A3F3715-7953-4247-8B5C-5D03050B9EA9}] : (CyberLink PresenterLink+.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{7A3F3715-7953-4247-8B5C-5D03050B9EA9}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{7A3F3715-7953-4247-8B5C-5D03050B9EA9}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7ABAD880-D14E-48D4-9EFD-C0B531AA566E}] : (Module linguistique de Dotfuscator and Analytics Community Edition 5.22.0 fr-FR.-.PreEmptive Solutions) -> MsiExec.exe /X{7ABAD880-D14E-48D4-9EFD-C0B531AA566E}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7B63B2922B174135AFC0E1377DD81EC2}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7BA87AB0-2055-11E7-8E16-000C2992F709}] : (Foxit PhantomPDF.-.Foxit Software Inc.) -> MsiExec.exe /I{7BA87AB0-2055-11E7-8E16-000C2992F709}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7BAA8C5C-160C-4258-AEC0-729E43638F9B}_is1] : (Remo Drive Wipe 2.0.0.-.Remo Software) -> "C:\Program Files (x86)\Remo Drive Wipe\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7BAC3F7A-B963-468E-982E-B5608A87408D}] : (Epson Software Updater.-.SEIKO EPSON CORPORATION) -> MsiExec.exe /X{7BAC3F7A-B963-468E-982E-B5608A87408D}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}] : (Nero Football (Soccer) Themes.-.Nero AG) -> MsiExec.exe /X{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}] : (CyberLink PowerDVD 16.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7DE4301F-6232-4db5-A380-EB1AC584E020}_is1] : (AnyMP4 Audio Convertisseur 6.5.12.-.AnyMP4 Studio) -> "C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Audio Converter\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}] : (Nero MediaHome.-.Nero AG) -> MsiExec.exe /X{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7F22DD97-256D-491D-9090-743FADC79BBE}] : (Nero RescueAgent.-.Nero AG) -> MsiExec.exe /X{7F22DD97-256D-491D-9090-743FADC79BBE}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82CA1714-13EA-F419-91FE-12834424745E}] : (CCC Help Italian.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}] : (Nero Retro Film Themes.-.Nero AG) -> MsiExec.exe /X{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}] : (LWS Launcher.-.Logitech) -> MsiExec.exe /I{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}] : (Manuels EPSON.-.SEIKO EPSON CORPORATION) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}] : (Roxio Video Capture USB.-.Roxio) -> MsiExec.exe /I{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{87C334CF-063A-4AEA-B523-1DE04014BA19}_is1] : (Kastor - Tube To Mp3 V 2.99.-.KastorSoft) -> "C:\Program Files (x86)\Kastor Tube To Mp3\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8937D274-C281-42E4-8CDB-A0B2DF979189}] : (LWS Webcam Software.-.Logitech) -> MsiExec.exe /I{8937D274-C281-42E4-8CDB-A0B2DF979189}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}] : (Nero Platinum Effects 12.-.Nero AG) -> MsiExec.exe /X{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8BC81320-F684-439E-89F2-7155E1C4EB22}_is1] : (Giveaway Club Reminder.-.Auslogics Labs Pty Ltd) -> "C:\Program Files (x86)\Auslogics\Giveaway Club Reminder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8C784F8B-89D0-4A59-A000-7EEF129E1574}] : (Jing.-.TechSmith Corporation) -> MsiExec.exe /I{8C784F8B-89D0-4A59-A000-7EEF129E1574}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}] : (CCC Help Turkish.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8D149BE2-6542-4F6A-AEC4-7D61E6DCAEFB}] : (CyberLink MediaEspresso 7.5.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{8D149BE2-6542-4F6A-AEC4-7D61E6DCAEFB}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{8D149BE2-6542-4F6A-AEC4-7D61E6DCAEFB}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8EFB7927-48AD-4E6D-91B7-6B2BD6C3F380}] : (Acronis Disk Director 11 Home.-.Acronis) -> MsiExec.exe /X{8EFB7927-48AD-4E6D-91B7-6B2BD6C3F380}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1] : (Zemana AntiLogger.-.Zemana Ltd.) -> "C:\Program Files (x86)\Zemana AntiLogger\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}] : (.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}\setup.exe" /z-uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}] : (Autorun File Remover.-.SecurityXploded) -> MsiExec.exe /I{8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}] : (CyberLink MediaShow 6.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\Setup.exe" /z-uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}] : (CCC Help Swedish.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9074000C-5331-4686-92D8-6C3066E99C63}] : (Studio Video Ultimate.-.Avanquest) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{910B539D-F257-46C8-9CB8-6C95EFF9CF22}] : (Stashimi Stub Installer.-.Nero AG) -> MsiExec.exe /X{910B539D-F257-46C8-9CB8-6C95EFF9CF22}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{91B33C97-7650-0EB0-B6C7-DDBA2932B7B4}_is1] : (Ashampoo Music Studio 4 v.4.1.2.-.Ashampoo GmbH & Co. KG) -> "C:\Program Files (x86)\Ashampoo\Ashampoo Music Studio 4\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{91B33C97-87C8-5585-2940-1AE1120D4DCC}_is1] : (Ashampoo Privacy Protector.-.Ashampoo GmbH & Co. KG) -> "C:\Program Files (x86)\Ashampoo\Ashampoo Privacy Protector\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{91B33C97-C878-6579-69BA-23E5405C7AAB}_is1] : (Ashampoo Burning Studio 2017.-.Ashampoo GmbH & Co. KG) -> "C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 2017\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{92EBE575-0C6E-4713-B095-34BB927E5AC6}] : (Nero CoverDesigner.-.Nero AG) -> MsiExec.exe /X{92EBE575-0C6E-4713-B095-34BB927E5AC6}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{933B4015-4618-4716-A828-5289FC03165F}] : (VC80CRTRedist - 8.0.50727.6195.-.DivX, Inc) -> MsiExec.exe /I{933B4015-4618-4716-A828-5289FC03165F}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{93DE1C79-7ADE-4e81-8E6C-4F7AD8FA157B}_is1] : (AnyMP4 Convertisseur 4K 6.0.56.-.AnyMP4 Studio) -> "C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 4K Converter\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{955BF340-C379-4375-AA2F-F3BCB2A498AB}] : (Nero Family and Events Themes.-.Nero AG) -> MsiExec.exe /X{955BF340-C379-4375-AA2F-F3BCB2A498AB}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9569E6BC-326A-432F-97AB-35263A327BF1}] : (Roxio Burn - Secure.-.Roxio) -> MsiExec.exe /I{9569E6BC-326A-432F-97AB-35263A327BF1}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{983FEDDC-AD2E-48D5-8593-331D3B93407C}_is1] : (Online Video Recorder 3.4.4.-.cyan soft ltd) -> "C:\Program Files (x86)\Online Video Recorder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9BF12010-8799-41A5-A671-E9CFDE9E79F3}_is1] : (iSkysoft Helper Compact 2.5.2.-.iSkysoft) -> "C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}] : (SX Network Suite.-.SecurityXploded) -> MsiExec.exe /I{9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9C637A56-4287-487F-95BF-1422FC1AA879}] : (Nero 2016.-.Nero AG) -> MsiExec.exe /I{9C637A56-4287-487F-95BF-1422FC1AA879}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9DAEA76B-E50F-4272-A595-0124E826553D}] : (LWS WLM Plugin.-.Logitech) -> MsiExec.exe /I{9DAEA76B-E50F-4272-A595-0124E826553D}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9F205E94-9E42-4486-A92A-DF3F6CB85444}] : (Epson Event Manager.-.Seiko Epson Corporation) -> MsiExec.exe /X{9F205E94-9E42-4486-A92A-DF3F6CB85444}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A163159C-B476-4501-B163-3F77809AC833}] : (Nero Burning Core.-.Nero AG) -> MsiExec.exe /X{A163159C-B476-4501-B163-3F77809AC833}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A306FD29-7D3A-4287-91AC-9A0180931395}_is1] : (Roadkil's Unstoppable Copier Version 5.2.-.Roadkil.Net) -> "C:\Program Files (x86)\Roadkil.Net\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A49D20B8-A2E7-485D-A4A4-29C475D486F3}_is1] : (Online Video Recorder Extras 3.0.2.-.Avanquest Software) -> "C:\Program Files (x86)\Online Video Recorder\unins001.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}] : (CCC Help Norwegian.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}] : (CCC Help Thai.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AAB42DD0-9551-4E30-A3E4-F87D4A4E1C52}] : (Roxio Creator 2012 Pro.-.Roxio) -> C:\ProgramData\Uninstall\{AAB42DD0-9551-4E30-A3E4-F87D4A4E1C52}\setup.exe /x {AAB42DD0-9551-4E30-A3E4-F87D4A4E1C52} ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ABC88553-8770-4B97-B43E-5A90647A5B63}] : (Nero ControlCenter.-.Nero AG) -> MsiExec.exe /X{ABC88553-8770-4B97-B43E-5A90647A5B63}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ACE49D50-19CD-44A6-B192-46F985283B26}] : (Nero PiP Effects Basic.-.Nero AG) -> MsiExec.exe /X{ACE49D50-19CD-44A6-B192-46F985283B26}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ADD5DB49-72CF-11D8-9D75-000129760D75}] : (CyberLink PowerBackup 2.6.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\Setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ADE1535C-C836-4F2E-BDA1-1C7C304743E3}_is1] : (Auslogics Disk Defrag Professional.-.Auslogics Labs Pty Ltd) -> "C:\Program Files (x86)\Auslogics\Disk Defrag Professional\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}] : (AMD Catalyst Control Center.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingAndroidRecovery}_is1] : (Free Any Android Data Recovery version 6.5.5.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free Any Android Data Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingCameraPhotoRecovery}_is1] : (Free Digital Camera Photo Recovery version 5.8.8.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free Digital Camera Photo Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingDataEncryption}_is1] : (Free Any Data Encryption version 5.1.1.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Free Any Data Encryption\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingExternalDriveRecovery}_is1] : (Free External Hard Drive Recovery version 5.8.8.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free External Hard Drive Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingFileRecovery}_is1] : (Free Any Data Recovery version 6.1.1.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Free Any Data Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingPartitionManager}_is1] : (Free Partition Manager version 5.1.1.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free Partition Manager\unins001.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingPhotoRecovery}_is1] : (Free Any Photo Recovery version 5.8.8.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Free Any Photo Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingScreenRecorder}_is1] : (Free Screen Recorder version 5.1.1.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free Screen Recorder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingSdCardRecovery}_is1] : (Free SD Memory Card Data Recovery version 5.8.8.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free SD Memory Card Data Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AmazingUsbFlashRecovery}_is1] : (Free USB Flash Drive Recovery version 5.8.8.8.-.www.Amazing-Share.com) -> "C:\Program Files (x86)\Amazing-Share\Free USB Flash Drive Recovery\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B07BBB6E-6753-41B0-B4B9-1E9FE4AF5C18}] : (.-.) -> C:\ProgramData\{4C13979D-F8C4-41F2-B4D5-07A2A4FB8F6B}\LavasoftPrivacyToolbox.exe##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}] : (Nero Recode.-.Nero AG) -> MsiExec.exe /X{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B398F6FE-E797-4764-B6F2-C4AE0121A71B}] : (PDQ Inventory.-.Admin Arsenal) -> MsiExec.exe /X{B398F6FE-E797-4764-B6F2-C4AE0121A71B}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B7B58EF9-6307-4DCF-8276-2F17D1E6DE69}] : (PreEmptive Analytics Client French Language Pack.-.PreEmptive Solutions) -> MsiExec.exe /I{B7B58EF9-6307-4DCF-8276-2F17D1E6DE69}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B839153C-D4D2-F89C-5033-0A160C62706B}] : (CCC Help Portuguese.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}] : (SmartSound Common Data.-.SmartSound Software Inc.) -> MsiExec.exe /I{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BBD54A11-C598-4789-8F12-AA189B3374C2}] : (SX Antivirus Kit.-.SecurityXploded) -> MsiExec.exe /I{BBD54A11-C598-4789-8F12-AA189B3374C2}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BD3EAE4D-862D-4D41-8BB5-F5C2CFFE6022}] : (Roxio BackOnTrackPE.-.Roxio) -> MsiExec.exe /I{BD3EAE4D-862D-4D41-8BB5-F5C2CFFE6022}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}] : (Nero Disc to Device.-.Nero AG) -> MsiExec.exe /X{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}] : (Nero Core Components.-.Nero AG) -> MsiExec.exe /X{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C1EA3764-1138-AE27-AD63-549BAD99BA15}] : (CCC Help Japanese.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C257E434-E8F1-4E06-A616-598E4933553E}_is1] : (File Identifier.-.Sharpened Productions) -> "C:\Program Files (x86)\File Identifier\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C2E9BCE3-56A8-4A85-9944-6FF3DDCCE816}_is1] : (Remo Repair ZIP.-.Remo Software) -> "C:\Program Files (x86)\Remo Repair ZIP 2.0\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}] : (CCC Help Czech.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C3E8DEF8-0993-4828-9C95-4FB450AE45C1}_is1] : (Fast File Copy version 1.0.-.Daanav Softwares) -> "C:\Program Files (x86)\Fast File Copy by Daanav.com\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}] : (Nero Image Samples.-.Nero AG) -> MsiExec.exe /X{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243}] : (CyberLink LabelPrint 2.5.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1] : (SRWare Iron version 59.0.3100.0.-.SRWare) -> "C:\Program Files (x86)\SRWare Iron\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}] : (CCC Help Dutch.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CB84FEF5-C573-4328-B9AF-B28568A4E10E}_is1] : (Kastor - All Video Downloader V 6.0.0.-.KastorSoft) -> "C:\Program Files (x86)\Kastor All Video Downloader\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CB84FEF6-C573-4328-B9A4-B29568A4E10E}_is1] : (Kastor - Stream Recorder V 1.0.-.KastorSoft) -> "C:\Program Files (x86)\Kastor Stream Recorder\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CDE9C04A-7F8B-40A8-A4A5-875E228254A6}] : (Roxio Creator Content 2012.-.Roxio) -> MsiExec.exe /X{CDE9C04A-7F8B-40A8-A4A5-875E228254A6}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CE675FBD-75C3-45F1-B6AF-8D250861D536}] : (Nero Disc Menus 3.-.Nero AG) -> MsiExec.exe /X{CE675FBD-75C3-45F1-B6AF-8D250861D536}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CE86D656-C887-4EF1-B2D7-2A1075435964}] : (Face Filter.-.Roxio) -> MsiExec.exe /I{CE86D656-C887-4EF1-B2D7-2A1075435964}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CEAC6D9F-944A-40F7-AB5D-A7412AF9CED9}] : (Acronis True Image WD Edition.-.Acronis) -> MsiExec.exe /X{CEAC6D9F-944A-40F7-AB5D-A7412AF9CED9}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}] : (Nero Burning ROM.-.Nero AG) -> MsiExec.exe /X{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{d031074f-a076-4a91-a6ed-770029b50a1b}_is1] : (GiliSoft Video Cutter 7.1.0.-.GiliSoft International LLC.) -> "C:\Program Files (x86)\GiliSoft\Video Cutter\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1] : (ISO to USB.-.isotousb.com) -> "C:\Program Files (x86)\ISO to USB\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{d0fb92d2-ec66-4b32-991e-b8e207090a64}] : (Ad-Aware Browser.-.Lavasoft) -> C:\Program Files (x86)\Ad-Aware Browser\AdAwareBrowserInstaller.exe --uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D15BFD7F-6BBA-49A7-A6B1-14C00DCA6842}] : (CyberLink PowerDVD 17.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{D15BFD7F-6BBA-49A7-A6B1-14C00DCA6842}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{D15BFD7F-6BBA-49A7-A6B1-14C00DCA6842}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D16A31F9-276D-4968-A753-FFEAC56995D0}] : (Epson Print CD.-.Seiko Epson Corporation) -> "C:\Program Files (x86)\InstallShield Installation Information\{D16A31F9-276D-4968-A753-FFEAC56995D0}\setup.exe" -runfromtemp -removeonly##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D25D3E15-CABD-420c-B62C-70C1C5EE63FD}] : (CyberLink Application Manager.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D25D3E15-CABD-420c-B62C-70C1C5EE63FD}\setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D3A5E63A-5648-48D8-9283-149D9BFE44E9}_is1] : (Remo Repair Word.-.Remo Software) -> "C:\Program Files (x86)\Remo Repair Word 2.0\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D40EB009-0499-459c-A8AF-C9C110766215}] : (Logitech Webcam Software.-.Logitech Inc.) -> "C:\Program Files (x86)\Common Files\LogiShrd\Installer\{D40EB009-0499-459c-A8AF-C9C110766215}\setup.exe" /lang=FRA /guid="{D40EB009-0499-459c-A8AF-C9C110766215}"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1] : (aTube Catcher version 3.8.-.DsNET Corp) -> "C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}] : (SX System Suite.-.SecurityXploded) -> MsiExec.exe /I{D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D627784F-B3EE-44E8-96B1-9509B991EA34}_is1] : (Auslogics Registry Defrag.-.Auslogics Labs Pty Ltd) -> "C:\Program Files (x86)\Auslogics\Registry Defrag\unins000.exe"[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D881F038-D767-45AA-90C1-1E5411A9670A}] : (e-Carte Bleue Caisse d'Epargne.-.e-Carte Bleue Caisse d'Epargne) -> MsiExec.exe /I{D881F038-D767-45AA-90C1-1E5411A9670A}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DD3D64A7-3165-458D-96D4-06FBC609C22A}] : (Google Ad Blocker.-.SecurityXploded) -> MsiExec.exe /I{DD3D64A7-3165-458D-96D4-06FBC609C22A}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DEF2E5A3-0317-4822-B930-8B721EB483E4}] : (ArcSoft VideoImpression 1.6.-.) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{DEF2E5A3-0317-4822-B930-8B721EB483E4}\setup.exe" -l0x40c -uninst ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}] : (Nero Disc Menus Basic.-.Nero AG) -> MsiExec.exe /X{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{e34dc417-19f0-4881-8438-130eeb95d85b}] : (Paragon Backup & Recovery™ 16.-.Paragon Software GmbH) -> "C:\ProgramData\Package Cache\{e34dc417-19f0-4881-8438-130eeb95d85b}\BR16_x64_ea.exe" /uninstall##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E3D04529-6EDB-11D8-A372-0050BAE317E1}] : (CyberLink PowerDVD Copy 1.5.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\Setup.exe" /z-uninstall[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E51C8DC9-BFE1-433F-8339-EA2321EF9F12}] : (InPixio Photo Editor.-.InPixio) -> "C:\Program Files (x86)\InstallShield Installation Information\{E51C8DC9-BFE1-433F-8339-EA2321EF9F12}\ISAdmin.exe" -runfromtemp -l0x040c -removeonly##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}] : (Advanced Windows Service Manager.-.SecurityXploded) -> MsiExec.exe /I{E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E6F5D79A-A339-45B9-B072-3BFF5929A86B}_is1] : (Super Password version 1.0.1.-.Hexameter Ltd) -> "C:\Program Files (x86)\Super Password\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E817E580-6318-AFC8-2102-322C73117EC4}] : (CCC Help Polish.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EE843B49-D9BC-4A9E-A8A7-B9F14C0381C7}_is1] : (Wondershare MirrorGo(Version 1.9.0).-.Wondershare) -> "C:\Program Files (x86)\Wondershare\MirrorGo\unins000.exe" /WAF##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EEBF1676-AF87-4266-93D8-0C14A34C4217}] : (Nero Disc Menus 1.-.Nero AG) -> MsiExec.exe /X{EEBF1676-AF87-4266-93D8-0C14A34C4217}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EF0BA418-AF37-471E-9594-EAE5913F4681}] : (Nero Launcher.-.Nero AG) -> MsiExec.exe /X{EF0BA418-AF37-471E-9594-EAE5913F4681}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F030BFE8-8476-4C08-A553-233DE80A2BE1}] : (Nero Info.-.Nero AG) -> MsiExec.exe /X{F030BFE8-8476-4C08-A553-233DE80A2BE1}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F0CF025B-D6F3-4F7C-939B-23291F52875C}] : (Paragon ExtFS for Windows.-.Paragon Software) -> MsiExec.exe /X{F0CF025B-D6F3-4F7C-939B-23291F52875C}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}] : (Realtek High Definition Audio Driver.-.Realtek Semiconductor Corp.) -> C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F53529E7-07B1-409A-ACE0-3910D2338D12}] : (Roxio Creator 2012 Pro.-.Roxio) -> MsiExec.exe /I{F53529E7-07B1-409A-ACE0-3910D2338D12}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F77474EE-EB6C-C87B-88AF-3310C848E068}] : (CCC Help Greek.-.Advanced Micro Devices, Inc.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}] : (SX WiFi Security Suite.-.SecurityXploded) -> MsiExec.exe /I{F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F8C774EE-B937-4694-9BE4-D20167FCF20F}] : (Laplink PCmover Professional.-.Laplink Software, Inc.) -> MsiExec.exe /X{F8C774EE-B937-4694-9BE4-D20167FCF20F}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}] : (CCC Help Danish.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FA285575-B543-4E6E-A573-A4F534AC9965}] : (CyberLink PowerDirector 15.-.CyberLink Corp.) -> C:\Program Files (x86)\NSIS Uninstall Information\{FA285575-B543-4E6E-A573-A4F534AC9965}\Setup.exe _?=C:\Program Files (x86)\NSIS Uninstall Information\{FA285575-B543-4E6E-A573-A4F534AC9965}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1] : (Windscribe version 1.70 build 4.-.Windscribe) -> "C:\Program Files (x86)\Windscribe\unins000.exe"##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}] : (Nero Disc Menus 2.-.Nero AG) -> MsiExec.exe /X{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}] : (LWS Facebook.-.Logitech) -> MsiExec.exe /I{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FFAC39DA-CF79-434B-A6E0-4055689667D9}] : (Roxio CinePlayer Decoder Pack.-.Roxio) -> MsiExec.exe /I{FFAC39DA-CF79-434B-A6E0-4055689667D9}[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{{91D821C9-ED4D-ED57-E224-CEF877967911}}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{{CA916A4C-52F7-5055-975F-9B4AD4204007}}] : (.-.) -> ---------- | Ports ---------- | Microsoft Specifications CheckID: AutoPlay999{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{BD6F4D10-E29E-49E3-8497-1D454AF5EEF8} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: FT_Mvc_VisualStudio140{44A100D0-C1AE-4BB7-A0CC-AA60B7566681} - NOT VS_INSTALL_DIR -> FT_Mvc_VisualStudio14CheckID: FT_TestTemplates_VisualStudio140{44A100D0-C1AE-4BB7-A0CC-AA60B7566681} - NOT VS_INSTALL_DIR OR NOT VISUALSTUDIO_TEST_PROJECTS -> FT_TestTemplates_VisualStudio14CheckID: FT_WebPages_VisualStudio140{C24A0C03-69ED-4AF8-9E79-52C1A72D2F7B} - NOT VS_INSTALL_DIR -> FT_WebPages_VisualStudio14CheckID: FileAssociations999{ABC88553-8770-4B97-B43E-5A90647A5B63} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: FT_WebPages_VisualStudio140{65A12DD3-9992-47D2-8BA2-510CA59F893F} - NOT VS_INSTALL_DIR -> FT_WebPages_VisualStudio14CheckID: AutoPlay999{60251665-84B4-41D6-84BF-6D50CE68DD08} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{60251665-84B4-41D6-84BF-6D50CE68DD08} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AutoPlay999{92EBE575-0C6E-4713-B095-34BB927E5AC6} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{92EBE575-0C6E-4713-B095-34BB927E5AC6} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: FT_Mvc_VisualStudio140{240E3426-3B55-4AE9-BB63-742651900BC4} - NOT VS_INSTALL_DIR -> FT_Mvc_VisualStudio14CheckID: FT_TestTemplates_VisualStudio140{240E3426-3B55-4AE9-BB63-742651900BC4} - NOT VS_INSTALL_DIR OR NOT VISUALSTUDIO_TEST_PROJECTS -> FT_TestTemplates_VisualStudio14CheckID: ExtensionsFeature0{603DCF17-E958-3A31-AFED-919086709DB6} - NOT VISUALSTUDIO_INSTALLDIR -> ExtensionsFeatureCheckID: AutoPlay999{7F22DD97-256D-491D-9090-743FADC79BBE} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{7F22DD97-256D-491D-9090-743FADC79BBE} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AAC_Decoding0{F53529E7-07B1-409A-ACE0-3910D2338D12} - AAC_DECODE_INCLUDED="0" -> AAC_DecodingCheckID: AAC_Encoding0{F53529E7-07B1-409A-ACE0-3910D2338D12} - AAC_ENCODE_INCLUDED="0" -> AAC_EncodingCheckID: MPEG20{F53529E7-07B1-409A-ACE0-3910D2338D12} - MPEG2_INCLUDED="0" -> MPEG2CheckID: AC30{F53529E7-07B1-409A-ACE0-3910D2338D12} - AC3ENCODE_INCLUDED="0" -> AC3CheckID: AC3Decode0{F53529E7-07B1-409A-ACE0-3910D2338D12} - AC3DECODE_INCLUDED="0" -> AC3DecodeCheckID: AudioMaster0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideAM = "1" -> AudioMasterCheckID: CreatorClassic0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideCC="1" -> CreatorClassicCheckID: VideoWave0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideVW = "1" -> VideoWaveCheckID: DVDBuilder0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideDVD ="1" -> DVDBuilderCheckID: EmailWizard0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideEM="1" -> EmailWizardCheckID: LabelCreator0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideLC = "1" -> LabelCreatorCheckID: MediaManager0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideMM="1" -> MediaManagerCheckID: PhotoCreator3D0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HIDEPS = "1" -> PhotoCreator3DCheckID: PhotoSuite0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HIDEPS = "1" -> PhotoSuiteCheckID: SonicHTTPClient0{F53529E7-07B1-409A-ACE0-3910D2338D12} - ACTIVATION_INCLUDED="Yes" -> SonicHTTPClientCheckID: SoundEditor0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideSE = "1" -> SoundEditorCheckID: VideoConvert0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideVC = "1" -> VideoConvertCheckID: VirtualDrive0{F53529E7-07B1-409A-ACE0-3910D2338D12} - HideDL="1" -> VirtualDriveCheckID: AutoPlay999{EF0BA418-AF37-471E-9594-EAE5913F4681} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{EF0BA418-AF37-471E-9594-EAE5913F4681} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AutoPlay999{F030BFE8-8476-4C08-A553-233DE80A2BE1} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{F030BFE8-8476-4C08-A553-233DE80A2BE1} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: ExtensionsFeature0{349DE029-E451-3661-A181-F29CE6F94349} - NOT VISUALSTUDIO_INSTALLDIR -> ExtensionsFeatureCheckID: FT_VisualStudio14_WebFXTools0{91D821C9-ED4D-ED57-E224-CEF877967911} - NOT VS_INSTALL_DIR -> FT_VisualStudio14_WebFXToolsCheckID: fe1559e6e1022144a8b5b0ae14281475a31{97B6FAD9-6F14-CC46-3165-F1785ECCE255} - "AMD64" ~= %PROCESSOR_ARCHITECTURE -> fe1559e6e1022144a8b5b0ae14281475a3CheckID: MyDVDContent0{CDE9C04A-7F8B-40A8-A4A5-875E228254A6} - INSTALL_MYDVD = "0" -> MyDVDContentCheckID: PhotoSuiteContent0{CDE9C04A-7F8B-40A8-A4A5-875E228254A6} - INSTALL_PS = "0" -> PhotoSuiteContentCheckID: AutoPlay999{1C63279A-BF36-4852-9924-B1978D6585A6} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{1C63279A-BF36-4852-9924-B1978D6585A6} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: Dev14ToolsLP_FRA1{1914EF4B-70F3-47AA-90A2-B5FB0C45E45D} - DIR_VS14 <> "" -> Dev14ToolsLP_FRACheckID: dokanlib.x640{F0CF025B-D6F3-4F7C-939B-23291F52875C} - Not VersionNT64 -> dokanlib.x64CheckID: dokandrv.x640{F0CF025B-D6F3-4F7C-939B-23291F52875C} - Not VersionNT64 -> dokandrv.x64CheckID: AutoPlay999{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: CrossFeature1{77BE1F2C-552C-438E-8E6B-4C0816BDEC5D} - CopyOfPlatformFiles = "yes" -> CrossFeatureCheckID: FT_VisualStudio14_WebFXTools0{CA916A4C-52F7-5055-975F-9B4AD4204007} - NOT VS_INSTALL_DIR -> FT_VisualStudio14_WebFXToolsCheckID: AutoPlay999{A163159C-B476-4501-B163-3F77809AC833} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{A163159C-B476-4501-B163-3F77809AC833} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AutoPlay999{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AutoPlay999{910B539D-F257-46C8-9CB8-6C95EFF9CF22} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{910B539D-F257-46C8-9CB8-6C95EFF9CF22} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AutoPlay999{6861C1AD-9829-4DE4-8647-4785ECEA421A} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{6861C1AD-9829-4DE4-8647-4785ECEA421A} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: AutoPlay999{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} - NERO.INSTALL_AUTOPLAY=0 -> AutoPlayCheckID: FileAssociations999{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4} - NERO.INSTALL_EXTENSIONS=0 -> FileAssociationsCheckID: fe691cf2e12069492d90ac31389ed768161{5247E16E-BCF8-95AB-1653-B3F8FBF8B3F1} - ("AMD64" ~= %PROCESSOR_ARCHITECTURE) AND ("x64" ~= ProductArchitecture) -> fe691cf2e12069492d90ac31389ed76816 ---------- | CLSID ---------- | Installer [HKCR\Installer\Products\00058CD18F0BF523DA1072073D56715D] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\005B5C34BE83F654C817ECB7F1F79967] : VirusTotal Scanner -> C:\WINDOWS\Installer\{43C5B500-38EB-456F-8C71-CE7B1F7F9976}\GooglePasswordDecryptor.exe[HKCR\Installer\Products\01D4F6DBE92E3E944879D154A45FEE8F] : Nero Disc to Device[HKCR\Installer\Products\026F45BF555911A362BC0B724CDD2F06] : Imaging Designer[HKCR\Installer\Products\03E7DF311F2DD894BA2C4A42D26B16E0] : IIS 10.0 Express -> C:\WINDOWS\Installer\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}\Icon_IisExpress[HKCR\Installer\Products\03FEB5E3269374B4EAAC39B7C6BBA086] : AvcEngine -> C:\WINDOWS\Installer\{3E5BEF30-3962-4B47-AECA-937B6CBB0A68}\ARPPRODUCTICON.exe[HKCR\Installer\Products\043FB559973C5734AAF23FCB2B4A89BA] : Nero Family and Events Themes -> C:\WINDOWS\Installer\{955BF340-C379-4375-AA2F-F3BCB2A498AB}\ARPPRODUCTICON.exe[HKCR\Installer\Products\04B0AFAF67FA8514D9AFD10225DC9036] : Composants requis pour SSDT -> C:\WINDOWS\Installer\{FAFA0B40-AF76-4158-9DFA-1D2052CD0963}\ARPIco[HKCR\Installer\Products\04FE16E415A899D3AAC4232F30730038] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\05D94ECADC916A441B29649F5882B362] : Nero PiP Effects Basic -> C:\WINDOWS\Installer\{ACE49D50-19CD-44A6-B192-46F985283B26}\ARPPRODUCTICON.exe[HKCR\Installer\Products\060DED06B6B01CC39B550DDC04F1F0AB] : Visual C++ IDE x64 Package[HKCR\Installer\Products\070DA1A8F96251A4AA5B67BA98E61F59] : Azure AD Authentication Connected Service[HKCR\Installer\Products\085E718E81368CFA122023C23711E74C] : CCC Help Polish -> C:\WINDOWS\Installer\{E817E580-6318-AFC8-2102-322C73117EC4}\ARPPRODUCTICON.exe[HKCR\Installer\Products\08735E734493A6A448F22717828E16E6] : Blend for Visual Studio SDK for .NET 4.5 -> C:\WINDOWS\Installer\{37E53780-3944-4A6A-842F-727128E8616E}\Application[HKCR\Installer\Products\088DABA7E41D4D84E9DF0C5B13AA65E6] : Module linguistique de Dotfuscator and Analytics Community Edition 5.22.0 fr-FR -> C:\WINDOWS\Installer\{7ABAD880-D14E-48D4-9EFD-C0B531AA566E}\DfIcon.ico[HKCR\Installer\Products\0A39224443547883CA4B78B6D3A55E41] : Visual C++ IDE Common Resource Package[HKCR\Installer\Products\0BA78AB755027E11E86100C092297F90] : Foxit PhantomPDF -> C:\WINDOWS\Installer\{7BA87AB0-2055-11E7-8E16-000C2992F709}\IconName.exe[HKCR\Installer\Products\0BE6E9B4DEE047E449979F283C52F417] : SQL Server Browser for SQL Server 2012 -> C:\WINDOWS\Installer\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}\ARPIco[HKCR\Installer\Products\0CCA1DC70DD34984097CFBA231C670D4] : [HKCR\Installer\Products\0D4A6A5A500250A2E212948580FC59DE] : CCC Help Norwegian -> C:\WINDOWS\Installer\{A5A6A4D0-2005-2A05-2E21-495808CF95ED}\ARPPRODUCTICON.exe[HKCR\Installer\Products\0D7D1075525004A3E8DC53B1DEB04DDA] : Visual C++ IDE Base Resource Package[HKCR\Installer\Products\0D98B927A649E7041A1243B33D23C004] : Roxio BackOnTrack[HKCR\Installer\Products\0E23F3A71E8D1C04E8B1F165392FDA0E] : [HKCR\Installer\Products\0EA8C7F7B169DEA49BA99DEB920C2FC4] : AdAwareProxyEngine -> C:\WINDOWS\Installer\{7F7C8AE0-961B-4AED-B99A-D9BE29C0F24C}\ARPPRODUCTICON.exe[HKCR\Installer\Products\0EF46B181CD54D535AE1DA1108C325C0] : Visual C++ IDE Core Package[HKCR\Installer\Products\0F76E360892CA2A8F06A481C35224A0E] : ccc-utility64 -> C:\WINDOWS\Installer\{063E67F0-C298-8A2A-0FA6-84C15322A4E0}\ARPPRODUCTICON.exe[HKCR\Installer\Products\10743651ECAB9444B8525176ADC8F93D] : CameraHelperMsi[HKCR\Installer\Products\10D8192B98D13D4378FE2A1812CBE67B] : VS Update core components[HKCR\Installer\Products\11A45DBB895C9874F821AA81B933472C] : SX Antivirus Kit -> C:\WINDOWS\Installer\{BBD54A11-C598-4789-8F12-AA189B3374C2}\SXAntivirusKit.exe[HKCR\Installer\Products\13B3A47134C4DD3468F6379CBD88B784] : LWS Twitter[HKCR\Installer\Products\13EB9E64CD0779742AB4BCF70FBB86BB] : FileOpen[HKCR\Installer\Products\157286B2947EC1444A3BF135E8625EE6] : Roxio System Rollback Recovery Disk[HKCR\Installer\Products\15E5F6B1E5753964CB2A573475D070D6] : Nero Kwik Themes Basic -> C:\WINDOWS\Installer\{1B6F5E51-575E-4693-BCA2-7543570D076D}\ARPPRODUCTICON.exe[HKCR\Installer\Products\166F59DC4C5A5F446AAACEDD192C14B0] : WinZip 21.0[HKCR\Installer\Products\188D52D43817F264598C99C01A49E4B0] : Nero PiP Effects 1 -> C:\WINDOWS\Installer\{4D25D881-7183-462F-95C8-990CA1944E0B}\ARPPRODUCTICON.exe[HKCR\Installer\Products\19D372D15D7D6304B848BE6451FFF518] : SmartSound Sonicfire Pro 5 -> C:\WINDOWS\Installer\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}\ARPPRODUCTICON.exe[HKCR\Installer\Products\1A15D4212C3FEA548B213DAC17420739] : SQL Server 2012 Common Files[HKCR\Installer\Products\1C2B4FAA72E2FE64B9E9B212030F653F] : FirewallEngine -> C:\WINDOWS\Installer\{AAF4B2C1-2E27-46EF-9B9E-2B2130F056F3}\ARPPRODUCTICON.exe[HKCR\Installer\Products\1D5F27E1E3559FFC603AC8A55F70DDC1] : CCC Help French -> C:\WINDOWS\Installer\{1E72F5D1-553E-CFF9-06A3-8C5AF507DD1C}\ARPPRODUCTICON.exe[HKCR\Installer\Products\1E6AF1658349876ED2A2AC998FDDBF0C] : Windows Assessment Services - Client (AMD64 Architecture Specific, Client SKU)[HKCR\Installer\Products\1F88D051FA0487643AD9CB2E33F2435E] : Nero Abstract Themes -> C:\WINDOWS\Installer\{150D88F1-40AF-4678-A39D-BCE2332F34E5}\ARPPRODUCTICON.exe[HKCR\Installer\Products\21E13F622273DF5409B394102268BBC4] : OnlineThreatsEngine -> C:\WINDOWS\Installer\{26F31E12-3722-45FD-903B-49012286BB4C}\ARPPRODUCTICON.exe[HKCR\Installer\Products\234989D47D950A67DD159B46226FFFF7] : Windows Phone Common Packaging and Test Tools (NT_x86_fre)[HKCR\Installer\Products\239FD3BA099C4D43FB3479F067D03ADC] : vs_update3notification[HKCR\Installer\Products\23B5E0C9FAB704E419F6C503AE7F2F9F] : SX Network Suite -> C:\WINDOWS\Installer\{9C0E5B32-7BAF-4E40-916F-5C30EAF7F2F9}\sxnetworksuite.exe[HKCR\Installer\Products\241A5D4605DBE627DEE92D05D8A2712E] : Catalyst Control Center InstallProxy -> C:\WINDOWS\Installer\{64D5A142-BD50-726E-ED9E-D2508D2A17E2}\ARPPRODUCTICON.exe[HKCR\Installer\Products\263AC5E16B930DB49B0C96FC510FEF2A] : AzureTools.Notifications[HKCR\Installer\Products\26A859D1089C7BC3CA9504FED0F18AE0] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\2C31622C4A7C16749A6011E6DCE44777] : SQL Server 2012 Database Engine Services[HKCR\Installer\Products\2E4D4D948E1264334A69A141511B5849] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\2EB941D82456A6F4EA4CD7166ECDEABF] : [HKCR\Installer\Products\2F12AC03A109BD444AF3CF13DCF04239] : Sql Server Customer Experience Improvement Program -> C:\WINDOWS\Installer\{30CA21F2-901A-44DB-A43F-FC31CD0F2493}\ARPIco[HKCR\Installer\Products\307BCCF8FBF37e944AF38AE1729D0BE7] : MediaShow -> C:\WINDOWS\Installer\{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}\ARPPRODUCTICON.exe[HKCR\Installer\Products\317725EEA8EBA8438845ADBCEC35612F] : Visual C++ MSBuild X64 Package[HKCR\Installer\Products\33305D78435EA394E889A094CB826FB4] : SQL Server 2012 Database Engine Services[HKCR\Installer\Products\34DFCB3A6D8523137AFD61EC40763227] : Visual Studio 2012 Verification SDK[HKCR\Installer\Products\35588CBA077879B44BE3A50946A7B536] : Nero ControlCenter -> C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ARPPRODUCTICON.exe[HKCR\Installer\Products\36978F1ADBDFB4635892B513D2250944] : Visual C++ Compiler/Tools X86 Base Resource Package[HKCR\Installer\Products\36DE92D79F487CE44BF999A4A313592B] : SQL Server 2012 Common Files[HKCR\Installer\Products\37298633C4F0DA04EABF9585F38067D7] : Composants nécessaires pour SSDT -> C:\WINDOWS\Installer\{33689273-0F4C-40AD-AEFB-59583F08767D}\ARPIco[HKCR\Installer\Products\375E4A382C2EBF64D96AA6B2BB5F5A88] : Nero Retro Film Themes -> C:\WINDOWS\Installer\{83A4E573-E2C2-46FB-9DA6-6A2BBBF5A588}\ARPPRODUCTICON.exe[HKCR\Installer\Products\37E58BB129D0A406A0FA7CAA5D3E3A6C] : CCC Help English -> C:\WINDOWS\Installer\{1BB85E73-0D92-604A-0AAF-C7AAD5E3A3C6}\ARPPRODUCTICON.exe[HKCR\Installer\Products\384482F5D8EEE744EBEBB21FB3804CFB] : Prerequisite installer -> C:\WINDOWS\Installer\{5F284483-EE8D-447E-BEBE-2BF13B08C4BF}\ARPPRODUCTICON.exe[HKCR\Installer\Products\39753950C43A27243316A79FEAEE6594] : Imaging And Configuration Designer[HKCR\Installer\Products\3978828F6B15FE74F2393D777666F35C] : Assessments on Client[HKCR\Installer\Products\39B33D60854982E4DBAE5FCE2B3C3CE0] : AntimalwareEngine -> C:\WINDOWS\Installer\{06D33B93-9458-4E28-BDEA-F5ECB2C3C30E}\ARPPRODUCTICON.exe[HKCR\Installer\Products\39E186EDACC5EC638A4EA2FEED987F9E] : Visual C++ Compiler/Tools X86 Base Resource Package[HKCR\Installer\Products\3A56CBC8BA0456EDC21B99A7DB8ADF86] : CCC Help Turkish -> C:\WINDOWS\Installer\{8CBC65A3-40AB-DE65-2CB1-997ABDA8FD68}\ARPPRODUCTICON.exe[HKCR\Installer\Products\3C1BCDF6CDE9CBC374C3DD58DEE54049] : CCC Help German -> C:\WINDOWS\Installer\{6FDCB1C3-9EDC-3CBC-473C-DD85ED5E0494}\ARPPRODUCTICON.exe[HKCR\Installer\Products\3CB65822398FFBC4592F1E6FC32D1BBA] : Nero Video Transitions 1 -> C:\WINDOWS\Installer\{22856BC3-F893-4CBF-95F2-E1F63CD2B1AB}\ARPPRODUCTICON.exe[HKCR\Installer\Products\3D4250324BDACC96A287698D973E22B1] : Windows PE x86 x64[HKCR\Installer\Products\3FD1021D439FA2435A68B252C58B2B51] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\4003DA6594B0F7696F280B65056BA187] : Windows Software Development Kit for Windows Store Apps DirectX x86 Remote[HKCR\Installer\Products\401EEA7469FB704E3DEF08BB4D72234F] : Windows PE x86 x64 wims[HKCR\Installer\Products\40EF163FE9873F24BBBA7E3B08AAE560] : Windows XP Targeting with C++[HKCR\Installer\Products\4171AC28AE31914F19EF2138444247E5] : CCC Help Italian -> C:\WINDOWS\Installer\{82CA1714-13EA-F419-91FE-12834424745E}\ARPPRODUCTICON.exe[HKCR\Installer\Products\41D30C80916B6DC439F82CBB6539460E] : FF Copy -> C:\WINDOWS\Installer\{08C03D14-B619-4CD6-938F-C2BB569364E0}\_6FEFF9B68218417F98F549.exe[HKCR\Installer\Products\42ACA5646D8BCEF44AD2E9CF9BC25D06] : TypeScript Power Tool -> C:\WINDOWS\Installer\{465ACA24-B8D6-4FEC-A42D-9EFCB92CD560}\TypeScriptIcon.ico[HKCR\Installer\Products\42C6FBF1Df1C10144AB2C065F4E9E897] : [HKCR\Installer\Products\42D654B067DD36141857F427E0F6C329] : calibre -> C:\WINDOWS\Installer\{0B456D24-DD76-4163-8175-4F720E6F3C92}\main_icon[HKCR\Installer\Products\42D78011D76588D7966C7D0AB8F5C474] : Catalyst Control Center - Branding -> C:\WINDOWS\Installer\{11087D24-567D-7D88-69C6-D7A08B5F4C47}\ARPPRODUCTICON.exe[HKCR\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1A] : Online Application -> C:\WINDOWS\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\online.exe[HKCR\Installer\Products\43A8FD62E4CCB143280A16D21412FCC6] : Roslyn Language Services - x86[HKCR\Installer\Products\443F20AFD3F8CDE479AD7A4B64E97CE2] : Paragon Backup & Recovery™ 16[HKCR\Installer\Products\4561C821E9B39594B8BFECF6900C0AD1] : MSBuild/NuGet Integration 14.0 (x86)[HKCR\Installer\Products\4631232B829ED5239A4539D35332B95E] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\4673AE1C831172EADA3645B9DA99AB51] : CCC Help Japanese -> C:\WINDOWS\Installer\{C1EA3764-1138-AE27-AD63-549BAD99BA15}\ARPPRODUCTICON.exe[HKCR\Installer\Products\472D7398182C4E24C8BD0A2BFD791998] : LWS Webcam Software[HKCR\Installer\Products\4751CE118CE368335BD1247C55A6490D] : Assemblys du Kit de développement logiciel (SDK) Windows Phone 8.0 pour Visual Studio 2015 - FRA[HKCR\Installer\Products\47B800D0226053F770197C3624F79396] : Volume Activation Management Tool[HKCR\Installer\Products\484E6865631747644A2B05C8B762CD4A] : LiteManager Pro - Viewer -> C:\WINDOWS\Installer\{5686E484-7136-4674-A4B2-508C7B26DCA4}\ARPPRODUCTICON.exe[HKCR\Installer\Products\48D76F9207A3E65408A62503B12070B0] : Nero Effects Basic -> C:\WINDOWS\Installer\{29F67D84-3A70-456E-806A-52301B02070B}\ARPPRODUCTICON.exe[HKCR\Installer\Products\4920FD12D9B61474BAF62BBABF2D83E7] : LWS YouTube Plugin[HKCR\Installer\Products\495334533A58AEE369E3E0E568B0286D] : Visual C++ MSBuild Base Package[HKCR\Installer\Products\496A34161EF56FDB7FE8F4B73F9E14B9] : Toolkit Documentation[HKCR\Installer\Products\49E502F924E968449AA2FDF3C68B4544] : Epson Event Manager -> C:\WINDOWS\Installer\{9F205E94-9E42-4486-A92A-DF3F6CB85444}\icon.exe[HKCR\Installer\Products\4E75276CC42F53C368BB9E7B5D4D9DBF] : Visual C++ IDE Professional Core Package[HKCR\Installer\Products\5025450D2EDA3CB4CBC8D9921ACDECD2] : Active Directory Authentication Library pour SQL Server (x86) -> C:\WINDOWS\Installer\{D0545205-ADE2-4BC3-BC8C-9D29A1DCCE2D}\ARPIco[HKCR\Installer\Products\50848F456110F764783198D9CF742253] : SQL Server 2012 Database Engine Shared[HKCR\Installer\Products\5104B339816461748A822598CF3061F5] : VC80CRTRedist - 8.0.50727.6195[HKCR\Installer\Products\5122AD3302FA12F31A17750F35A3C5FA] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\514D163353AB34143B10669119AB2691] : MyEpson Portal[HKCR\Installer\Products\5173F3A735977424B8C5D53050B0E99A] : [HKCR\Installer\Products\51E3D52DDBACc0246BC2071C5CEE36DF] : Application Manager -> C:\WINDOWS\Installer\{D25D3E15-CABD-420c-B62C-70C1C5EE63FD}\ARPPRODUCTICON.exe[HKCR\Installer\Products\52FD6C4C95E0EE642BB4FD78948DFFA3] : Nero Image Samples -> C:\WINDOWS\Installer\{C4C6DF25-0E59-46EE-B24B-DF8749D8FF3A}\ARPPRODUCTICON.exe[HKCR\Installer\Products\54D9CEFB4DABC7D36B7A88D7126E2CA5] : Visual C++ Compiler/Tools X86 Base Package[HKCR\Installer\Products\5517DCEB75CD98F41B8A9AB030C32690] : AdAwareUpdater -> C:\WINDOWS\Installer\{BECD7155-DC57-4F89-B1A8-A90B033C6209}\ARPPRODUCTICON.exe[HKCR\Installer\Products\554590D7179DC4D4E9DFA96F6A85F4A3] : Bing Bureau -> C:\WINDOWS\Installer\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}\icon.ico[HKCR\Installer\Products\566152064B486D1448FBD605EC86DD80] : Nero Express -> C:\WINDOWS\Installer\{60251665-84B4-41D6-84BF-6D50CE68DD08}\ARPPRODUCTICON.exe[HKCR\Installer\Products\574AFF175D42BF445AF1936B993E8DC2] : LiteManager Pro - Server -> C:\WINDOWS\Installer\{71FFA475-24D5-44FB-A51F-39B699E3D82C}\ARPPRODUCTICON.exe[HKCR\Installer\Products\575582AF345BE6E45A374A5F43CA9956] : [HKCR\Installer\Products\575EBE29E6C031740B5943BB29E7A56C] : Nero CoverDesigner -> C:\WINDOWS\Installer\{92EBE575-0C6E-4713-B095-34BB927E5AC6}\ARPPRODUCTICON.exe[HKCR\Installer\Products\578F71502BBB21846AE337B333EC2F51] : Roxio System Rollback -> C:\WINDOWS\Installer\{0517F875-BBB2-4812-A63E-733B33CEF215}\BackupCentral.exe[HKCR\Installer\Products\591761FF4EE90C64C87DBF3A54E788BA] : LWS Facebook[HKCR\Installer\Products\59EBDD8FEBCD5B303595ED631041E612] : CCC Help Danish -> C:\WINDOWS\Installer\{F8DDBE95-DCBE-03B5-5359-DE3601146E21}\ARPPRODUCTICON.exe[HKCR\Installer\Products\5B6E18EFB2567E043B2B17176C2F79AD] : Nero Disc Menus 2 -> C:\WINDOWS\Installer\{FE81E6B5-652B-40E7-B3B2-7171C6F297DA}\ARPPRODUCTICON.exe[HKCR\Installer\Products\5C894BC8B276C6F31934480BBB1CAE3B] : Visual C++ MSBuild X86 Package[HKCR\Installer\Products\5E16E053C2C6C3F2A341E790A46B3D0A] : CCC Help Spanish -> C:\WINDOWS\Installer\{350E61E5-6C2C-2F3C-3A14-7E094AB6D3A0}\ARPPRODUCTICON.exe[HKCR\Installer\Products\5E921ED7A4BB71546ADC6CE9BE437618] : AntispamEngine -> C:\WINDOWS\Installer\{7DE129E5-BB4A-4517-A6CD-C69EEB346781}\ARPPRODUCTICON.exe[HKCR\Installer\Products\620ADC77068359C42833433FEC1F12BF] : Roxio Creator 2012 Pro[HKCR\Installer\Products\6485FC70AEAF10A4B807094112A67A70] : YouTube Video Ad Blocker -> C:\WINDOWS\Installer\{07CF5846-FAEA-4A01-8B70-9014216AA707}\VistaUACMaker.exe[HKCR\Installer\Products\656D68EC788C1FE42B7DA20157349546] : Face Filter -> C:\WINDOWS\Installer\{CE86D656-C887-4EF1-B2D7-2A1075435964}\ARPPRODUCTICON.exe[HKCR\Installer\Products\65A736C97824F78459FB4122CFA18A97] : Nero 2016 -> C:\WINDOWS\Installer\{9C637A56-4287-487F-95BF-1422FC1AA879}\ARPPRODUCTICON.exe[HKCR\Installer\Products\65EC0961132295E409600A78D649E98A] : Tools for .Net 3.5[HKCR\Installer\Products\66122D971C874DA2407EDB22DB85DF64] : CCC Help Chinese Traditional -> C:\WINDOWS\Installer\{79D22166-78C1-2AD4-04E7-BD22BD58FD46}\ARPPRODUCTICON.exe[HKCR\Installer\Products\66F055D925D5AC92825BEEC0C2C0FDEB] : Windows Deployment Customizations[HKCR\Installer\Products\6761FBEE78FA6624398DC0413AC42471] : Nero Disc Menus 1 -> C:\WINDOWS\Installer\{EEBF1676-AF87-4266-93D8-0C14A34C4217}\ARPPRODUCTICON.exe[HKCR\Installer\Products\67BCB71E42995DB46B6D053D04B7E447] : Nero Disc Menus Basic -> C:\WINDOWS\Installer\{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}\ARPPRODUCTICON.exe[HKCR\Installer\Products\67E362B767E5F7236AC59B176E43AD63] : Visual C++ IDE Base Resource Package[HKCR\Installer\Products\6828BC1A3BFC589A7D9927A1F0A2723F] : Windows Software Development Kit DirectX x86 Remote[HKCR\Installer\Products\68ADF0FAB7E6C6A1154D34FA0581E12D] : AMD Catalyst Control Center -> C:\WINDOWS\Installer\{AF0FDA86-6E7B-1A6C-51D4-43AF50181ED2}\ARPPRODUCTICON.exe[HKCR\Installer\Products\6C1C2E92A67D3D1489F0E643A69A6A8A] : Nero Cliparts -> C:\WINDOWS\Installer\{29E2C1C6-D76A-41D3-980F-6E346AA9A6A8}\ARPPRODUCTICON.exe[HKCR\Installer\Products\6D32A5DBF9E1873398FC9E968070D835] : Visual C++ IDE Common Package[HKCR\Installer\Products\6DAFD6D95E90E5444A5B3A88EFBE9DD0] : RBVirtualFolder64Inst -> C:\WINDOWS\Installer\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}\ARPPRODUCTICON.exe[HKCR\Installer\Products\6FE33D76AAA3D673DA3C90E8D6CA694E] : Visual C++ IDE Debugger Resource Package[HKCR\Installer\Products\7040BB568CC47CD459E2E3FEFD5006A2] : Nero Update -> C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe[HKCR\Installer\Products\7297BFE8DA84D6E4197BB6B26D3C3F08] : Acronis Disk Director 11 Home -> C:\WINDOWS\Installer\{8EFB7927-48AD-4E6D-91B7-6B2BD6C3F380}\product.ico[HKCR\Installer\Products\72BCCFF8D2EEF85DA5DBDEC5609BE118] : CCC Help Swedish -> C:\WINDOWS\Installer\{8FFCCB27-EE2D-D58F-5ABD-ED5C06B91E81}\ARPPRODUCTICON.exe[HKCR\Installer\Products\73C44F0DB22A3374BB7A689C4F897852] : SQL Server 2012 Database Engine Shared[HKCR\Installer\Products\74D7C1FA6AB55844890D97E3B649C45D] : Visual Studio 2015 Prerequisites - FRA Language Pack[HKCR\Installer\Products\77E99DA1CC73E44793AC766FDF4365A5] : Catalyst Control Center Localization All -> C:\WINDOWS\Installer\{1AD99E77-37CC-744E-39CA-67F6FD34565A}\ARPPRODUCTICON.exe[HKCR\Installer\Products\797ECA52ADBEB4E090F6F99EA7E1A2F6] : CCC Help Russian -> C:\WINDOWS\Installer\{25ACE797-EBDA-0E4B-096F-9FE97A1E2A6F}\ARPPRODUCTICON.exe[HKCR\Installer\Products\79DD22F7D652D194090947F3DA7CB9EB] : Nero RescueAgent -> C:\WINDOWS\Installer\{7F22DD97-256D-491D-9090-743FADC79BBE}\ARPPRODUCTICON.exe[HKCR\Installer\Products\7A46D3DD5613D854694D60BF6C902CA2] : Google Ad Blocker -> C:\WINDOWS\Installer\{DD3D64A7-3165-458D-96D4-06FBC609C22A}\VistaUACMaker.exe[HKCR\Installer\Products\7A817E1A38BB8B14AB69CB12C923B2E8] : COMODO Internet Security Pro[HKCR\Installer\Products\7E2BBDD2E4BC56E46A9B9B9CE57DD724] : Triple Scoop Music -> C:\WINDOWS\Installer\{2DDBB2E7-CB4E-4E65-A6B9-B9C95ED77D42}\ARPPRODUCTICON.exe[HKCR\Installer\Products\7E92535F1B70A904CA0E93012D33D821] : Roxio Creator 2012 Pro -> C:\WINDOWS\Installer\{F53529E7-07B1-409A-ACE0-3910D2338D12}\ARPPRODUCTICON.exe[HKCR\Installer\Products\7F34C9BDF0B034E4E9B69F547CC164E9] : VD64Inst -> C:\WINDOWS\Installer\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}\ARPPRODUCTICON.exe[HKCR\Installer\Products\814AB0FE73FAE1745949AE5E19F36418] : Nero Launcher -> C:\WINDOWS\Installer\{EF0BA418-AF37-471E-9594-EAE5913F4681}\ARPPRODUCTICON.exe[HKCR\Installer\Products\815BF5C8C87E0F8FFBCEE8CA565F0130] : Windows Assessment Services - Client (Client SKU)[HKCR\Installer\Products\821B6C5004B15944C99B90B063B8AFA0] : Nero Video Samples -> C:\WINDOWS\Installer\{05C6B128-1B40-4495-9CB9-090B368BFA0A}\ARPPRODUCTICON.exe[HKCR\Installer\Products\830F188D767DAA54091CE145119A76A0] : e-Carte Bleue Caisse d'Epargne -> C:\WINDOWS\Installer\{D881F038-D767-45AA-90C1-1E5411A9670A}\ARPPRODUCTICON.exe[HKCR\Installer\Products\833DA5B8CBA7BCE4C9C286F748EADD1B] : Nero Platinum Effects 12 -> C:\WINDOWS\Installer\{8B5AD338-7ABC-4ECB-9C2C-687F84AEDDB1}\ARPPRODUCTICON.exe[HKCR\Installer\Products\849FBE4FE00FFE9298C41DA017F889D1] : Windows Assessment Toolkit[HKCR\Installer\Products\881D49CF80E17073D9324F11874D6446] : Windows Espc Resource Package[HKCR\Installer\Products\886FF42F8317FCC48AF3179EBF1071E0] : Folder Size (64-bit) -> C:\WINDOWS\Installer\{F24FF688-7138-4CCF-A83F-71E9FB01170E}\FolderSize.ico[HKCR\Installer\Products\89201680EA92B5443BD7FEEB50089276] : LWS Pictures And Video[HKCR\Installer\Products\8AC6637E9717EA777E21AB817DA0A070] : AMD Fuel -> C:\WINDOWS\Installer\{E7366CA8-7179-77AE-E712-BA18D70A0A07}\ARPPRODUCTICON.exe[HKCR\Installer\Products\8AF7AC5E39C51E5469A94175A1BF0F3A] : Advanced Windows Service Manager -> C:\WINDOWS\Installer\{E5CA7FA8-5C93-45E1-969A-14571AFBF0A3}\WinServiceManager.exe[HKCR\Installer\Products\8BA31D3CA8644710D160BDA9EAA831B1] : CCC Help Czech -> C:\WINDOWS\Installer\{C3D13AB8-468A-0174-1D06-DB9AAE8A131B}\ARPPRODUCTICON.exe[HKCR\Installer\Products\8C796185CD33AB447A3C99B2D5920C11] : Advanced Installer 13.8.1 -> C:\WINDOWS\Installer\{581697C8-33DC-44BA-A7C3-992B5D29C011}\AdvancedInstaller.exe[HKCR\Installer\Products\8CDE6B8F91975ED42A5F3B0F97A893C7] : SX WiFi Security Suite -> C:\WINDOWS\Installer\{F8B6EDC8-7919-4DE5-A2F5-B3F0798A397C}\APPDIR_1.exe[HKCR\Installer\Products\8E96EC9DA77D49C39A0146612297E44D] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\8EFB030F674880C45A3532D38EA0B21E] : Nero Info -> C:\WINDOWS\Installer\{F030BFE8-8476-4C08-A553-233DE80A2BE1}\ARPPRODUCTICON.exe[HKCR\Installer\Products\9202FB7DD2BE3254FA0A59EC06E596E6] : AdAwareInstaller -> C:\WINDOWS\Installer\{D7BF2029-EB2D-4523-AFA0-95CE605E696E}\ARPPRODUCTICON.exe[HKCR\Installer\Products\92540D3EBDE68D113A270005AB3E711E] : PowerDVD Copy -> C:\WINDOWS\Installer\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\ARPPRODUCTICON.exe[HKCR\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E] : Google Update Helper[HKCR\Installer\Products\94BD5DDAFC278D11D95700109267D057] : PowerBackup -> C:\WINDOWS\Installer\{ADD5DB49-72CF-11D8-9D75-000129760D75}\ARPPRODUCTICON.exe[HKCR\Installer\Products\96DCEE65824F4C14DA6FC6ED1ED4FDF3] : Paragon UIM[HKCR\Installer\Products\9767203404DF6E239A0FB73BDCBE4E61] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\985E2342652631540BFBFE8A3E525D0F] : Nero SharedVideoCodecs[HKCR\Installer\Products\98881006F0E98E34B998928E8C824BA0] : Dotfuscator and Analytics Community Edition 5.22.0 -> C:\WINDOWS\Installer\{60018889-9E0F-43E8-9B89-29E8C828B40A}\DfIcon.ico[HKCR\Installer\Products\9947451521A46CC3EAD3C3E5787D9290] : Visual C++ MSBuild ARM Package[HKCR\Installer\Products\9B5328D62EDA2503DACF553B3ECBEA00] : Visual F# 4.0 VS Language Pack - FRA[HKCR\Installer\Products\9D3C8BF856DED0D4C91A264ADFAC899A] : Autorun File Remover -> C:\WINDOWS\Installer\{8FB8C3D9-ED65-4D0D-9CA1-62A4FDCA98A9}\GooglePasswordDecryptor.exe[HKCR\Installer\Products\9DAF6B7941F664CC13561F87E5CC2E55] : WPTx64[HKCR\Installer\Products\9EE39CB71F443873DA676FDBC6F8B685] : Visual C++ Compiler/Tools X86 Base Package[HKCR\Installer\Products\9EFB902DADE36063FAB6CDDA8AA72258] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\9F51B3928A194D44CABB1EE3E8E29CD7] : [HKCR\Installer\Products\9FE85B7B7036FCD42867F2711D6EED96] : PreEmptive Analytics Client French Language Pack -> C:\WINDOWS\Installer\{B7B58EF9-6307-4DCF-8276-2F17D1E6DE69}\icon.ico[HKCR\Installer\Products\A2B16319147F195E03B3E49F753FAB1F] : Windows Assessment Toolkit (AMD64 Architecture Specific)[HKCR\Installer\Products\A40C9EDCB8F78A044A5A78E52228456A] : Roxio Creator Content 2012 -> C:\WINDOWS\Installer\{CDE9C04A-7F8B-40A8-A4A5-875E228254A6}\ARPPRODUCTICON.exe[HKCR\Installer\Products\A4285C8195DFD354D91CD568AF303475] : [HKCR\Installer\Products\A5254F69D074C51F97E6859D89C8E3F5] : Windows Software Development Kit for Windows Store Apps DirectX x64 Remote[HKCR\Installer\Products\A748067A9D4CFE7E17F6706CBC6F1B74] : CCC Help Thai -> C:\WINDOWS\Installer\{A760847A-C4D9-E7EF-716F-07C6CBF6B147}\ARPPRODUCTICON.exe[HKCR\Installer\Products\A78AB7755245E563F9F0BC884DE246B8] : Visual C++ MSBuild Base Resource Package[HKCR\Installer\Products\A7F3CAB7369BE86489E25B06A87804D8] : Epson Software Updater -> C:\WINDOWS\Installer\{7BAC3F7A-B963-468E-982E-B5608A87408D}\icon.ico[HKCR\Installer\Products\A927A03CAB9E8F73C38546DAF9D16449] : Imaging Tools Support[HKCR\Installer\Products\A97236C163FB258499421B79D856586A] : Nero Device Updates[HKCR\Installer\Products\AAE8AD66DC4DCD039B39E0FD27E81D6F] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\AD93CAFF97FCB4346A0E04558669769D] : Roxio CinePlayer Decoder Pack -> C:\WINDOWS\Installer\{FFAC39DA-CF79-434B-A6E0-4055689667D9}\CPIcon.exe[HKCR\Installer\Products\ADEDAA7FA3329701DC5130EA0B050F6C] : User State Migration Tool[HKCR\Installer\Products\B1CCEC48FE121B14A919E327E4D5993D] : Manuels EPSON -> C:\WINDOWS\Installer\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}\EPSMICO.ICO[HKCR\Installer\Products\B21B54B413DC5324D944303A86156053] : Avanquest MergeModules[HKCR\Installer\Products\B520FC0F3F6DC7F439B93292F12578C5] : Paragon ExtFS for Windows -> C:\WINDOWS\Installer\{F0CF025B-D6F3-4F7C-939B-23291F52875C}\ExtFS4Win.ico[HKCR\Installer\Products\B54B166CA2D1C7FA720D4BFF6D074AEF] : Kits Configuration Installer[HKCR\Installer\Products\B67AEAD9F05E27245A5910428E6255D3] : LWS WLM Plugin[HKCR\Installer\Products\B7A8B595D352E4A4592C8A32DEDD4569] : Macrium Reflect Free Edition -> C:\WINDOWS\Installer\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}\Reflect.ico[HKCR\Installer\Products\B7E5D71BDDAF4BE45B73BCE73B33D379] : Nero Recode -> C:\WINDOWS\Installer\{B17D5E7B-FADD-4EB4-B537-CB7EB3333D97}\ARPPRODUCTICON.exe[HKCR\Installer\Products\B8F487C80D9895A40A00E7FE21E95147] : Jing[HKCR\Installer\Products\B9847DD564CEFA74BB86224F273522B8] : Spy BHO Remover -> C:\WINDOWS\Installer\{5DD7489B-EC46-47AF-BB68-22F47253228B}\BHORemover.exe[HKCR\Installer\Products\BCC71A82BB779C9448B7060E67CD341D] : UxStyle[HKCR\Installer\Products\C000470913356864298DC603669EC936] : Studio Video Ultimate[HKCR\Installer\Products\C01965A28C96D594E88D09080F1AE485] : Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 -> C:\WINDOWS\Installer\{2A56910C-69C8-495D-8ED8-9080F0A14E58}\setup.ico[HKCR\Installer\Products\C0DBE580E42F49BED633A222FE465CFC] : CCC Help Finnish -> C:\WINDOWS\Installer\{085EBD0C-F24E-EB94-6D33-2A22EF64C5CF}\ARPPRODUCTICON.exe[HKCR\Installer\Products\C14E23FDDA4278A44BA33B58351B08E6] : Visual Studio 2015 Prerequisites[HKCR\Installer\Products\C2F1EB77C255E834E8B6C48061DBCED5] : Rebit Pro (64-bit) -> C:\WINDOWS\Installer\{77BE1F2C-552C-438E-8E6B-4C0816BDEC5D}\InstallerIcon[HKCR\Installer\Products\C351938B2D4DC98F0533A061C02607B6] : CCC Help Portuguese -> C:\WINDOWS\Installer\{B839153C-D4D2-F89C-5033-0A160C62706B}\ARPPRODUCTICON.exe[HKCR\Installer\Products\C3AF8C38AE4F4C6438293DEC5373836D] : LWS Launcher[HKCR\Installer\Products\C3CE67F61B43E63479BF845CD8B7DEDC] : LWS Gallery[HKCR\Installer\Products\C51E70D24A9A6D8D3D1729CE78975E78] : CCC Help Hungarian -> C:\WINDOWS\Installer\{2D07E15C-A9A4-D8D6-D371-92EC8779E587}\ARPPRODUCTICON.exe[HKCR\Installer\Products\C6D7BA53712C07442B7D20211907F84F] : SX Blocker Suite -> C:\WINDOWS\Installer\{35AB7D6C-C217-4470-B2D7-021291708FF4}\SXPasswordDumpSuite.exe[HKCR\Installer\Products\C845D413FF068F84EBEA9C9464073694] : WCF Data Services 5.6.4 FRA Language Pack[HKCR\Installer\Products\C8A2FA24BBE6E2D3B91F165373F9ABCB] : Windows Espc Package[HKCR\Installer\Products\C951361A674B10541B36F37708A98C33] : Nero Burning Core[HKCR\Installer\Products\C971C95CD8669A946BAE1012CCCF2134] : LabelPrint -> C:\WINDOWS\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe[HKCR\Installer\Products\CB6E9659A623F23479BA5362A323B71F] : Roxio Burn - Secure[HKCR\Installer\Products\CC67F423DD8D78D47BD74DFAE5A17A3B] : [HKCR\Installer\Products\CDD6F3998F36DCB4B9829D1479A1C9CA] : Windows XP Targeting with C++[HKCR\Installer\Products\CE67D3639B5BB7D5F0951C39FFF630CF] : Windows System Image Manager on amd64[HKCR\Installer\Products\D08BFDF01E191F635B32B00924F1DD1C] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\D0C630325B456A649ADEB0691B03C187] : [HKCR\Installer\Products\D1ACF320195E9FA3D9F2896736A915A1] : Visual C++ Library PGO X86 Package[HKCR\Installer\Products\D21F22296DD948F3FBD87AB0B94BCEBA] : Applications hybrides multi-appareils en C# - Modèles - FRA[HKCR\Installer\Products\D2DAD9455052C402CE859508F76E0E73] : WPT Redistributables[HKCR\Installer\Products\D43EEBEB2A48DDE4B8AE69CC45732136] : Nero Core Components[HKCR\Installer\Products\D53DAE4D52D52594A9C0AA4ADA315C69] : SX System Suite -> C:\WINDOWS\Installer\{D4EAD35D-5D25-4952-9A0C-AAA4AD13C596}\sxsystemsuite.exe[HKCR\Installer\Products\D73F0BFC7E2273F4F8EA3B915AA85C9B] : Nero Burning ROM -> C:\WINDOWS\Installer\{CFB0F37D-22E7-4F37-8FAE-B319A58AC5B9}\ARPPRODUCTICON.exe[HKCR\Installer\Products\D8130315AEF76E5329D710639801DBCF] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\D935B019752F8C64C98BC659FE9FFC22] : Stashimi Stub Installer[HKCR\Installer\Products\D95C25420405A9A49AF79B529360911E] : Silent Install Builder 5 -> C:\WINDOWS\Installer\{2452C59D-5040-4A9A-A97F-B925390619E1}\app_icon.ico[HKCR\Installer\Products\DA1C168692894ED468747458CEAE24A1] : Nero Video -> C:\WINDOWS\Installer\{6861C1AD-9829-4DE4-8647-4785ECEA421A}\ARPPRODUCTICON.exe[HKCR\Installer\Products\DAADDD689BEA5E24EB10E0F8BA2DBB92] : Roxio Video Capture USB -> C:\WINDOWS\Installer\{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}\ARPPRODUCTICON.exe[HKCR\Installer\Products\DB7E58BDDD2B4D343B0C327D5B725B79] : WCF Data Services 5.6.4 Runtime[HKCR\Installer\Products\DBE4EEF20BEC62E34950FCD018C2AFC3] : Visual C++ IDE Core Professional Plus Resource Package[HKCR\Installer\Products\DBF576EC3C571F546BFAD85280165D63] : Nero Disc Menus 3 -> C:\WINDOWS\Installer\{CE675FBD-75C3-45F1-B6AF-8D250861D536}\ARPPRODUCTICON.exe[HKCR\Installer\Products\DD81A634C2F5C3B489E5DAC3310BCC52] : PreEmptive Analytics Visual Studio Components -> C:\WINDOWS\Installer\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}\icon.ico[HKCR\Installer\Products\DE48D40557EA58F46AB8BBD3C43B1E96] : Nero Holiday and Sports Themes -> C:\WINDOWS\Installer\{504D84ED-AE75-4F85-A68B-BB3D4CB3E169}\ARPPRODUCTICON.exe[HKCR\Installer\Products\DED17A5318AD313153A2CEA8B072FDB3] : CCC Help Chinese Standard -> C:\WINDOWS\Installer\{35A71DED-DA81-1313-352A-EC8A0B27DF3B}\ARPPRODUCTICON.exe[HKCR\Installer\Products\DF367203AEC5FFD4088CB91414C48422] : Roxio CinePlayer[HKCR\Installer\Products\DF3AB8F29AF197246B6917A2BB210FF9] : SmartSound Quicktracks 5 -> C:\WINDOWS\Installer\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}\ARPPRODUCTICON.exe[HKCR\Installer\Products\E065AE25F05EF8CD41D6B1365184AB92] : Windows Deployment Tools[HKCR\Installer\Products\E165DB015B21D3E49B28FD3478E9D7CA] : Active Directory Authentication Library pour SQL Server -> C:\WINDOWS\Installer\{10BD561E-12B5-4E3D-B982-DF43879E7DAC}\ARPIco[HKCR\Installer\Products\E197C4E0E87BD774DBA5DC0D89B56ACE] : Application Insights Tools for Visual Studio 2015[HKCR\Installer\Products\E3A623703B208701527D8B66B68AEF51] : CCC Help Korean -> C:\WINDOWS\Installer\{07326A3E-02B3-1078-25D7-B8666BA8FE15}\ARPPRODUCTICON.exe[HKCR\Installer\Products\E4AF4541CB851FE2A99141B7E094E930] : UEV Tools on amd64[HKCR\Installer\Products\E5AE57E7AF9DBD546964EE5A5CFB164D] : Nero MediaHome -> C:\WINDOWS\Installer\{7E75EA5E-D9FA-45DB-9646-EEA5C5BF61D4}\NeroKwikMedia._63C8A7B0BBE5459F9AC436392B2FF50D.exe[HKCR\Installer\Products\E6121561DA7E0524291ABFE86D31199C] : LWS Help_main[HKCR\Installer\Products\E61E74258FCBBA5961353B8FBF8F3B1F] : Windows Software Development Kit DirectX x64 Remote[HKCR\Installer\Products\E6BBB70B35760B144B9BE1F94EFAC581] : Lavasoft Privacy Toolbox[HKCR\Installer\Products\E9682A8BAC035C04C98FDB37455EE78F] : SmartSound Common Data -> C:\WINDOWS\Installer\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}\ARPPRODUCTICON.exe[HKCR\Installer\Products\EA58071E856963AAEA36A29785D1B846] : MXAx64[HKCR\Installer\Products\EAE32F3F716DF1A37871AFDC531ACEEE] : Visual C++ IDE Debugger Package[HKCR\Installer\Products\EC9283ECB955AFB3AB7EF047F5FADC82] : Application Compatibility Toolkit[HKCR\Installer\Products\EE26973C42EEF9E4A81415A4DC9771C7] : Tools for .Net 3.5 - FRA Lang Pack[HKCR\Installer\Products\EE47477FC6BEB78C88FA33018C840E86] : CCC Help Greek -> C:\WINDOWS\Installer\{F77474EE-EB6C-C87B-88AF-3310C848E068}\ARPPRODUCTICON.exe[HKCR\Installer\Products\EE477C8F739B4964B94E2D1076CF2FF0] : Laplink PCmover Professional -> C:\WINDOWS\Installer\{F8C774EE-B937-4694-9BE4-D20167FCF20F}\ARPPRODUCTICON.exe[HKCR\Installer\Products\EF311DB58D8BA7E4B91A716C9434B2E3] : PDQ Deploy -> C:\WINDOWS\Installer\{5BD113FE-B8D8-4E7A-9BA1-17C649432B3E}\MainIcon.ico[HKCR\Installer\Products\EF6F893B797E46746B2F4CEA10127AB1] : PDQ Inventory -> C:\WINDOWS\Installer\{B398F6FE-E797-4764-B6F2-C4AE0121A71B}\MainIcon.ico[HKCR\Installer\Products\EF7A7642EA3F8FD348E75C2949B34C17] : Visual F# 4.0 SDK Language Pack - FRA[HKCR\Installer\Products\F28962C8543B78C3D871E588DAADFF6F] : Visual Studio Graphics Analyzer[HKCR\Installer\Products\F3D66E17900ABA447848572E18B94AAB] : LWS Motion Detection[HKCR\Installer\Products\F7150B0381E154D37AC82C3EB4A963D8] : Visual C++ IDE Base Package[HKCR\Installer\Products\F75D59AC3CF97DD0C76363F2478D0CE4] : CCC Help Dutch -> C:\WINDOWS\Installer\{CA95D57F-9FC3-0DD7-7C36-362F74D8C04E}\ARPPRODUCTICON.exe[HKCR\Installer\Products\F7DFB51DABB67A946A1B410CD0AC8624] : [HKCR\Installer\Products\F9D6CAECA4497F04BAD57A14A29FEC9D] : Acronis True Image WD Edition -> C:\WINDOWS\Installer\{CEAC6D9F-944A-40F7-AB5D-A7412AF9CED9}\product.ico[HKCR\Installer\Products\FB4A7DB746AEEFB49A3DF3CDB9E6CF32] : Nero Football (Soccer) Themes -> C:\WINDOWS\Installer\{7BD7A4BF-EA64-4BFE-A9D3-3FDC9B6EFC23}\ARPPRODUCTICON.exe[HKCR\Installer\Products\FFC5F60053DEFA14B9A25FB2F045B54F] : Nero 2016 Content Pack -> C:\WINDOWS\Installer\{006F5CFF-ED35-41AF-9B2A-F52B0F545BF4}\ARPPRODUCTICON.exe ---------- | ADS ---------- | Drives Disk: 0 Size=954G Pos MBRndx Type/Name Size Active Hide Start Sector Sectors --- ------ ---------- ---- ------ ---- ------------ ------------ 0 0 EE-UNKNWN 954G No No 1 953,525,167 ---------- | MBR Windows Version: Windows Information: (build 9200), 64-bitBase Board Manufacturer: Hewlett-PackardBIOS Manufacturer: AMISystem Manufacturer: Hewlett-PackardSystem Product Name: CQ2904EFLogical Drives Mask: 0x001000fcAnalysis of file "C:\QuickDiag\MBR.bin":Unknown MBR code64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog Nom de l’application défaillante TweakingRegistryBackup.exe, version : 3.5.0.3, horodatage : 0x582f3b59 Nom du module défaillant : MSVBVM60.DLL, version : 6.0.98.15, horodatage : 0x49b01fc3 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000c9ba6 ID du processus défaillant : 0x58bc Heure de début de l’application défaillante : 0x01d303225eb6c696 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\registry_backup_tool\TweakingRegistryBackup.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\MSVBVM60.DLL ID de rapport : 92fcbebc-75d4-4bd2-9151-0dc51874e099 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Produit : Stashimi Stub Installer -- Erreur 1719. Impossible d'accéder au service Windows Installer. Veuillez contacter votre support technique pour vérifier s'il est activé et enregistré correctement. ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Stashimi Stub Installer. ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Fast HTML Checker ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Fast HTML Checker ; Erreur = 0x8007043c). ------------ Produit : Stashimi Stub Installer -- Erreur 1719. Impossible d'accéder au service Windows Installer. Veuillez contacter votre support technique pour vérifier s'il est activé et enregistré correctement. ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Stashimi Stub Installer. ; Erreur = 0x8007043c). ------------ Produit : Stashimi Stub Installer -- Erreur 1719. Impossible d'accéder au service Windows Installer. Veuillez contacter votre support technique pour vérifier s'il est activé et enregistré correctement. ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Stashimi Stub Installer. ; Erreur = 0x8007043c). ------------ Product: Roslyn Language Services - x86 -- Error 1719. The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance. ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Office 16 Click-to-Run Localization Component ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Office 16 Click-to-Run Localization Component ; Erreur = 0x8007043c). ------------ Product: Office 16 Click-to-Run Licensing Component -- Error 1706. Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM. ------------ Produit : Office 16 Click-to-Run Extensibility Component -- Erreur 1719. Impossible d’accéder au service Windows Installer. Ceci peut se produire si le programme d’installation de Windows n’est pas bien installé. Contactez votre support technique pour assistance. ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Supprimé Office 16 Click-to-Run Extensibility Component ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\ProgramData\Package Cache\{d6f233bd-3f8c-43f6-878b-07bd0568d595}\VC_redist.x64.exe Cache\{d6f233bd-3f8c-43f6-878b-07bd0568d595}\VC_redist.x64.exe" /uninstall /quiet ; Description = Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25017 ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\ProgramData\Package Cache\{cb7c3049-21de-415b-bd85-b65c14e547df}\VC_redist.x86.exe Cache\{cb7c3049-21de-415b-bd85-b65c14e547df}\VC_redist.x86.exe" /uninstall /quiet ; Description = Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Vole Edutainment ; Erreur = 0x8007043c). ------------ Échec de la création d’un point de restauration (Processus = C:\WINDOWS\system32\msiexec.exe /V ; Description = Removed Vole Edutainment ; Erreur = 0x8007043c). ------------ ----------( EOF )---------- - 1 | 21:57:48