--------------- QuickDiag | g3n-h@ckm@n | V3_01.07.17.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 27/08/2017 22:39:35 Updated 01/07/2017 | 11.30 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [Emmanuelle (Administrator)] - [LAPTOP-O5ULGE56] (S-1-5-21-2395831268-3694815761-1612603451-1001) System: Microsoft Windows 10 Famille - - (10.0.14393) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> (1607) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Famille|C:\WINDOWS|\Device\Harddisk0\Partition3 Boot : Normal boot PC: Aspire E5-573G - Acer - IdNumber: NXMW4EF02561112F5C7600 - UUID: 1CA8A392-F42A-8B4C-A84B-54AB3A5DC86F Processor : X64 - 2394 Mhz - Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz V1.37 - - Insyde Corp. - S/N: NXMW4EF02561112F5C7600 - V1.37 - ACRSYS - 1 CoreTemp : 28 Celsius ----------| Quick ---------- | SoundDevice Realtek High Definition Audio - Status: OK - Manufacturer: Realtek - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0255&SUBSYS_10250987&REV_1000\4&1A145AB6&0&0001 NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: ROOT\UNNAMED_DEVICE\0000 ---------- | Video NVIDIA GeForce 920M - Resolution: x - Colors: - RefreshRate: - Bits Per Pixel - DeviceID: VideoController1 - Drivers: C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvd3dumx,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvwgf2umx,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvwgf2umx,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvwgf2umx,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvd3dum,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvwgf2um,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvwgf2um,C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvwgf2um - PNPDeviceID: PCI\VEN_10DE&DEV_1299&SUBSYS_09881025&REV_A1\4&2F89C491&0&00E4 - AdapterCompatibility: NVIDIA - RAM: -2147483648 Intel(R) HD Graphics Family - Resolution: 1366x768 - Colors: 4294967296 - RefreshRate: 60 - 32 Bits Per Pixel - DeviceID: VideoController2 - Drivers: igdumdim64.dll,igd10iumd64.dll,igd10iumd64.dll,igd12umd64.dll,igdumdim32,igd10iumd32,igd10iumd32,igd12umd32 - PNPDeviceID: PCI\VEN_8086&DEV_0A16&SUBSYS_09871025&REV_0B\3&11583659&0&10 - AdapterCompatibility: Intel Corporation - RAM: 1073741824 Inegrated Video Chipset DeviceName: NVIDIA GeForce 920M - DriverVersion: 21.21.13.7654 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35696 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34640 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25352 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 87040 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42936 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 54272 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 27648 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK ---------- | CPU CPU #1 value:7 % CPU #2 value:20 % CPU #3 value:1 % CPU #4 value:7 % Total Overall CPU Usage value:9 % ---------- | Network Realtek PCIe GBE Family Controller : SENT:0 bytes/sec / RECVD:0 bytes/sec Qualcomm Atheros QCA9377 Wireless Network Adapter : SENT:0 bytes/sec / RECVD:0 bytes/sec Teredo Tunneling Pseudo-Interface : SENT:0 bytes/sec / RECVD:0 bytes/sec isatap.home : SENT:0 bytes/sec / RECVD:0 bytes/sec Overall -> SEND Maxium:9 bytes/sec, / RECEIVE Maximum:0 bytes/sec Microsoft Kernel Debug Network Adapter - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000 Qualcomm Atheros QCA9377 Wireless Network Adapter - Ethernet 802.3 - Qualcomm Atheros Communications Inc. - Status: - PnPID : PCI\VEN_168C&DEV_0042&SUBSYS_E09A105B&REV_30\4&1FF26431&0&00E3 Realtek PCIe GBE Family Controller - Ethernet 802.3 - Realtek - Status: - PnPID : PCI\VEN_10EC&DEV_8168&SUBSYS_09871025&REV_15\4&2B3FC636&0&00E2 Teredo Tunneling Pseudo-Interface - Tunnel - Microsoft - Status: - PnPID : SWD\IP_TUNNEL_VBUS\TEREDO_TUNNEL_DEVICE Microsoft Wi-Fi Direct Virtual Adapter - Ethernet 802.3 - Microsoft - Status: - PnPID : {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_WFD\5&1A571AD&0&02 Microsoft ISATAP Adapter - - - Status: - PnPID : Microsoft ISATAP Adapter #2 - Tunnel - Microsoft - Status: - PnPID : SWD\IP_TUNNEL_VBUS\ISATAP_1 WAN Miniport (SSTP) - - - Status: - PnPID : WAN Miniport (IKEv2) - - - Status: - PnPID : WAN Miniport (L2TP) - - - Status: - PnPID : WAN Miniport (PPTP) - - - Status: - PnPID : WAN Miniport (PPPOE) - - - Status: - PnPID : WAN Miniport (IP) - - - Status: - PnPID : WAN Miniport (IPv6) - - - Status: - PnPID : WAN Miniport (Network Monitor) - - - Status: - PnPID : ---------- | Memory RAM = Total (MB) : 4113 | Free (MB) : 1050 Pagefile = Total (MB) : 6472 | Free (MB) : 2268 Virtual = Total (MB) : 4194 | Free (MB) : 3947 Physical Memory 0 : Capacity: 4294967296 - ChannelA-DIMM0 - Posit.: 1 - Manufacturer: Hynix/Hyundai - PartNumber: HMT451S6BFR8A-PB - S/N: 22535513 ---------- | SID Users Administrateur : [S-1-5-21-2395831268-3694815761-1612603451-500] DefaultAccount : [S-1-5-21-2395831268-3694815761-1612603451-503] Emmanuelle : [S-1-5-21-2395831268-3694815761-1612603451-1001] Invité : [S-1-5-21-2395831268-3694815761-1612603451-501] Administrateurs : [S-1-5-32-544] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] ---------- | SystemAccounts Name: Tout le monde - SID: S-1-1-0 - SIDType: 5 - Status: OK Name: LOCAL - SID: S-1-2-0 - SIDType: 5 - Status: OK Name: CREATEUR PROPRIETAIRE - SID: S-1-3-0 - SIDType: 5 - Status: OK Name: GROUPE CREATEUR - SID: S-1-3-1 - SIDType: 5 - Status: OK Name: CREATOR OWNER SERVER - SID: S-1-3-2 - SIDType: 5 - Status: OK Name: CREATOR GROUP SERVER - SID: S-1-3-3 - SIDType: 5 - Status: OK Name: DROITS DU PROPRIÉTAIRE - SID: S-1-3-4 - SIDType: 5 - Status: OK Name: LIGNE - SID: S-1-5-1 - SIDType: 5 - Status: OK Name: RESEAU - SID: S-1-5-2 - SIDType: 5 - Status: OK Name: TACHE - SID: S-1-5-3 - SIDType: 5 - Status: OK Name: INTERACTIF - SID: S-1-5-4 - SIDType: 5 - Status: OK Name: SERVICE - SID: S-1-5-6 - SIDType: 5 - Status: OK Name: ANONYMOUS LOGON - SID: S-1-5-7 - SIDType: 5 - Status: OK Name: Proxy - SID: S-1-5-8 - SIDType: 5 - Status: OK Name: Système - SID: S-1-5-18 - SIDType: 5 - Status: OK Name: ENTERPRISE DOMAIN CONTROLLERS - SID: S-1-5-9 - SIDType: 5 - Status: OK Name: SELF - SID: S-1-5-10 - SIDType: 5 - Status: OK Name: Utilisateurs authentifiés - SID: S-1-5-11 - SIDType: 5 - Status: OK Name: RESTRICTED - SID: S-1-5-12 - SIDType: 5 - Status: OK Name: UTILISATEUR TERMINAL SERVER - SID: S-1-5-13 - SIDType: 5 - Status: OK Name: REMOTE INTERACTIVE LOGON - SID: S-1-5-14 - SIDType: 5 - Status: OK Name: IUSR - SID: S-1-5-17 - SIDType: 5 - Status: OK Name: SERVICE LOCAL - SID: S-1-5-19 - SIDType: 5 - Status: OK Name: SERVICE RÉSEAU - SID: S-1-5-20 - SIDType: 5 - Status: OK Name: BUILTIN - SID: S-1-5-32 - SIDType: 3 - Status: OK ---------- | Drives C:\ -> [Fixed] | [Acer] | Total : 930.91 Go | Free : 717.59 Go -> NTFS [SATA] Disk Usage Information [1 total Physical Disks] Physical Drive #0 [C:] : Read:522,120 bytes/sec, Written:5,792,274 bytes/sec Max Read:522,120 bytes/sec, Max Write:5,792,274 bytes/sec Overall - Read Maximum:522,120 bytes/sec, Write Maximum:5,792,274 bytes/sec DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 3 Part. - PnPID : SCSI\DISK&VEN_TOSHIB_&PROD_MQ01ABD100\4&2C357454&0&000000 ---------- | Windows updates Test 1 : Windows Is Activated Test 2 : Possible Fixed Windows (Notification Mode) Test 3 : Possible Fixed Windows (Notification Mode) ---------- | Browsers IE : 11.0.14393.953 (© Microsoft Corporation. Tous droits réservés.) FF : 55.0.2.6435 (©Firefox and Mozilla Developers; available under the MPL 2 license.) Default : "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "" ---------- | FlashPlayer FlashPlayer ActiveX : 26.0.0.151 ---------- | Security WMI : OK WU: Windows Update Service [Manual(3)] = Running AS: Windows Defender [Manual(3)] = stopped WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 400 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.14393.0) = C:\Windows\System32\smss.exe [16/07/2016 13:42:27] CPU Usage:0 % 676 | [Owner : Système | Parent : 504() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.14393.0) = C:\Windows\System32\csrss.exe [16/07/2016 13:42:27] CPU Usage:0 % 784 | [Owner : Système | Parent : 504() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.14393.0) = C:\Windows\System32\wininit.exe [16/07/2016 13:42:27] CPU Usage:0 % 796 | [Owner : Système | Parent : 776() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.14393.0) = C:\Windows\System32\csrss.exe [16/07/2016 13:42:27] CPU Usage:0 % 856 | [Owner : Système | Parent : 784(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.14393.479) = C:\Windows\System32\services.exe [01/03/2017 12:29:38] CPU Usage:0 % 864 | [Owner : Système | Parent : 784(wininit.exe) | 14.95 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.14393.187) = C:\Windows\System32\lsass.exe [23/10/2016 13:10:58] CPU Usage:0 % 956 | [Owner : Système | Parent : 856(services.exe) | 21.83 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 84 | [Owner : SERVICE RÉSEAU | Parent : 856(services.exe) | 11.04 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 588 | [Owner : Système | Parent : 776() | 7.37 Mo] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.14393.594) = C:\Windows\System32\winlogon.exe [01/03/2017 12:29:07] CPU Usage:0 % 480 | [Owner : DWM-1 | Parent : 588(winlogon.exe) | 57.12 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (10.0.14393.0) = C:\Windows\System32\dwm.exe [16/07/2016 13:42:23] CPU Usage:0 % 916 | [Owner : Système | Parent : 856(services.exe) | 64.91 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1028 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 21.22 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1036 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 23.58 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1184 | [Owner : Système | Parent : 856(services.exe) | 77.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1348 | [Owner : Système | Parent : 856(services.exe) | 7.62 Mo] - (.Intel Corporation - igfxCUIService Module.) - (6.15.10.4531) = C:\Windows\System32\igfxCUIService.exe [02/09/2015 11:46:13] CPU Usage:0 % 1436 | [Owner : SERVICE RÉSEAU | Parent : 856(services.exe) | 20.77 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1444 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 22.31 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1492 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 9.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1628 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 9.83 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1828 | [Owner : Système | Parent : 856(services.exe) | 12.37 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 1952 | [Owner : Système | Parent : 856(services.exe) | 13.56 Mo] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.14393.953) = C:\Windows\System32\spoolsv.exe [09/05/2017 15:13:19] CPU Usage:0 % 2060 | [Owner : SERVICE RÉSEAU | Parent : 856(services.exe) | 5.83 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 2196 | [Owner : Système | Parent : 856(services.exe) | 9.17 Mo] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - (2.5.11.45) = C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [19/03/2016 18:29:33] CPU Usage:0 % 2204 | [Owner : Système | Parent : 856(services.exe) | 6.24 Mo] - (.McAfee, Inc. - McAfee Management Service.) - (15.6.0.1220) = C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [31/08/2015 12:52:28] CPU Usage:0 % 2224 | [Owner : Système | Parent : 856(services.exe) | 41.7 Mo] - (.McAfee, Inc. - McAfee Module Core Service.) - (1.6.121.0) = C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [15/03/2017 22:36:31] CPU Usage:0 % 2244 | [Owner : Système | Parent : 856(services.exe) | 2.66 Mo] - (.Acer Incorporated - CCD Monitor Service.) - (2.1.3007.0) = C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [31/08/2015 12:55:05] CPU Usage:0 % 2256 | [Owner : Système | Parent : 856(services.exe) | 4.64 Mo] - (.LeapFrog Enterprises, Inc. - CommandService Application.) - (6.1.3.0) = C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [12/02/2016 13:50:46] CPU Usage:0 % 2276 | [Owner : Système | Parent : 856(services.exe) | 5.62 Mo] - (.Windows (R) Win 7 DDK provider - Windows Setup API.) - (6.1.7600.16385) = C:\Windows\System32\AdminService.exe [23/10/2016 10:35:10] CPU Usage:0 % 2292 | [Owner : Système | Parent : 856(services.exe) | 10.28 Mo] - (.NVIDIA Corporation - NVIDIA Streamer Service.) - (4.1.1975.3517) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [19/03/2016 18:29:26] CPU Usage:0 % 2312 | [Owner : Système | Parent : 856(services.exe) | 24.96 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 2328 | [Owner : Système | Parent : 856(services.exe) | 4.82 Mo] - (.McAfee, Inc. - McAfee Process Validation Service.) - (15.6.0.1220) = C:\Windows\System32\mfevtps.exe [31/08/2015 12:52:29] CPU Usage:0 % 2496 | [Owner : Système | Parent : 856(services.exe) | 8.8 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.0.0.0) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [18/02/2017 20:30:44] CPU Usage:0 % 2512 | [Owner : Système | Parent : 856(services.exe) | 6.01 Mo] - (.Intel Security, Inc. - Intel Security PEF Service.) - (1.4.108.0) = C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [23/08/2016 07:01:56] CPU Usage:0 % 2520 | [Owner : Système | Parent : 856(services.exe) | 8.74 Mo] - (.NVIDIA Corporation - NVIDIA Network Service.) - (2.4.11.66) = C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [19/03/2016 18:29:22] CPU Usage:0 % 2560 | [Owner : Système | Parent : 856(services.exe) | 10.45 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\AVAST Software\SecureLine\vpnsvc.exe [22/08/2016 23:45:40] CPU Usage:0 % 2796 | [Owner : Système | Parent : 856(services.exe) | 18.99 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 2804 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 7.26 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 316 | [Owner : Système | Parent : 2204(mfemms.exe) | 9.62 Mo] - (.McAfee, Inc. - McAfee Process Validation Service.) - (15.6.0.1220) = C:\Windows\System32\mfevtps.exe [31/08/2015 12:52:29] CPU Usage:0 % 3124 | [Owner : Système | Parent : 2496(NVDisplay.Container.exe) | 21.55 Mo] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.7654) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [23/10/2016 12:26:38] CPU Usage:0 % 3768 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 7.16 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 3792 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 23.22 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.14393.0) = C:\Windows\System32\sihost.exe [16/07/2016 13:42:09] CPU Usage:0 % 3340 | [Owner : Emmanuelle | Parent : 3124(nvxdsync.exe) | 12.41 Mo] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.7654) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [23/10/2016 12:26:38] CPU Usage:0 % 4124 | [Owner : Emmanuelle | Parent : 1332() | 99.71 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.14393.953) = C:\Windows\explorer.exe [09/05/2017 15:11:17] CPU Usage:0 % 4208 | [Owner : Emmanuelle | Parent : 3340(nvtray.exe) | 17.77 Mo] - (.NVIDIA Corporation - NVIDIA Backend.) - (20.0.11.0) = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [19/03/2016 18:29:25] CPU Usage:0 % 4464 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 15.94 Mo] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.8763) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe [23/10/2016 12:53:28] CPU Usage:0 % 2440 | [Owner : Emmanuelle | Parent : 3124(nvxdsync.exe) | 14.05 Mo] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.7654) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [23/10/2016 12:26:38] CPU Usage:0 % 3856 | [Owner : Emmanuelle | Parent : 2356() | 12.21 Mo] - (.Intel Corporation - igfxEM Module.) - (6.15.10.4531) = C:\Windows\System32\igfxEM.exe [02/09/2015 11:46:14] CPU Usage:0 % 3860 | [Owner : Emmanuelle | Parent : 2356() | 9.43 Mo] - (.Intel Corporation - igfxHK Module.) - (6.15.10.4531) = C:\Windows\System32\igfxHK.exe [02/09/2015 11:46:14] CPU Usage:0 % 3876 | [Owner : Emmanuelle | Parent : 2356() | 10.99 Mo] - (.-.) - (0.0.0.0) = C:\Windows\System32\igfxTray.exe [02/09/2015 11:46:15] CPU Usage:0 % 1292 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 43.5 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.14393.0) = C:\Windows\System32\RuntimeBroker.exe [16/07/2016 13:42:05] CPU Usage:0 % 4564 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 22.66 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.14393.0) = C:\Windows\System32\dllhost.exe [16/07/2016 13:42:27] CPU Usage:0 % 5460 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 14.6 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.14393.0) = C:\Windows\System32\taskhostw.exe [16/07/2016 13:42:36] CPU Usage:0 % 5012 | [Owner : Système | Parent : 2204(mfemms.exe) | 8.22 Mo] - (.McAfee, Inc. - McAfee Core Firewall Service.) - (15.6.0.1220) = C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [31/08/2015 12:52:39] CPU Usage:0 % 2932 | [Owner : Système | Parent : 856(services.exe) | 43.21 Mo] - (.McAfee, Inc. - McAfee Service Host.) - (6.4.4016.0) = C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [31/08/2015 12:52:20] CPU Usage:0 % 3196 | [Owner : Système | Parent : 956(svchost.exe) | 40.56 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.14393.0) = C:\Windows\System32\wbem\WmiPrvSE.exe [16/07/2016 13:42:31] CPU Usage:0 % 6248 | [Owner : Emmanuelle | Parent : 856(services.exe) | 17.73 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 6776 | [Owner : Emmanuelle | Parent : 4124(explorer.exe) | 12.2 Mo] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) - (1.0.0.971) = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19/03/2016 15:07:53] CPU Usage:0 % 4580 | [Owner : Emmanuelle | Parent : 4124(explorer.exe) | 13.69 Mo] - (.© 2015 Microsoft Corporation - Microsoft Bing Service.) - (1.0.6.0) = C:\Users\Emmanuelle\AppData\Local\Microsoft\BingSvc\BingSvc.exe [27/11/2016 11:52:04] CPU Usage:0 % 7948 | [Owner : Système | Parent : 856(services.exe) | 18.82 Mo] - (.McAfee, Inc. - McAfee CSP Service Host.) - (2.3.322.0) = C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\McCSPServiceHost.exe [28/02/2017 11:10:36] CPU Usage:0 % 308 | [Owner : Emmanuelle | Parent : 7272() | 13.79 Mo] - (.LeapFrog Enterprises, Inc. - Monitor Application.) - (6.1.3.0) = C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [12/02/2016 13:50:42] CPU Usage:0 % 5844 | [Owner : Emmanuelle | Parent : 2224(ModuleCoreService.exe) | 34.07 Mo] - (.McAfee, Inc. - McAfee Module Core Service.) - (1.6.121.0) = C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [15/03/2017 22:36:31] CPU Usage:0 % 1520 | [Owner : Emmanuelle | Parent : 5844(ModuleCoreService.exe) | 4.7 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 8344 | [Owner : Système | Parent : 2204(mfemms.exe) | 73.3 Mo] - (.McAfee, Inc. - McAfee Scanner service.) - (1.5.0.2512) = C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [31/08/2015 12:52:55] CPU Usage:0 % 8648 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 9.92 Mo] - (.Microsoft Corporation - InstallAgent.) - (10.0.14393.1066) = C:\Windows\System32\InstallAgent.exe [09/05/2017 15:12:51] CPU Usage:0 % 7736 | [Owner : Système | Parent : 856(services.exe) | 6.99 Mo] - (.Acer Incorporated - QASvc.) - (2.0.3008.0) = C:\Program Files\Acer\Acer Quick Access\QASvc.exe [04/09/2015 20:49:34] CPU Usage:0 % 8660 | [Owner : SERVICE LOCAL | Parent : 856(services.exe) | 6.33 Mo] - (.Acer Incorporated - QALSvc.) - (2.0.3008.0) = C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [04/09/2015 20:49:32] CPU Usage:0 % 600 | [Owner : Système | Parent : 856(services.exe) | 8.01 Mo] - (.Acer Incorporated - ePowerSvc.) - (7.0.8109.0) = C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [14/05/2015 11:00:02] CPU Usage:0 % 5132 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 1.01 Mo] - (.Acer Incorporated - Background Agent.) - (1.0.1.7) = C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [30/08/2016 15:09:52] CPU Usage:0 % 5504 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 0.88 Mo] - (.Acer - Acer Portal.) - (3.0.12.2004) = C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [09/09/2016 11:00:40] CPU Usage:0 % 7144 | [Owner : Emmanuelle | Parent : 600(ePowerSvc.exe) | 11.27 Mo] - (.Acer Incorporated - ePowerTray.) - (7.0.8109.0) = C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [14/05/2015 11:00:04] CPU Usage:0 % 6228 | [Owner : Emmanuelle | Parent : 6860() | 0.51 Mo] - (.Acer Incorporated - QAAgent.) - (2.0.3008.0) = C:\Program Files\Acer\Acer Quick Access\QAAgent.exe [04/09/2015 20:49:28] CPU Usage:0 % 5808 | [Owner : Système | Parent : 7736(QASvc.exe) | 10.71 Mo] - (.Acer Incorporated - QAAdminAgent.) - (2.0.3008.0) = C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe [04/09/2015 20:49:26] CPU Usage:0 % 2728 | [Owner : Système | Parent : 7736(QASvc.exe) | 7.13 Mo] - (.Acer Incorporated - QALockHandler.) - (2.0.3008.0) = C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe [04/09/2015 20:49:30] CPU Usage:0 % 9108 | [Owner : Système | Parent : 956(svchost.exe) | 5.94 Mo] - (.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) - (10.0.14393.0) = C:\Windows\System32\wbem\unsecapp.exe [16/07/2016 13:42:31] CPU Usage:0 % 1280 | [Owner : Système | Parent : 956(svchost.exe) | 8.68 Mo] - (.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) - (10.0.14393.0) = C:\Windows\System32\wbem\unsecapp.exe [16/07/2016 13:42:31] CPU Usage:0 % 7612 | [Owner : Système | Parent : 856(services.exe) | 4.88 Mo] - (.McAfee, Inc. - McAfee Core Firewall Service.) - (15.6.0.1220) = C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [31/08/2015 12:52:39] CPU Usage:0 % 5740 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 9.57 Mo] - (.Intel Corporation - igfxext Module.) - (6.15.10.4531) = C:\Windows\System32\igfxext.exe [02/09/2015 11:46:14] CPU Usage:0 % 7508 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 8.68 Mo] - (.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) - (10.0.14393.0) = C:\Windows\System32\wbem\unsecapp.exe [16/07/2016 13:42:31] CPU Usage:0 % 5564 | [Owner : Système | Parent : 600(ePowerSvc.exe) | 9.62 Mo] - (.Acer Incorporated - ePowerEvent.) - (7.0.8109.0) = C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe [14/05/2015 11:00:00] CPU Usage:0 % 5936 | [Owner : Système | Parent : 956(svchost.exe) | 8.62 Mo] - (.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) - (10.0.14393.0) = C:\Windows\System32\wbem\unsecapp.exe [16/07/2016 13:42:31] CPU Usage:0 % 5328 | [Owner : Système | Parent : 2244(CCDMonitorService.exe) | 14.9 Mo] - (.Acer Cloud Technology - AcerCloud Client.) - (0.0.0.0) = C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe [20/09/2016 14:21:28] CPU Usage:4 % 7040 | [Owner : Système | Parent : 5328(ccd.exe) | 4.43 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 7904 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 1.38 Mo] - (.- ACCStd.) - (2.0.3305.0) = C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [10/07/2015 12:38:50] CPU Usage:0 % 4852 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 15.52 Mo] - (.Microsoft Corporation - InstallAgentUserBroker.) - (10.0.14393.1066) = C:\Windows\System32\InstallAgentUserBroker.exe [09/05/2017 15:12:51] CPU Usage:0 % 6768 | [Owner : Système | Parent : 856(services.exe) | 6.66 Mo] - (.WildTangent - WildTangent Games App Integration Service.) - (4.0.39.17) = C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [14/04/2015 20:43:58] CPU Usage:0 % 2408 | [Owner : Système | Parent : 856(services.exe) | 5.28 Mo] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host Interface.) - (11.0.0.1153) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [24/06/2015 02:08:22] CPU Usage:0 % 5848 | [Owner : Système | Parent : 856(services.exe) | 9.55 Mo] - (.Intel Corporation - Intel(R) Local Management Service.) - (11.0.0.1153) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [24/06/2015 02:08:10] CPU Usage:0 % 8360 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 1.8 Mo] - (.Acer Incorporated - ePowerButton_NB.) - (7.0.8109.0) = C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe [14/05/2015 13:23:12] CPU Usage:0 % 8116 | [Owner : Système | Parent : 856(services.exe) | 4.99 Mo] - (.McAfee, Inc. - McAfee WebAdvisor.) - (4.0.5.139) = C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [19/05/2017 18:42:38] CPU Usage:0 % 6400 | [Owner : Système | Parent : 856(services.exe) | 8.8 Mo] - (.McAfee, Inc. - McAfee Access Protection.) - (6.0.4041.0) = C:\Program Files\Common Files\McAfee\VSCore_15_6\mcapexe.exe [20/03/2017 12:31:36] CPU Usage:0 % 4916 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 23.5 Mo] - (.Microsoft Corporation - SmartScreen.) - (10.0.14393.1066) = C:\Windows\System32\smartscreen.exe [09/05/2017 15:13:18] CPU Usage:0 % 4224 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 23.54 Mo] - (.Microsoft Corporation - Application Frame Host.) - (10.0.14393.0) = C:\Windows\System32\ApplicationFrameHost.exe [16/07/2016 13:42:40] CPU Usage:0 % 6664 | [Owner : Emmanuelle | Parent : 3244() | 29.7 Mo] - (.Microsoft Corporation - Microsoft OneDrive.) - (17.3.6943.625) = C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\OneDrive.exe [22/08/2016 23:50:51] CPU Usage:0 % 10720 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 15.34 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.14393.0) = C:\Windows\System32\dllhost.exe [16/07/2016 13:42:27] CPU Usage:0 % 9388 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 72.33 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.14393.447) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe [03/12/2016 14:28:11] CPU Usage:2 % 7984 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 38.39 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.14393.953) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe [09/05/2017 15:11:53] CPU Usage:0 % 10704 | [Owner : Emmanuelle | Parent : 7888() | 33.04 Mo] - (.Dashlane, Inc. - Dashlane.) - (4.8.5.35155) = C:\Users\Emmanuelle\AppData\Roaming\Dashlane\Dashlane.exe [19/09/2016 01:23:15] CPU Usage:0 % 6744 | [Owner : Emmanuelle | Parent : 10704(Dashlane.exe) | 27.9 Mo] - (.Dashlane, Inc. - Dashlane.) - (4.8.5.35155) = C:\Users\EMMANU~1\AppData\Roaming\Dashlane\DashlanePlugin.exe [19/09/2016 01:22:58] CPU Usage:0 % 10620 | [Owner : Système | Parent : 856(services.exe) | 37.08 Mo] - (.Microsoft Corporation - Microsoft Office Click-to-Run (SxS).) - (16.0.8326.2076) = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe [23/08/2016 06:59:43] CPU Usage:0 % 10812 | [Owner : Emmanuelle | Parent : 10620(OfficeClickToRun.exe) | 7.19 Mo] - (.Microsoft Corporation - AppVShNotify.) - (5.0.10348.0) = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe [23/08/2016 06:59:42] CPU Usage:0 % 10400 | [Owner : Emmanuelle | Parent : 7196() | 1.41 Mo] - (.SweetLabs, Inc - Host App Service Updater.) - (1.0.0.0) = C:\Users\Emmanuelle\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [14/07/2017 12:12:02] CPU Usage:0 % 8056 | [Owner : Système | Parent : 856(services.exe) | 12.78 Mo] - (.Intel Corporation - Intel(R) Security Assist.) - (1.0.0.532) = C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [19/05/2015 10:11:00] CPU Usage:0 % 1988 | [Owner : Emmanuelle | Parent : 1184(svchost.exe) | 13.67 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.14393.0) = C:\Windows\System32\taskhostw.exe [16/07/2016 13:42:36] CPU Usage:0 % 652 | [Owner : Système | Parent : 1184(svchost.exe) | 6.35 Mo] - (.Microsoft Corporation - Tâches de fond de la protection du système Microsoft® Windows..) - (10.0.14393.0) = C:\Windows\System32\SrTasks.exe [16/07/2016 13:44:01] CPU Usage:0 % 9028 | [Owner : Système | Parent : 652(SrTasks.exe) | 4.47 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 3416 | [Owner : Système | Parent : 1184(svchost.exe) | 5.9 Mo] - (.Microsoft Corporation - Tâches de fond de la protection du système Microsoft® Windows..) - (10.0.14393.0) = C:\Windows\System32\SrTasks.exe [16/07/2016 13:44:01] CPU Usage:0 % 1716 | [Owner : Système | Parent : 3416(SrTasks.exe) | 4.28 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 10944 | [Owner : Système | Parent : 1184(svchost.exe) | 2.31 Mo] - (.McAfee, Inc. - McAfee DAT Reputation Agent.) - (1.1.0.395) = C:\Program Files\Common Files\McAfee\amcontent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [15/03/2017 22:34:15] CPU Usage:0 % 460 | [Owner : Système | Parent : 10944(mcdatrep.exe) | 0.61 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 9648 | [Owner : Système | Parent : 856(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.14393.0) = C:\Windows\System32\svchost.exe [16/07/2016 13:42:27] CPU Usage:0 % 3268 | [Owner : SERVICE LOCAL | Parent : 916(svchost.exe) | 3.98 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (10.0.14393.82) = C:\Windows\System32\dasHost.exe [23/10/2016 13:11:12] CPU Usage:0 % 11460 | [Owner : Emmanuelle | Parent : 4124(explorer.exe) | 86.98 Mo] - (.Skype Technologies S.A. - Skype.) - (7.30.80.105) = C:\Program Files (x86)\Skype\Phone\Skype.exe [15/11/2016 17:34:00] CPU Usage:0 % 9044 | [Owner : Système | Parent : 588(winlogon.exe) | 2.88 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.14393.1066) = C:\Windows\System32\fontdrvhost.exe [09/05/2017 15:10:55] CPU Usage:0 % 3680 | [Owner : LogonSessionId_0_19880543 | Parent : 856(services.exe) | 15.34 Mo] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.14393.953) = C:\Windows\System32\SearchIndexer.exe [09/05/2017 15:14:09] CPU Usage:0 % 8092 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 73.6 Mo] - (.Microsoft Corporation - Microsoft Edge.) - (11.0.14393.1066) = C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe [09/05/2017 15:13:36] CPU Usage:0 % 4436 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 18.07 Mo] - (.Microsoft Corporation - Browser_Broker.) - (11.0.14393.0) = C:\Windows\System32\browser_broker.exe [16/07/2016 13:43:10] CPU Usage:0 % 8604 | [Owner : Emmanuelle | Parent : 1292(RuntimeBroker.exe) | 184.68 Mo] - (.Microsoft Corporation - Microsoft Edge Content Process.) - (11.0.14393.953) = C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe [09/05/2017 15:13:16] CPU Usage:6 % 10380 | [Owner : Emmanuelle | Parent : 1292(RuntimeBroker.exe) | 42.06 Mo] - (.Microsoft Corporation - Microsoft Edge Content Process.) - (11.0.14393.953) = C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe [09/05/2017 15:13:16] CPU Usage:0 % 4372 | [Owner : LogonSessionId_0_22906697 | Parent : 956(svchost.exe) | 25.22 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.14393.0) = C:\Windows\System32\wbem\WmiPrvSE.exe [16/07/2016 13:42:31] CPU Usage:0 % 6976 | [Owner : SERVICE RÉSEAU | Parent : 2292(NvStreamService.exe) | 11.86 Mo] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) - (4.1.1974.1729) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [19/03/2016 18:29:26] CPU Usage:0 % 11532 | [Owner : SERVICE RÉSEAU | Parent : 6976(NvStreamNetworkService.exe) | 4.92 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 6216 | [Owner : Système | Parent : 2292(NvStreamService.exe) | 13.1 Mo] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) - (4.1.1976.1377) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe [19/03/2016 18:29:26] CPU Usage:0 % 11524 | [Owner : Système | Parent : 6216(NvStreamUserAgent.exe) | 7.43 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.14393.0) = C:\Windows\System32\conhost.exe [16/07/2016 13:42:23] CPU Usage:0 % 3216 | [Owner : Emmanuelle | Parent : 1636() | 32.64 Mo] - (.McAfee, Inc. - McAfee.) - (8.4.4019.0) = C:\PROGRA~1\COMMON~1\McAfee\platform\McUICnt.exe [31/08/2015 12:52:45] CPU Usage:0 % 11352 | [Owner : LogonSessionId_0_24211442 | Parent : 956(svchost.exe) | 9.49 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.14393.0) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [16/07/2016 13:42:56] CPU Usage:0 % 10356 | [Owner : LogonSessionId_0_24521529 | Parent : 856(services.exe) | 6.56 Mo] - (.Microsoft Corporation - Programme d’installation pour les modules Windows.) - (10.0.14393.479) = C:\Windows\servicing\TrustedInstaller.exe [01/03/2017 12:29:34] CPU Usage:0 % 9756 | [Owner : Système | Parent : 956(svchost.exe) | 46.56 Mo] - (.Microsoft Corporation - Windows Modules Installer Worker.) - (10.0.14393.693) = C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.1051_none_7f2bf7ea21d201b2\TiWorker.exe [11/02/2017 21:50:05] CPU Usage:15 % 6468 | [Owner : Emmanuelle | Parent : 3216(McUICnt.exe) | 12.35 Mo] - (.McAfee, Inc. - McAfee.) - (15.4.4022.0) = C:\Program Files\mcafee\CoreUI\Launch.exe [09/05/2017 15:29:55] CPU Usage:0 % 2028 | [Owner : Emmanuelle | Parent : 6468(Launch.exe) | 19.34 Mo] - (.McAfee, Inc. - McAfee Chromium Container Delegate.) - (1.6.118.0) = C:\Program Files\Common Files\McAfee\ChromiumContainer\delegate.exe [02/04/2017 08:02:04] CPU Usage:0 % 11864 | [Owner : Emmanuelle | Parent : 956(svchost.exe) | 25.4 Mo] - (.Microsoft Corporation - Background Task Host.) - (10.0.14393.0) = C:\Windows\System32\backgroundTaskHost.exe [16/07/2016 13:42:09] CPU Usage:0 % 9132 | [Owner : SERVICE LOCAL | Parent : 1492(svchost.exe) | 14.45 Mo] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (10.0.14393.0) = C:\Windows\System32\audiodg.exe [16/07/2016 13:42:22] CPU Usage:0 % 11892 | [Owner : Aucun | Parent : 4124(explorer.exe) | 38.82 Mo] - (.SosVirus - QuickDiag.) - (1.7.17.1) = C:\Users\Emmanuelle\Desktop\QuickDiag.exe [27/08/2017 09:49:36] CPU Usage:0 % ---------- | MD5 [MD5.F2D58A2E27C2CD486F8F0A123A3F34C3] - [09/05/2017 15:11:17] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4564.8 Ko] - (10.0.14393.953) : C:\WINDOWS\Explorer.exe [MD5.F4F684066175B77E0C3A000549D2922C] - [16/07/2016 13:42:36] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [227.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\cmd.exe [MD5.77DBC745D957B4F0404ABABC10696784] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Processus d’exécution client-serveur.) - [17.72 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\csrss.exe [MD5.DA63852A2B0340E94D74EAF0CD444979] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. - COM Surrogate.) - [20.84 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\dllhost.exe [MD5.6955067712F2F4752CA12192B08EF860] - [16/07/2016 13:42:16] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [683.48 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Kernel32.dll [MD5.6F8E95716C1A27FF2FE96D30B147F1C1] - [23/10/2016 13:10:58] - (.© Microsoft Corporation. - Local Security Authority Process.) - [56.05 Ko] - (10.0.14393.187) : C:\WINDOWS\System32\lsass.exe [MD5.7BD259FC59CF9C2AE1B979564B374CC6] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. - Distributed COM Services.) - [867.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\rpcss.dll [MD5.C7645D43451C6D94D87F4D07BDE59C89] - [16/07/2016 13:42:42] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [68 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\rundll32.exe [MD5.3C69CC28665854F1AAB4B4005005FA31] - [01/03/2017 12:29:38] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [443.94 Ko] - (10.0.14393.479) : C:\WINDOWS\System32\services.exe [MD5.36F670D89040709013F6A460176767EC] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [43.45 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\svchost.exe [MD5.C46EA86BF0E7C96235E9064CBAD6ED26] - [01/03/2017 12:27:30] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de l’API uilisateur de Windows multi-utilisateurs.) - [1426.95 Ko] - (10.0.14393.576) : C:\WINDOWS\System32\user32.dll [MD5.C1B1FFC800BE2F31EB2CF8CB40629C69] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Userinit.) - [32.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\userinit.exe [MD5.99A19C9A74E2F9820E501DCE77F84F70] - [16/07/2016 13:42:27] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [297.11 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Wininit.exe [MD5.917F081E2AB667C44F7D96DE1D16DFAE] - [01/03/2017 12:29:07] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Windows.) - [658 Ko] - (10.0.14393.594) : C:\WINDOWS\System32\Winlogon.exe [MD5.323AA1953ED9C01E23F740FA891FE064] - [02/11/2016 09:44:50] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de fonction connexe pour WinSock.) - [570.34 Ko] - (10.0.14393.351) : C:\WINDOWS\System32\Drivers\afd.sys [MD5.A10F989A812B57B9695F6C305907C9C6] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [27.84 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\atapi.sys [MD5.65DEB05FC234BFF207379F06F0754402] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [187.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\ataport.sys [MD5.F8FB51B9EF6372610E9B31A1D86B62FC] - [16/07/2016 13:42:35] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [90 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\cdfs.sys [MD5.613D0137C269187FA298A157E3D14A18] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [169 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\cdrom.sys [MD5.4BC21E937E9F9F408672D2C2CBE4A153] - [09/05/2017 15:12:07] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [142 Ko] - (10.0.14393.953) : C:\WINDOWS\System32\Drivers\dfsc.sys [MD5.10E3515FE5DBA6656FA62C29342EC4A1] - [16/07/2016 13:41:52] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [81.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\hdaudbus.sys [MD5.B54B30992620C97230013A74461C8517] - [16/07/2016 13:41:54] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [111.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\i8042prt.sys [MD5.F1DAECC3B3D6399875D4F10529D6A77C] - [16/07/2016 13:42:39] - (.© Microsoft Corporation. - IP Network Address Translator.) - [207.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\ipnat.sys [MD5.D559FF28B1AD9B1E15A4186E785E61F6] - [09/05/2017 15:12:08] - (.© Microsoft Corporation. Tous droits réservés. - Minirdr SMB Windows NT.) - [439.84 Ko] - (10.0.14393.953) : C:\WINDOWS\System32\Drivers\mrxsmb.sys [MD5.63560E6BC9BCA978A6B72DF65F7A8930] - [09/05/2017 15:13:25] - (.© Microsoft Corporation. Tous droits réservés. - NDIS (Network Driver Interface Specification).) - [1153.34 Ko] - (10.0.14393.1066) : C:\WINDOWS\System32\Drivers\ndis.sys [MD5.6FEBB0A847FFD5F057B9AC8889F1B9A7] - [16/07/2016 13:42:35] - (.© Microsoft Corporation. - MBT Transport driver.) - [272.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\netbt.sys [MD5.98BBD81DC481E9D58EEB31C81EBDEFF5] - [09/05/2017 15:11:11] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [2202.84 Ko] - (10.0.14393.953) : C:\WINDOWS\System32\Drivers\ntfs.sys [MD5.6B81BF7853D161DB8AC62CD8B9C2DE6B] - [16/07/2016 13:41:53] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [94.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\parport.sys [MD5.17E565710172ED71B8531D8822E1C5D1] - [16/07/2016 13:42:39] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [102.5 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\rasl2tp.sys [MD5.7135785C21CA79D270D11037C43D3F19] - [16/07/2016 13:44:03] - (.© Microsoft Corporation. Tous droits réservés. - Redirecteur de périphérique de Microsoft RDP.) - [173 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\rdpdr.sys [MD5.F3CFBE74DAF9ABD06F0B2A037DC4C90A] - [09/05/2017 15:13:35] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [2474.34 Ko] - (10.0.14393.1066) : C:\WINDOWS\System32\Drivers\tcpip.sys [MD5.0B237F8A96952BF95A14865030E131F2] - [09/05/2017 15:13:10] - (.© Microsoft Corporation. - TDI Translation Driver.) - [115.84 Ko] - (10.0.14393.953) : C:\WINDOWS\System32\Drivers\tdx.sys [MD5.BF2546583BB75F01DDA60A7921DFB230] - [16/07/2016 13:42:35] - (.© Microsoft Corporation. - Volume Shadow Copy driver.) - [382.34 Ko] - (10.0.14393.0) : C:\WINDOWS\System32\Drivers\volsnap.sys ---------- | Locked Applications ---------- | Explorer.exe component call (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\CoreUIComponents.dll (.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.12.2.0) -- C:\WINDOWS\System32\winsqlite3.dll (..-..) - (0.0.0.0) -- C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL differs from file image: (..-..) - (0.0.0.0) -- : Sat Aug 12 14:49:42 2017 (..-..) - (0.0.0.0) -- : Tue Apr 18 15:02:10 2017 (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\VCRUNTIME140.dll differs from file image: (..-..) - (0.0.0.0) -- : Fri Feb 17 01:09:46 2017 (..-..) - (0.0.0.0) -- : Fri Jun 10 07:14:56 2016 (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\MSVCP140.dll differs from file image: (..-..) - (0.0.0.0) -- : Fri Feb 17 01:10:10 2017 (..-..) - (0.0.0.0) -- : Fri Jun 10 07:15:23 2016 (..-..) - (0.0.0.0) -- C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1036\GrooveIntlResource.dll differs from file image: (..-..) - (0.0.0.0) -- : Sat Aug 12 08:28:48 2017 (..-..) - (0.0.0.0) -- : Tue Apr 18 08:35:08 2017 (.Intel Corporation.-.User Mode Driver for Intel(R) Graphics Technology.) - (20.19.15.4531) -- C:\WINDOWS\SYSTEM32\igd10iumd64.dll (.Intel Corporation.-.Unified Shader Compiler for Intel(R) Graphics Accelerator.) - (20.19.15.4531) -- C:\WINDOWS\SYSTEM32\igdusc64.dll (.Acer Incorporated.-.SysHook Dynamic Link Library.) - (7.0.8109.0) -- C:\Program Files\Acer\Acer Power Management\SysHook.dll (..-.Clearfishellext Dynamic Link Library.) - (1.0.0.0) -- C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll (.NVIDIA Corporation.-.NVIDIA NVAPI Library, Version 376.54.) - (21.21.13.7654) -- C:\WINDOWS\system32\nvapi64.dll (.NVIDIA Corporation.-.NVIDIA French language resource library.) - (8.17.13.7654) -- C:\WINDOWS\SYSTEM32\Nv3DAppShExtR.dll (.NVIDIA Corporation.-.NVIDIA Display Shell Extension.) - (1.2.0.1) -- C:\WINDOWS\system32\nvshext.dll (.Intel Corporation.-.igfxDTCM Module.) - (6.15.10.4531) -- C:\WINDOWS\system32\igfxDTCM.dll (..-..) - (0.0.0.0) -- :\PROGRA~1\mcafee\msc\MCCTXM~1.DLL (..-..) - (0.0.0.0) -- :\PROGRA~1\mcafee\virusscan\mcctxmnu.dll (.McAfee, Inc..-.McAfee Runtime MUI API.) - (6.3.3038.0) -- C:\Program Files\Common Files\McAfee\Platform\McRtMui.dll (.Intel Corporation.-.McAfee Language Selection Library.) - (7.3.3038.0) -- C:\Program Files\Common Files\McAfee\Platform\LangSel.dll (..-..) - (0.0.0.0) -- :\PROGRA~1\mcafee\mqs\shredext.dll (.Foxit Software Inc..-.ConvertToPDFShellExtension.) - (7.0.6.1223) -- C:\Program Files (x86)\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll (.NVIDIA Corporation.-.NVIDIA Shell Extensions.) - (8.17.13.7654) -- C:\WINDOWS\system32\nv3dappshext.dll ---------- | Svchost.exe component call (Microsoft Files Whitelisted) (.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.12.2.0) -- C:\WINDOWS\System32\winsqlite3.dll (.NVIDIA Corporation.-.NVIDIA Capture Server Proxy.) - (2.5.11.45) -- C:\WINDOWS\system32\nvspcap64.dll (.NVIDIA Corporation.-.NVIDIA NVAPI Library, Version 376.54.) - (21.21.13.7654) -- C:\WINDOWS\system32\nvapi64.dll ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE LOCAL OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE RÉSEAU OneDrive - ("C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\...\Run]) - User: LAPTOP-O5ULGE56\Emmanuelle Dashlane - ("C:\Users\Emmanuelle\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\...\Run]) - User: LAPTOP-O5ULGE56\Emmanuelle DashlanePlugin - ("C:\Users\Emmanuelle\AppData\Roaming\Dashlane\DashlanePlugin.exe" ws [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\...\Run]) - User: LAPTOP-O5ULGE56\Emmanuelle BingSvc - (C:\Users\Emmanuelle\AppData\Local\Microsoft\BingSvc\BingSvc.exe [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\...\Run]) - User: LAPTOP-O5ULGE56\Emmanuelle RTHDVCPL - ("C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [HKLM\SOFTWARE\...\Run]) - User: Public NvBackend - ("C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [HKLM\SOFTWARE\...\Run]) - User: Public ShadowPlay - (C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart [HKLM\SOFTWARE\...\Run]) - User: Public [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background "Dashlane"="C:\Users\Emmanuelle\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup "DashlanePlugin"="C:\Users\Emmanuelle\AppData\Roaming\Dashlane\DashlanePlugin.exe" ws "BingSvc"=C:\Users\Emmanuelle\AppData\Local\Microsoft\BingSvc\BingSvc.exe [27/11/2016 11:52:04] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall 17.3.6917.0607\amd64"=C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64" "Uninstall 17.3.6917.0607"=C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6917.0607" [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "IsMRUEstablished"=0 "LegacyDefaultPrinterMode"=0 "Device"=Foxit PhantomPDF Printer,winspool,Ne02: "UserSelectedDefault"=0 [HKLM\Software\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"=C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "RTHDVCPL"=0x040000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32] "mcpltui_exe"=0x040000000000000000000000 "BacKGround Agent"=0x040000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D255C50DCC143C [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "Monitor"="C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List ACC ACCAgent ACCBackgroundApplication AcerCloud App Explorer Avast SecureLine avast! SL Update BacKGroundAgent FUBTrackingByPLD Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse McAfeeLogon OneDrive Standalone Update Task OneDrive Standalone Update Task-S-1-5-21-2395831268-3694815761-1612603451-1001 Power Button Power Management Quick Access Secured Yahoo Powered lolor Software Update Application UbtFrameworkService User_Feed_Synchronization-{426D0793-68B3-4987-8B43-0D2D55A52E82} {617C32D5-70A6-6F08-17EE-424A28C3DD2E} ---------- | Startings up registry ¦ Folder ---------- | Other keys [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "InstanceID"=573788b5-3000-49e5-8663-2cc344e "GlassSessionId"=1 [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "ResourceTimeoutCount"=648000 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "PendingFileRenameOperations"=\??\C:\WINDOWS\TEMP\019383~1.EXE \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SETED76.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\SA_main.inf \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET938A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\SA_x64.inf \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET9793.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\saupkeep.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETA0EA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McBrwCtl.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETAAEE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\DownloadScan.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETB196.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETB531.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McPlgUI.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETBCA4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\NPMcFFPlg64.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETBFF1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SETC040.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SETC40A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\sasshmod.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETD36C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McSACorePS.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\SETD532.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\saSets.ini \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SETFA01.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\SA_indep.inf \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SETFADD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\chr.inf \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET5FA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\uninstall.exe \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET668.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\saProd.ini \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SETF62.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\mcbrwctl.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET160A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\DownloadScan.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET1772.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\saSets.ini \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET190A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\icon.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET192A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET19B7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\siteadvisor.mcafee.chrome.extension.json \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET19D9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\default.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET1C6A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\saUpd.exe \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET23ED.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET295C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET2E01.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET2F79.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\McPlgUI.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET3268.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\sares.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET3641.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\McSACorePS.dll \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET3ECE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe \??\C:\Program Files (x86)\McAfee\SiteAdvisor\SET3FAA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\licenses.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4383.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\logic.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET43A3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET46D1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_green.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4E63.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_yellow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET52E8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_red.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET55E7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_grey.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET57FB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_black.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59C1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_disabled.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5B78.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_hs.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6165.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_cashback.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6398.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_green_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET64D2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_yellow_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET70C9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_red_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET72ED.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_grey_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET79B4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_black_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7BA9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_hs_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET806D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_green.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET830E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_yellow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET87A3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_red.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8DAF.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_grey.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET909E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_black.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET93BC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_disabled.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9524.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_hs.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET95F0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_cashback.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET967E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_green_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9834.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_yellow_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET98A3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_red_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9CF9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_grey_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9E90.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_black_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA1CD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_hs_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA7F8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_cashback_lock.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETC11F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_cashback.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETC585.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_disabled.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETC76A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_green.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETCDF3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_grey.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETD046.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_hs.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETD18F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_red.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETD50B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small_button_yellow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETD51B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_arrow_down.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETD52C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_arrow_up.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETD8D6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_logo.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETDEC3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_logo.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETDF12.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_logo_plus.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETDF13.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\xup.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETE250.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\xdown.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETE4B3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\xup_light.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETE9B5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_blocked.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETEC17.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_logo_shield.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETF0FA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_x_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETF5CE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-logo-white.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\vertical_divider.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET168.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\vertical_divider_live.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET1A8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\green.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2A3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yellow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET36F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\red.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET380.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\untested.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET565.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protection.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET70C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cashback.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7B9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cashback_mcsecureLogo.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETAB7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cashback_ebatesLogo.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETCFC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\siteadvisor.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETF4E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\down_arrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETF9D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ytri.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET1125.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafeesiteadvisor.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET123F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\download_careful.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET14E0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\download_unsafe.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET14F1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\empty.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET18BB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\hs.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET1F63.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\hackersafe.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET1F83.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\searchglass.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET1F94.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\bullet.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET1FA4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\hs_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET234F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cb_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET263E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\grightarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET264E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\gleftarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET28E0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2B52.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2B53.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2D09.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2E04.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2E15.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_balloon_banner.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2E25.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_balloon_banner.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET2E26.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_balloon_banner.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET325D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_balloon_banner.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET32BC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_x.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET32BD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_upsell_border.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET337A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_facet.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET337B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3476.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3542.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3543.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3592.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_footer_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET35A3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_footer_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET35B3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_footer_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET35B4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_header_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET35C5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_header_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3633.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_header_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3644.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yrightarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3645.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yleftarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3684.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET36C4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET36E4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET37FE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET381F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3820.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_upsell_border.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3840.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_facet.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3850.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3890.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3891.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET38A2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET38C2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_footer_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET38C3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_footer_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET38D3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_footer_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET38E4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET38E5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3C22.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3C62.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_r_nox.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3C82.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\rrightarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3C83.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\rleftarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET3E97.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET41B5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4243.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET42F0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4300.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4311.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_upsell_border.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4370.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_facet.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4380.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET43A0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET43B1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET43C2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET43C3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_footer_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET43D3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_footer_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4655.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_footer_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4666.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4676.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4704.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4714.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_r_nox.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4725.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wrightarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4726.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wleftarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4737.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET47D4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET47F4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4834.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4854.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4855.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_upsell_border.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4866.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4886.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4896.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET48A7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_sep.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET48B8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_footer_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET48C8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_footer_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET48C9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_footer_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET49C4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_header_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET49C5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_header_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4A24.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_header_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4A54.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-xup.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4A74.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-noxup.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4A85.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-background.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4A95.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-top.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4AA6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-warningbackground.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4BB1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sachplg.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4C5E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4C7E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-logo.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4CDD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-logo-plus.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4CED.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-intel-logo.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4D1D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-intel-logo-plus.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4D2E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\blackpixel.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4D4E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\unselected_tab.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4EB6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\selected_tab.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4F15.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protectedmode.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4F45.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcwedge.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4FA4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protmode-on.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4FC4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protmode-off.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4FD5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\corner-solid.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET4FD6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small-buttonL.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5054.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small-buttonC.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5064.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small-buttonR.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5075.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\large-buttonL.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5076.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\large-buttonC.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5086.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\large-buttonR.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5097.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\error-icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5098.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\question-icon.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET50C8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SAPlus-graphic.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET50D9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\redarrow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET50DA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cornersm-solid.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET50EA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cornersm-hollow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET51F5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA1.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5736.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA2.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET57A4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA3.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET57F3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA4.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5852.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD1.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5853.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD2.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5863.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD3.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5864.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD4.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET58E2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\favicon.ico \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5903.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_green.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5913.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_grey.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5953.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_yellow.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5983.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_red.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59B3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_bottom_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59B4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_bottom_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59C4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_bottom_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59C5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_footer_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59D6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_footer_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59D7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_footer_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59E7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_header_l.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET59E8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_header_c.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5A38.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_header_r.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5B23.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_twitter_on.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5E31.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_twitter_off.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5E42.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_facebook_on.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5E62.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_facebook_off.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5EB1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_copylink_on.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5EE1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_copylink_off.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5F40.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\orange_btn_left.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5F50.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\orange_btn_center.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET5FDE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\orange_btn_right.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET603F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\settings_cashback.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET60AD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\telemetry.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET616B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-options.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6275.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-ui-options.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6303.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-options.css \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET67F6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-uninstall.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6883.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-uninstall.css \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET68F2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-ui-uninstall.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6921.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-warning.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6942.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\passwordProtect.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET69FE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\green_check.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6A4D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\main_close.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET6B0A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_shield.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET76B3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\white_check.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7AFA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\white_exclamation.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7BC6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\white_exclamation.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7BE6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\white_questionmark.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7C93.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\white_downchevron.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET7DCD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\white_timer.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET803F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\about.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET811A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\about_selected.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET812C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\email.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET838E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\help.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET841C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\help_selected.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET84F8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\setting.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8537.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\setting_selected.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET874C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\exclamation_mark_3angls_41x38.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET878C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\Mshield_watermark.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8849.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\web_advisor_30x230.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8859.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\X_close.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8906.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\downloadWarning.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8917.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\twitter.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8918.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\facebook.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8976.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\switch_on.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8A71.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\switch_off.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8A72.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\main_close_large.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8C39.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_safe_icon.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8CD6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_threat_annotation.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8CF6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_threat_icon.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8D26.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_warning_annotation.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8D37.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_warning_icon.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8D47.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_safe_annotation.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET8ECF.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_shield_small.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET920C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\uninstaller_check.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET924B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\installer_background.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET954A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\screen.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET958A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\blue_arrow.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9646.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\spinner_large.gif \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET96A5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-sstoast.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET96C5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-ui-sstoast.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET96D6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-sstoast.css \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET96F6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-icsstoast.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET989D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-ui-icsstoast.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET990B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-icsstoast.css \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET991C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-install.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET995B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-ui-install.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET99E9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-install.css \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9D55.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\icon_complete.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9E50.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\icon_failed.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SET9E51.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\icon_laptop.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA007.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\check-icon.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA0E3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\chrome.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA2F7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\error-icon.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA3B4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ie.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA403.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee-desktop-bg.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA423.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mozilla.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA434.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\warning.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA493.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wa-warning_ff.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4A3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\annotationBalloon_wa.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4A4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\annotationBalloon_wa.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4B5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\annotationEngine_wa.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4C6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\annotations_wa.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4C7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4D7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cashback.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4D8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\engine.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4D9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\facebook.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4EA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\google.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA4EB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\logo.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA605.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\options.png \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA616.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\referrers.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA626.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\selectors.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA637.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sizzle.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA648.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\warning.html \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA677.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\warning.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA678.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yahoo.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SETA689.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safe.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA784.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA7B4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA7D4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA7E5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA7E6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA8D1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAD95.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB111.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB160.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB190.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB21D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB395.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB636.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB6B4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB780.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB975.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETBA12.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETD51D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETD935.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETDA21.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETDBE7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETE415.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETE7B0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETE986.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETE997.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETEA72.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETECB6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETEDB1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETEDF0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF42B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-uninstall-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF46A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF47B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF6FD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF70D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF71E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF8F4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETF991.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1085.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1095.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET11EE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET127C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET127D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET129D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET12AE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET12BE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET12DF.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET12E0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1300.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET135F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1544.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1555.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1565.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1576.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET15A6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET15A7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET15B7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET15E7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET15E8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1608.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1609.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-sstoast-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET161A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET161B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET162C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET162D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET163D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET163E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET164F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1660.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET17E7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1875.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18A5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18B5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18B6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18C7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18C8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18D9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18E9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18EA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET18FB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET191B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET191C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET192D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET192E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET193E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET194F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET19AE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET19DE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1A4C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1D99.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1DD8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-shared-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1EB4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1F03.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1F14.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1F44.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1FA2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET1FB3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET2D50.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET2E99.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET30DD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3206.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET33AD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET37F4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3805.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3806.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3A58.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3AA8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3B83.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3BB3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3BC4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3C32.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3C52.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3C63.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3C64.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3D30.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3DCD.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3F84.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET3FB4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4041.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET41C9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET41DA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-options-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4248.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4268.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET42D7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4307.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4356.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4357.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4377.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4378.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET43A8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4416.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4446.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4447.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET44C5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4591.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET45B1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET45C2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET48B1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET49DB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4B43.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4B54.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET4C6E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET50C5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET523D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5589.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5740.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5750.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET587A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET59A4.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5A22.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5AFE.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-install-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5BCA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5BDB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5DC0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5E9C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5EBC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5EDC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5F1C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET5F3C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6008.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6096.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET60D5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET60E6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6145.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET63E6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET65AC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6687.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6763.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET67B2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6811.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6851.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET692C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET693D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET696D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6A29.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6A78.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6AC8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6AD8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6C12.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6CED.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6DC9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-icsstoast-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6E18.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-zh-TW.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6E77.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-zh-CN.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6E78.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-tr-TR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6EE6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-sv-SE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6FC2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-sr-Latn-CS.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET6FE2.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-sk-SK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7041.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-ru-RU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7052.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-pt-PT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET714D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-pt-BR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET717D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-pl-PL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET71CC.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-nl-NL.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7259.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-nb-NO.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7306.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-ko-KR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7327.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-ja-JP.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7412.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-it-IT.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7432.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-hu-HU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET778F.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-hr-HR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7955.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-fr-FR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET7CC1.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-fr-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET80D9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-fi-FI.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8231.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-es-MX.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET82BF.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-es-ES.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET82EF.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-en-US.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET83AB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-en-GB.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET83DB.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-en-CA.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET840B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-en-AU.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET843B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-el-GR.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET84B9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-de-DE.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET84E9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-da-DK.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8596.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\wa-res-checklist-cs-CZ.js \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET87BA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-zh-TW.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8857.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-zh-CN.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET89A0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-tr-TR.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8A8B.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-sv-SE.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8B48.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-sr-Latn-CS.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8B78.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-sk-SK.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8BE6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-ru-RU.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET8E68.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-pt-PT.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET930C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-pt-BR.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET99E3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-pl-PL.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SET9EF5.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-nl-NL.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA3F7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-nb-NO.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA4D3.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-ko-KR.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA66A.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-ja-JP.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA6E8.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-it-IT.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA851.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-hu-HU.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETA94C.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-hr-HR.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAA76.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-fr-FR.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAB42.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-fr-CA.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAB81.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-fi-FI.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETABF0.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-es-MX.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAC4E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-es-ES.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAD69.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-en-US.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETAF4E.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-en-GB.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB0A7.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-en-CA.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB2EA.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-en-AU.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB3B6.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-el-GR.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB609.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-de-DE.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB80D.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-da-DK.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\SETB8F9.tmp !\??\C:\Program Files (x86)\McAfee\SiteAdvisor\scripts\jslang\eula-cs-CZ.txt \??\C:\Program Files (x86)\McAfee\SiteAdvisor\Temp1406999610\mcinst.exe \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\mso40uiwin32client.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVIntegration.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVFileSystemMetadata.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVIsvStreamingManager.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVCatalog.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVIsvApi.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVIsvSubsystemController.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVIsvVirtualization.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVManifest.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVOrchestration.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVPolicy.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\mso30win32client.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\mso20win32client.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\mso40uires.dll.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe.bak \??\C:\Program Files\Common Files\Microsoft Shared\ClickToRun\StreamServer.dll.bak \??\C:\Program Files (x86)\Microsoft Office\Updates\Apply\FilesInUse\80B482F8-CB20-4626-B7F2-984ED9AE2293\OFFICE.ODF.bak \??\C:\Program Files (x86)\Microsoft Office\Updates\Apply\FilesInUse\80B482F8-CB20-4626-B7F2-984ED9AE2293\GROOVEEX.DLL.bak \??\C:\Program Files (x86)\Microsoft Office\Updates\Apply\FilesInUse\80B482F8-CB20-4626-B7F2-984ED9AE2293\GrooveIntlResource.dll.bak \??\C:\WINDOWS\TEMP\msvcp140.dll.bak \??\C:\WINDOWS\TEMP\vcruntime140.dll.bak \??\C:\WINDOWS\system32\spool\V4Dirs\523C05D1-0692-4657-B977-169C652D66D5\94766af2.BUD \??\C:\WINDOWS\system32\spool\V4Dirs\523C05D1-0692-4657-B977-169C652D66D5\94766af2.gpd \??\C:\WINDOWS\system32\spool\V4Dirs\523C05D1-0692-4657-B977-169C652D66D5 \??\c:\Config.Msi\189e96.rbf \??\c:\Config.Msi\189e9e.rbf \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\agcore.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\agcp.exe \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ar\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ar\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ar\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ar\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ar \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\bg\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\bg\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\bg\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\bg\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\bg \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ca\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ca\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ca\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ca\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ca \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\coreclr.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\coregen.exe \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\cs\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\cs\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\cs\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\cs\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\cs \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\da\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\da\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\da\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\da\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\da \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\de\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\de\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\de\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\de\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\de \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\el\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\el\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\el\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\el\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\el \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\es\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\es\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\es\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\es\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\es \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\et\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\et\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\et\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\et\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\et \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\eu\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\eu\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\eu\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\eu\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\eu \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fi\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fi\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fi\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fi\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fi \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fr\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fr\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fr\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fr\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\fr \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\he\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\he\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\he\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\he\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\he \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hr\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hr\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hr\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hr\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hr \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hu\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hu\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hu\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hu\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\hu \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\id\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\id\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\id\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\id\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\id \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\it\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\it\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\it\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\it\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\it \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ja\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ja\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ja\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ja\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ja \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ko\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ko\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ko\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ko\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ko \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lt\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lt\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lt\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lt\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lt \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lv\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lv\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lv\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lv\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\lv \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.VisualBasic.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.Graphics.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.Graphics.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.Graphics.Shaders.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.Graphics.Shaders.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ms\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ms\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ms\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ms\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ms \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\mscorlib.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\mscorlib.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\nl\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\nl\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\nl\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\nl\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\nl \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\no\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\no\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\no\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\no\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\no \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrlui.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pl\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pl\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pl\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pl\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pl \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt-BR\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt-BR\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt-BR\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt-BR\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\pt-BR \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ro\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ro\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ro\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ro\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ro \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ru\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ru\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ru\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ru\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\ru \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Silverlight.Configuration.exe \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\Silverlight.ConfigurationUI.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sk\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sk\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sk\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sk\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sk \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sl\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sl\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sl\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sl\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sl \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\SLMSPRBootstrap.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\slr.dll.managed_manifest \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sv\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sv\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sv\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sv\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\sv \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Core.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Core.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\system.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Net.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Net.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Runtime.Serialization.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Runtime.Serialization.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.ServiceModel.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.ServiceModel.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.ServiceModel.Web.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.ServiceModel.Web.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.Browser.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.Browser.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.RuntimeHost.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.RuntimeHost.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.Xna.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Windows.Xna.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Xml.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\System.Xml.ni.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\th\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\th\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\th\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\th\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\th \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\tr\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\tr\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\tr\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\tr\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\tr \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\uk\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\uk\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\uk\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\uk\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\uk \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\vi\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\vi\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\vi\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\vi\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\vi \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hans\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hans\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hans\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hans\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hans \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hant\Microsoft.VisualBasic.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hant\mscorlib.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hant\mscorrc.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hant\system.resources.dll \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\zh-Hant \??\C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0 \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\agcore.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\agcp.exe \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ar\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ar\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ar\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ar\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ar \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\bg\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\bg\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\bg\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\bg\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\bg \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ca\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ca\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ca\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ca\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ca \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\coreclr.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\coregen.exe \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\cs\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\cs\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\cs\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\cs\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\cs \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\da\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\da\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\da\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\da\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\da \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\de\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\de\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\de\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\de\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\de \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\el\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\el\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\el\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\el\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\el \??\C:\WINDOWS\system32\spool\V4Dirs\7092B4EF-122C-4C5B-AF10-E82463A87B2B\94766af2.BUD \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\es\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\es\mscorlib.resources.dll \??\C:\WINDOWS\system32\spool\V4Dirs\7092B4EF-122C-4C5B-AF10-E82463A87B2B\94766af2.gpd \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\es\mscorrc.dll \??\C:\WINDOWS\system32\spool\V4Dirs\7092B4EF-122C-4C5B-AF10-E82463A87B2B \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\es\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\es \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\et\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\et\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\et\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\et\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\et \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\eu\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\eu\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\eu\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\eu\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\eu \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fi\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fi\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fi\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fi\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fi \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fr\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fr\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fr\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fr\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\fr \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\he\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\he\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\he\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\he\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\he \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hr\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hr\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hr\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hr\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hr \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hu\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hu\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hu\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hu\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\hu \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\id\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\id\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\id\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\id\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\id \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\it\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\it\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\it\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\it\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\it \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ja\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ja\mscorlib.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ja\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ja\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ja \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ko\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ko\mscorlib.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ko\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ko\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ko \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lt\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lt\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lt\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lt\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lt \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lv\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lv\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lv\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lv\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\lv \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\Microsoft.VisualBasic.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.Graphics.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\Microsoft.Xna.Framework.Graphics.Shaders.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ms\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ms\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ms\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ms\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ms \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\mscorlib.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\mscorlib.ni.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\mscorrc.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\nl\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\nl\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\nl\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\nl\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\nl \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\no\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\no\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\no\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\no\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\no \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrlui.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pl\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pl\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pl\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pl\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pl \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt-BR\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt-BR\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt-BR\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt-BR\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\pt-BR \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ro\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ro\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ro\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ro\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ro \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ru\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ru\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ru\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ru\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\ru \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\Silverlight.Configuration.exe \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\Silverlight.ConfigurationUI.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sk\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sk\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sk\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sk\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sk \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sl\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sl\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sl\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sl\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sl \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\SLMSPRBootstrap.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\slr.dll.managed_manifest \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Cyrl-CS \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sr-Latn-CS \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sv\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sv\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sv\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sv\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\sv \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Core.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Core.ni.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\system.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Net.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Net.ni.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.ni.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Runtime.Serialization.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.ServiceModel.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.ServiceModel.Web.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Windows.Browser.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Windows.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Windows.RuntimeHost.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Windows.Xna.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\System.Xml.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\th\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\th\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\th\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\th\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\th \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\tr\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\tr\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\tr\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\tr\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\tr \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\uk\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\uk\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\uk\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\uk\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\uk \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\vi\Microsoft.VisualBasic.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\vi\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\vi\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\vi\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\vi \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hans\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hans\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hans\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hans\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hans \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hant\Microsoft.VisualBasic.resources.DLL \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hant\mscorlib.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hant\mscorrc.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hant\system.resources.dll \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0\zh-Hant \??\C:\Program Files\Microsoft Silverlight\5.1.50906.0 [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=UsoSvc gpsvc trustedinstaller "WaitToKillServiceTimeout"=200 "SystemStartOptions"= NOEXECUTE=OPTIN NOVGA "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(3) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=3 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Security Packages"="" [22/08/2016 23:45:46] "Notification Packages"=scecli "Authentication Packages"=msv1_0 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "fullprivilegeauditing"=0x80 "LsaPid"=864 "ProductType"=3 "restrictanonymous"=0 "restrictanonymoussam"=1 "SecureBoot"=1 ---------- | .LNK with Arguments c:\oem\preload\command\alaunchx\backuplinks\acheter en ligne.lnk - Encrypted: False - Target: C:\Program Files\Accessory Store\StartUrl.exe - Args: (hxxp://go.acer.com/?id=13415&model=Aspire E5-573G) - Hidden: False - Status: OK c:\oem\preload\command\alaunchx\backuplinks\booking.com.lnk - Encrypted: False - Target: C:\Program Files\Booking.COM\StartURL.exe - Args: (hxxp://www.booking.com/index.html?aid=379334) - Hidden: False - Status: OK c:\program files\accessory store\accessory store.lnk - Encrypted: False - Target: C:\Program Files\Accessory Store\StartUrl.exe - Args: (hxxp://go.acer.com/?id=13469&model=Aspire E5-573G) - Hidden: False - Status: OK c:\program files\accessory store\boutique accessoires acer.lnk - Encrypted: False - Target: C:\Program Files\Accessory Store\StartUrl.exe - Args: (hxxp://go.acer.com/?id=13469&model=Aspire E5-573G) - Hidden: False - Status: OK c:\program files\booking.com\booking.com.lnk - Encrypted: False - Target: C:\Program Files\Booking.COM\StartURL.exe - Args: (hxxp://www.booking.com/index.html?aid=379334) - Hidden: False - Status: OK c:\users\public\desktop\acheter en ligne.lnk - Encrypted: False - Target: C:\Program Files\Accessory Store\StartUrl.exe - Args: (hxxp://go.acer.com/?id=13415&model=Aspire E5-573G) - Hidden: False - Status: OK c:\users\public\desktop\booking.com.lnk - Encrypted: False - Target: C:\Program Files\Booking.COM\StartURL.exe - Args: (hxxp://www.booking.com/index.html?aid=379334) - Hidden: False - Status: OK ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallPaper"=C:\Users\Emmanuelle\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{d6e2c55f-6ef3-49b6-8417-620bcfd7a88b}.JPG [31/08/2016 21:47:12] "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "ScreenSaveActive"=1 "Win8DpiScaling"=0 "DpiScalingVer"=4096 "UserPreferencesMask"=0x9E1E078012000000 "MaxVirtualDesktopDimension"=1366 "MaxMonitorDimension"=1366 "TranscodedImageCount"=2 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC301004F2A2B00C00C00009009000080F3ADAF5FCFD00143003A005C00550073006500720073005C0045006D006D0061006E00750065006C006C0065005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E00500068006F0074006F0073005F003800770065006B007900620033006400380062006200770065005C004C006F00630061006C00530074006100740065005C00500068006F0074006F0073004100700070004200610063006B00670072006F0075006E0064005C007B00640036006500320063003500350066002D0036006500660033002D0034003900620036002D0038003400310037002D003600320030006200630066006400370061003800380062007D002E004A005000470000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "WaitToKillAppTimeout"=200 [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "ShellState"=0x240000003428000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "TelemetrySalt"=0 "GlobalAssocChangedCounter"=164 "AppReadinessLogonComplete"=1 "FirstRunTelemetryComplete"=1 "SlowContextMenuEntries"=0x3CA4E2FFB956F54B9A79CC6D4285608AB61B0000D3EFA9CCED290A43BA6DE6BBFF0A60C2752B00006024B221EA3A6910A2DC08002B30309D24210000119826C5294A1848A4BB111F9FC63A5FEB1A0000AF75193DC6488E4FA182BE0E08FA86A9A1360000 [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=2 "ShowCompColor"=1 "HideFileExt"=1 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StoreAppsOnTaskbar"=1 "EnableStartMenu"=1 "StartMenuInit"=13 "ReindexedProfile"=1 "TaskbarStateLastRun"=0xA487A05900000000 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "SmartScreenEnabled"=RequireAdmin "GlobalAssocChangedCounter"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=10 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=14393 "FirstLogon"=0 "PUUActive"=0x0BB991440500000002001400E5680000E46D00005C8D0000D10000000D000E007FFE9C6415D70D00DDAE000010430000723400007B040000EF3E00002490000015040000270000009A54FE05721FD301CD210200000000000100000000000000 "ParseAutoexec"=1 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DefaultDomainName"= "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "LastLogOffEndTimePerfCounter"=21803644080234 "ShutdownFlags"=2147483687 "Userinit"=C:\Windows\system32\userinit.exe, "scremoveoption"=0 "AutoAdminLogon"=0 "DefaultUserName"=Emmanuelle "DisableCad"=1 "DisableLockWorkstation"=0 "EnableFirstLogonAnimation"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "EnableSIHostIntegration"=1 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Clients\StartMenuInternet\Chromium.N6IAG6ZCD2RCSUUN4QXABTRTJA\Shell\open\Command] ""="C:\Users\Emmanuelle\AppData\Local\Chromium\Application\chrome.exe" [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Clients\StartMenuInternet\Chromium.N6IAG6ZCD2RCSUUN4QXABTRTJA\InstallInfo] "ReinstallCommand"="C:\Users\Emmanuelle\AppData\Local\Chromium\Application\chrome.exe" --make-default-browser [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=iexplore.exe [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=iexplore.exe [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall ---------- | AppcompatFlags [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files\Acer\Acer Quick Access\QAAgent.exe"=0x5341435001000000000000000700000028000000601B06006EB6060001000000000000000000000A73220000D5B3B31A57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000D27DBD27010000001100000011000000 "C:\OEM\Preload\DPOP\OEMCustomize\FirstBoot.cmd"=0x5341435001000000000000000700000028000000008C030022EE030001000000000000000000010500100000078CBF8EFFBAD0010000000000000000 "C:\OEM\Preload\Autorun\CheckFiles.exe"=0x5341435001000000000000000700000028000000207A0D00AD780E00010000000000000000000006710000000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000900F0000000000000100000001000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C03802000BA5020001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Users\Emmanuelle\Downloads\Setup.X86.fr-FR_O365HomePremRetail_0c6252e1-910e-4189-979a-462161cb0472_TX_DB_.exe"=0x5341435001000000000000000700000028000000C0C439007F963A0001000000000000000000000A002100000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000004ABD2000000000000100000001000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8BA020001D3020001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C0AC02007050030001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe"=0x5341435001000000000000000700000028000000609108003576090001000000000000000000000AF5220000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000E1E11E3E000000000700000007000000 "C:\Program Files\mcafee\msc\mcsync.exe"=0x534143500100000000000000070000002800000080C939007FCF390001000000000000000000000A00210000078CBF8EFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000000C4C0000000000000100000001000000 "C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe"=0x5341435001000000000000000700000028000000D8E62400268C250001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000C3D2D30D000000000300000003000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C0AC02007050030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\CyberLink\PowerDVD12\PDVDLP.exe"=0x5341435001000000000000000700000028000000B83D05003CB1050001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000008000000000000000000000000000000000000000059E0000000000000100000001000000 "C:\Program Files (x86)\Windows Media Player\wmplayer.exe"=0x5341435001000000000000000700000028000000008C02001930030001000000010000000000000A7122000033504C2B57DFD1010000000000000000 "C:\Users\Emmanuelle\Downloads\SkypeSetupFull.exe"=0x5341435001000000000000000700000028000000D8899D027BCE9D0201000000000000000000000A0021000033504C2B57DFD1010000000000000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\BingSvc\BSvcProcessor.exe"=0x534143500100000000000000070000002800000098101100C837110001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000CEEA0000000000006E0100006E010000 "C:\Program Files (x86)\Skype\Phone\Skype.exe"=0x5341435001000000000000000700000028000000D87F9F01E62DA00101000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000010000000000000000000000000000000003730904E000000000500000005000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000E07E03004B44040001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe"=0x5341435001000000000000000700000028000000C8C205002A42060001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000BE6E0200000000000100000001000000 "C:\Users\Emmanuelle\Downloads\picasa (1).exe"=0x5341435001000000000000000700000028000000388913000FF35C090100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000061DE669C000000000100000001000000 "C:\Program Files (x86)\Google\Picasa3\PicasaPhotoViewer.exe"=0x534143500100000000000000070000002800000048494900B20D4A000100000000000000000002067122000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000057261000000000000100000001000000 "C:\Users\Emmanuelle\Downloads\LeapFrogConnectSetup_LeapReader.exe"=0x534143500100000000000000070000002800000078DCD1004B61D2000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000002BFC303F000000000100000001000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D87E030025C1030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Emmanuelle\Downloads\vlc-2.2.4-win32.exe"=0x534143500100000000000000070000002800000038E8D1015414D2010100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000055480300000000000100000001000000 "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe"=0x5341435001000000000000000700000028000000C01702001B81020001000000000000000000000A6122000033504C2B57DFD1010000000000000000020000005000000000000000000000100000000000000000000000000000000080B72114000000000C0000000500000000000000800000100000000000000000000000000000000077010000000000000100000000000000 "C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE"=0x5341435001000000000000000700000028000000C85E1C00A6AF1C0001000000000000000000000A0021000033504C2B57DFD1010000009100000000 "C:\Program Files (x86)\Google\Picasa3\Picasa3.exe"=0x534143500100000000000000070000002800000048E99A00A8D59B0001000000000000000000000A7122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000002053782A000000000200000002000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D88003007F30040001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files\ByteFence\Uninstall.exe"=0x5341435001000000000000000700000028000000F4050100166877000300000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000B128C135000000000100000001000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D88203009CF3030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\Mozilla Firefox\updater.exe"=0x5341435001000000000000000700000028000000C8E7040081CD050001000000000000000000000A0021000033504C2B57DFD1010000008000000000020000002800000000000000000000400000000000000000000000000000000021680000000000000200000002000000 "C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE"=0x5341435001000000000000000700000028000000C8A61D005EF31D0001000000000000000000000A0021000033504C2B57DFD1010000009100000000 "C:\Users\Emmanuelle\Downloads\Silverlight_x64.exe"=0x5341435001000000000000000700000028000000E0E8C8003ADBC9000100000000000000000001057100000033504C2B57DFD101000000000000000002000000280000000000000080010000000000000000000000000000000000001A700100000000000300000003000000 "C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE"=0x5341435001000000000000000700000028000000C8E0220214A9230201000000000000000000000A0021000033504C2B57DFD1010000009100000000 "C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe"=0x5341435001000000000000000700000028000000C07E3B00881C3C0001000000000000000000000A00210000D5B3B31A57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000009032569C010000000200000002000000 "C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE"=0x5341435001000000000000000700000028000000C0249501AA1A960101000000000000000000000A0021000033504C2B57DFD1010000009100000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000D05E9301F3E9930101000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D09A0300AA58040001000000000000000000000A7120000033504C2B57DFD1010000000100000000 "C:\Users\Emmanuelle\AppData\Local\chromium\Application\chrome.exe"=0x534143500100000000000000070000002800000000CA0F00B265100001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000B1B20100000000000200000002000000 "C:\Program Files (x86)\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000D01F0800736C080001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000D0F2A6017F93A70101000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6943.0625\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0960300F48A040001000000000000000000000A7120000033504C2B57DFD1010000000100000000 "C:\Users\Emmanuelle\AppData\Roaming\Dashlane\Dashlane.exe"=0x5341435001000000000000000700000028000000D0B707007145080001000000000000000000000A0021000033504C2B57DFD1010000000000000000 "C:\Program Files (x86)\Mozilla Firefox\pingsender.exe"=0x5341435001000000000000000700000028000000D0D700002994010001000000000000000000000A7120000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000D2110000000000000100000001000000 "C:\Program Files\Internet Explorer\iexplore.exe"=0x5341435001000000000000000700000028000000C0960C006CE60C0001000000010000000000000A00210000D5B3B31A57DFD1010000000000000000 "C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe"=0x5341435001000000000000000700000028000000C88243003263440001000000000000000000000A00210000D5B3B31A57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000003CD80400000000000100000001000000 "C:\Users\Emmanuelle\Desktop\QuickDiag.exe"=0x5341435001000000000000000700000028000000A83547001933480001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000149F0C00000000000100000001000000 ---------- | IFEO ---------- | Mountpoints2 ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=131216942051394686 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "DisableAntiSpyware"=1 "TrustedImageIdentifier"=POP010KY63X8EC04-PAP010M663X85C71 "ProductType"=2 "ManagedDefenderProductType"=0 "ProductStatus"=0 "InstallTime"=0x55ABBDB1DB81D101 "DisableAntiVirus"=1 "InstallLocation"=C:\Program Files\Windows Defender\ [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfencbdc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfencbdc.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts ---------- | Ping La requ?te Ping n'a pas pu trouver l'h?te google.com. V?rifiez le nom et essayez ? nouveau. ---------- | @ [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Cache_Update_Frequency"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=%11%\blank.htm "Save_Session_History_On_Exit"=no "Search Page"=http://www.google.com "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE13&ocid=UE13DHP "Default_Page_URL"=http://acer15.msn.com/?pc=ACTE "DisableFirstRunCustomize"=1 "ApplicationTileImmersiveActivation"=0 "AssociationActivationMode"=2 "OperationalData"=13 "EdgeSwitchingOSBuildNumber"=10240.th1.150819-1946 "Secondary Start Pages"= "FormSuggest PW Ask"=no "FormSuggest Passwords"=no "Use FormSuggest"=no "ImageStoreRandomFolder"=rtiq21z "Search Bar"=http://www.google.com/ie "Default_Search_URL"=http://www.google.com/ie "CompatibilityFlags"=0 "FullScreen"=no "Window_Placement"=0x2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF8C00000000000000AC03000058020000 "Start Page_TIMESTAMP"=0xA4BF7668F6CFD201 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"= [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"=http://www.google.com/ie "Default_Search_URL"=http://www.google.com/ie [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Internet Explorer\SearchURL] "provider"=gogl ""=http://www.google.com/search?q=%s [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "CertificateRevocation"=1 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "ZonesSecurityUpgrade"=0xD46123A80AC9D201 "WarnonZoneCrossing"=0 "EnableNegotiate"=1 "MigrateProxy"=1 "ProxyEnable"=0 "EnableAutodial"=0 "SyncMode5"=2 [HKLM\Software\Microsoft\Internet Explorer\Main] "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Start Page"=https://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_17_02_ssg01¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyDyE0A0BtA0AyD0D0CzzyC0FtD0EyDzztN0D0Tzu0StCzztAyBtN1L2XzutAtFtByEtFtByBtFyDtDtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2SyBtB0B0ByDtByE0AtGtC0A0AyDtG0CyDyB0DtGtB0F0DyCtGyD0AzyyCtDtBzy0D0AtD0FtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzyyBzyzztC0B0DtGtByDyE0AtGyEyE0DzytG0B0DzyyEtGyCtB0FyDzyzztA0DtB0CyEtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyEyDyC%26cr%3D1604917835%26a%3Dwbf_secureddownload_17_02_ssg01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "DisableRandomFlighting"=0 "EnableLegacyEdgeSwitching"=1 "TabProcGrowth"=Medium [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\SysWOW64\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Start Page"=https://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_17_02_ssg01¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyDyE0A0BtA0AyD0D0CzzyC0FtD0EyDzztN0D0Tzu0StCzztAyBtN1L2XzutAtFtByEtFtByBtFyDtDtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2SyBtB0B0ByDtByE0AtGtC0A0AyDtG0CyDyB0DtGtB0F0DyCtGyD0AzyyCtDtBzy0D0AtD0FtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzyyBzyzztC0B0DtGtByDyE0AtGyEyE0DzytG0B0DzyyEtGyCtB0FyDzyzztA0DtB0CyEtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyEyDyC%26cr%3D1604917835%26a%3Dwbf_secureddownload_17_02_ssg01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 ---------- | Proxy [HKLM\System\CurrentControlSet\Services\NLASVC\Parameters\Internet\Manualproxies] ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | Execution FileExts ---------- | SIOI | SEH | URLSH [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudSynced] - {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} -- C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [20/09/2016 14:19:14] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudSyncing] - {C1E1456F-C2D8-4C96-870D-35F1E13941EE} -- C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [20/09/2016 14:19:14] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudToBeSynced] - {307523FA-DDC0-4068-983F-2A6B34627744} -- C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [20/09/2016 14:19:14] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7} -- C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [23/08/2016 07:17:27] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE} -- C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [23/08/2016 07:17:27] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} -- C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [23/08/2016 07:17:27] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [16/07/2016 13:42:17] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudSynced] - {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} -- C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [20/09/2016 14:19:14] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudSyncing] - {C1E1456F-C2D8-4C96-870D-35F1E13941EE} -- C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [20/09/2016 14:19:14] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudToBeSynced] - {307523FA-DDC0-4068-983F-2A6B34627744} -- C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [20/09/2016 14:19:14] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= ---------- | Toolbar [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} "KnownProvidersUpgradeTime"=0xD46123A80AC9D201 "Version"=5 "UpgradeTime"=0xD46123A80AC9D201 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={3954855F-FE2B-4D7B-9EAC-2ADB863ECFE2} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Toolbar] "{669695BC-A811-4A9D-8CDF-BA8C795F261C}"=Dashlane Toolbar [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={3954855F-FE2B-4D7B-9EAC-2ADB863ECFE2} ---------- | Extensions [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (Se&nd to OneNote) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] : (Lync Click to Call) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{48A61126-9A19-4C50-A214-FF08CB94995C}] : (McAfee WebAdvisor) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (OneNote Lin&ked Notes) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (Se&nd to OneNote) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{48A61126-9A19-4C50-A214-FF08CB94995C}] : (McAfee WebAdvisor) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (OneNote Lin&ked Notes) - [] ---------- | SearchScopes [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE15 : [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0CE02FFA-A6B0-46F6-BA2F-BD32C3630126}] - (Yahoo! Powered Search) - https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_17_02_ssg01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyDyE0A0BtA0AyD0D0CzzyC0FtD0EyDzztN0D0Tzu0StCzztAyBtN1L2XzutAtFtByEtFtByBtFyDtDtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2SyBtB0B0ByDtByE0AtGtC0A0AyDtG0CyDyB0DtGtB0F0DyCtGyD0AzyyCtDtBzy0D0AtD0FtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzyyBzyzztC0B0DtGtByDyE0AtGyEyE0DzytG0B0DzyyEtGyCtB0FyDzyzztA0DtB0CyEtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyEyDyC%26cr%3D1604917835%26a%3Dwbf_secureddownload_17_02_ssg01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms} : [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2812A237-8F20-11E6-9BD0-54AB3A5DC86F}] - (Bing Search) - https://www.bing.com/search?pc=cosp&ptag=AB59A10D666&form=CONBDF&conlogo=CT3210127&q={searchTerms} : [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Goo) - http://www.google.com/search?q={sear : [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6AE0334F-77E8-11E6-9BD0-54AB3A5DC86F}] - (Bing Search) - https://www.bing.com/search?pc=cosp&ptag=AB59A10D666&form=CONBDF&conlogo=CT3210127&q={searchTerms} : [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}] - (Yahoo!) - http://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0CE02FFA-A6B0-46F6-BA2F-BD32C3630126}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=PRACE1&src=IE11TR&pc=ACTE : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3954855F-FE2B-4D7B-9EAC-2ADB863ECFE2}] - (Yahoo! Powered Search) - https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_17_02_ssg01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyDyE0A0BtA0AyD0D0CzzyC0FtD0EyDzztN0D0Tzu0StCzztAyBtN1L2XzutAtFtByEtFtByBtFyDtDtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2SyBtB0B0ByDtByE0AtGtC0A0AyDtG0CyDyB0DtGtB0F0DyCtGyD0AzyyCtDtBzy0D0AtD0FtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzyyBzyzztC0B0DtGtByDyE0AtGyEyE0DzytG0B0DzyyEtGyCtB0FyDzyzztA0DtB0CyEtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyEyDyC%26cr%3D1604917835%26a%3Dwbf_secureddownload_17_02_ssg01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms} : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}] - (Yahoo!) - http://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0CE02FFA-A6B0-46F6-BA2F-BD32C3630126}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=PRACE1&src=IE11TR&pc=ACTE : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{3954855F-FE2B-4D7B-9EAC-2ADB863ECFE2}] - (Yahoo! Powered Search) - https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_17_02_ssg01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyDyE0A0BtA0AyD0D0CzzyC0FtD0EyDzztN0D0Tzu0StCzztAyBtN1L2XzutAtFtByEtFtByBtFyDtDtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2SyBtB0B0ByDtByE0AtGtC0A0AyDtG0CyDyB0DtGtB0F0DyCtGyD0AzyyCtDtBzy0D0AtD0FtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzyyBzyzztC0B0DtGtByDyE0AtGyEyE0DzytG0B0DzyyEtGyCtB0FyDzyzztA0DtB0CyEtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyEyDyC%26cr%3D1604917835%26a%3Dwbf_secureddownload_17_02_ssg01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms} : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}] - (Yahoo!) - http://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} : ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] -> (McAfee WebAdvisor BHO) : c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [19/05/2017 18:42:40] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}] -> (Dashlane BHO) : C:\Users\Emmanuelle\AppData\Roaming\Dashlane\ie\Dashlanei.dll [19/09/2016 01:23:00] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] -> (McAfee WebAdvisor BHO) : c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [19/05/2017 18:42:40] ---------- | Chrome [HKLM\Software\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho] ---------- | Opera ---------- | Firefox C:\Users\Emmanuelle\AppData\Roaming\Mozilla\Firefox\Profiles\1db9k7yu.default\Extensions\partnerdefaults@mozilla.com : : Mozilla Partner Defaults - : https://mozilla.com/ C:\Users\Emmanuelle\AppData\Roaming\Mozilla\Firefox\Profiles\1db9k7yu.default\Extensions\bingsearch.full@microsoft.com.xpi C:\Users\Emmanuelle\AppData\Roaming\Mozilla\Firefox\Profiles\1db9k7yu.default\Extensions\jetpack-extension@dashlane.com.xpi C:\Users\Emmanuelle\AppData\Roaming\Mozilla\Firefox\Profiles\1db9k7yu.default\Extensions\langpack-fr@firefox.mozilla.org.xpi [HKLM\Software\mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10] - (McAfee Total Protection MIME Plugin) : c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf] - () : C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf] - () : C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp] - () : C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf] - () : C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0] - (Picasa3 plugin) : C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68] - (Intel IPT WebApi plugin) : C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater] - (This plugin updates Intel WebAPI component) : C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@mcafee.com/MSC,version=10] - (McAfee Total Protection MIME Plugin) : c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (WildTangent Games App V2 Presence Detector Plugin) : C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll C:\Users\Emmanuelle\AppData\Roaming\Mozilla\Firefox\Profiles\1db9k7yu.default\Prefs.js user_pref("browser.newtab.url", "about:newtab"); user_pref("browser.search.defaultenginename", "Yahoo! Powered Search"); user_pref("browser.search.order.1", "Recherche sécurisée"); user_pref("browser.search.selectedEngine", "Yahoo! Powered Search"); user_pref("browser.startup.homepage", "https://www.google.fr/"); user_pref("browser.startup.homepage_override.buildID", "20170814072924"); user_pref("browser.startup.homepage_override.mstone", "55.0.2"); user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-button\",\"history-panelmenu\",\"fullscreen-button\",\"find-button\",\"preferences-button\",\"add-ons-button\",\"developer-button\",\"sync-button\"],\"addon-bar\":[\"addonbar-closebutton\",\"status-bar\"],\"PersonalToolbar\":[\"personal-bookmarks\"],\"nav-bar\":[\"urlbar-container\",\"search-container\",\"bookmarks-menu-button\",\"downloads-button\",\"home-button\",\"loop-button\",\"pocket-button\",\"toggle-button--jetpack-extensiondashlanecom-kw-button\",\"jetpack-extension_dashlane_com-browser-action\"],\"TabsToolbar\":[\"tabbrowser-tabs\",\"new-tab-button\",\"alltabs-button\"],\"toolbar-menubar\":[\"menubar-items\"]},\"seen\":[\"loop-button\",\"pocket-button\",\"developer-button\",\"toggle-button--jetpack-extensiondashlanecom-kw-button\",\"jetpack-extension_dashlane_com-browser-action\",\"webide-button\"],\"dirtyAreaCache\":[\"PersonalToolbar\",\"nav-bar\",\"TabsToolbar\",\"toolbar-menubar\",\"PanelUI-contents\",\"addon-bar\"],\"currentVersion\":6,\"newElementCount\":0}"); user_pref("extensions.blocklist.pingCountTotal", 65); user_pref("extensions.blocklist.pingCountVersion", -1); user_pref("extensions.databaseSchema", 21); user_pref("extensions.e10s.rollout.blocklist", ""); user_pref("extensions.e10s.rollout.hasAddon", true); user_pref("extensions.e10s.rollout.policy", "50allmpc"); user_pref("extensions.e10sBlockedByAddons", true); user_pref("extensions.e10sMultiBlockedByAddons", true); user_pref("extensions.getAddons.cache.lastUpdate", 1503690963); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20170302.01"); user_pref("extensions.installedDistroAddon.langpack-fr@firefox.mozilla.org", true); user_pref("extensions.installedDistroAddon.partnerdefaults@mozilla.com", true); user_pref("extensions.lastAppVersion", "55.0.2"); user_pref("extensions.lastPlatformVersion", "55.0.2"); user_pref("extensions.partnerdefaults.firstRunDate", "1471903042280"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shield-recipe-client.api_url", "https://normandy.cdn.mozilla.net/api/v1"); user_pref("extensions.shield-recipe-client.dev_mode", false); user_pref("extensions.shield-recipe-client.enabled", true); user_pref("extensions.shield-recipe-client.first_run", false); user_pref("extensions.shield-recipe-client.logging.level", 50); user_pref("extensions.shield-recipe-client.run_interval_seconds", 86400); user_pref("extensions.shield-recipe-client.startup_delay_seconds", 300); user_pref("extensions.shield-recipe-client.user_id", "c9826fc7-33bc-4c81-9b39-e1f8a77fd511"); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.webextensions.uuids", "{\"jetpack-extension@dashlane.com\":\"a31c3b1e-8330-44cc-b414-e477d2fb0bd5\"}"); [Profile0] - Name=default -> Profiles/1db9k7yu.default ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{69dfe292-6c5b-4e9d-a918-302e395438cf}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{83a851b7-2594-4c56-bac2-13c30a4234c8}] "DhcpNameServer"=40.32.1.55 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{69dfe292-6c5b-4e9d-a918-302e395438cf}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{83a851b7-2594-4c56-bac2-13c30a4234c8}] "DhcpNameServer"=40.32.1.55 ---------- | Applications [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\Classes\Applications\MSOXMLED.EXE] : "C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLED.EXE" "%1" [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\PicasaPhotoViewer.exe] : "C:\Program Files (x86)\Google\Picasa3\PicasaPhotoViewer.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\vlc.exe] : "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MSOXMLED.EXE] : "C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLED.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\PicasaPhotoViewer.exe] : "C:\Program Files (x86)\Google\Picasa3\PicasaPhotoViewer.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vlc.exe] : "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | SvcHost (Whitelist) [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=Power LSM BrokerInfrastructure PlugPlay DeviceInstall SystemEventsBroker DcomLaunch "Camera"=FrameS "smbsvcs"=lanmanserver browser [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=PlugPlay DeviceInstall DcomLaunch "smbsvcs"=lanmanserver ---------- | SvcHost - Netsvcs (Whitelist) ---------- | Software [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Acer] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\AppDataLow] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Chromium] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Clients] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\csastats] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\CyberLink] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Dashlane] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\DashlaneUpgrade] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Dashlane_profiles] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Foxit Software] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\g3n-h@ckm@n] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Google] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Host App Service] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\IM Providers] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Intel] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Local AppWizard-Generated Applications] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\McAfee] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Mine] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Mozilla] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\MozillaPlugins] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Netscape] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\NVIDIA Corporation] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\ODBC] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\OEM] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Policies] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\ProductSetup] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Realtek] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\RegisteredApplications] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Skype] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\sysinternals] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\undefined] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Wow6432Node] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\AppDataLow\Software\Amazon] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\Roaming] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\ShellNoRoam] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\acer] [HKLM\Software\AGEIA Technologies] [HKLM\Software\Atheros] [HKLM\Software\Clearfi] [HKLM\Software\Clients] [HKLM\Software\Dell] [HKLM\Software\Dolby] [HKLM\Software\DTS] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\Google] [HKLM\Software\IM Providers] [HKLM\Software\Intel] [HKLM\Software\Intel Security] [HKLM\Software\Khronos] [HKLM\Software\Knowles] [HKLM\Software\Macromedia] [HKLM\Software\McAfee] [HKLM\Software\McAfee.com] [HKLM\Software\McAfee.logging] [HKLM\Software\Microsoft] [HKLM\Software\Mozilla] [HKLM\Software\MozillaPlugins] [HKLM\Software\Nahimic] [HKLM\Software\Network Associates] [HKLM\Software\Nuance] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\Partner] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\RTLSetup] [HKLM\Software\SiteAdvisor] [HKLM\Software\SonicFocus] [HKLM\Software\SoundResearch] [HKLM\Software\SRS Labs] [HKLM\Software\sysinternals] [HKLM\Software\Waves Audio] [HKLM\Software\WOW6432Node] [HKLM\Software\Yamaha APO] [HKLM\Software\Microsoft\Windows\ClickNote] [HKLM\Software\Microsoft\Windows\Configuration] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\DWM] [HKLM\Software\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\Software\WOW6432Node\AGEIA Technologies] [HKLM\Software\WOW6432Node\Amazon] [HKLM\Software\WOW6432Node\AppDataLow] [HKLM\Software\WOW6432Node\ATHEROS] [HKLM\Software\WOW6432Node\AVAST Software] [HKLM\Software\WOW6432Node\Clearfi] [HKLM\Software\WOW6432Node\CyberLink] [HKLM\Software\WOW6432Node\DashlaneUpgrade] [HKLM\Software\WOW6432Node\DivXNetworks] [HKLM\Software\WOW6432Node\Foxit Software] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\IM Providers] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\Lake] [HKLM\Software\WOW6432Node\LeapFrog] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\McAfee] [HKLM\Software\WOW6432Node\McAfee.com] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\MimarSinan] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\mozilla.org] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\Network Associates] [HKLM\Software\WOW6432Node\Nuance] [HKLM\Software\WOW6432Node\NVIDIA Corporation] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\OEM] [HKLM\Software\WOW6432Node\Qualcomm Atheros] [HKLM\Software\WOW6432Node\Realtek] [HKLM\Software\WOW6432Node\Realtek Semiconductor Corp.] [HKLM\Software\WOW6432Node\SiteAdvisor] [HKLM\Software\WOW6432Node\Skype] [HKLM\Software\WOW6432Node\SRS Labs] [HKLM\Software\WOW6432Node\SyncIntegrationClients] [HKLM\Software\WOW6432Node\VideoLAN] [HKLM\Software\WOW6432Node\WildTangent] [HKLM\Software\WOW6432Node\WOW6432Node] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] ---------- | Drives ---------- | C: [22/10/2016 12:04:06] - |HD| - [3470354266] - C:\$GetCurrent [10/07/2015 13:04:22] - |SHD| - [17339947982] - C:\$Recycle.Bin [05/05/2017 09:22:10] - |D| - [13724237] - C:\7af8eacf082d0a6149fe7b [MD5.CDF075B70E5F612B4399A54B25D55192] - [10/07/2015 15:20:06] - |RASH| - (.-.) - [395268] - (0.0.0.0) - C:\bootmgr [MD5.93B885ADFE0DA089CDF634904FD59F71] - [10/07/2015 15:20:06] - |ASH| - (.-.) - [1] - (0.0.0.0) - C:\BOOTNXT [22/10/2016 12:24:56] - |SHD| - [1444832] - C:\Config.Msi [10/07/2015 14:21:38] - |SHD| - [0] - C:\Documents and Settings [05/05/2017 10:25:37] - |D| - [13724237] - C:\e6d535fcf8b2b69dcac6a0949479c2 [MD5.D41D8CD98F00B204E9800998ECF8427E] - [23/10/2016 12:43:11] - |ASH| - (.-.) - [1684619264] - (0.0.0.0) - C:\hiberfil.sys [19/03/2016 15:15:23] - |HD| - [295648] - C:\Intel [31/08/2015 13:43:34] - |HD| - [1704168788] - C:\OEM [MD5.D41D8CD98F00B204E9800998ECF8427E] - [19/03/2016 23:27:32] - |ASH| - (.-.) - [2415919104] - (0.0.0.0) - C:\PageFile.sys [16/07/2016 13:47:47] - |D| - [0] - C:\PerfLogs [16/07/2016 08:04:24] - |RD| - [4418556656] - C:\Program Files [16/07/2016 08:04:24] - |RD| - [5281809160] - C:\Program Files (x86) [16/07/2016 13:47:48] - |HD| - [2521347586] - C:\ProgramData [27/08/2017 22:25:31] - |D| - [262051] - C:\QuickDiag [MD5.2C352405C33840BB9C43560FA489DD3C] - [27/08/2017 22:26:37] - |A| - (.-.) - [284194] - (0.0.0.0) - C:\QuickDiag.txt [31/08/2015 12:46:29] - |SHD| - [6041714846] - C:\Recovery [MD5.D41D8CD98F00B204E9800998ECF8427E] - [19/03/2016 14:33:28] - |ASH| - (.-.) - [268435456] - (0.0.0.0) - C:\swapfile.sys [19/03/2016 14:33:25] - |SHD| - [0] - C:\System Volume Information [16/07/2016 08:04:24] - |RD| - [157601914993] - C:\Users [16/07/2016 08:04:24] - |D| - [42060896123] - C:\Windows [22/10/2016 11:58:50] - |D| - [16166948] - C:\Windows10Upgrade ---------- | C:\WINDOWS [MD5.A486C15BA34B4C23677AA34F47CE2C0D] - [19/03/2016 15:11:29] - |A| - (.-.) - [1078] - (0.0.0.0) - C:\WINDOWS\ACU.ico [16/07/2016 13:47:48] - |D| - [802] - C:\WINDOWS\addins [16/07/2016 13:47:48] - |D| - [21047118] - C:\WINDOWS\appcompat [16/07/2016 13:47:48] - |D| - [12472678] - C:\WINDOWS\AppPatch [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\AppReadiness [16/07/2016 13:47:47] - |RSD| - [963086622] - C:\WINDOWS\assembly [16/07/2016 13:47:48] - |D| - [325008] - C:\WINDOWS\bcastdvr [MD5.7B465E25ADF5D6DBCE9DCAE3C6545405] - [16/07/2016 13:42:16] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [61440] - (10.0.14393.0) - C:\WINDOWS\bfsvc.exe [16/07/2016 13:47:48] - |D| - [38115947] - C:\WINDOWS\Boot [MD5.7325C54FB9AB0325C22C96EBC80F7D63] - [23/10/2016 12:23:02] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [16/07/2016 13:47:48] - |D| - [3715608] - C:\WINDOWS\Branding [16/07/2016 13:36:22] - |D| - [231716012] - C:\WINDOWS\CbsTemp [MD5.29C7A2E1DBF8D12763F099B4A2FC568B] - [19/03/2016 22:52:50] - |A| - (.-.) - [41] - (0.0.0.0) - C:\WINDOWS\ChangeLang_Done.tag [MD5.79604F3CABF0B4BC041C7FD7C8543177] - [23/10/2016 12:46:44] - |A| - (.-.) - [8202] - (0.0.0.0) - C:\WINDOWS\comsetup.log [MD5.D6CE3EEAB0B72F8014E62C728CEA5605] - [17/07/2016 00:46:34] - |A| - (.-.) - [33498] - (0.0.0.0) - C:\WINDOWS\Core.xml [MD5.E47260AD508E7761913C7D61C6A345E9] - [31/08/2015 13:44:52] - |A| - (.-.) - [10] - (0.0.0.0) - C:\WINDOWS\CSUP.txt [16/07/2016 13:47:48] - |D| - [8970858] - C:\WINDOWS\Cursors [16/07/2016 13:47:48] - |D| - [9845230] - C:\WINDOWS\debug [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [23/10/2016 12:59:59] - |A| - (.-.) - [7623] - (0.0.0.0) - C:\WINDOWS\diagerr.xml [16/07/2016 13:47:48] - |D| - [4543876] - C:\WINDOWS\diagnostics [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [23/10/2016 12:59:59] - |A| - (.-.) - [7623] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml [17/07/2016 00:40:08] - |D| - [0] - C:\WINDOWS\DigitalLocker [16/07/2016 13:47:48] - |SD| - [65] - C:\WINDOWS\Downloaded Program Files [MD5.EF39EAD8334E95D3609EF0CBF6031329] - [19/03/2016 18:34:25] - |A| - (.-.) - [9936] - (0.0.0.0) - C:\WINDOWS\DPINST.LOG [MD5.8D68A042824DC62468653E92DC19EBEA] - [16/07/2016 13:49:13] - |A| - (.-.) - [4176] - (0.0.0.0) - C:\WINDOWS\DtcInstall.log [16/07/2016 13:47:48] - |HD| - [129104] - C:\WINDOWS\ELAMBKUP [17/07/2016 00:40:08] - |D| - [0] - C:\WINDOWS\en-US [MD5.F2D58A2E27C2CD486F8F0A123A3F34C3] - [09/05/2017 15:11:17] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4674360] - (10.0.14393.953) - C:\WINDOWS\explorer.exe [16/07/2016 13:47:48] - |RSD| - [374152640] - C:\WINDOWS\Fonts [17/07/2016 00:40:08] - |D| - [122368] - C:\WINDOWS\fr-FR [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\GameBarPresenceWriter [16/07/2016 13:47:48] - |D| - [20737866] - C:\WINDOWS\Globalization [16/07/2016 13:47:48] - |D| - [71968513] - C:\WINDOWS\Help [MD5.DD3887563D64E631168B8C107C61A1EC] - [09/05/2017 15:12:09] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [975872] - (10.0.14393.1066) - C:\WINDOWS\HelpPane.exe [MD5.52AFE6DE5E463B7A08C184B1EB49DD6A] - [16/07/2016 13:42:21] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.14393.0) - C:\WINDOWS\hh.exe [16/07/2016 13:47:48] - |D| - [173189928] - C:\WINDOWS\IME [16/07/2016 13:47:48] - |RD| - [6842480] - C:\WINDOWS\ImmersiveControlPanel [16/07/2016 13:45:54] - |D| - [133343741] - C:\WINDOWS\INF [16/07/2016 13:47:48] - |D| - [1237441746] - C:\WINDOWS\InfusedApps [16/07/2016 13:47:48] - |D| - [36285422] - C:\WINDOWS\InputMethod [16/07/2016 13:47:48] - |SHD| - [543212816] - C:\WINDOWS\Installer [16/07/2016 13:47:48] - |D| - [89407] - C:\WINDOWS\L2Schemas [16/07/2016 13:47:48] - |D| - [12102476] - C:\WINDOWS\LiveKernelReports [16/07/2016 08:04:29] - |D| - [315365214] - C:\WINDOWS\Logs [16/07/2016 13:47:48] - |RSD| - [20316123] - C:\WINDOWS\Media [MD5.23AF90D2355D8C83AA4567EF1763B467] - [16/07/2016 13:42:12] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [16/07/2016 13:47:47] - |RD| - [787054312] - C:\WINDOWS\Microsoft.NET [16/07/2016 13:47:48] - |D| - [2563] - C:\WINDOWS\Migration [16/07/2016 13:47:48] - |RD| - [484593] - C:\WINDOWS\MiracastView [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\ModemLogs [19/03/2016 22:41:23] - |D| - [19545002] - C:\WINDOWS\NAPP_Dism_Log [MD5.3B508CAE5DEBCBA928B5BC355517E2E6] - [16/07/2016 13:43:51] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [243200] - (10.0.14393.0) - C:\WINDOWS\notepad.exe [MD5.74F28574BB8F61FFC7DD419FE6B6E0D5] - [18/02/2017 20:30:44] - |A| - (.-.) - [1951] - (0.0.0.0) - C:\WINDOWS\NvContainerRecovery.bat [17/07/2016 00:41:15] - |D| - [199472] - C:\WINDOWS\OCR [22/08/2016 23:42:22] - |D| - [1264] - C:\WINDOWS\oem [16/07/2016 13:47:48] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [23/10/2016 13:19:42] - |DC| - [267683785] - C:\WINDOWS\Panther [MD5.EE49CD6B62CA6E0F388B97E5DD787080] - [19/03/2016 18:50:13] - |A| - (.-.) - [3626] - (0.0.0.0) - C:\WINDOWS\Patch.log [MD5.81051BCC2CF1BEDF378224B0A93E2877] - [20/03/2016 04:38:54] - |A| - (.-.) - [2] - (0.0.0.0) - C:\WINDOWS\PBR_success.log [16/07/2016 13:47:48] - |D| - [29389072] - C:\WINDOWS\Performance [MD5.3688586462ED62BBAE1B458F70E8E671] - [23/10/2016 12:43:11] - |A| - (.-.) - [35390] - (0.0.0.0) - C:\WINDOWS\PFRO.log [16/07/2016 13:47:48] - |D| - [1136442] - C:\WINDOWS\PLA [16/07/2016 13:47:48] - |D| - [2649609] - C:\WINDOWS\PolicyDefinitions [23/10/2016 12:20:58] - |D| - [24396870] - C:\WINDOWS\Prefetch [16/07/2016 13:47:48] - |RD| - [2037042] - C:\WINDOWS\PrintDialog [MD5.09394999ADB19901C665454EE964B13C] - [23/10/2016 09:07:30] - |A| - (.-.) - [36] - (0.0.0.0) - C:\WINDOWS\progress.ini [16/07/2016 13:47:48] - |D| - [1419214] - C:\WINDOWS\Provisioning [MD5.BF5D30514FEA913E25CCC9E546257088] - [09/05/2017 15:10:26] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [320512] - (10.0.14393.953) - C:\WINDOWS\regedit.exe [MD5.5DDB105C20BE94DD51769920ACD85B9C] - [20/03/2016 04:38:51] - |A| - (.-.) - [233] - (0.0.0.0) - C:\WINDOWS\regedit.log [16/07/2016 13:47:48] - |D| - [1095144] - C:\WINDOWS\Registration [16/07/2016 13:47:48] - |D| - [7195452] - C:\WINDOWS\rescache [16/07/2016 13:47:48] - |D| - [3661206] - C:\WINDOWS\Resources [MD5.429D9EEB1DA2386625DF4601CC1C875A] - [19/03/2016 15:07:37] - |A| - (.Copyright (C) 2015 Realtek Semiconductor Corp. - RtlExUpd DLL for setup utility function.) - [2825944] - (1.0.6.5) - C:\WINDOWS\RtlExUpd.dll [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\SchCache [16/07/2016 13:47:48] - |D| - [121229] - C:\WINDOWS\schemas [16/07/2016 13:47:48] - |D| - [5523098] - C:\WINDOWS\security [23/10/2016 12:21:35] - |D| - [45329578] - C:\WINDOWS\ServiceProfiles [16/07/2016 08:04:24] - |D| - [297179539] - C:\WINDOWS\servicing [16/07/2016 13:49:46] - |D| - [349] - C:\WINDOWS\Setup [MD5.D7541CA649097C7E2400EAFD21BA5487] - [23/10/2016 12:22:49] - |A| - (.-.) - [28980] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D060131CD55776F1C058590263CFF30E] - [23/10/2016 12:22:49] - |A| - (.-.) - [168] - (0.0.0.0) - C:\WINDOWS\setuperr.log [16/07/2016 13:47:48] - |D| - [31190016] - C:\WINDOWS\ShellExperiences [17/07/2016 00:40:46] - |D| - [3070736] - C:\WINDOWS\SKB [19/03/2016 18:27:13] - |D| - [1466018627] - C:\WINDOWS\SoftwareDistribution [16/07/2016 13:47:48] - |D| - [86037697] - C:\WINDOWS\Speech [16/07/2016 13:47:48] - |D| - [53541356] - C:\WINDOWS\Speech_OneCore [MD5.BCDB205132974EC3AB6F5C01DD93489B] - [02/11/2016 09:43:55] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [130560] - (10.0.14393.351) - C:\WINDOWS\splwow64.exe [MD5.A17D9D6F56B4F9EB0ACFE2F35E5B8576] - [19/03/2016 18:34:25] - |A| - (.-.) - [1366] - (0.0.0.0) - C:\WINDOWS\Synaptics.log [16/07/2016 13:47:48] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [10/07/2015 13:04:27] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [16/07/2016 08:04:24] - |D| - [21650532379] - C:\WINDOWS\System32 [16/07/2016 13:47:48] - |D| - [144071051] - C:\WINDOWS\SystemApps [16/07/2016 13:47:48] - |D| - [17560957] - C:\WINDOWS\SystemResources [16/07/2016 08:04:27] - |D| - [1476359609] - C:\WINDOWS\SysWOW64 [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\TAPI [10/07/2015 13:04:23] - |D| - [1344] - C:\WINDOWS\Tasks [16/07/2016 13:47:48] - |D| - [39597270] - C:\WINDOWS\Temp [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\tracing [16/07/2016 13:47:48] - |D| - [7680] - C:\WINDOWS\twain_32 [MD5.21F91141B4796108A50733B14850CDF2] - [16/07/2016 13:43:52] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [66560] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [19/10/2016 17:18:22] - |D| - [5769434] - C:\WINDOWS\UpdateAssistant [16/07/2016 13:47:48] - |D| - [12420] - C:\WINDOWS\Vss [16/07/2016 13:47:48] - |D| - [26983002] - C:\WINDOWS\Web [MD5.60CDAF0811BF825164C0E246F4F5620D] - [10/07/2015 13:04:27] - |A| - (.-.) - [124] - (0.0.0.0) - C:\WINDOWS\win.ini [MD5.C844CA459F3B209329984772269B6E56] - [16/07/2016 13:42:32] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.038356387332650843BCB352BB89A101] - [10/07/2015 14:22:08] - |A| - (.-.) - [275] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.9328E170E5407D9DDE7EB1E208A2CBB4] - [16/07/2016 13:42:48] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [10240] - (10.0.14393.0) - C:\WINDOWS\winhlp32.exe [16/07/2016 08:04:24] - |D| - [11318444913] - C:\WINDOWS\WinSxS [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [16/07/2016 13:43:08] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.E87C6A38E61A712C48025A6AD54C1113] - [16/07/2016 13:42:39] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.14393.0) - C:\WINDOWS\write.exe ---------- | C:\WINDOWS\System32\GroupPolicy [MD5.E12324ACF507ACE937B7FEC19E97D9AE] - [11/01/2017 11:43:16] - |A| - (.-.) - [127] - (0.0.0.0) - C:\WINDOWS\System32\GroupPolicy\GPT.INI [11/01/2017 11:43:16] - |D| - [94] - C:\WINDOWS\System32\GroupPolicy\Machine [11/01/2017 11:43:16] - |D| - [0] - C:\WINDOWS\System32\GroupPolicy\User ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [15/08/2016 12:11:10] - C:\WINDOWS\Installer\1021b0.msi : (abPhoto - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [27/02/2014 09:30:54] - C:\WINDOWS\Installer\14f56.msi : (Explorer Agent - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/05/2015 07:04:42] - C:\WINDOWS\Installer\14f5a.msi : (Power Management - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/09/2015 07:50:04] - C:\WINDOWS\Installer\14f62.msi : (Quick Access - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [31/07/2015 10:30:53] - C:\WINDOWS\Installer\14f7b.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/03/2016 18:46:33] - C:\WINDOWS\Installer\14f80.msi : (Foxit PhantomPDF - Foxit Software Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [09/07/2015 23:48:10] - C:\WINDOWS\Installer\204cb.msi : (Care Center - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [26/05/2015 12:02:42] - C:\WINDOWS\Installer\204cf.msi : (User Experience Improvement Program - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/05/2017 00:17:42] - C:\WINDOWS\Installer\26101.msi : (Amazon Assistant - Amazon) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/07/2015 02:29:36] - C:\WINDOWS\Installer\2a040.msi : (DriverSetupUtility - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [16/06/2015 15:44:34] - C:\WINDOWS\Installer\2a044.msi : (Intel(R) Chipset Device Software - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/06/2015 02:11:38] - C:\WINDOWS\Installer\2a048.msi : (Intel(R) ME UninstallLegacy - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/06/2015 02:12:42] - C:\WINDOWS\Installer\2a04c.msi : (Intel(R) Management Engine Components - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/06/2015 02:12:58] - C:\WINDOWS\Installer\2a05e.msi : (Intel(R) Management Engine Components - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [22/05/2015 18:27:22] - C:\WINDOWS\Installer\2a062.msi : (Intel(R) Trusted Connect Service Client - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [22/05/2015 02:25:00] - C:\WINDOWS\Installer\2a066.msi : (Intel® Security Assist - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/06/2015 17:01:14] - C:\WINDOWS\Installer\2a06a.msi : (Intel(R) Rapid Storage Technology - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/03/2016 15:10:10] - C:\WINDOWS\Installer\2a06e.msi : (Blank Project Template - InstallShield) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/03/2016 15:10:41] - C:\WINDOWS\Installer\2a089.msi : (Blank Project Template - InstallShield) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [16/06/2015 10:37:48] - C:\WINDOWS\Installer\30fd3.msi : (Intel(R) Serial IO - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/01/2017 14:06:57] - C:\WINDOWS\Installer\6052c074.msi : (LeapFrog Connect - LeapFrog Enterprises, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/01/2017 14:05:23] - C:\WINDOWS\Installer\6052c079.msi : (LeapFrog LeapReader Plugin Installer - LeapFrog) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [27/04/2015 08:36:02] - C:\WINDOWS\Installer\6b9ff.msi : ( -) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [27/11/2016 11:51:13] - C:\WINDOWS\Installer\7f281ac1.msi : (Skype - Skype Technologies S.A.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [09/09/2016 05:04:13] - C:\WINDOWS\Installer\91d0bef6.msi : (Acer Portal - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [30/08/2016 09:11:08] - C:\WINDOWS\Installer\91d0bf15.msi : (AOP Framework - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/05/2015 09:51:03] - C:\WINDOWS\Installer\cefd.msi : (abFiles - Acer Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] ---------- | %System%\*.in* [16/07/2016 13:43:08] - [3458] - C:\WINDOWS\System32\ieuinit.inf [31/08/2015 13:01:26] - [1825302] - C:\WINDOWS\System32\PerfStringBackup.INI [16/07/2016 13:42:39] - [60124] - C:\WINDOWS\System32\tcpmon.ini [16/07/2016 13:42:11] - [2307] - C:\WINDOWS\System32\WimBootCompress.ini [16/07/2016 13:43:59] - [3458] - C:\WINDOWS\Syswow64\ieuinit.inf [16/07/2016 13:42:43] - [2307] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\AppPatch\Custom\Custom64 [MD5.B7C476BBE4F001F4F33C04D9ABC33DC8] - |A| - [16/07/2016 13:42:17] - (.-.) - [14.52 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\AppPatch64\pcamain.sdb [MD5.8BE31B88D8523648580AFAFB92B78A30] - |A| - [09/05/2017 15:11:24] - (.-.) - [540.84 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\AppPatch64\sysmain.sdb [MD5.0265653D5B51653398B6F18659EC5AA3] - |A| - [25/08/2017 22:35:34] - (.Copyright © 2015 McAfee, Inc. - McAfee Installer.) - [862.33 Ko] - (9.0.154.0) - C:\WINDOWS\Temp\0138761503693334mcinst.exe [MD5.7324E6699F1AA83C2A977D0E0F531788] - |A| - [26/02/2017 22:42:42] - (.Copyright © 2016 McAfee, Inc. - McAfee Installer.) - [1006.74 Ko] - (10.0.4003.0) - C:\WINDOWS\Temp\0193831488141761mcinst.exe [MD5.00000000000000000000000000000000] - |D| - [09/05/2017 14:49:34] - [0 Ko] - C:\WINDOWS\Temp\842449224542100369368 [MD5.DDE63530E104786872369CAF2A310D60] - |A| - [29/01/2017 14:24:52] - (.-.) - [2596 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Amazon1ButtonApp-FR.msi [MD5.79EE868A1B23B2239F3318C1FC1D23BE] - |A| - [12/02/2017 22:24:01] - (.-.) - [2612 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\AmazonAssistant-FR.msi [MD5.4C7EDE7B38F2CFC2C0FF42E28406B865] - |A| - [10/05/2017 00:17:37] - (.-.) - [2616 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\AmazonAssistant-US.msi [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/11/2016 12:12:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.2t981rvaidqcu2up78svu7m9b.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 09:34:21] - (.-.) - [11.89 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.2w4khpeogjxnnksifizmaehng.tmp [MD5.4782288652FFE7B232116B195C995422] - |AT| - [27/11/2016 12:10:23] - (.-.) - [26.41 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.3exu5u5sxa_u2cxwe0dsu7m.tmp [MD5.4A3F3DEBA14CAEA005767EAEE86276F2] - |AT| - [27/11/2016 12:10:26] - (.-.) - [10.35 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.3r127c38w_qull6pehbefie2e.tmp [MD5.EF1B851D7B6FB31E47DC463F513C42F5] - |AT| - [27/11/2016 12:10:13] - (.-.) - [17.51 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.451roa8o0tlborqqpbu12hete.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/11/2016 12:11:28] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.4yupi01nej9lfv1bftfq0bbr.tmp [MD5.D4F67310C3D389A2DE85CCEC81CE0553] - |AT| - [27/11/2016 12:11:28] - (.-.) - [3.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.4zi0ytsdp5n_3aksvicitug_b.tmp [MD5.5C4B8A590A8631700085764500B96A0A] - |AT| - [27/11/2016 12:12:15] - (.-.) - [4.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.5a0of7rftd7s0sn9xhisikjrb.tmp [MD5.9B33865678F420C425EC4DD02741662E] - |AT| - [27/11/2016 12:10:26] - (.-.) - [3.23 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.5m5p8y06m4__rhxqkagvcw6rb.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 22:27:00] - (.-.) - [1.04 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.5uew0rjkwq03y3g0gl70uta6g.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 09:34:20] - (.-.) - [1695.55 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.7ijk2oai_4o4w7guy29uajyub.tmp [MD5.35E8C141556FC14FC6A8C45579071C06] - |AT| - [27/11/2016 12:11:42] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.7ktjmbvnqxo8_tymyqbn58rg.tmp [MD5.DA45547F22BAAFAC0BDB85025A539751] - |AT| - [27/11/2016 12:10:23] - (.-.) - [10.39 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.b54rgtgnu0w6qtbk8f0wkjxlc.tmp [MD5.115285CB87E0534067A5606DBC505C1A] - |AT| - [27/11/2016 12:11:28] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.cvsvrctpgnrvl08a4dir_agcg.tmp [MD5.9FC3B4A429570512525CEE87F20531B9] - |AT| - [27/11/2016 12:11:05] - (.-.) - [10.39 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.da3ix4b3n44od7xgw7wuusp_f.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 09:34:21] - (.-.) - [4.88 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.day8qlx_qilsdv1ybba9l19yb.tmp [MD5.CB8C93F6B7E21E6E67B5CF52B71F05EB] - |AT| - [27/11/2016 12:12:22] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.fmwe_czbv7awg2d5j92d8681.tmp [MD5.A738F7EE31D81ADF6EE8339C2ED454BB] - |AT| - [27/11/2016 12:10:26] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.gmjzwf1kim_8ptecjm2aa2zdf.tmp [MD5.22FB87F1E6848618C502D090C103402C] - |AT| - [27/11/2016 12:10:23] - (.-.) - [10.64 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.grc2711q98_nm9fp0qcdedre.tmp [MD5.09BC282584930BEE9A94E8D94ADFF5A3] - |AT| - [27/11/2016 12:11:28] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.h1wsieznq4910w4rpo_77p8b.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 22:26:50] - (.-.) - [19.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.jgqygaq4s8hlvwnvf4o5apeud.tmp [MD5.88BFE973D9B1BB091D994A121662B7E4] - |AT| - [27/11/2016 12:10:00] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.kysm002f4m0e8_pg16dt3d2ah.tmp [MD5.5CE3228F671C1A4C4F951784CA060CFE] - |AT| - [27/11/2016 12:10:26] - (.-.) - [18.12 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.l9aqfit01x8pnwd4ep2m5hi3c.tmp [MD5.2B2D5201622D2DC1D6336B41E07E4A0D] - |AT| - [27/11/2016 12:11:42] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.lh20wr7cjfp530qbyqq14n2vg.tmp [MD5.20D8D6BB1962A024819FB9687D63A731] - |AT| - [27/11/2016 12:11:28] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.md8a4rnbx0tybghohu1sh8k3f.tmp [MD5.1AED95F800388099D18C90239C424F3A] - |AT| - [27/11/2016 12:10:00] - (.-.) - [10.35 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.mh4pbf1k3czlx9h94nsmws3xd.tmp [MD5.DED7C874592962301763D057722F0D1C] - |AT| - [27/11/2016 12:11:05] - (.-.) - [11.21 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.nrsybi9xa1ve5xobjhr4tyj9g.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 22:27:03] - (.-.) - [1.01 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.o_oxme06o_0t5t7e9u9fcqy8d.tmp [MD5.5B2E7A8092651FDA34432A01AC6D8250] - |AT| - [27/11/2016 12:11:05] - (.-.) - [5.69 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.pn8oo_671_8uua3bw_4gj88rd.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 09:34:21] - (.-.) - [10.31 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.rpiledhpuetmbgm0nmm8bkqhg.tmp [MD5.10E6ED5A19620B4A8875F4F0B6B912D5] - |AT| - [27/11/2016 12:11:28] - (.-.) - [10.35 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.wkum958kgdoksq0mfct0ovmph.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/11/2016 12:11:05] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.xd4i6h_kbx75ovyjz9qt26epe.tmp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/11/2016 12:11:42] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\APPX.zblaek0fhy0_c2uqflwe2fuhe.tmp [MD5.9DE9F7272B0E7254DDAFBF4E652C43AA] - |A| - [23/10/2016 12:32:08] - (.-.) - [0.93 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ASPNETSetup_00000.log [MD5.C1384042675C9BEA10AE5591057D7755] - |A| - [23/10/2016 12:32:09] - (.-.) - [0.94 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ASPNETSetup_00001.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [23/10/2016 12:50:06] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\CMcUploader.log [MD5.2165B8D949E542E5F4BDDE28A4E75926] - |A| - [03/12/2016 09:30:41] - (.-.) - [128.47 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\CSPInstall.log [MD5.09D2F2B71F800A9438086A4AEAE0475D] - |A| - [26/02/2017 22:41:22] - (.-.) - [5.16 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\CSPUninstall.log [MD5.9AEE47D277025E62CDA7459AC4960560] - |A| - [03/12/2016 09:13:27] - (.-.) - [74.2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\dat618E.tmp [MD5.846BD77FBE0EEE585E543BB79672627C] - |A| - [08/05/2017 09:35:42] - (.-.) - [419.46 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\dd_vcredistMSI1CCC.txt [MD5.DBE302F93202B6D2E35F24F01E65BF5F] - |A| - [08/05/2017 09:37:44] - (.-.) - [430.76 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\dd_vcredistMSI1E5A.txt [MD5.42F6E130730FF09D28FA818657BAF897] - |A| - [08/05/2017 09:35:40] - (.-.) - [15.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\dd_vcredistUI1CCC.txt [MD5.04A7949D12293223AE8749C209669BDB] - |A| - [08/05/2017 09:37:42] - (.-.) - [15.21 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\dd_vcredistUI1E5A.txt [MD5.00000000000000000000000000000000] - |D| - [23/10/2016 12:25:29] - [5053.71 Ko] - C:\WINDOWS\Temp\DisplayAudio [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [23/10/2016 12:46:31] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\FXSTIFFDebugLogFile.txt [MD5.00000000000000000000000000000000] - |D| - [18/02/2017 20:24:08] - [0 Ko] - C:\WINDOWS\Temp\intel-gfx-installer-C3D9886E-5DDF-48BC-AD93-09E28F54964A [MD5.0795B006845FA3E54E747FCD540C14ED] - |A| - [23/10/2016 13:19:58] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161023-1319.log [MD5.0BB3445DD9A15AEA821896C660BB8123] - |A| - [23/10/2016 13:49:43] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161023-1349.log [MD5.27AE34BB1FC9578351946F205EBDE000] - |A| - [23/10/2016 14:19:43] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161023-1419.log [MD5.6812CAA5A7E87E14367C179F76C2F737] - |A| - [26/10/2016 06:27:47] - (.-.) - [155.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161026-0627.log [MD5.F0076212B40178BE66A308996CEAE9A1] - |A| - [26/10/2016 06:29:19] - (.-.) - [7.2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161026-0629.log [MD5.244766EDE35D784D19CFE474FD870A97] - |A| - [26/10/2016 06:29:19] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161026-0629a.log [MD5.6BA76D29AA03CC5EC3F323FD1FA2C923] - |A| - [27/10/2016 09:17:38] - (.-.) - [7.2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161027-0917.log [MD5.99026F939179452311539E90C29976D0] - |A| - [27/10/2016 09:19:23] - (.-.) - [2.93 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161027-0919.log [MD5.3313D930E44FA09F26B4E93035607390] - |A| - [28/10/2016 08:52:26] - (.-.) - [2.95 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161028-0852.log [MD5.E6EAA3B4C82E8E2856774AC39D18A4EE] - |A| - [28/10/2016 08:54:37] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161028-0854.log [MD5.D8171780CA2F206D634387EB95B9E685] - |A| - [28/10/2016 08:54:37] - (.-.) - [2.95 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161028-0854a.log [MD5.8DE4725EA0F6A23A949BE9A40A9903EB] - |A| - [28/10/2016 15:04:43] - (.-.) - [7.23 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161028-1504.log [MD5.E9B90BBC1F6A7338343A61F1F63EC460] - |A| - [02/11/2016 08:04:45] - (.-.) - [7.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161102-0704.log [MD5.BFE9A78A968037296F0612972AF5AA40] - |A| - [02/11/2016 08:04:45] - (.-.) - [5.17 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161102-0704a.log [MD5.03B45D6FD1D3C05BC2AD83A19C3A2177] - |A| - [02/11/2016 08:54:46] - (.-.) - [2.95 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161102-0754.log [MD5.8F45CC48BE407F6ED455A9BF5454FE52] - |A| - [02/11/2016 09:19:23] - (.-.) - [2.95 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161102-0819.log [MD5.E86C9CE9DCA9CC90CE53509B9D0598E2] - |A| - [02/11/2016 19:17:08] - (.-.) - [116.64 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161102-1817.log [MD5.0361618A23D5E4F42E2A4FF0EE175FC2] - |A| - [02/11/2016 19:35:43] - (.-.) - [6.45 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161102-1835.log [MD5.DE1827D5727E6AA90DF75C5DFE5A199D] - |A| - [03/11/2016 19:27:10] - (.-.) - [7.18 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161103-1827.log [MD5.15DF7D2107BE81BB68ECA5C6AA6C981D] - |A| - [27/11/2016 11:38:04] - (.-.) - [7.2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161127-1038.log [MD5.C2C511D8ECFAFF24BA14C13A41ADC949] - |A| - [27/11/2016 11:39:40] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161127-1039.log [MD5.A446B2774BF2D829ACAA5DDFE1012A79] - |A| - [27/11/2016 11:40:10] - (.-.) - [2.93 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161127-1040.log [MD5.DDC6180EA2D24728458E1E49B998108D] - |A| - [27/11/2016 11:42:58] - (.-.) - [684.57 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161127-1042.log [MD5.588132C866584F84D973CAD97F8A32DA] - |A| - [03/12/2016 13:55:09] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1255.log [MD5.F078EA0DE3E7AA3D4E2E923D34BBB8D0] - |A| - [03/12/2016 14:02:53] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1302.log [MD5.36B9C1E53FAFCCE830B6E69E6D3BA9E8] - |A| - [03/12/2016 14:24:16] - (.-.) - [5.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1324.log [MD5.5BD88BCB346A6A28BBBEDD66FC4B121C] - |A| - [03/12/2016 14:36:17] - (.-.) - [228.64 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1336.log [MD5.35E4273E2C64209ED337126F0FD73F01] - |A| - [03/12/2016 14:36:19] - (.-.) - [55.81 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1336a.log [MD5.1E120BAD11DBB6D47A4394F511E4D0A9] - |A| - [03/12/2016 14:54:16] - (.-.) - [5.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1354.log [MD5.44DEF51CE2A903CA4E1E518BEE196DE9] - |A| - [03/12/2016 14:54:34] - (.-.) - [47.53 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1354a.log [MD5.7494866115BE49249F0112FE902B7994] - |A| - [03/12/2016 14:55:06] - (.-.) - [10.49 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1355.log [MD5.3F80BAE34E60A22F82AA3CF93D699DC6] - |A| - [03/12/2016 14:55:17] - (.-.) - [31.01 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1355a.log [MD5.4A34F1EB34A2EA9A67CE1910E605194F] - |A| - [03/12/2016 18:44:06] - (.-.) - [461.37 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1744.log [MD5.EC68EA8F123E98E340ABF816C1834CBA] - |A| - [03/12/2016 19:03:48] - (.-.) - [5.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1803.log [MD5.0D4CF51F12F945259EFDF320A00AB9FC] - |A| - [03/12/2016 19:04:36] - (.-.) - [67.37 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161203-1804.log [MD5.5B761D84B0B8BA90E2010C67BF3D64A6] - |A| - [04/12/2016 11:17:32] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161204-1017.log [MD5.418899089FDD48CF7A56537A2B33A031] - |A| - [04/12/2016 11:17:32] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161204-1017a.log [MD5.6603A8618AF2ED4CBD0E408FA2FC0D4E] - |A| - [04/12/2016 11:18:20] - (.-.) - [58.95 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161204-1018.log [MD5.A51B3DDE78E085959002F6724553C30C] - |A| - [05/12/2016 22:27:36] - (.-.) - [6.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161205-2127.log [MD5.5B98ACEFDAE25129B8254F78184301C4] - |A| - [05/12/2016 22:29:54] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161205-2129.log [MD5.4730C048BC07E4A7616CE823E884BE8D] - |A| - [07/12/2016 10:46:08] - (.-.) - [6.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161207-0946.log [MD5.AB68E818B075ADE7C2F2B407AA2889C4] - |A| - [07/12/2016 10:48:48] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161207-0948.log [MD5.76D7CD5D8655D964791D32CE99D7E32D] - |A| - [07/12/2016 10:48:48] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161207-0948a.log [MD5.58FB81DB0E002F37A37110F07D127A66] - |A| - [07/12/2016 10:49:39] - (.-.) - [58.48 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161207-0949.log [MD5.66F7A5E215B9542FB8473A0E4E35C065] - |A| - [07/12/2016 19:15:05] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161207-1815.log [MD5.AC2706F493B2242965BAF072591553F2] - |A| - [11/12/2016 13:10:16] - (.-.) - [5.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161211-1210.log [MD5.10AB4ED6B1CDDF2ECE06253F7553ADDF] - |A| - [11/12/2016 13:10:16] - (.-.) - [6.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161211-1210a.log [MD5.7460832675BE5CBA51BD868B4F5A32AA] - |A| - [11/12/2016 13:11:20] - (.-.) - [58.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161211-1211.log [MD5.F8E2FCC7E15B5B06A908F9ACE9B85F9C] - |A| - [11/12/2016 22:38:15] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161211-2138.log [MD5.4E203391918687FA8526B2546CF8BF5D] - |A| - [14/12/2016 17:00:51] - (.-.) - [6.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161214-1600.log [MD5.81A630FCB03274CA41FF6DE4CBA5E5FD] - |A| - [14/12/2016 17:03:19] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161214-1603.log [MD5.586AEEC28681EDFFADE7850FD27B7734] - |A| - [14/12/2016 17:03:19] - (.-.) - [2.6 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161214-1603a.log [MD5.7B3932633616113BBA1A030D65E0772D] - |A| - [26/12/2016 19:44:16] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161226-1844.log [MD5.A3C2748C02D9FA47DE76A9D18564CD26] - |A| - [26/12/2016 19:45:29] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161226-1845.log [MD5.9030DF6DC7ABA39FDEEC32F85ACCA9D2] - |A| - [27/12/2016 17:29:45] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161227-1629.log [MD5.579B85EEF6F5B2E8A939FBA17EFD51F2] - |A| - [28/12/2016 10:36:27] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161228-0936.log [MD5.F19BC1DFA04560A3E93A2BB4B40DDB6A] - |A| - [28/12/2016 10:50:04] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161228-0950.log [MD5.15E9FCB9E20F5D5980A3EC1170DF27A0] - |A| - [28/12/2016 11:17:43] - (.-.) - [2.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161228-1017.log [MD5.50C73CE7B4D1E90059D4944D197DAD35] - |A| - [29/12/2016 13:24:12] - (.-.) - [6.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1224.log [MD5.FFEFD967B37031272EDF9906EAEA3CE8] - |A| - [29/12/2016 13:25:52] - (.-.) - [5.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1225.log [MD5.EBCBCB5956E3C72A24A68B018351019B] - |A| - [29/12/2016 13:26:36] - (.-.) - [2.6 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1226.log [MD5.5089A4AD468D06189E1272F520154D3C] - |A| - [29/12/2016 13:27:07] - (.-.) - [166.04 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1227.log [MD5.23D3BE2250577A86AB7DA3CBD054CAA1] - |A| - [29/12/2016 14:27:13] - (.-.) - [197.91 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1327.log [MD5.5EDF5C0D98C3AF66CE26C783F9B9FCC2] - |A| - [29/12/2016 14:27:39] - (.-.) - [11.81 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1327a.log [MD5.638AE260F0FF305529F4AFA10B132777] - |A| - [29/12/2016 14:27:55] - (.-.) - [39.01 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161229-1327b.log [MD5.F450672675E79071267A70967C14BC83] - |A| - [31/12/2016 11:05:08] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161231-1005.log [MD5.C8659BD837299235C67B8AB43A51CA69] - |A| - [31/12/2016 11:05:08] - (.-.) - [5.77 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161231-1005a.log [MD5.81666EC5D05F0E9F652748284123588D] - |A| - [31/12/2016 11:06:17] - (.-.) - [52.94 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20161231-1006.log [MD5.77EBFB49E6866296364D01585567D879] - |A| - [10/01/2017 21:23:08] - (.-.) - [6.93 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2023.log [MD5.C0134EBF1259E3D58D1EA308D598F7D3] - |A| - [10/01/2017 21:23:08] - (.-.) - [5.77 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2023a.log [MD5.E729611A4394523257DC60FAB44C9B34] - |A| - [10/01/2017 21:23:19] - (.-.) - [88.08 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2023b.log [MD5.16ECFEA71C1B19E5A8E96D6267CA2929] - |A| - [10/01/2017 21:24:34] - (.-.) - [106.47 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2024.log [MD5.E00ACBCE53A03A4591457CBAA8B6825D] - |A| - [10/01/2017 21:33:56] - (.-.) - [5.77 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2033.log [MD5.DFCF18717D8389AB368DFB5EB4140DAF] - |A| - [10/01/2017 21:34:09] - (.-.) - [402.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2034.log [MD5.2E3B7C238615DDDAB1DDD602CCAC7C0D] - |A| - [10/01/2017 21:34:29] - (.-.) - [12.53 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2034a.log [MD5.B0B21E4EB1E574A5644DE24EB1BDE2E1] - |A| - [10/01/2017 21:34:37] - (.-.) - [27.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170110-2034b.log [MD5.159F282F64C23055AD2E067B18BC929F] - |A| - [11/01/2017 11:29:36] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170111-1029.log [MD5.1290DCE94A13FC81DDCEF387CDFA932F] - |A| - [12/01/2017 21:56:05] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170112-2056.log [MD5.0A7D2278891C16201CB5D3DC5DB65E64] - |A| - [14/01/2017 10:24:15] - (.-.) - [8.62 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170114-0924.log [MD5.5A93B5E30100761E9D5C20E1A4CDA6AC] - |A| - [14/01/2017 10:24:58] - (.-.) - [5.73 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170114-0924a.log [MD5.8EA9447D19B72355092A9C551009E887] - |A| - [14/01/2017 10:26:00] - (.-.) - [52.96 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170114-0926.log [MD5.79FB8D2DC469289BE5C2FA06DA5E3ACE] - |A| - [14/01/2017 23:16:06] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170114-2216.log [MD5.56C491E40BBAC9FD05B863445DF3CDA0] - |A| - [15/01/2017 10:48:45] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170115-0948.log [MD5.EB4016376001751891B82F921292AC11] - |A| - [15/01/2017 10:49:56] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170115-0949.log [MD5.942C250E3C6E041BE95A2BAE4AC5FBE6] - |A| - [15/01/2017 10:49:56] - (.-.) - [5.73 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170115-0949a.log [MD5.A2A4E64D5553089C1C35CC2FCC1DC95D] - |A| - [29/01/2017 11:58:01] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170129-1057.log [MD5.1258E42D90CB8396E36ABFC5D247D514] - |A| - [29/01/2017 11:58:12] - (.-.) - [5.75 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170129-1058.log [MD5.48EA0E8F2B90C0F813089C35D8235B41] - |A| - [08/02/2017 20:16:34] - (.-.) - [7.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170208-1916.log [MD5.83F88BFD359DE11F78FA983EAED0E2C1] - |A| - [08/02/2017 20:16:35] - (.-.) - [5.75 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170208-1916a.log [MD5.989130696554FBAC89F41C7B3D80F851] - |A| - [08/02/2017 20:19:01] - (.-.) - [125.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170208-1919.log [MD5.2A7279F48EB3E8FF5C7F8AEAAF72F030] - |A| - [08/02/2017 20:39:41] - (.-.) - [156.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170208-1939.log [MD5.4F2AC6F9BF2D4B7E310093A1E443D032] - |A| - [08/02/2017 20:40:09] - (.-.) - [10.39 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170208-1940.log [MD5.FDB252EE71C56EF0F3DCC928D549515D] - |A| - [08/02/2017 20:40:23] - (.-.) - [37.77 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170208-1940a.log [MD5.14AD8144A0C099DAAD2BBAD413F4C75D] - |A| - [10/02/2017 20:30:37] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170210-1930.log [MD5.8DB4763819F11FABA774F3B9385E3DAC] - |A| - [11/02/2017 21:08:44] - (.-.) - [21.45 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170211-2008.log [MD5.185426D2D7D86034A00EB0F2AA62C17C] - |A| - [11/02/2017 21:09:28] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170211-2009.log [MD5.BA2BBEDA4F0A1512B7637AED3D66D1AF] - |A| - [12/02/2017 22:29:47] - (.-.) - [6.92 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170212-2129.log [MD5.6689EE18BF83AB8C771432759CE0B22B] - |A| - [12/02/2017 22:29:48] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170212-2129a.log [MD5.784E37D49F4CE16B48635248130A89BF] - |A| - [12/02/2017 22:29:54] - (.-.) - [534.18 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170212-2129b.log [MD5.58E01BC58CB1D50562506F964007C169] - |A| - [12/02/2017 22:30:39] - (.-.) - [53.52 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170212-2130.log [MD5.68D19F06FF72A68A3325BBAEE9F8AA96] - |A| - [12/02/2017 22:38:47] - (.-.) - [4.88 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170212-2138.log [MD5.E300E6FB14D567A6E1721B0556634207] - |A| - [14/02/2017 22:08:55] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170214-2108.log [MD5.1A9EE1E4CE464506C8D21E9800CFE632] - |A| - [14/02/2017 22:08:55] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170214-2108a.log [MD5.C75A7AD47AB3CCE253FC07644086281B] - |A| - [14/02/2017 22:10:08] - (.-.) - [4.88 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170214-2110.log [MD5.5ACE023207F118F610D199ECA2DA522E] - |A| - [14/02/2017 22:10:10] - (.-.) - [2.58 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170214-2110a.log [MD5.F8F6153546E0F8E4D2BF841EE360D6DA] - |A| - [14/02/2017 22:22:36] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170214-2122.log [MD5.133FC22093F7598E2C287B902C012F8C] - |A| - [18/02/2017 20:00:48] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-1900.log [MD5.6765F671057E6BD24A292AAE28647638] - |A| - [18/02/2017 20:00:48] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-1900a.log [MD5.28828F4A4147936C652E5936DC6D357A] - |A| - [18/02/2017 20:01:42] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-1901.log [MD5.DD29961B41F0263936A5B476CC23DA17] - |A| - [18/02/2017 20:01:42] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-1901a.log [MD5.779FC3C14E665F4C7C7ECCB2647B855B] - |A| - [18/02/2017 20:29:38] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-1929.log [MD5.681C9C4720CC14C4573B64ACA0E32162] - |A| - [18/02/2017 22:25:57] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-2125.log [MD5.448C6F02BF2F35C6F02DA4E5B28FA0DF] - |A| - [18/02/2017 22:31:29] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170218-2131.log [MD5.40E7F6DDAEAA014C92E017C1A876AD71] - |A| - [19/02/2017 10:06:16] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170219-0906.log [MD5.84F53AA8B0EB98EDD0859A3C6960A5EE] - |A| - [19/02/2017 10:06:16] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170219-0906a.log [MD5.1C21939D46BB11F720EEC2FDCE95EB1B] - |A| - [22/02/2017 17:15:55] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170222-1615.log [MD5.4D5A246F03D19A1DAB8B797EFA9D7E1C] - |A| - [22/02/2017 17:15:55] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170222-1615a.log [MD5.BF2AD05CF2A0059FC7313898BEEBD9B9] - |A| - [26/02/2017 22:26:20] - (.-.) - [6.83 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170226-2126.log [MD5.B2C524F5EA099EBB3850495975DA2D8E] - |A| - [26/02/2017 22:26:20] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170226-2126a.log [MD5.409E0E0CB5FF8E7743D7519F1EA6BE29] - |A| - [26/02/2017 22:30:53] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170226-2130.log [MD5.F249975E383D9C384537EF84579D71E2] - |A| - [27/02/2017 02:17:05] - (.-.) - [198.78 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170227-0117.log [MD5.5540AB7A2F4D5D95B88B165DF07AA43A] - |A| - [27/02/2017 02:32:33] - (.-.) - [4.88 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170227-0132.log [MD5.43E877ECD65C2F6005407EF24079B5A7] - |A| - [27/02/2017 22:27:28] - (.-.) - [6.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170227-2127.log [MD5.D09CAC3DD96A8D3E776CD9EFE2B4EC1F] - |A| - [01/03/2017 11:16:04] - (.-.) - [6.84 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170301-1016.log [MD5.AAC9552ECB431E02C02E046D3A32AB12] - |A| - [01/03/2017 11:16:49] - (.-.) - [4.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170301-1016a.log [MD5.00DB1889AE4B2767E886AFC6FF1116A7] - |A| - [01/03/2017 11:16:53] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170301-1016b.log [MD5.ACB2EFA86B1E7AFC28625ECD60537BD5] - |A| - [01/03/2017 11:17:41] - (.-.) - [108.7 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170301-1017.log [MD5.482EC1A55C1EC1B7B66A26FBAF17014D] - |A| - [08/03/2017 22:07:22] - (.-.) - [4.87 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2107.log [MD5.DD767513DBF2A7836E16B3B8DB6605EA] - |A| - [08/03/2017 22:07:22] - (.-.) - [6.84 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2107a.log [MD5.970C70E21ABCB7F39BEE5CCADA19607E] - |A| - [08/03/2017 22:07:58] - (.-.) - [39.83 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2107b.log [MD5.705D349B29830F1175EC363EA9FCE60A] - |A| - [08/03/2017 22:26:30] - (.-.) - [2.58 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2126.log [MD5.B33F8256B5C7C27FAF00B905C4C821E6] - |A| - [08/03/2017 23:09:51] - (.-.) - [44.74 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2209.log [MD5.FBABEDB722F57DCCBB6C754E8575B754] - |A| - [08/03/2017 23:10:07] - (.-.) - [53.16 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2210.log [MD5.D421C8DB01E69B2EEC97A32577C67FA0] - |A| - [08/03/2017 23:13:23] - (.-.) - [409.28 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2213.log [MD5.4CFE8703F4F43FEB4D5841CD0D63793C] - |A| - [08/03/2017 23:13:40] - (.-.) - [9.65 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2213a.log [MD5.AE30FD03E9B79B43D65287A24EB182E4] - |A| - [08/03/2017 23:14:24] - (.-.) - [32.91 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170308-2214.log [MD5.8F83C0704A75F5D5F7ECEFF8D6F98F70] - |A| - [12/03/2017 14:17:14] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170312-1317.log [MD5.C143BA0452E76051D153AF5E22CCACB7] - |A| - [12/03/2017 14:17:14] - (.-.) - [6.22 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170312-1317a.log [MD5.2EDE464A706CE4BFDC422C1F8CE5095E] - |A| - [12/03/2017 14:18:08] - (.-.) - [53.11 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170312-1318.log [MD5.64AA626AB62C9791A4081FE1FC6EC589] - |A| - [13/03/2017 22:33:53] - (.-.) - [6.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170313-2133.log [MD5.5D6C79375B5EA31943BB149180373877] - |A| - [13/03/2017 22:35:33] - (.-.) - [1.99 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170313-2135.log [MD5.9E9E3BE0F4DA57D67AA7CB915A0AB511] - |A| - [15/03/2017 22:20:01] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170315-2120.log [MD5.639FB32EB34BEF6BBEBB29BE87C5BB1E] - |A| - [15/03/2017 22:20:02] - (.-.) - [6.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170315-2120a.log [MD5.D08881F454C6846D84E2E10056B2FBA4] - |A| - [15/03/2017 22:36:57] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170315-2136.log [MD5.1E17004ACE1A04F9213D54FF59C443FF] - |A| - [20/03/2017 12:31:24] - (.-.) - [6.23 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170320-1131.log [MD5.8CDCFCE28DCABD92A2A2347829B96A8C] - |A| - [20/03/2017 12:31:24] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170320-1131a.log [MD5.33B761C95FB9913D4D8A890F0DD7C269] - |A| - [20/03/2017 12:32:46] - (.-.) - [104.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170320-1132.log [MD5.FE736D741CF5F4D69CC986088F704BD2] - |A| - [12/04/2017 18:25:45] - (.-.) - [13.42 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170412-1825.log [MD5.3C41272F701D6A2FBBE93B3B5538BF63] - |A| - [12/04/2017 18:26:45] - (.-.) - [6.47 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170412-1826.log [MD5.EFAA061C64786B8E0145A7BAB2A5DDE5] - |A| - [12/04/2017 18:35:15] - (.-.) - [116.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170412-1835.log [MD5.A577B5D4D15FE28C9602A3549441FB12] - |A| - [12/04/2017 18:56:23] - (.-.) - [515.9 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170412-1856.log [MD5.6A6CF2ED758C66DBAFD168F00E61266A] - |A| - [12/04/2017 18:56:47] - (.-.) - [9.65 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170412-1856a.log [MD5.3F98A5FD2045066C4DF31E33D30E0B4D] - |A| - [12/04/2017 18:57:06] - (.-.) - [34.11 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170412-1857.log [MD5.980AB80D3B6F0CBF2985C3DE26A24634] - |A| - [14/04/2017 18:50:57] - (.-.) - [6.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170414-1850.log [MD5.2B2C79C0B5CD541DB1F5708E96C7ADE5] - |A| - [14/04/2017 18:50:57] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170414-1850a.log [MD5.66C2A86965E3D7C565A17ABFC6CDB96C] - |A| - [14/04/2017 18:52:07] - (.-.) - [52.58 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170414-1852.log [MD5.1B0B2492831D6CE63FF5D485B5E34B9E] - |A| - [16/04/2017 10:56:13] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170416-1056.log [MD5.2C7D5C3C67396873CCFA5DBA4A47DDFD] - |A| - [16/04/2017 10:56:48] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170416-1056a.log [MD5.F0F84E807B769067D1BF7175305366A2] - |A| - [16/04/2017 10:56:48] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170416-1056b.log [MD5.AF38E43008BB366FC6894EBBCB0F80E7] - |A| - [18/04/2017 12:21:50] - (.-.) - [6.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170418-1221.log [MD5.1F8E3E07954C6E24DD228438CAE7B403] - |A| - [18/04/2017 12:21:50] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170418-1221a.log [MD5.A776FE83010C240CB50119508AC50EED] - |A| - [24/04/2017 21:14:29] - (.-.) - [6.22 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170424-2114.log [MD5.778103077B1D0EBCA4672EE485A95913] - |A| - [24/04/2017 21:14:36] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170424-2114a.log [MD5.3D680E9817FE1A582902EB6793732F8D] - |A| - [01/05/2017 20:58:08] - (.-.) - [6.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170501-2058.log [MD5.FF6EA9925343AD2FDC486EB4EE366EEC] - |A| - [01/05/2017 20:59:09] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170501-2059.log [MD5.5B75F3A312FE0E2AF7A8DF8D04EB25D8] - |A| - [01/05/2017 20:59:09] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170501-2059a.log [MD5.4D94F7556D0457911A439DA19EE74DFE] - |A| - [01/05/2017 21:00:23] - (.-.) - [170.73 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170501-2100.log [MD5.67506B242470655229B1B640E7946F09] - |A| - [01/05/2017 21:14:33] - (.-.) - [1.99 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170501-2114.log [MD5.A8DFECC6715F3EA8D1061E6CC754ECA9] - |A| - [05/05/2017 09:12:05] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-0912.log [MD5.F142E0B914363A73A4AD3CA0307B3256] - |A| - [05/05/2017 09:12:06] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-0912a.log [MD5.08F1ED6E199D8106BAE18FFE1F98BDD5] - |A| - [05/05/2017 09:12:28] - (.-.) - [17.99 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-0912b.log [MD5.DF2AE935D356B9CB5129E0457690DEF7] - |A| - [05/05/2017 10:17:07] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-1017.log [MD5.37EAB43F8871CB1539848045657174F4] - |A| - [05/05/2017 11:02:26] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-1102.log [MD5.F173769FE0267D2D4D79320F83EE842A] - |A| - [05/05/2017 11:33:21] - (.-.) - [4.28 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-1133.log [MD5.1E7D1CA6C2FBAFE1511687C8F9BFE59F] - |A| - [05/05/2017 12:03:21] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-1203.log [MD5.35DAAA365BE9C3CD2ECD90E69EB15E7E] - |A| - [05/05/2017 16:44:21] - (.-.) - [144.43 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-1644.log [MD5.E7DE02502DA93FDBAAA53B8DF88D9ADC] - |A| - [05/05/2017 16:44:27] - (.-.) - [33.76 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170505-1644a.log [MD5.C8321CBC64B40C2588C320FFEA972A39] - |A| - [08/05/2017 08:03:12] - (.-.) - [6.25 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170508-0803.log [MD5.EB74B042F1482F446426C8064B5855D5] - |A| - [08/05/2017 08:03:12] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170508-0803a.log [MD5.3B7C45DFED8C6515E0CD32DF85053BAC] - |A| - [08/05/2017 08:03:30] - (.-.) - [33.75 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170508-0803b.log [MD5.52DA448CFFB68E4C0319A3D4DE239ABD] - |A| - [09/05/2017 14:51:49] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170509-1451.log [MD5.1F3979C459C9CFA10675320CFD1E5436] - |A| - [09/05/2017 14:51:49] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170509-1451a.log [MD5.E6537E9C3AE55D60EF4275C261D4FA53] - |A| - [09/05/2017 14:52:12] - (.-.) - [32.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170509-1452.log [MD5.3109458750B2308DF10CCDE7B9E986B1] - |A| - [10/05/2017 00:17:12] - (.-.) - [35.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0017.log [MD5.25228E3BA9E73C838C253BA7D2D6CBF6] - |A| - [10/05/2017 00:17:25] - (.-.) - [49.57 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0017a.log [MD5.9AD9AFBE94CE1DB75998862CECD6D113] - |A| - [10/05/2017 00:19:04] - (.-.) - [611.98 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0019.log [MD5.B30C31FFB74DF91474D37F30A9D43B8B] - |A| - [10/05/2017 00:19:34] - (.-.) - [9.63 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0019a.log [MD5.3DB4B30759145CD8985DF69AC2F13FE0] - |A| - [10/05/2017 00:20:01] - (.-.) - [31.83 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0020.log [MD5.364E73608CE71A63E60471FB1E203929] - |A| - [10/05/2017 00:40:02] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0040.log [MD5.87D90BBC9813CCB6D09F885FA9FCADDC] - |A| - [10/05/2017 00:40:55] - (.-.) - [52.51 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-0040a.log [MD5.D4691532BD15FD40BE5647227A9F6E67] - |A| - [10/05/2017 11:52:20] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170510-1152.log [MD5.8B279FB3C64335DD320E99F4DAB64B18] - |A| - [18/05/2017 18:47:20] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170518-1847.log [MD5.B0BC49C5F34368998ECA6F5364D645A2] - |A| - [18/05/2017 18:52:06] - (.-.) - [5.75 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170518-1852.log [MD5.CF30E44ECADD4676BD64FAFC9B1B8541] - |A| - [18/05/2017 18:52:06] - (.-.) - [3.45 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170518-1852a.log [MD5.0D2396D8A0DDEA8663E43AADC4AF9D6D] - |A| - [18/05/2017 19:04:20] - (.-.) - [89.11 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170518-1904.log [MD5.A38278A6C6C8BB11DA4FDED695F179AE] - |A| - [19/05/2017 18:41:30] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170519-1841.log [MD5.2587291035C8E5BD4E5D12B4C0742005] - |A| - [19/05/2017 18:44:00] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170519-1844.log [MD5.D285196EFBD8434DD81008E571A65497] - |A| - [19/05/2017 18:44:01] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170519-1844a.log [MD5.849D5FAE141AE63CA5DCC38D9C554190] - |A| - [19/05/2017 18:44:21] - (.-.) - [32.54 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170519-1844b.log [MD5.6B5DD0A80802ECE2B67CF0D3D87C155E] - |A| - [19/05/2017 18:49:10] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170519-1849.log [MD5.BB63A3515D243CA4AE02323F303FC2BC] - |A| - [20/05/2017 09:42:45] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170520-0942.log [MD5.DB1668247D5845FEE75B560FDD477AB5] - |A| - [20/05/2017 18:57:28] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170520-1857.log [MD5.DA38C463D8829CE169C23A0CD7E12CD0] - |A| - [06/06/2017 20:31:04] - (.-.) - [6.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170606-2031.log [MD5.98D6997283166FA599F26186F427E2B4] - |A| - [06/06/2017 20:31:05] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170606-2031a.log [MD5.8F8F8F96826395B8CBF32D42855EB30D] - |A| - [06/06/2017 20:32:46] - (.-.) - [244.53 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170606-2032.log [MD5.3B16CD21AA32D2F31D03FA4685D0C189] - |A| - [07/06/2017 20:53:39] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170607-2053.log [MD5.462B58D70C4BFA83939FF06ECD678109] - |A| - [07/06/2017 20:55:02] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170607-2055.log [MD5.C0DE5A279F5682AD5BF7000021FAAF05] - |A| - [14/07/2017 19:43:19] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170714-1943.log [MD5.7B5C500AF65EF26251E24BAD173D8475] - |A| - [14/07/2017 19:43:26] - (.-.) - [6.22 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170714-1943a.log [MD5.A9980294E4ABA320E005F810DC3C04B9] - |A| - [14/07/2017 19:45:05] - (.-.) - [6.54 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170714-1945.log [MD5.E35E32A99BBE808C06BA69282D3E470A] - |A| - [14/07/2017 20:23:06] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170714-2023.log [MD5.0952A1C81FF9D17FE3B50D4D97B6A87A] - |A| - [25/08/2017 21:46:26] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2146.log [MD5.7005DD0A7DD42096A574D67D417B1455] - |A| - [25/08/2017 21:46:26] - (.-.) - [6.26 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2146a.log [MD5.B978334B1417E27C1288B7FE2E73F8D3] - |A| - [25/08/2017 21:47:19] - (.-.) - [95 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2147.log [MD5.D261BB3E70DA163914199D395BB8CD21] - |A| - [25/08/2017 22:22:29] - (.-.) - [85.56 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2222.log [MD5.72C2DE097627E6520E408C69D5357AB3] - |A| - [25/08/2017 22:24:02] - (.-.) - [6.63 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2224.log [MD5.EFCB079685C072CE7B1E548501A01F3E] - |A| - [25/08/2017 22:45:39] - (.-.) - [4.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2245.log [MD5.884E47A028C605420815663EC12BBA83] - |A| - [25/08/2017 22:46:03] - (.-.) - [49.85 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2246.log [MD5.6AEFECF010AD270DDCB7F80E902A3ED4] - |A| - [25/08/2017 22:47:02] - (.-.) - [365.09 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2247.log [MD5.4303A2A966FDB1CFA75828BAA676B161] - |A| - [25/08/2017 22:47:22] - (.-.) - [9.79 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2247a.log [MD5.3530B4E0F571C115A31E1AF8ABB98DC1] - |A| - [25/08/2017 22:47:33] - (.-.) - [40.72 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170825-2247b.log [MD5.A96A62DF72402D242A441465987FC0DB] - |A| - [26/08/2017 11:56:30] - (.-.) - [2.14 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170826-1156.log [MD5.4488567048EF174740B5471D2FC18F63] - |A| - [27/08/2017 09:18:40] - (.-.) - [6.38 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170827-0918.log [MD5.1D79D6D087FF5FC54CFB7EECFA9399E1] - |A| - [27/08/2017 09:18:40] - (.-.) - [7.5 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170827-0918a.log [MD5.E0685E446BD64BDB779102971419E777] - |A| - [27/08/2017 09:19:00] - (.-.) - [90.6 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170827-0919.log [MD5.79DEAC25E15DF5B4E46A0DD329774C92] - |A| - [27/08/2017 09:29:50] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170827-0929.log [MD5.D36AD38F3FB443E7D6A55FB18F9FD8AA] - |A| - [27/08/2017 09:30:16] - (.-.) - [24.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\LAPTOP-O5ULGE56-20170827-0930.log [MD5.8FAD3A22AE9D44B691CD3B0CBD79FA53] - |AT| - [27/11/2016 12:01:08] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\mcafee_AJh7XdaeTtdN7Tg [MD5.8FAD3A22AE9D44B691CD3B0CBD79FA53] - |AT| - [10/05/2017 18:49:27] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\mcafee_GKVPbpXSS62JKwg [MD5.8FAD3A22AE9D44B691CD3B0CBD79FA53] - |AT| - [04/12/2016 22:19:01] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\mcafee_Qq4nqplMSgROAnp [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [27/08/2017 09:43:57] - (.-.) - [2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\mcafee_Y8g2DLj87ih3cs4 [MD5.3279A031EE98B1639D2D45D63B247169] - |A| - [28/02/2017 11:10:34] - (.Copyright © 2016 McAfee, Inc. - McAfee CSP Install Library.) - [238.54 Ko] - (2.3.322.0) - C:\WINDOWS\Temp\McCSPInstall.dll [MD5.00000000000000000000000000000000] - |D| - [08/05/2017 09:33:47] - [0 Ko] - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_10.0.30319 [MD5.200D01EAA77C3A82965F2CF5D1291A6A] - |A| - [08/05/2017 09:34:43] - (.-.) - [299.98 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20170508_093345440-Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319-MSP0.txt [MD5.551CAEB8DCF5BA3CCD9CF122251B751D] - |A| - [08/05/2017 09:34:06] - (.-.) - [316.76 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20170508_093345440-MSI_vc_red.msi.txt [MD5.965429FB306A8E17209562A3F061F46C] - |A| - [08/05/2017 09:33:35] - (.-.) - [96.57 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20170508_093345440.html [MD5.00000000000000000000000000000000] - |D| - [08/05/2017 09:35:02] - [0 Ko] - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_10.0.30319 [MD5.9830EB31162A8FFCCD2A8F69C64C5BE1] - |A| - [08/05/2017 09:35:29] - (.-.) - [324.61 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20170508_093501407-Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-MSP0.txt [MD5.429A826D84B27616023B7373B59E90CB] - |A| - [08/05/2017 09:35:12] - (.-.) - [340.83 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20170508_093501407-MSI_vc_red.msi.txt [MD5.441CAE1044551135B045462EC9615F17] - |A| - [08/05/2017 09:34:57] - (.-.) - [90.82 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20170508_093501407.html [MD5.2AE5691E68AACB0C8017D50C36A11104] - |A| - [23/10/2016 13:02:58] - (.-.) - [24.83 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpCmdRun.log [MD5.00000000000000000000000000000000] - |D| - [05/05/2017 10:08:52] - [0 Ko] - C:\WINDOWS\Temp\MPTelemetrySubmit [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [02/11/2016 19:17:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(20161102181715980).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [27/11/2016 11:42:58] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(201611271042582840).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [29/12/2016 14:27:13] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(20161229132713148C).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [11/02/2017 21:08:46] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(20170211200846880).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [12/02/2017 22:29:54] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(201702122129542554).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [12/04/2017 18:56:24] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(201704121856241CD8).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [10/05/2017 00:19:04] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(20170510001904119C).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [25/08/2017 22:47:02] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\officeclicktorun.exe_streamserver(20170825224702297C).log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [03/12/2016 09:13:03] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\OLicenseHeartbeat.exe_c2rdll(20161203081248D4).log [MD5.52FA00D6FED33CFAFD2C8ACBB31730D3] - |A| - [27/08/2017 09:29:49] - (.-.) - [2.44 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\Silverlight0.log [MD5.F3DAD352C3DD82C4757CF20F1DA98266] - |A| - [27/08/2017 09:29:53] - (.-.) - [2918.78 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\SilverlightMSI.log [MD5.25C915542CA8694B7AC03DA977B097C1] - |A| - [23/10/2016 12:40:11] - (.-.) - [0.17 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\tem1FF4.tmp [MD5.C9A014AD350F1B62F57D924A60F88A29] - |A| - [23/10/2016 12:40:13] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\tem2727.tmp [MD5.8F5553D8C3BB70DDAD63AB426666C239] - |A| - [23/10/2016 13:02:58] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\tem47B0.tmp [MD5.7E3C6DF57760B211EDF72122CB1FD740] - |A| - [10/05/2017 00:24:35] - (.-.) - [256 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_9D39.tmp [MD5.96B22D51732BB7DDE15DFE0ED89F17E9] - |A| - [10/05/2017 00:24:35] - (.-.) - [192 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_9E15.tmp [MD5.F56D7F60467A3EA0942B471DEE49D6AF] - |A| - [10/05/2017 00:24:36] - (.-.) - [192 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_9F3E.tmp [MD5.5A36D2D84D1B5EFE998970C840D892D8] - |A| - [10/05/2017 00:18:03] - (.-.) - [192 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_A202.tmp [MD5.8179FEDDC3413211B0ED414AEF1E2E6B] - |A| - [10/05/2017 00:18:04] - (.-.) - [256 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_A5EB.tmp [MD5.2793107E5173F571A89C00C2AAA0FE2D] - |A| - [10/05/2017 00:18:05] - (.-.) - [192 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_A87D.tmp [MD5.3008E6165E2A3B2135BA4CEA2183A59C] - |A| - [02/11/2016 19:18:39] - (.-.) - [256 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_A909.tmp [MD5.6262D3EC8C47DA6EE427D24493A61A2E] - |A| - [02/11/2016 19:18:40] - (.-.) - [192 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_AB4C.tmp [MD5.9AE9156AF816E7A083620AF3DB9E6D33] - |A| - [02/11/2016 19:17:46] - (.-.) - [256 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_DC03.tmp [MD5.E5C8DAF7F2C429E7A378B0EFC089AA69] - |A| - [02/11/2016 19:17:47] - (.-.) - [128 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\TS_DDB9.tmp [MD5.00000000000000000000000000000000] - |D| - [18/02/2017 20:31:53] - [8.58 Ko] - C:\WINDOWS\Temp\VulkanRT [MD5.D78719B2ABFD8E13F601F4ED61A1A6B6] - |AT| - [10/05/2017 00:13:24] - (.-.) - [4976 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WAX4305.tmp [MD5.5F509BE2F2623409ACE725EEF4561007] - |A| - [18/02/2017 20:29:51] - (.-.) - [59.5 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WER676A.tmp.csv [MD5.548A29B2DFD2017FB9E62DBDAB449BA0] - |A| - [18/02/2017 20:29:51] - (.-.) - [12.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WER6807.tmp.txt [MD5.F1F9A7A0148ADF784560584E83385B40] - |A| - [18/02/2017 20:04:58] - (.-.) - [59.35 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WER9DFB.tmp.csv [MD5.E79E9CAC54F86A197DD2DA2A333B629B] - |A| - [18/02/2017 20:04:58] - (.-.) - [12.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WER9E2B.tmp.txt [MD5.A0AF80E6D4762E5EE35A08625090255A] - |A| - [07/12/2016 20:11:11] - (.-.) - [56.38 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WERDDB4.tmp.csv [MD5.C44451536FB11C6439EDEDA6B1699DDE] - |A| - [07/12/2016 20:11:11] - (.-.) - [12.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WERDEAF.tmp.txt [MD5.38AE6EAFDCB21CC626F02277EC9DDF50] - |A| - [12/03/2017 14:16:41] - (.-.) - [62.39 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WERE156.tmp.csv [MD5.3FFCF1CBA20A71002566BDA60CC080D3] - |A| - [12/03/2017 14:16:42] - (.-.) - [12.8 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WERE1E4.tmp.txt [MD5.E0E14BE851241A645488EE90C01FE587] - |A| - [23/10/2016 12:40:09] - (.-.) - [0.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\wmsetup.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [02/04/2017 07:51:26] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{08B3E7C8-C6FA-41D0-B625-5D39CAD56198} - OProcSessId.dat [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [10/05/2017 00:19:04] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{14B3806E-B6DE-4F8B-B30B-D0EF3DD98955} - OProcSessId.dat [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [12/04/2017 18:56:23] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{2874BDDB-D12A-48A6-B443-6B479796D053} - OProcSessId.dat [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [08/03/2017 23:02:43] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{425A36C4-542A-4CC9-855F-439BE5E0BE6C} - OProcSessId.dat [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [02/04/2017 07:50:50] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{7B03F795-E4B5-40E1-A039-8C5C0E3C96FF} - OProcSessId.dat [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [16/04/2017 10:56:48] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{7F2E7EA6-BE76-4353-9500-D54FBF5E37E5} - OProcSessId.dat [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [11/02/2017 21:08:42] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\{DA333DF4-2670-42D4-8113-442D3757C695} - OProcSessId.dat [MD5.00000000000000000000000000000000] - |D| - [08/02/2017 20:06:15] - [1130.72 Ko] - C:\WINDOWS\Temp\~un0690d054a [MD5.BC0F6124BD792AF86C4BDC83239E7BA2] - |A| - [31/08/2015 13:03:17] - (.-.) - [1.17 Ko] - (0.0.0.0) - C:\WINDOWS\System32\$Acer$.cmd [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:09] - [0 Ko] - C:\WINDOWS\System32\0409 [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [16/07/2016 13:42:35] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AudioToastIcon.png [MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |A| - [16/07/2016 13:42:05] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@BackgroundAccessToastIcon.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [16/07/2016 13:42:38] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@EnrollmentToastIcon.png [MD5.373CF57FF3DAAEEB629F90CE7226B30D] - |A| - [16/07/2016 13:42:41] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@language_notification_icon.png [MD5.46DACDA5036EBECEDF08427407E3017C] - |A| - [16/07/2016 13:42:40] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@optionalfeatures.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [16/07/2016 13:42:38] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@VpnToastIcon.png [MD5.7AC3EA1A5175106ED6467FF0C5315541] - |A| - [16/07/2016 13:42:38] - (.-.) - [14.75 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WiFiNotificationIcon.png [MD5.58B6CB6A8528BA1B267CFAE325E6B834] - |A| - [16/07/2016 13:42:23] - (.-.) - [20.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsHelloFaceToastIcon.png [MD5.F2CF417EF502555B139EDCD9FEBF9CD3] - |A| - [19/03/2016 15:07:40] - (.-.) - [107.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AcpiServiceVnA64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:29] - [3176.34 Ko] - C:\WINDOWS\System32\AdvancedInstallers [MD5.1E53DBCFBA49AB327BF00CC7E0759B6C] - |A| - [09/05/2017 15:13:51] - (.-.) - [437.78 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ApnDatabase.xml [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\AppLocker [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [2471.82 Ko] - C:\WINDOWS\System32\appraiser [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [272 Ko] - C:\WINDOWS\System32\ar-SA [MD5.8113D6E1884940FC3F9DED886B364A1E] - |A| - [19/03/2016 15:07:40] - (.-.) - [94.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\audioLibVc.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [247.5 Ko] - C:\WINDOWS\System32\bg-BG [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [4474.05 Ko] - C:\WINDOWS\System32\Boot [MD5.BC2D2E56F702422665853F409A9AB988] - |A| - [23/10/2016 10:35:11] - (.Qualcomm Atheros Communications Inc. - Qualcomm Atheros Bluetooth Driver Coinstaller.) - [194.53 Ko] - (1.0.0.0) - C:\WINDOWS\System32\btcoinst.dll [MD5.3B7D1F3F4E8C5374B8569D9F2A1D39CF] - |A| - [23/10/2016 10:35:11] - (.© Qualcomm Atheros, Inc. - Atheros Bluetooth Module.) - [195.53 Ko] - (8.0.1.302) - C:\WINDOWS\System32\BtContextMenu.dll [MD5.ACF278099C36903181E78DA91B044000] - |A| - [23/10/2016 10:35:11] - (.© Qualcomm Atheros, Inc. - Atheros Bluetooth Module.) - [28.03 Ko] - (8.0.1.302) - C:\WINDOWS\System32\BtContextMenu.dll.muien-US [MD5.31ABC8C02F1CCE0DA39550D763384184] - |A| - [16/07/2016 13:42:12] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [91.5 Ko] - (1.0.0.1) - C:\WINDOWS\System32\BthpanContextHandler.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0.93 Ko] - C:\WINDOWS\System32\Bthprops [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:24] - [137236.03 Ko] - C:\WINDOWS\System32\CatRoot [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [60540.39 Ko] - C:\WINDOWS\System32\catroot2 [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [2141.23 Ko] - C:\WINDOWS\System32\CodeIntegrity [MD5.64430E214B5B229D426D2D35538C402D] - |A| - [02/09/2015 11:46:04] - (.-.) - [366.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ColorImageEnhancement.wmv [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [360 Ko] - C:\WINDOWS\System32\Com [MD5.6E14F444A2506049EEC25CB5EDFE0905] - |A| - [19/03/2016 15:07:40] - (.2013 © Real Sound Lab SIA, iSoft Solutions - CONEQ™ Media Suite APO GUI Library.) - [110.91 Ko] - (1.0.0.4) - C:\WINDOWS\System32\CONEQMSAPOGUILibrary.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:24] - [457963.45 Ko] - C:\WINDOWS\System32\config [MD5.00000000000000000000000000000000] - |SD| - [16/07/2016 13:47:48] - [51.22 Ko] - C:\WINDOWS\System32\Configuration [MD5.82DF5576BDD96CE8DF5A06C0571EA463] - |A| - [02/09/2015 11:46:05] - (.-.) - [499.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\cp_resources.bin [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [292.5 Ko] - C:\WINDOWS\System32\cs-CZ [MD5.66E6010C31A70C8C5C2853AF597D853E] - |A| - [19/03/2016 15:07:40] - (.©Conexant Systems Inc. - Conexant APO.) - [1540.02 Ko] - (1.28.0.0) - C:\WINDOWS\System32\CX64APO.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [288.5 Ko] - C:\WINDOWS\System32\da-DK [MD5.00000000000000000000000000000000] - |D| - [23/10/2016 12:27:13] - [4219.34 Ko] - C:\WINDOWS\System32\DAX2 [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [177.63 Ko] - C:\WINDOWS\System32\DDFs [MD5.CAC823DDBB6E785DB76906BFCCFE55AF] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby Digital Plus API x86.) - [255.34 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPA64.dll [MD5.AEE27C741500BF38E93052DF736F5FAD] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby Digital Plus API x86.) - [291.77 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPA64F3.dll [MD5.018EFD4A9BF6FDA0F1AA3A6DE5712CD9] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1894.34 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPD64A.dll [MD5.F03945762D4F7DF6195095B538E5C6A2] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1888.27 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPD64AF3.dll [MD5.DE67ADEAC731C1ED3BD76527AB530BA5] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [308.34 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPO64A.dll [MD5.863B03900C286CDEB6B329CD6D0BB395] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [341.77 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPO64AF3.dll [MD5.C71D1DAFA22B5D3B71853783E5AA09D2] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6921.34 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPP64A.dll [MD5.FB1F9765499981384AA360E9D3B2A2AA] - |A| - [19/03/2016 15:07:41] - (.©2014 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6109.27 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPP64AF3.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [324.5 Ko] - C:\WINDOWS\System32\de-DE [MD5.306B90493D00011EB635E161C6C024B8] - |A| - [16/07/2016 13:42:22] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultHrtfs.bin [MD5.664AA698FC0106A2B075A641E8DC6302] - |A| - [16/07/2016 13:47:52] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultQuestions.json [MD5.74CBFD8DD24538D3E5E24305905841F1] - |A| - [10/07/2015 14:22:52] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DESKTOP-M7P1NB6_Administrator_HistoryPrediction.bin [MD5.00000000000000000000000000000000] - |SD| - [16/07/2016 13:47:48] - [642 Ko] - C:\WINDOWS\System32\DiagSvcs [MD5.8B5F7B8C2EFE38CA571FBE24658DF11F] - |A| - [16/07/2016 13:42:36] - (.-.) - [90.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DiskSnapshot.conf [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:27] - [7611.09 Ko] - C:\WINDOWS\System32\Dism [MD5.17FBCE91AEBA666E5BC2423C8EB34E8B] - |A| - [23/12/2016 10:30:30] - (.-.) - [812.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplayAudiox64.cab [MD5.1689D0E01CDD0DFF021ECF9D67CDD895] - |A| - [19/03/2016 15:07:41] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 APO Property Page.) - [922.84 Ko] - (0.4.0.19) - C:\WINDOWS\System32\DolbyDAX2APOProp.dll [MD5.E018154C2CD09511D39D65337A48A6FC] - |A| - [19/03/2016 15:07:41] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [2337.34 Ko] - (0.4.0.19) - C:\WINDOWS\System32\DolbyDAX2APOv201.dll [MD5.2D6527EA6B43700FFE4D5E869D0217CA] - |A| - [19/03/2016 15:07:41] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [2403.84 Ko] - (0.4.0.19) - C:\WINDOWS\System32\DolbyDAX2APOv211.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:27] - [1116.16 Ko] - C:\WINDOWS\System32\downlevel [MD5.60E6C68CB0B797EDD0386A68526935A4] - |A| - [02/09/2015 11:46:06] - (.-.) - [0.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DPTopologyApp.exe.config [MD5.899E708E589C09700BFF1C73CB7D7002] - |A| - [02/09/2015 11:46:06] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DPTopologyAppv2_0.exe.config [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:24] - [171457.08 Ko] - C:\WINDOWS\System32\drivers [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:24] - [17428555.01 Ko] - C:\WINDOWS\System32\DriverStore [MD5.00000000000000000000000000000000] - |SD| - [16/07/2016 13:47:48] - [158 Ko] - C:\WINDOWS\System32\dsc [MD5.8B5A737AD11EF45D9B1AEB4ED6884968] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Bass Enhancement COM DLL.) - [711.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBassEnhancementDLL64.dll [MD5.21B38D4D86A87909491F690883AE6D1E] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Boost COM DLL.) - [1452.1 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBoostDLL64.dll [MD5.FF31A2F57AAAB58DB78FCC961A58B206] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Gain Compensator COM DLL.) - [418.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSGainCompensatorDLL64.dll [MD5.BC0474E5476E5EA0D0E1AA5AC41E2061] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS GFX APO.) - [237.1 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPO64.dll [MD5.3B8FB5376F5431C0101747D5138BCB9B] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS GFX APO.) - [236.1 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPONS64.dll [MD5.B3977C8BA77559F4F8752AE8EB724C87] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS LFX APO.) - [237.1 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSLFXAPO64.dll [MD5.192A03A21636D3775CEE4C049C3BEB2A] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Limiter COM DLL.) - [422.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSLimiterDLL64.dll [MD5.2EF5442E8E7ED20F7634EEFB09640C8F] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS NEO:PC COM DLL.) - [479.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSNeoPCDLL64.dll [MD5.F7C357462077156DC211AC2112FC8C53] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Surround Sensation Headphone COM DLL.) - [1531.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2HeadphoneDLL64.dll [MD5.F132C08BD8C58579B400DFAA71F34CFB] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Surround Sensation Speaker COM DLL.) - [1715.1 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2SpeakerDLL64.dll [MD5.9948969B2C1987B1D64789EFEB284A84] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Symmetry COM DLL.) - [695.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSSymmetryDLL64.dll [MD5.37B8A8089ECED77F6CEAF74917C5D12B] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS GFX APO.) - [475.94 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PGFX64.dll [MD5.8AE860D92752CFA136979B1FF797FFDC] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS LFX APO.) - [489.44 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PLFX64.dll [MD5.A9B98F96FBE514ADEABD20B2BD132172] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS LFX APO.) - [405.94 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PREC64.dll [MD5.DE32448E6B40141C80DAABFF6FBE1744] - |A| - [19/03/2016 15:07:41] - (.(c) DTS. - DTS Voice Clarity COM DLL.) - [677.1 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSVoiceClarityDLL64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [320.5 Ko] - C:\WINDOWS\System32\el-GR [MD5.FBEF62AE9B715836FF48A64D54768608] - |A| - [23/10/2016 12:50:46] - (.-.) - [22.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\emptyregdb.dat [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:09] - [0 Ko] - C:\WINDOWS\System32\en [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [236 Ko] - C:\WINDOWS\System32\en-GB [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [2200.6 Ko] - C:\WINDOWS\System32\en-US [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [313.5 Ko] - C:\WINDOWS\System32\es-ES [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [257.5 Ko] - C:\WINDOWS\System32\es-MX [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [232 Ko] - C:\WINDOWS\System32\et-EE [MD5.00000000000000000000000000000000] - |SD| - [16/07/2016 13:47:48] - [25882.16 Ko] - C:\WINDOWS\System32\F12 [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [292.5 Ko] - C:\WINDOWS\System32\fi-FI [MD5.A08B87CC51FB774ED45FDF4284B1974F] - |A| - [02/09/2015 11:46:06] - (.-.) - [626.49 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FilmModeDetection.wmv [MD5.8DCDE3E4FDB0EC101B534B298984E648] - |A| - [23/10/2016 12:21:18] - (.-.) - [322.69 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FNTCACHE.DAT [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:09] - [3393.5 Ko] - C:\WINDOWS\System32\fr [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [264 Ko] - C:\WINDOWS\System32\fr-CA [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [44136.25 Ko] - C:\WINDOWS\System32\fr-FR [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\FxsTmp [MD5.D07F2281427BD098356EE74B6CB26B86] - |A| - [16/07/2016 13:42:12] - (.-.) - [89 Ko] - (0.0.0.0) - C:\WINDOWS\System32\gatherNetworkInfo.vbs [MD5.899E708E589C09700BFF1C73CB7D7002] - |A| - [02/09/2015 11:46:06] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Gfxv2_0.exe.config [MD5.60E6C68CB0B797EDD0386A68526935A4] - |A| - [02/09/2015 11:46:06] - (.-.) - [0.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Gfxv4_0.exe.config [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [18/02/2017 20:24:08] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GfxValDisplayLog.bin [MD5.00000000000000000000000000000000] - |HD| - [10/07/2015 13:04:22] - [0.22 Ko] - C:\WINDOWS\System32\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [10/07/2015 13:04:22] - [0 Ko] - C:\WINDOWS\System32\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [259.5 Ko] - C:\WINDOWS\System32\he-IL [MD5.7343F1A3B7BAC94625F2AD26887D80D2] - |A| - [19/03/2016 15:07:49] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 HiFi API.) - [341.34 Ko] - (0.4.0.21) - C:\WINDOWS\System32\HiFiDAX2API.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [241.5 Ko] - C:\WINDOWS\System32\hr-HR [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [296 Ko] - C:\WINDOWS\System32\hu-HU [MD5.2A571B7728F23E83A800527879105180] - |A| - [16/07/2016 13:42:04] - (.-.) - [44.17 Ko] - (0.0.0.0) - C:\WINDOWS\System32\hypervisor.mof [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [5.36 Ko] - C:\WINDOWS\System32\ias [MD5.B9178219A1B69431A12ED114B409E8C9] - |A| - [19/03/2016 15:07:49] - (.Copyright (c) 2015, ICEpower a/s - ICEpower ICEsound audio effects.) - [321.11 Ko] - (1.0.0.15) - C:\WINDOWS\System32\ICEsoundAPO64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [36.27 Ko] - C:\WINDOWS\System32\icsxml [MD5.AB2D50B6F3C665B55C8E5A049D59E7CC] - |A| - [23/12/2016 10:31:18] - (.-.) - [5663.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igdclbif.bin [MD5.1F651295257CF4C395ECBBF04AEC86E6] - |A| - [01/02/2017 02:03:58] - (.Copyright (C) 2012-2015 - MDF(CM) Runtime DX11 Dynamic Link Library.) - [188.79 Ko] - (5.0.0.1148) - C:\WINDOWS\System32\igfx11cmrt64.dll [MD5.9D0C950F2B1312E3EFEE15D222F2E439] - |A| - [01/02/2017 02:01:56] - (.Copyright (C) 2010 - 2015 - MDF(CM) JIT Dynamic Link Library.) - [1562.02 Ko] - (5.0.0.1148) - C:\WINDOWS\System32\igfxcmjit64.dll [MD5.CDA972E015B0FF5B01E1CBEAA5CD9213] - |A| - [01/02/2017 02:03:58] - (.Copyright (C) 2010 - 2015 - MDF(CM) Runtime Dynamic Link Library.) - [189.79 Ko] - (5.0.0.1148) - C:\WINDOWS\System32\igfxcmrt64.dll [MD5.A2188F09CFD6BD852C61BD3237ABCD40] - |A| - [01/02/2017 02:01:56] - (.-.) - [275.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igfxCPL.cpl [MD5.F6ED8FD2D1168CE7237F5E64C1FC29F7] - |A| - [01/02/2017 02:01:56] - (.-.) - [109.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igfxCUIServicePS.dll [MD5.5D905E0E3BEF7E30D55604E291213B6B] - |A| - [01/02/2017 02:01:56] - (.-.) - [91.02 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxDHLib.dll [MD5.ED692DE03EF0FE8426DCF749E5DDD690] - |A| - [01/02/2017 02:01:56] - (.-.) - [101.52 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxDHLibv2_0.dll [MD5.23530131EA9855E0B15B076F88A8FBBC] - |A| - [01/02/2017 02:01:56] - (.-.) - [37.02 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxDILib.dll [MD5.468279E6B6DA47285D1B797298DBF97B] - |A| - [01/02/2017 02:01:56] - (.-.) - [37.02 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxDILibv2_0.dll [MD5.FD586861046533DC37B7B745F0C51A3F] - |A| - [01/02/2017 02:01:56] - (.-.) - [35.52 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxEMLib.dll [MD5.238ED0503A169A1CE62D592FC31727C6] - |A| - [01/02/2017 02:01:56] - (.-.) - [35.52 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxEMLibv2_0.dll [MD5.F9D4B2E599FF8EBCFD78DE349F4E0646] - |A| - [01/02/2017 02:01:56] - (.-.) - [30.52 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxLHMLib.dll [MD5.C2ACC816D5862326654FC39E0F8B2298] - |A| - [01/02/2017 02:01:56] - (.-.) - [30.52 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxLHMLibv2_0.dll [MD5.0C90DDEE201AF9DABF9E6BA4D1F636F1] - |A| - [01/02/2017 02:01:56] - (.-.) - [1011.49 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igfxSDK.exe [MD5.79EBCD3D3AC1BA4EDF98888CB26E21DB] - |A| - [01/02/2017 02:01:56] - (.-.) - [107.02 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxSDKLib.dll [MD5.23C962A8A4A92E5664880F3FE2F4DE9B] - |A| - [01/02/2017 02:01:56] - (.-.) - [117.52 Ko] - (1.0.0.0) - C:\WINDOWS\System32\igfxSDKLibv2_0.dll [MD5.1F2F5410FBC616E700A9F9E3A8EF0FD3] - |A| - [02/09/2015 11:46:15] - (.-.) - [400.99 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igfxTray.exe [MD5.6C0F36ABFE80433B352FA7748ED887BF] - |A| - [02/09/2015 11:46:15] - (.-.) - [2748 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxa64.cpa [MD5.0D3AF85E1F169395885151038ADE9317] - |A| - [23/12/2016 10:31:56] - (.-.) - [1.1 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxa64.vp [MD5.A0D0A10C8DA1B00A2EE378357F72BA90] - |A| - [23/12/2016 10:31:56] - (.-.) - [39.37 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxc64.vp [MD5.7B929507BB2C2A3FBD2956EC3515364C] - |A| - [23/12/2016 10:31:56] - (.-.) - [40.33 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxc64_dev.vp [MD5.1A8302994182D4FC003A71DC6D23EE81] - |A| - [23/12/2016 10:31:56] - (.-.) - [38.73 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxg64.vp [MD5.38FA402460982FE9A071BEC11C58B0D3] - |A| - [23/12/2016 10:31:58] - (.-.) - [38.87 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxg64_dev.vp [MD5.26526A63D35D8E4E19C46F920AAF48F2] - |A| - [23/12/2016 10:31:58] - (.-.) - [39.4 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxo64.vp [MD5.9CD97189D5A5E409BBEC1B28A8AFD428] - |A| - [23/12/2016 10:31:58] - (.-.) - [39.97 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxo64_dev.vp [MD5.5685FB155F24B60E2D6D9031B459828E] - |A| - [23/12/2016 10:31:58] - (.-.) - [4.75 Ko] - (0.0.0.0) - C:\WINDOWS\System32\iglhxs64.vp [MD5.8898B09A8D08E138F238224648DF0739] - |A| - [16/07/2016 13:42:35] - (.-.) - [170.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\IHDS.dll [MD5.3ED204C864E5CC3C78D3DBB707D102D1] - |A| - [02/09/2015 11:46:16] - (.-.) - [394.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ImageStabilization.wmv [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [25924.17 Ko] - C:\WINDOWS\System32\IME [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\inetsrv [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [4803 Ko] - C:\WINDOWS\System32\InputMethod [MD5.070076E29E004FAC04A7EAD773561E33] - |A| - [01/02/2017 02:01:56] - (.Copyright (C) 2015 - IntelCpHDCPSvc Executable.) - [446.5 Ko] - (1.0.0.1) - C:\WINDOWS\System32\IntelCpHDCPSvc.exe [MD5.111F633A0DF9041337414DA0A45EF496] - |A| - [01/02/2017 02:01:58] - (.Copyright © The Khronos Group Inc 2014 - OpenCL Client DLL.) - [106.02 Ko] - (2.0.2.0) - C:\WINDOWS\System32\Intel_OpenCL_ICD64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\Ipmi [MD5.5EA855B4A875E08AD93FF901B5D9E275] - |A| - [16/07/2016 13:42:09] - (.-.) - [226 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ism32k.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [318.5 Ko] - C:\WINDOWS\System32\it-IT [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [231.5 Ko] - C:\WINDOWS\System32\ja-jp [MD5.6F7D1601DA55BBE5C7A79E01E236D7B9] - |A| - [19/03/2016 15:07:49] - (.© Knowles Electronics. - Knowles HD Audio APO.) - [589.83 Ko] - (4.1105.6000.53) - C:\WINDOWS\System32\KAAPORT64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [229 Ko] - C:\WINDOWS\System32\ko-KR [MD5.8E20CDF3907D570C4193E7C32662FCD4] - |A| - [22/08/2016 23:45:43] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LAPTOP-O5ULGE56_defaultuser0_HistoryPrediction.bin [MD5.050BC9351A3386458B696F8BCA78B27B] - |A| - [16/07/2016 13:42:22] - (.-.) - [145.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LargeRoom.bin [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [73.41 Ko] - C:\WINDOWS\System32\Licenses [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [8596 Ko] - C:\WINDOWS\System32\LogFiles [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [237 Ko] - C:\WINDOWS\System32\lt-LT [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [238.5 Ko] - C:\WINDOWS\System32\lv-LV [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [29887.32 Ko] - C:\WINDOWS\System32\Macromed [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [32.68 Ko] - C:\WINDOWS\System32\MailContactsCalendarSync [MD5.75616F8DB5C092A8A50AFEC273859DD7] - |A| - [19/03/2016 15:07:49] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [311.34 Ko] - (2.2.9.0) - C:\WINDOWS\System32\MaxxAudioAPO20.dll [MD5.06080807E61471A18AD99F3E6FF3C9B5] - |A| - [19/03/2016 15:07:49] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [647.75 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxAudioAPO30.dll [MD5.A0DEEB5F93530A3C67E913F2EAE7AF7C] - |A| - [19/03/2016 15:07:49] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1118.42 Ko] - (4.5.8.0) - C:\WINDOWS\System32\MaxxAudioAPO4064.dll [MD5.7C0186E421B1B5FC5824837D5078B4C1] - |A| - [19/03/2016 15:07:49] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1164.42 Ko] - (5.6.5.0) - C:\WINDOWS\System32\MaxxAudioAPO5064.dll [MD5.06059CB3AACCBDA5865EFD9922832F82] - |A| - [19/03/2016 15:07:49] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1342.42 Ko] - (6.1.12.0) - C:\WINDOWS\System32\MaxxAudioAPO6064.dll [MD5.CD2A9C650A6441544E4E4EB0B6F7C16E] - |A| - [19/03/2016 15:07:49] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [2724.42 Ko] - (7.0.10.0) - C:\WINDOWS\System32\MaxxAudioAPO7064.dll [MD5.71947A1775D4CBD9CBE580C6E97FF78E] - |A| - [19/03/2016 15:07:49] - (.Copyright (C) 2010-2013 - MaxxAudio APO Shell.) - [901.25 Ko] - (4.10.8.0) - C:\WINDOWS\System32\MaxxAudioAPOShell64.dll [MD5.E93ADE8C38CA41442FE60E844DED92AC] - |A| - [19/03/2016 15:07:49] - (.Copyright © 1996-2014 -.) - [1993.59 Ko] - (4.1.1.0) - C:\WINDOWS\System32\MaxxAudioEQ64.dll [MD5.CB56F27AFF28FB9576C6FC79E6D14036] - |A| - [19/03/2016 15:07:49] - (.Copyright © 1996-2013 -.) - [13719.25 Ko] - (4.4.10.0) - C:\WINDOWS\System32\MaxxAudioRealtek64.dll [MD5.581778867AEB80C4366057B3DE1DC4D0] - |A| - [19/03/2016 15:07:50] - (.© Waves Audio Ltd. - MaxxSpeech APO.) - [1283.11 Ko] - (1.1.4.0) - C:\WINDOWS\System32\MaxxSpeechAPO64.dll [MD5.4209912F4FC493FCB0816771448F9E8E] - |A| - [19/03/2016 15:07:50] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [957.42 Ko] - (2.6.2.0) - C:\WINDOWS\System32\MaxxVoiceAPO2064.dll [MD5.DF3632EDBC612F4112F6FEDB024F6118] - |A| - [19/03/2016 15:07:51] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [12691.92 Ko] - (3.1.13.0) - C:\WINDOWS\System32\MaxxVoiceAPO3064.dll [MD5.6C100BAE708BD61F65932087D9A69ECA] - |A| - [19/03/2016 15:07:52] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [12533.92 Ko] - (4.0.8.0) - C:\WINDOWS\System32\MaxxVoiceAPO4064.dll [MD5.587A8CF457604D84266FF858CEB60223] - |A| - [19/03/2016 15:07:52] - (.© Waves Audio Ltd. - MaxxVolumeSD APO.) - [647.25 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxVolumeSDAPO.dll [MD5.BC74BDA8DC53F722C2CA686071600AE2] - |A| - [16/07/2016 13:42:22] - (.-.) - [107.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediumRoom.bin [MD5.43DB4E36146D076EBD7B864162C8C242] - |A| - [31/08/2015 12:52:29] - (.Copyright© 1995-2017 McAfee, Inc. - McAfee Process Validation Service.) - [335.73 Ko] - (15.6.0.1220) - C:\WINDOWS\System32\mfevtps.exe [MD5.00000000000000000000000000000000] - |D| - [23/10/2016 12:58:20] - [1113.19 Ko] - C:\WINDOWS\System32\Microsoft [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [5313.62 Ko] - C:\WINDOWS\System32\migration [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [47559.48 Ko] - C:\WINDOWS\System32\migwiz [MD5.52D09193B954697371DFA7BE9E520D05] - |A| - [19/03/2016 15:07:53] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [5112.26 Ko] - (6.3.9600.17231) - C:\WINDOWS\System32\NAHIMICAPOlfx.dll [MD5.4E5442D9B14EF9EF679CD8D65CD50A51] - |A| - [19/03/2016 15:07:53] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO Settings Communication Dll.) - [971.8 Ko] - (1.0.0.14866) - C:\WINDOWS\System32\NahimicAPONSControl.dll [MD5.024A8951D4E8710379CD16656F4F8FA1] - |A| - [19/03/2016 15:07:53] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [5580.94 Ko] - (6.3.9600.17336) - C:\WINDOWS\System32\NAHIMICV2apo.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [283.5 Ko] - C:\WINDOWS\System32\nb-NO [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\NDF [MD5.9649C73A57FC0AAEE9FAE5F1719EB0C2] - |A| - [23/10/2016 12:21:41] - (.-.) - [25.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetSetupMig.log [MD5.C146E873B22C3B300B21A859FE66C27A] - |A| - [16/07/2016 13:42:12] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetTrace.PLA.Diagnostics.xml [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [51 Ko] - C:\WINDOWS\System32\networklist [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [303.5 Ko] - C:\WINDOWS\System32\nl-NL [MD5.00000000000000000000000000000000] - |SD| - [16/07/2016 13:47:48] - [16570.66 Ko] - C:\WINDOWS\System32\Nui [MD5.B71AD74A91E472CC8B283B8A7D2C9677] - |A| - [17/01/2017 01:59:06] - (.-.) - [0.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nv-vk64.json [MD5.4240979A448272046F79876A36C1EA7A] - |A| - [23/10/2016 12:26:38] - (.-.) - [7471.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvcoproc.bin [MD5.1A5E7C21DFEBB78C10001758A7B7E2D1] - |A| - [23/10/2016 10:35:48] - (.-.) - [41.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvinfo.pb [MD5.F54598052A618ADC0231853D870A22BE] - |A| - [16/07/2016 13:47:53] - (.-.) - [15.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OEMDefaultAssociations.xml [MD5.2901049544FDF863362FABA2363EB647] - |A| - [16/07/2016 13:42:11] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\onlinesetup.cmd [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [36683.12 Ko] - C:\WINDOWS\System32\oobe [MD5.42D2360079B1DF3230024AE920737367] - |A| - [16/07/2016 13:42:22] - (.-.) - [45.81 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OutdoorAudioEnvironment.bin [MD5.C9DF2DD8F2A30F7CB324A577A30044F1] - |A| - [16/07/2016 13:49:31] - (.-.) - [186.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc009.dat [MD5.28FB5A2C88C20BEEC0777781F4E9BA9C] - |A| - [17/07/2016 00:40:24] - (.-.) - [133.99 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc00C.dat [MD5.32BC2E0CC95E2DCEE25B15BFB82D07B8] - |A| - [16/07/2016 13:49:35] - (.-.) - [32.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd009.dat [MD5.AA180E09E4990FF71FBEAC8C4455CF47] - |A| - [17/07/2016 00:40:24] - (.-.) - [39.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd00C.dat [MD5.F2697D32BA4914C2F61B2ECA836AB0BE] - |A| - [16/07/2016 13:49:31] - (.-.) - [770.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh009.dat [MD5.DF4EC015CFC66A428B8DDFDBE6CB5660] - |A| - [17/07/2016 00:40:24] - (.-.) - [693.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh00C.dat [MD5.DB2A0E04CF1048FD34A6CEE9E60CE3C5] - |A| - [31/08/2015 13:01:26] - (.-.) - [1782.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PerfStringBackup.INI [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [301.5 Ko] - C:\WINDOWS\System32\pl-PL [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [560 Ko] - C:\WINDOWS\System32\PointOfService [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:10] - [420.42 Ko] - C:\WINDOWS\System32\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\ProximityToast [MD5.007893E8374C766471239EB291BA8C17] - |A| - [16/07/2016 13:42:31] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\psmodulediscoveryprovider.mof [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [303.5 Ko] - C:\WINDOWS\System32\pt-BR [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [299 Ko] - C:\WINDOWS\System32\pt-PT [MD5.8882AD10853E45402CABD3BAF48A7EFC] - |A| - [19/03/2016 15:07:53] - (.©2012 Dolby Laboratories. - Dolby PCEE4 ASL Analog x64.) - [121.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEA64A.dll [MD5.0B5EF50E26CFD1E7BF01E32E053532B2] - |A| - [19/03/2016 15:07:53] - (.©2012 Dolby Laboratories. - Dolby PCEE4 COM DLL x64.) - [424.77 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EED64A.dll [MD5.01096663377134C41D618AF0E53A953E] - |A| - [19/03/2016 15:07:53] - (.©2012 Dolby Laboratories. - Dolby PCEE4 GFX APO x64.) - [73.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEG64A.dll [MD5.D0EB28022A91A5C084E8A7DEBB08D8D2] - |A| - [19/03/2016 15:07:53] - (.©2012 Dolby Laboratories. - Dolby PCEE4 LFX APO x64.) - [138.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEL64A.dll [MD5.03625A179B27362D3A90E3331AEBE95E] - |A| - [19/03/2016 15:07:53] - (.©2012 Dolby Laboratories. - Dolby PCEE4 Control Panel x64.) - [6996.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEP64A.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [23.75 Ko] - C:\WINDOWS\System32\ras [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\System32\RasToast [MD5.692DC6EF573FFCDD9DFB55D1C783DB93] - |A| - [16/07/2016 13:42:04] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\removehypervisor.mof [MD5.D67CDB8D2584AAC165A77488C5A7A987] - |A| - [16/07/2016 13:42:37] - (.-.) - [8.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageList [MD5.4FE9CE56EFA89779D81B988698D2454C] - |A| - [16/07/2016 13:42:37] - (.-.) - [8.4 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageList [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0.07 Ko] - C:\WINDOWS\System32\restore [MD5.24DDE1C164F3599482BD5667E5DB1E7F] - |A| - [19/03/2016 18:24:13] - (.-.) - [16.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\results.xml [MD5.E9D4A333DF15D06C68AC4BFB9B6581CB] - |A| - [19/03/2016 15:07:55] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x64.) - [302.84 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DAA64.dll [MD5.B6FE01558CC03F3866C9AD0ED19261D8] - |A| - [19/03/2016 15:07:55] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x64.) - [302.84 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DHT64.dll [MD5.C6CBDD0B6C2FF72A2F4E6467423B38ED] - |A| - [22/08/2016 23:46:19] - (.Copyright (C) 2014 - RtCRX.) - [89.75 Ko] - (1.11.9600.0) - C:\WINDOWS\System32\RtCRX64.dll [MD5.A6286A6C7A1BBFCBA17AA54384A21D1C] - |A| - [19/03/2016 15:07:58] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x64.) - [199.34 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEED64A.dll [MD5.6F4CD493196100EEF349D7132CECAFD9] - |A| - [19/03/2016 15:07:58] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x64.) - [76.84 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEG64A.dll [MD5.ECAEC5FBBBEF8612AF0A866AFA5F7EF2] - |A| - [19/03/2016 15:07:58] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x64.) - [98.84 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEL64A.dll [MD5.D0D0D82B7366E691275E433CD34F89B2] - |A| - [19/03/2016 15:07:58] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x64.) - [366.34 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEP64A.dll [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [16/07/2016 13:43:50] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScavengeSpace.xml [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |A| - [16/07/2016 13:42:34] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\settings.dat [MD5.17ABCAD44A75C635583A238ED6333357] - |A| - [19/03/2016 15:07:59] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFAPO.DLL.) - [76.84 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFAPO64.dll [MD5.2C25AF115BDDC05D9A84D26227A08E63] - |A| - [19/03/2016 15:07:59] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFCOM.DLL.) - [79.34 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFCOM64.dll [MD5.7B3E9344FB43D799C6462227A0E65877] - |A| - [19/03/2016 15:07:59] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFNHK.DLL.) - [215.84 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFNHK64.dll [MD5.DBB99601D716F92CDD97CE4E60865319] - |A| - [19/03/2016 15:07:59] - (.Copyright (C) 2013 DTS, Inc. - DTS Studio Sound.) - [921.66 Ko] - (3.1.38.0) - C:\WINDOWS\System32\sl3apo64.dll [MD5.6F8B108E8B57AC88F90D6EA13B2A1755] - |A| - [19/03/2016 15:08:00] - (.Copyright (C) 2011 SRS Labs, Inc. - SRS Labs.) - [1078.16 Ko] - (3.1.38.0) - C:\WINDOWS\System32\slcnt64.dll [MD5.00000000000000000000000000000000] - |D| - [23/10/2016 12:21:35] - [7778.02 Ko] - C:\WINDOWS\System32\SleepStudy [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:10] - [52.14 Ko] - C:\WINDOWS\System32\slmgr [MD5.2E4C258CB2FF3D249FD0ABBCABC664A1] - |A| - [19/03/2016 15:08:00] - (.TODO: (c) . - TODO: .) - [244.66 Ko] - (1.0.0.1) - C:\WINDOWS\System32\slprp64.dll [MD5.EC05C33DF2CF20D839FE3650505ED6ED] - |A| - [19/03/2016 15:08:01] - (.Copyright (C) 2013 DTS, Inc. - DTS Studio Sound.) - [717.16 Ko] - (3.1.38.0) - C:\WINDOWS\System32\sltech64.dll [MD5.1C6F12AA3D178A0A953E8005B3CD4CDE] - |A| - [16/07/2016 13:42:22] - (.-.) - [68.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SmallRoom.bin [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:24] - [13385.02 Ko] - C:\WINDOWS\System32\SMI [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [7600.34 Ko] - C:\WINDOWS\System32\Speech [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [7900.14 Ko] - C:\WINDOWS\System32\Speech_OneCore [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [73646.63 Ko] - C:\WINDOWS\System32\spool [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [12232.58 Ko] - C:\WINDOWS\System32\spp [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [31.88 Ko] - C:\WINDOWS\System32\sppui [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [243.5 Ko] - C:\WINDOWS\System32\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [244 Ko] - C:\WINDOWS\System32\sr-Latn-RS [MD5.A5F6491F71A0DAF25140CA915600AB37] - |A| - [19/03/2016 15:08:01] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRAPO.DLL.) - [443.64 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRAPO64.dll [MD5.48435D12B45AB1F954CB579D1EA15D52] - |A| - [19/03/2016 15:08:01] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [321.64 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM.dll [MD5.18F4327F7A659F4B1017C0E4C03EB50B] - |A| - [19/03/2016 15:08:01] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [360.64 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM64.dll [MD5.C1AA14DBA23EB5AE5044727DF182FE5C] - |A| - [16/07/2016 13:42:16] - (.-.) - [54.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms.dat [MD5.D47D28D2AD44318805CF5EF15665D570] - |A| - [19/03/2016 15:08:01] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRRPTR.DLL.) - [1380.64 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRRPTR64.dll [MD5.A88BE9A6C4E646A2B2A1BD3A7F4B58E7] - |A| - [19/03/2016 15:08:01] - (.(c) 2007 SRS Labs, Inc. - COM object implementing SRS Headphone 360.) - [194.23 Ko] - (1.1.0.0) - C:\WINDOWS\System32\SRSHP64.dll [MD5.A028717B791416182959B325D5B40679] - |A| - [19/03/2016 15:08:01] - (.Copyright (c) 2006 SRS Labs, Inc.. - TruSurround HD and HD4 COM object for Windows.) - [206.23 Ko] - (1.1.4.0) - C:\WINDOWS\System32\SRSTSH64.dll [MD5.018D3D2478754AA411DE6DA6DE5F8F21] - |A| - [19/03/2016 15:08:01] - (.Copyright 2002 SRS Labs, Inc. - TruSurroundXT Module.) - [506.73 Ko] - (3.2.0.0) - C:\WINDOWS\System32\SRSTSX64.dll [MD5.2FCADCC14F8E540F6ADE4BF92BD8AEDD] - |A| - [19/03/2016 15:08:01] - (.(c) 2006 SRS Labs, Inc. - WOW HD COM object for Windows.) - [152.23 Ko] - (1.1.3.0) - C:\WINDOWS\System32\SRSWOW64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [3736 Ko] - C:\WINDOWS\System32\sru [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [289 Ko] - C:\WINDOWS\System32\sv-SE [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:27] - [1623.07 Ko] - C:\WINDOWS\System32\Sysprep [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [913.28 Ko] - C:\WINDOWS\System32\SystemResetPlatform [MD5.D602CA245CC6774A0981B607F0675609] - |A| - [16/07/2016 13:42:39] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\tcpmon.ini [MD5.C8F2952DAE3971614DBD0C509F35BE93] - |A| - [16/07/2016 13:42:38] - (.-.) - [10.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlan.xslt [MD5.2F05390B798363D51EBE65D6320CD45E] - |A| - [16/07/2016 13:42:38] - (.-.) - [1.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlanCredentials.xslt [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [240 Ko] - C:\WINDOWS\System32\uk-UA [MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:00:57] - [2199.72 Ko] - C:\WINDOWS\System32\UNP [MD5.E7482D1D449217C8641762F5C38E157C] - |A| - [16/07/2016 13:42:12] - (.-.) - [9.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\VpnSohDesktop.dll [MD5.8140DA331F52518CC5FF25E69093BC5C] - |A| - [09/09/2016 20:25:10] - (.Copyright (C) 2015-2016 - Vulkan Loader.) - [255.78 Ko] - (1.0.26.0) - C:\WINDOWS\System32\vulkan-1-1-0-26-0.dll [MD5.8140DA331F52518CC5FF25E69093BC5C] - |A| - [18/02/2017 20:31:54] - (.Copyright (C) 2015-2016 - Vulkan Loader.) - [255.78 Ko] - (1.0.26.0) - C:\WINDOWS\System32\vulkan-1.dll [MD5.61DA784EB8C8E133EB3BB4AFBDD66758] - |A| - [09/09/2016 20:24:38] - (.-.) - [122.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo-1-1-0-26-0.exe [MD5.61DA784EB8C8E133EB3BB4AFBDD66758] - |A| - [18/02/2017 20:31:54] - (.-.) - [122.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo.exe [MD5.D5DBBF94106B931112FBFB19A1351506] - |A| - [19/03/2016 15:08:01] - (.Copyright © 1996-2012 - General Library for Plug-Ins.) - [2052.59 Ko] - (4.4.5.0) - C:\WINDOWS\System32\WavesGUILib64.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [82433.32 Ko] - C:\WINDOWS\System32\wbem [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:10] - [0 Ko] - C:\WINDOWS\System32\WCN [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [49598.74 Ko] - C:\WINDOWS\System32\WDI [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [16/07/2016 13:42:11] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WdsUnattendTemplate.xml [MD5.00000000000000000000000000000000] - |D| - [10/07/2015 13:04:22] - [0 Ko] - C:\WINDOWS\System32\wfp [MD5.87F77EC6D7A723A04B6E8C7D47ADBD76] - |A| - [31/08/2015 13:04:53] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WIN-F1LA66P8QOU_Administrator_HistoryPrediction.bin [MD5.F4B0F9FCD51B75A661143109A3C00B09] - |A| - [19/03/2016 19:37:16] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WIN-VH5LQVV0254_Administrator_HistoryPrediction.bin [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [1.1 Ko] - C:\WINDOWS\System32\WinBioDatabase [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [42585.77 Ko] - C:\WINDOWS\System32\WinBioPlugIns [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [8369.08 Ko] - C:\WINDOWS\System32\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [107876 Ko] - C:\WINDOWS\System32\winevt [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [4228.5 Ko] - C:\WINDOWS\System32\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:11] - [107.53 Ko] - C:\WINDOWS\System32\winrm [MD5.C30C621748C66CE751B19B2788559A3E] - |A| - [16/07/2016 13:42:35] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcmon.png [MD5.B6B479B04C64AF5EF36C24EBDF278302] - |A| - [16/07/2016 13:42:27] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpr.config.xml [MD5.5C5A797761421CF9B72087F3BC8A5259] - |A| - [23/10/2016 12:25:41] - (.-.) - [0.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat [MD5.1373F6562D5E4C715D5D3583E350093E] - |A| - [23/10/2016 12:25:41] - (.-.) - [0.2 Ko] - (0.0.0.0) - C:\WINDOWS\System32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:11] - [0 Ko] - C:\WINDOWS\SysWOW64\0409 [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [16/07/2016 13:43:00] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AudioToastIcon.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [16/07/2016 13:43:02] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@EnrollmentToastIcon.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [16/07/2016 13:43:02] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@VpnToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 08:04:30] - [2141.84 Ko] - C:\WINDOWS\SysWOW64\AdvancedInstallers [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\AppLocker [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [250 Ko] - C:\WINDOWS\SysWOW64\ar-SA [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [222 Ko] - C:\WINDOWS\SysWOW64\bg-BG [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0.93 Ko] - C:\WINDOWS\SysWOW64\Bthprops [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [318 Ko] - C:\WINDOWS\SysWOW64\Com [MD5.8E976055354596B1BE8453DB4C8CA02C] - |A| - [19/03/2016 18:25:36] - (.-.) - [37.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\Gms.log [MD5.49B046546085BBB9461DBA8264ADD42C] - |A| - [26/08/2015 23:04:58] - (.© 2004-2011 Google Inc. - Google Photos Screensaver.) - [4480 Ko] - (3.9.140.248) - C:\WINDOWS\SysWOW64\GPhotos.scr [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0.01 Ko] - C:\WINDOWS\SysWOW64\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [238.5 Ko] - C:\WINDOWS\SysWOW64\he-IL [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [217 Ko] - C:\WINDOWS\SysWOW64\hr-HR [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [270.5 Ko] - C:\WINDOWS\SysWOW64\hu-HU [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [36.27 Ko] - C:\WINDOWS\SysWOW64\icsxml [MD5.113B57560B391BB8B2B14E949E51E15A] - |A| - [01/02/2017 02:01:56] - (.Copyright © The Khronos Group Inc 2014 - OpenCL Client DLL.) - [110.02 Ko] - (2.0.2.0) - C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\Ipmi [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [293 Ko] - C:\WINDOWS\SysWOW64\it-IT [MD5.9EA3CD2CB18622637DD032743D7750C9] - |A| - [17/01/2017 01:59:06] - (.-.) - [0.65 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\nv-vk32.json [MD5.48435D12B45AB1F954CB579D1EA15D52] - |A| - [19/03/2016 15:08:01] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [321.64 Ko] - (4.0.0.59) - C:\WINDOWS\SysWOW64\SRCOM.dll [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\sru [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [265.5 Ko] - C:\WINDOWS\SysWOW64\sv-SE [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:11] - [0 Ko] - C:\WINDOWS\SysWOW64\sysprep [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\Tasks [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [205 Ko] - C:\WINDOWS\SysWOW64\th-TH [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [261.5 Ko] - C:\WINDOWS\SysWOW64\tr-TR [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [215.5 Ko] - C:\WINDOWS\SysWOW64\uk-UA [MD5.2F28B023406F83D17ACE4294E2510F44] - |A| - [09/09/2016 20:25:58] - (.Copyright (C) 2015-2016 - Vulkan Loader.) - [263.28 Ko] - (1.0.26.0) - C:\WINDOWS\SysWOW64\vulkan-1-1-0-26-0.dll [MD5.2F28B023406F83D17ACE4294E2510F44] - |A| - [18/02/2017 20:31:54] - (.Copyright (C) 2015-2016 - Vulkan Loader.) - [263.28 Ko] - (1.0.26.0) - C:\WINDOWS\SysWOW64\vulkan-1.dll [MD5.6448CF3F64B96B8C72A9D5905F7C07B0] - |A| - [09/09/2016 20:25:28] - (.-.) - [108.28 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-26-0.exe [MD5.6448CF3F64B96B8C72A9D5905F7C07B0] - |A| - [18/02/2017 20:31:54] - (.-.) - [108.28 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [15540.58 Ko] - C:\WINDOWS\SysWOW64\wbem [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:11] - [0 Ko] - C:\WINDOWS\SysWOW64\WCN [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [7726.32 Ko] - C:\WINDOWS\SysWOW64\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [4228.5 Ko] - C:\WINDOWS\SysWOW64\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [17/07/2016 00:40:11] - [107.53 Ko] - C:\WINDOWS\SysWOW64\winrm [MD5.00000000000000000000000000000000] - |D| - [23/10/2016 12:54:18] - [10.16 Ko] - C:\WINDOWS\SysWOW64\XPSViewer [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [190.5 Ko] - C:\WINDOWS\SysWOW64\zh-CN [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [185 Ko] - C:\WINDOWS\SysWOW64\zh-HK [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 13:47:48] - [185 Ko] - C:\WINDOWS\SysWOW64\zh-TW ---------- | Shell Folders [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "!Do not use this registry key"=Use the SHGetFolderPath or SHGetKnownFolderPath function instead "AppData"=C:\Users\Emmanuelle\AppData\Roaming [23/10/2016 12:32:49] "Local AppData"=C:\Users\Emmanuelle\AppData\Local [23/10/2016 12:32:49] "{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Libraries [22/08/2016 23:46:22] "My Video"=C:\Users\Emmanuelle\Videos [22/08/2016 23:45:46] "My Pictures"=C:\Users\Emmanuelle\Pictures [22/08/2016 23:45:46] "Desktop"=C:\Users\Emmanuelle\Desktop [22/08/2016 23:45:46] "History"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\History [22/08/2016 23:45:46] "NetHood"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Network Shortcuts [23/10/2016 12:32:49] "{56784854-C6CB-462B-8169-88E350ACB882}"=C:\Users\Emmanuelle\Contacts [22/08/2016 23:46:23] "{00BCFC5A-ED94-4E48-96A1-3F6217F21990}"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\RoamingTiles [22/08/2016 23:46:23] "Cookies"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\INetCookies [22/08/2016 23:45:46] "Favorites"=C:\Users\Emmanuelle\Favorites [22/08/2016 23:45:46] "SendTo"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\SendTo [23/10/2016 12:32:49] "Start Menu"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu [23/10/2016 12:32:49] "My Music"=C:\Users\Emmanuelle\Music [22/08/2016 23:45:46] "Programs"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [23/10/2016 12:32:49] "Recent"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Recent [22/08/2016 23:45:46] "CD Burning"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\Burn\Burn [23/10/2016 13:10:26] "PrintHood"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Printer Shortcuts [23/10/2016 12:32:49] "{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}"=C:\Users\Emmanuelle\Searches [22/08/2016 23:46:24] "{374DE290-123F-4565-9164-39C4925E467B}"=C:\Users\Emmanuelle\Downloads [22/08/2016 23:45:46] "{A520A1A4-1780-4FF6-BD18-167343C5AF16}"=C:\Users\Emmanuelle\AppData\LocalLow [22/08/2016 23:46:00] "Startup"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [22/08/2016 23:46:24] "Administrative Tools"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [22/08/2016 23:46:24] "Personal"=C:\Users\Emmanuelle\Documents [22/08/2016 23:45:46] "{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}"=C:\Users\Emmanuelle\Links [22/08/2016 23:45:46] "Cache"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\INetCache [23/10/2016 12:32:49] "Templates"=C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Templates [23/10/2016 12:32:49] "{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}"=C:\Users\Emmanuelle\Saved Games [22/08/2016 23:45:46] "Fonts"=C:\WINDOWS\Fonts [16/07/2016 13:47:48] [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "AppData"=%USERPROFILE%\AppData\Roaming "Desktop"=%USERPROFILE%\Desktop "Favorites"=%USERPROFILE%\Favorites "History"=%USERPROFILE%\AppData\Local\Microsoft\Windows\History "Local AppData"=%USERPROFILE%\AppData\Local "My Music"=%USERPROFILE%\Music "My Pictures"=%USERPROFILE%\Pictures "My Video"=%USERPROFILE%\Videos "NetHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts "Personal"=%USERPROFILE%\Documents "PrintHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts "Programs"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs "Recent"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent "SendTo"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo "Start Menu"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu "Startup"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup "Templates"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates "{374DE290-123F-4565-9164-39C4925E467B}"=%USERPROFILE%\Downloads "Cache"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\INetCache [23/10/2016 12:32:49] "Cookies"=C:\Users\Emmanuelle\AppData\Local\Microsoft\Windows\INetCookies [22/08/2016 23:45:46] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [16/07/2016 13:47:48] "Common AppData"=C:\ProgramData [16/07/2016 13:47:48] "Common Desktop"=C:\Users\Public\Desktop [10/07/2015 13:04:22] "Common Documents"=C:\Users\Public\Documents [10/07/2015 13:04:22] "Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [16/07/2016 13:47:48] "Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [16/07/2016 13:47:48] "Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [16/07/2016 13:47:48] "Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [10/07/2015 13:04:22] "CommonMusic"=C:\Users\Public\Music [10/07/2015 13:04:22] "CommonPictures"=C:\Users\Public\Pictures [10/07/2015 13:04:22] "CommonVideo"=C:\Users\Public\Videos [10/07/2015 13:04:22] "OEM Links"=C:\ProgramData\OEM\Links [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "Common AppData"=%ProgramData% "Common Desktop"=%PUBLIC%\Desktop "Common Documents"=%PUBLIC%\Documents "Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs "Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu "Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup "Common Templates"=%ProgramData%\Microsoft\Windows\Templates "CommonMusic"=%PUBLIC%\Music "CommonPictures"=%PUBLIC%\Pictures "CommonVideo"=%PUBLIC%\Videos "{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [16/07/2016 13:47:48] "Common AppData"=C:\ProgramData [16/07/2016 13:47:48] "Common Desktop"=C:\Users\Public\Desktop [10/07/2015 13:04:22] "Common Documents"=C:\Users\Public\Documents [10/07/2015 13:04:22] "Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [16/07/2016 13:47:48] "Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [16/07/2016 13:47:48] "Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [16/07/2016 13:47:48] "Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [10/07/2015 13:04:22] "CommonMusic"=C:\Users\Public\Music [10/07/2015 13:04:22] "CommonPictures"=C:\Users\Public\Pictures [10/07/2015 13:04:22] "CommonVideo"=C:\Users\Public\Videos [10/07/2015 13:04:22] "OEM Links"=C:\ProgramData\OEM\Links [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "Common AppData"=%ProgramData% "Common Desktop"=%PUBLIC%\Desktop "Common Documents"=%PUBLIC%\Documents "Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs "Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu "Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup "Common Templates"=%ProgramData%\Microsoft\Windows\Templates "CommonMusic"=%PUBLIC%\Music "CommonPictures"=%PUBLIC%\Pictures "CommonVideo"=%PUBLIC%\Videos "{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads ---------- | [Emmanuelle] [23/10/2016 12:32:49] - |D| - [5955077927] - C:\Users\Emmanuelle\AppData\Local [22/08/2016 23:46:00] - |D| - [535084] - C:\Users\Emmanuelle\AppData\LocalLow [23/10/2016 12:32:49] - |D| - [678243376] - C:\Users\Emmanuelle\AppData\Roaming [22/08/2016 23:48:03] - |D| - [1859545] - C:\Users\Emmanuelle\AppData\Local\AOP SDK [23/10/2016 12:32:49] - |SHD| - [62906158161] - C:\Users\Emmanuelle\AppData\Local\Application Data [22/08/2016 23:49:09] - |D| - [6485] - C:\Users\Emmanuelle\AppData\Local\CareCenter [25/08/2017 21:59:27] - |D| - [0] - C:\Users\Emmanuelle\AppData\Local\CEF [29/01/2017 18:15:01] - |D| - [332635449] - C:\Users\Emmanuelle\AppData\Local\chromium [22/08/2016 23:50:31] - |D| - [243334009] - C:\Users\Emmanuelle\AppData\Local\clear.fi [23/08/2016 07:28:05] - |D| - [20996120] - C:\Users\Emmanuelle\AppData\Local\Comms [23/10/2016 13:04:39] - |D| - [1979228] - C:\Users\Emmanuelle\AppData\Local\ConnectedDevicesPlatform [31/08/2016 10:15:20] - |D| - [37797974] - C:\Users\Emmanuelle\AppData\Local\CrashDumps [26/10/2016 09:02:15] - |D| - [123664] - C:\Users\Emmanuelle\AppData\Local\CyberLink [11/01/2017 11:44:44] - |D| - [2695995562] - C:\Users\Emmanuelle\AppData\Local\Google [23/10/2016 12:32:49] - |SHD| - [130] - C:\Users\Emmanuelle\AppData\Local\Historique [22/08/2016 23:45:46] - |D| - [112142694] - C:\Users\Emmanuelle\AppData\Local\Host App Service [02/11/2016 19:10:25] - |AH| - [6291456] - C:\Users\Emmanuelle\AppData\Local\IconCache.db [19/09/2016 01:15:59] - |D| - [174080] - C:\Users\Emmanuelle\AppData\Local\IIIQF [23/10/2016 12:32:49] - |D| - [1148445643] - C:\Users\Emmanuelle\AppData\Local\Microsoft [24/08/2016 14:30:18] - |D| - [82095] - C:\Users\Emmanuelle\AppData\Local\MicrosoftEdge [22/08/2016 23:57:06] - |D| - [16472762] - C:\Users\Emmanuelle\AppData\Local\Mozilla [25/08/2016 00:45:14] - |D| - [0] - C:\Users\Emmanuelle\AppData\Local\NetworkTiles [22/08/2016 23:46:06] - |D| - [81809080] - C:\Users\Emmanuelle\AppData\Local\NVIDIA [14/12/2016 17:00:31] - |D| - [0] - C:\Users\Emmanuelle\AppData\Local\NVIDIA Corporation [22/08/2016 23:46:12] - |D| - [848709415] - C:\Users\Emmanuelle\AppData\Local\Packages [22/08/2016 23:47:28] - |D| - [0] - C:\Users\Emmanuelle\AppData\Local\Publishers [23/10/2016 12:32:49] - |D| - [389956494] - C:\Users\Emmanuelle\AppData\Local\Temp [23/10/2016 12:32:49] - |SHD| - [15789275] - C:\Users\Emmanuelle\AppData\Local\Temporary Internet Files [22/08/2016 23:46:05] - |D| - [12410880] - C:\Users\Emmanuelle\AppData\Local\TileDataLayer [27/08/2017 09:04:14] - |D| - [0] - C:\Users\Emmanuelle\AppData\Local\UNP [29/01/2017 18:13:30] - |D| - [1459771] - C:\Users\Emmanuelle\AppData\Local\UpdateTask [22/08/2016 23:46:13] - |D| - [0] - C:\Users\Emmanuelle\AppData\Local\VirtualStore [29/01/2017 18:12:50] - |D| - [2398485] - C:\Users\Emmanuelle\AppData\Local\{0DC33B9F-296B-5727-44F3-72CF609B8E57} [19/09/2016 01:23:35] - |D| - [2024] - C:\Users\Emmanuelle\AppData\LocalLow\Dashlane [22/08/2016 23:46:02] - |SD| - [533060] - C:\Users\Emmanuelle\AppData\LocalLow\Microsoft [04/12/2016 22:19:49] - |D| - [0] - C:\Users\Emmanuelle\AppData\LocalLow\Mozilla [11/09/2016 08:24:31] - |D| - [445] - C:\Users\Emmanuelle\AppData\Roaming\Acer Incorporated [22/08/2016 23:46:18] - |D| - [0] - C:\Users\Emmanuelle\AppData\Roaming\Adobe [23/08/2016 06:50:43] - |D| - [0] - C:\Users\Emmanuelle\AppData\Roaming\AVAST Software [26/10/2016 09:02:47] - |D| - [0] - C:\Users\Emmanuelle\AppData\Roaming\CyberLink [19/09/2016 01:18:23] - |D| - [563514918] - C:\Users\Emmanuelle\AppData\Roaming\Dashlane [22/02/2017 17:17:40] - |D| - [271] - C:\Users\Emmanuelle\AppData\Roaming\dvdcss [10/10/2016 21:30:13] - |D| - [0] - C:\Users\Emmanuelle\AppData\Roaming\Foxit Software [29/01/2017 18:13:37] - |A| - [0] - C:\Users\Emmanuelle\AppData\Roaming\Lakimekim [22/08/2016 23:51:43] - |D| - [506] - C:\Users\Emmanuelle\AppData\Roaming\Macromedia [23/10/2016 12:32:49] - |SD| - [50753228] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft [22/08/2016 23:57:06] - |D| - [36252198] - C:\Users\Emmanuelle\AppData\Roaming\Mozilla [27/08/2016 18:45:54] - |D| - [27634892] - C:\Users\Emmanuelle\AppData\Roaming\Skype [11/02/2017 21:16:46] - |D| - [86876] - C:\Users\Emmanuelle\AppData\Roaming\vlc [27/02/2017 01:13:27] - |A| - [42] - C:\Users\Emmanuelle\AppData\Roaming\WB.CFG [22/08/2016 23:46:23] - |ASH| - [174] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [23/10/2016 12:32:49] - |SHD| - [29214] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [23/10/2016 12:32:49] - |RD| - [29214] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [23/10/2016 12:32:49] - |RD| - [3888] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [23/10/2016 12:32:49] - |RD| - [2933] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [22/08/2016 23:46:24] - |RD| - [174] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [29/01/2017 18:18:29] - |A| - [2367] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk [22/08/2016 23:46:09] - |D| - [3011] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane [23/10/2016 13:05:50] - |ASH| - [174] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [22/08/2016 23:50:26] - |A| - [1337] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gestionnaire audio HD.lnk [23/10/2016 12:32:49] - |D| - [170] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [22/08/2016 23:50:52] - |A| - [2430] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [22/08/2016 23:46:24] - |RD| - [174] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [23/10/2016 12:32:49] - |RD| - [5318] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [23/10/2016 12:32:49] - |RD| - [7238] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [22/08/2016 23:46:24] - |ASH| - [174] - C:\Users\Emmanuelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Public] ---------- | C:\ProgramData [31/08/2015 12:50:21] - |D| - [4139678] - C:\ProgramData\Acer [23/10/2016 13:03:53] - |SHD| - [29486195262] - C:\ProgramData\Application Data [31/08/2015 12:50:43] - |D| - [27720] - C:\ProgramData\AVAST Software [23/08/2016 06:29:02] - |SHD| - [14362] - C:\ProgramData\Bureau [19/03/2016 18:46:28] - |D| - [157] - C:\ProgramData\CLSK [16/07/2016 13:47:48] - |D| - [0] - C:\ProgramData\Comms [19/03/2016 18:46:18] - |D| - [144590] - C:\ProgramData\CyberLink [22/08/2016 23:43:01] - |D| - [3093644] - C:\ProgramData\Dashlane [23/10/2016 13:03:53] - |SHD| - [278] - C:\ProgramData\Documents [23/10/2016 12:27:21] - |AH| - [0] - C:\ProgramData\DP45977C.lfl [19/03/2016 15:02:07] - |D| - [6024] - C:\ProgramData\DriverSetupUtility [19/03/2016 18:44:53] - |D| - [468119] - C:\ProgramData\install_clap [19/03/2016 15:03:27] - |D| - [49628651] - C:\ProgramData\Intel [23/08/2016 07:01:57] - |D| - [384] - C:\ProgramData\Intel Security [29/01/2017 14:04:34] - |D| - [61978107] - C:\ProgramData\Leapfrog [31/08/2015 12:52:12] - |D| - [741736371] - C:\ProgramData\McAfee [23/08/2016 06:29:03] - |SHD| - [161664] - C:\ProgramData\Menu Démarrer [19/09/2016 01:15:58] - |D| - [2545162] - C:\ProgramData\miaEDDE.tmp [16/07/2016 13:47:48] - |SD| - [704536954] - C:\ProgramData\Microsoft [23/10/2016 13:10:53] - |D| - [0] - C:\ProgramData\Microsoft OneDrive [23/08/2016 06:29:03] - |SHD| - [0] - C:\ProgramData\Modèles [31/08/2015 12:51:38] - |D| - [164] - C:\ProgramData\Mozilla [11/01/2017 11:43:17] - |RASH| - [290] - C:\ProgramData\ntuser.pol [23/10/2016 12:26:47] - |D| - [24067] - C:\ProgramData\NVIDIA [23/10/2016 12:26:10] - |D| - [274397899] - C:\ProgramData\NVIDIA Corporation [22/08/2016 23:46:50] - |HD| - [38322979] - C:\ProgramData\O949 [31/08/2015 12:50:21] - |D| - [4081438] - C:\ProgramData\OEM [22/08/2016 23:46:38] - |D| - [28] - C:\ProgramData\OEM_YAHOO [19/03/2016 15:02:19] - |D| - [9498822] - C:\ProgramData\Package Cache [16/07/2016 13:47:48] - |AD| - [5306] - C:\ProgramData\regid.1991-06.com.microsoft [27/11/2016 11:51:13] - |D| - [43524096] - C:\ProgramData\Skype [16/07/2016 13:47:48] - |D| - [0] - C:\ProgramData\SoftwareDistribution [23/08/2016 07:08:53] - |D| - [0] - C:\ProgramData\Synaptics [19/03/2016 18:44:54] - |D| - [361176] - C:\ProgramData\Temp [16/07/2016 13:47:48] - |D| - [8249] - C:\ProgramData\USOPrivate [24/10/2016 02:31:20] - |D| - [2170880] - C:\ProgramData\USOShared [31/08/2015 12:50:51] - |D| - [569856994] - C:\ProgramData\WildTangent [29/01/2017 18:13:45] - |D| - [895554] - C:\ProgramData\{3A5FFF3C-B01D-75FA-36DB-EBB8AC996076} [19/09/2016 01:16:02] - |HD| - [10551830] - C:\ProgramData\{6C65EBE1-72AC-48E2-A6B6-76C310D3B83A} ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [16/07/2016 13:47:50] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [23/08/2016 06:29:03] - |SHD| - [161490] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [16/07/2016 13:47:48] - |RD| - [161490] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [23/08/2016 07:12:07] - |A| - [2518] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk [16/07/2016 13:47:48] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [16/07/2016 13:47:48] - |RD| - [14299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [31/08/2015 12:50:20] - |D| - [18488] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer [16/07/2016 13:47:48] - |RD| - [20488] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [10/05/2017 00:19:01] - |A| - [2275] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AmazonAssistant.lnk [21/03/2015 02:28:50] - |A| - [3236] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\App Explorer.lnk [31/08/2015 12:50:47] - |D| - [1084] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software [19/03/2016 18:46:17] - |RD| - [2340] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 12 [16/07/2016 13:47:50] - |ASH| - [796] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [23/08/2016 07:12:07] - |A| - [2491] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk [19/03/2016 18:47:03] - |D| - [1037] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF [31/08/2015 12:50:53] - |RD| - [36745] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [16/07/2016 13:43:50] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [29/01/2017 18:40:32] - |D| - [2340] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LeapFrog Connect [16/07/2016 13:47:48] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [27/08/2017 22:28:22] - |D| - [2177] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee [05/05/2017 09:22:44] - |D| - [2342] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [16/07/2016 13:42:22] - |RAS| - [2219] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk [31/08/2015 12:51:38] - |A| - [1238] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [19/03/2016 18:30:22] - |D| - [1472] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [23/08/2016 07:12:07] - |A| - [2491] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk [22/10/2016 12:22:26] - |D| - [5203] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 [23/08/2016 07:12:08] - |A| - [2479] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk [11/01/2017 11:44:44] - |D| - [3699] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 [23/08/2016 07:12:08] - |A| - [2518] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk [16/07/2016 13:43:50] - |RAS| - [2199] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk [23/08/2016 07:12:08] - |A| - [2441] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk [27/11/2016 11:51:30] - |D| - [2141] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [16/07/2016 13:47:48] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [16/07/2016 13:47:48] - |RD| - [2670] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [11/02/2017 21:15:49] - |D| - [7236] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [31/08/2015 12:50:56] - |A| - [2444] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - acer.lnk [23/10/2016 12:40:09] - |A| - [1576] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [23/08/2016 07:12:08] - |A| - [2501] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [16/07/2016 13:47:50] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | C:\Program Files (x86) [31/08/2015 12:50:20] - |D| - [417895343] - C:\Program Files (x86)\Acer [10/05/2017 00:19:00] - |D| - [2534879] - C:\Program Files (x86)\Amazon [16/07/2016 08:04:24] - |D| - [109785688] - C:\Program Files (x86)\Common Files [19/03/2016 18:45:57] - |D| - [204184809] - C:\Program Files (x86)\CyberLink [19/09/2016 01:16:02] - |D| - [478933] - C:\Program Files (x86)\Dashlane [16/07/2016 13:47:50] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [19/03/2016 18:46:58] - |AD| - [207358718] - C:\Program Files (x86)\Foxit PhantomPDF [11/01/2017 11:43:32] - |D| - [86301574] - C:\Program Files (x86)\Google [19/03/2016 15:07:38] - |HD| - [130551046] - C:\Program Files (x86)\InstallShield Installation Information [19/03/2016 15:03:26] - |D| - [24790546] - C:\Program Files (x86)\Intel [16/07/2016 13:47:48] - |D| - [1989769] - C:\Program Files (x86)\Internet Explorer [29/01/2017 14:04:35] - |AD| - [113912217] - C:\Program Files (x86)\LeapFrog [31/08/2015 12:52:13] - |D| - [54062916] - C:\Program Files (x86)\McAfee [31/08/2015 12:52:14] - |D| - [544160] - C:\Program Files (x86)\mcafee.com [19/03/2016 14:52:36] - |AD| - [3042599791] - C:\Program Files (x86)\Microsoft Office [05/05/2017 09:22:41] - |D| - [85335684] - C:\Program Files (x86)\Microsoft Silverlight [16/07/2016 13:47:48] - |D| - [8175999] - C:\Program Files (x86)\Microsoft.NET [04/12/2016 11:41:22] - |AD| - [126379254] - C:\Program Files (x86)\Mozilla Firefox [31/08/2015 12:51:37] - |D| - [306964] - C:\Program Files (x86)\Mozilla Maintenance Service [23/10/2016 12:54:17] - |D| - [25757] - C:\Program Files (x86)\MSBuild [19/03/2016 18:29:22] - |D| - [219365557] - C:\Program Files (x86)\NVIDIA Corporation [22/08/2016 23:47:04] - |D| - [367728] - C:\Program Files (x86)\OEM [19/03/2016 15:10:11] - |AD| - [5504164] - C:\Program Files (x86)\Qualcomm Atheros [19/03/2016 15:07:38] - |D| - [19063249] - C:\Program Files (x86)\Realtek [23/10/2016 12:54:17] - |D| - [38450433] - C:\Program Files (x86)\Reference Assemblies [27/11/2016 11:51:27] - |RD| - [85163213] - C:\Program Files (x86)\Skype [19/03/2016 15:07:38] - |HD| - [0] - C:\Program Files (x86)\Temp [23/10/2016 12:26:33] - |HD| - [0] - C:\Program Files (x86)\Uninstall Information [11/02/2017 21:15:26] - |D| - [126263314] - C:\Program Files (x86)\VideoLAN [18/02/2017 20:31:53] - |D| - [846194] - C:\Program Files (x86)\VulkanRT [31/08/2015 12:50:57] - |AD| - [103047513] - C:\Program Files (x86)\WildGames [31/08/2015 12:50:51] - |D| - [38121791] - C:\Program Files (x86)\WildTangent Games [16/07/2016 13:47:48] - |D| - [1942016] - C:\Program Files (x86)\Windows Defender [16/07/2016 13:47:48] - |D| - [5958656] - C:\Program Files (x86)\Windows Mail [16/07/2016 13:47:48] - |D| - [3275928] - C:\Program Files (x86)\Windows Media Player [16/07/2016 13:47:48] - |D| - [34128] - C:\Program Files (x86)\Windows Multimedia Platform [16/07/2016 13:47:48] - |D| - [7584962] - C:\Program Files (x86)\Windows NT [16/07/2016 13:47:48] - |D| - [5424832] - C:\Program Files (x86)\Windows Photo Viewer [16/07/2016 13:47:48] - |D| - [34128] - C:\Program Files (x86)\Windows Portable Devices [16/07/2016 13:47:48] - |SHD| - [0] - C:\Program Files (x86)\Windows Sidebar [16/07/2016 13:47:48] - |D| - [4147133] - C:\Program Files (x86)\WindowsPowerShell ---------- | C:\Program Files [22/08/2016 23:46:19] - |D| - [153135] - C:\Program Files\Accessory Store [31/08/2015 12:52:07] - |D| - [55345367] - C:\Program Files\Acer [31/08/2015 12:50:43] - |D| - [66365366] - C:\Program Files\AVAST Software [19/03/2016 18:38:34] - |D| - [37026] - C:\Program Files\Booking.COM [16/07/2016 08:04:24] - |D| - [688177321] - C:\Program Files\Common Files [16/07/2016 13:47:50] - |ASH| - [174] - C:\Program Files\desktop.ini [29/01/2017 18:40:45] - |D| - [680440] - C:\Program Files\DIFX [19/03/2016 15:02:07] - |D| - [1883121] - C:\Program Files\DriverSetupUtility [23/08/2016 06:29:03] - |SHD| - [688177321] - C:\Program Files\Fichiers communs [23/10/2016 12:25:22] - |D| - [61194243] - C:\Program Files\Intel [16/07/2016 13:47:47] - |D| - [2582644] - C:\Program Files\Internet Explorer [31/08/2015 12:52:13] - |AD| - [242446122] - C:\Program Files\mcafee [31/08/2015 12:52:13] - |D| - [3738506] - C:\Program Files\mcafee.com [23/08/2016 06:59:45] - |D| - [8850832] - C:\Program Files\Microsoft Office 15 [05/05/2017 09:22:41] - |AD| - [98117764] - C:\Program Files\Microsoft Silverlight [23/10/2016 12:54:17] - |D| - [25757] - C:\Program Files\MSBuild [23/10/2016 12:25:47] - |D| - [1022025122] - C:\Program Files\NVIDIA Corporation [23/10/2016 12:26:58] - |D| - [79777482] - C:\Program Files\Realtek [23/10/2016 12:54:17] - |D| - [36850857] - C:\Program Files\Reference Assemblies [26/08/2017 12:01:01] - |D| - [812345] - C:\Program Files\rempl [10/07/2015 14:21:54] - |HD| - [0] - C:\Program Files\Uninstall Information [26/08/2017 12:00:56] - |D| - [4552970] - C:\Program Files\UNP [16/07/2016 13:47:47] - |RD| - [14914884] - C:\Program Files\Windows Defender [16/07/2016 13:47:47] - |D| - [6181888] - C:\Program Files\Windows Mail [16/07/2016 13:47:47] - |D| - [4989628] - C:\Program Files\Windows Media Player [16/07/2016 13:47:47] - |D| - [37784] - C:\Program Files\Windows Multimedia Platform [16/07/2016 13:47:47] - |D| - [7848642] - C:\Program Files\Windows NT [16/07/2016 13:47:47] - |D| - [6223552] - C:\Program Files\Windows Photo Viewer [16/07/2016 13:47:47] - |D| - [37784] - C:\Program Files\Windows Portable Devices [16/07/2016 13:47:47] - |SHD| - [0] - C:\Program Files\Windows Sidebar [16/07/2016 13:47:47] - |HD| - [2002592274] - C:\Program Files\WindowsApps [16/07/2016 13:47:47] - |D| - [4570474] - C:\Program Files\WindowsPowerShell ---------- | C:\Program Files (x86)\Common Files [19/03/2016 15:11:19] - |D| - [17387] - C:\Program Files (x86)\Common Files\Atheros [25/08/2017 22:48:54] - |D| - [23240] - C:\Program Files (x86)\Common Files\DESIGNER [23/10/2016 12:25:05] - |D| - [68272579] - C:\Program Files (x86)\Common Files\Intel [31/08/2015 12:52:13] - |D| - [8631180] - C:\Program Files (x86)\Common Files\McAfee [16/07/2016 13:47:48] - |AD| - [20384411] - C:\Program Files (x86)\Common Files\Microsoft Shared [19/03/2016 15:03:34] - |D| - [204796] - C:\Program Files (x86)\Common Files\PostureAgent [19/03/2016 15:10:08] - |D| - [28966] - C:\Program Files (x86)\Common Files\Qualcomm Atheros [16/07/2016 13:47:48] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [27/11/2016 11:51:28] - |AD| - [2581120] - C:\Program Files (x86)\Common Files\Skype [16/07/2016 13:47:48] - |D| - [9639307] - C:\Program Files (x86)\Common Files\System ---------- | C:\Program Files\Common files [23/10/2016 12:27:36] - |D| - [148] - C:\Program Files\Common files\Atheros [23/08/2016 06:56:01] - |D| - [4147912] - C:\Program Files\Common files\AV [23/08/2016 07:00:48] - |D| - [21114014] - C:\Program Files\Common files\Intel Security [31/08/2015 12:52:13] - |D| - [492546123] - C:\Program Files\Common files\McAfee [16/07/2016 13:47:47] - |D| - [160060719] - C:\Program Files\Common files\microsoft shared [19/03/2016 15:10:42] - |D| - [59676] - C:\Program Files\Common files\QCA_Bluetooth [16/07/2016 13:47:47] - |D| - [2702] - C:\Program Files\Common files\Services [16/07/2016 13:47:47] - |D| - [10246027] - C:\Program Files\Common files\System ---------- | Tasks [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [23/10/2016 12:50:19] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.758A3F87847A4A631953BA51B0CF5AFC] - [29/01/2017 18:13:45] - |A| - [1028] - C:\WINDOWS\Tasks\Secured Yahoo Powered lolor.job [MD5.C8CDFC3D34CEBCDB523AE217381B4C38] - [29/01/2017 18:13:43] - |A| - [310] - C:\WINDOWS\Tasks\{617C32D5-70A6-6F08-17EE-424A28C3DD2E}.job [MD5.FEA03E33BF51DC7993843F9904304C60] - [23/10/2016 12:50:17] - |A| - [2888] - C:\WINDOWS\System32\Tasks\ACC : C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [MD5.84136E01EA34982A86898558E285F3D2] - [23/10/2016 12:50:17] - |A| - [3852] - C:\WINDOWS\System32\Tasks\ACCAgent : C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [MD5.5515A9151E4A933753D301AD28A2DEB2] - [23/10/2016 12:50:17] - |A| - [2328] - C:\WINDOWS\System32\Tasks\ACCBackgroundApplication : C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [MD5.11ED8A92028E995089F3980A66A2224E] - [23/10/2016 12:50:17] - |A| - [2534] - C:\WINDOWS\System32\Tasks\AcerCloud : C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [MD5.C02573B2E3868D3AB249C66106B67AF1] - [23/10/2016 12:50:17] - |A| - [2614] - C:\WINDOWS\System32\Tasks\App Explorer : %LOCALAPPDATA%\Host App Service\Engine\HostAppServiceUpdater.exe [MD5.387519F0B419270EAB60BCD110F9FFAD] - [23/10/2016 12:50:17] - |A| - [2654] - C:\WINDOWS\System32\Tasks\Avast SecureLine : C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [MD5.B1CADAD7DFF0494CACB9EB7D6F2FDF35] - [23/10/2016 12:50:17] - |A| - [2926] - C:\WINDOWS\System32\Tasks\avast! SL Update : C:\Program Files\AVAST Software\SecureLine\SLUpdate.exe [MD5.0DA91BF710858F3B7ABC70D71E312654] - [23/10/2016 12:50:17] - |A| - [2762] - C:\WINDOWS\System32\Tasks\BacKGroundAgent : C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [MD5.3C7961C1600E65E0E70EAF6613186B00] - [23/10/2016 12:50:17] - |A| - [2074] - C:\WINDOWS\System32\Tasks\FUBTrackingByPLD : "C:\OEM\Preload\FubTracking\FubTracking.exe" [MD5.C53693CC89F4750F2F25027EE689D953] - [26/08/2017 11:49:45] - |A| - [4034] - C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse : C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [MD5.9B81746135BC5B987D36FEC9CDADD56E] - [05/05/2017 11:17:09] - |A| - [4222] - C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse : C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [MD5.00000000000000000000000000000000] - [23/10/2016 12:50:17] - |D| - [6502] - C:\WINDOWS\System32\Tasks\McAfee [MD5.81AD0B7B83DB6CFB2CE12947B2549041] - [23/10/2016 12:50:17] - |A| - [3126] - C:\WINDOWS\System32\Tasks\McAfeeLogon : C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe [MD5.00000000000000000000000000000000] - [16/07/2016 13:47:48] - |D| - [546898] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.22E27CAAB728CF5C2CE631594F595D13] - [23/10/2016 12:50:19] - |A| - [2834] - C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task : C:\Users\Emmanuelle\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [MD5.9F52FD8922F3BBC2C2B83794A47D3A30] - [25/08/2017 22:32:22] - |A| - [3388] - C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2395831268-3694815761-1612603451-1001 : %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MD5.490253CD895E95C5D20E0C9654E36007] - [23/10/2016 12:50:19] - |A| - [2264] - C:\WINDOWS\System32\Tasks\Power Button : "C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe" [MD5.A346414C11A91C50D68CB00DC3C26F88] - [23/10/2016 12:50:19] - |A| - [2222] - C:\WINDOWS\System32\Tasks\Power Management : "C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe" [MD5.760C30966D3054340AADAAA5A9DCE46B] - [23/10/2016 12:50:19] - |A| - [2180] - C:\WINDOWS\System32\Tasks\Quick Access : "C:\Program Files\Acer\Acer Quick Access\QALauncher.exe" [MD5.B17734B8C2070FF1B0DA6D146D29FC95] - [29/01/2017 18:13:46] - |A| - [4130] - C:\WINDOWS\System32\Tasks\Secured Yahoo Powered lolor : C:\Windows\system32\wscript.exe [MD5.A949D58A38B0FDBF90ED213A8F8017B5] - [23/10/2016 12:50:19] - |A| - [4302] - C:\WINDOWS\System32\Tasks\Software Update Application : "C:\ProgramData\OEM\UpgradeTool\ListCheck.exe" [MD5.3CC16E8F3168983BB825AF5B93FCF37B] - [23/10/2016 12:50:19] - |A| - [2706] - C:\WINDOWS\System32\Tasks\UbtFrameworkService : "C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe" [MD5.1D60EE3397DC1F001064E686DC8A8250] - [10/05/2017 00:29:22] - |A| - [4188] - C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{426D0793-68B3-4987-8B43-0D2D55A52E82} : C:\WINDOWS\system32\msfeedssync.exe [MD5.1F5D1805B800C46C3616596F2CA98374] - [29/01/2017 18:13:43] - |A| - [2850] - C:\WINDOWS\System32\Tasks\{617C32D5-70A6-6F08-17EE-424A28C3DD2E} : C:\Users\EMMANU~1\AppData\Local\UPDATE~1\Sync.exe [MD5.00000000000000000000000000000000] - [16/07/2016 13:47:48] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "Wininit-Shutdown-In-Rule-TCP-RPC"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36753|Desc=@firewallapi.dll,-36754|EmbedCtxt=@firewallapi.dll,-36751| "Wininit-Shutdown-In-Rule-TCP-RPC-EPMapper"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC-EPMap|App=%systemroot%\system32\wininit.exe|Name=@firewallapi.dll,-36755|Desc=@firewallapi.dll,-36756|EmbedCtxt=@firewallapi.dll,-36751| "Netlogon-NamedPipe-In"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "Netlogon-TCP-RPC-In"=v2.26|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010| "WirelessDisplay-In-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-UDP"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Infra-In-TCP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100| "MDNS-In-UDP"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort2_24=mDNS|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37303|Desc=@%SystemRoot%\system32\firewallapi.dll,-37304|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302| "MDNS-Out-UDP"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|LPort=5353|App=%SystemRoot%\system32\svchost.exe|Svc=dnscache|Name=@%SystemRoot%\system32\firewallapi.dll,-37305|Desc=@%SystemRoot%\system32\firewallapi.dll,-37306|EmbedCtxt=@%SystemRoot%\system32\firewallapi.dll,-37302| "DeliveryOptimization-TCP-In"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "DeliveryOptimization-UDP-In"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "{C9F015B4-0B36-4037-91FB-1D90C4721879}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe|Name=CyberLink PowerDVD12 Movie Module|Desc=CyberLink PowerDVD12 Movie Module| "{491F6117-4262-4F1B-86DB-C3AB1A00ACF7}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe|Name=CyberLink PowerDVD12 Moovie Live|Desc=CyberLink PowerDVD12 Moovie Live| "{B00A3DEE-E206-42E0-84A5-64EDAE4B7DE8}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe|Name=CyberLink PowerDVD12 Agent|Desc=CyberLink PowerDVD12 Agent| "{81B175E1-B8B8-42D8-960C-285344F16BA2}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe|Name=CyberLink PowerDVD 12 Media Server Service|Desc=CyberLink Media Server| "{993258F5-57EB-4692-9FFB-BC68CE564BA2}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe|Name=CyberLink PowerDVD 12 DMREngine|Desc=CyberLink PowerDVD 12 DMREngine| "{7C700CEC-8C9E-4DB7-802F-30FA235671F5}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe|Name=CyberLink PowerDVD12|Desc=CyberLink PowerDVD12| "{C479B802-6EFE-4947-8505-763456F9C994}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=47995|LPort=47998|LPort=47999|LPort=48000|LPort=48010|App=C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe|Name=SHIELD Streaming NvStreamer UDP Exception|Desc=UDP exceptions for SHIELD Streaming NvStreamer (RTSP/RI/A/V)| "{16944918-BACC-4185-BED2-70B1692FAFAE}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=35043|LPort=47995|LPort=48010|App=C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe|Name=SHIELD Streaming NvStreamer TCP Exception|Desc=TCP exceptions for SHIELD Streaming NvStreamer (RTSP/RI)| "{1B6AD860-C569-46B3-B749-F0EA4CFD6471}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=47998|App=C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe|Name=SHIELD Streaming SSAU UDP Exception|Desc=UDP exceptions for SHIELD Streaming SSAU (NWT)| "{FCFF4A79-80F6-4175-8C2B-C0E58AD941B5}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe|Name=SHIELD Streaming NSS UDP Exception|Desc=UDP exceptions for SHIELD Streaming NSS (mDNS)| "{DCD04014-4AEB-4C90-9F7D-CDF20AF5EF22}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=47984|LPort=47989|App=C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe|Name=SHIELD Streaming NSS TCP Exception|Desc=TCP exceptions for SHIELD Streaming NSS (HTTP)| "{5E1E3184-D5DF-4E36-89F6-CE6C14062F36}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=443|App=C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe|Name=NVIDIA Network Service TCP Exception (HTTPS)|Desc=TCP exceptions for NVIDIA Network Service| "{F9A1CDD1-B47C-4F4E-A872-FD83DA2D8CF3}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=80|App=C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe|Name=NVIDIA Network Service TCP Exception (HTTP)|Desc=TCP exceptions for NVIDIA Network Service| "{8C5BC139-5C33-46B5-AC85-904B5EE8DE29}"=v2.24|Action=Allow|Active=TRUE|Dir=Out|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-500|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{BA76611A-53EA-4E98-9240-01D77C34D7E0}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe|Name=abPhotoWindowsUpnp| "{9374E55F-F31F-454E-8D92-4D68414A5ACB}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe|Name=abPhotoWindowsUpnp| "{05EBF720-9C08-4032-9F83-DDB35AB3D67E}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe|Name=abPhotoDMCDaemon| "{D1449E72-5288-4FF3-88B1-34F6AC527BFF}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe|Name=abPhotoDMCDaemon| "{153D9351-68F9-4CE6-AE66-5419EB374260}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe|Name=AcerPortalccd| "{227DE642-B4A4-40DB-B65D-741AF59B20FE}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe|Name=AcerPortalccd| "{E0BBD98A-E2CA-44F7-97E6-4DC6B859B476}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe|Name=McAfee Shared Service Host|Desc=McAfee Shared Service Host| "{DA225F5C-C571-418A-9132-30223D45C585}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Mozilla Firefox\firefox.exe|Name=Firefox (C:\Program Files (x86)\Mozilla Firefox)| "{91692DC0-BF42-45CE-82A5-6E667F038C2E}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Mozilla Firefox\firefox.exe|Name=Firefox (C:\Program Files (x86)\Mozilla Firefox)| "{EAB70B30-C8D3-4941-906A-FAC370DF7510}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-18|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{D45FD11A-1E66-447B-9D57-EF5C00D5A479}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Acer Explorer|Desc=AcerExplorer|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-4064078117-538652333-2642387017-2477701237-3887694816-3370591880-4054822867|EmbedCtxt=Acer Explorer|Platform=2:6:2|Platform2=GTEQ| "{5B2DB934-BD54-4509-ABD7-FDA8EB2C0B70}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Acer Explorer|Desc=AcerExplorer|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-4064078117-538652333-2642387017-2477701237-3887694816-3370591880-4054822867|EmbedCtxt=Acer Explorer|Platform=2:6:2|Platform2=GTEQ| "{005F6C85-6731-4D61-A250-ACDA7C6D48F2}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Store Purchase App|Desc=Store Purchase App|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-2246242352-370130666-2593524754-1827188282-2313440240-2317694540-2761805292|EmbedCtxt=Store Purchase App|Platform=2:6:2|Platform2=GTEQ| "{841AC8DC-C58A-41AA-890E-651997B40ED4}"=v2.26|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Skype\Phone\Skype.exe|Name=Skype| "{44B75D4F-4B35-4935-9BB1-83521A217990}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Users\Emmanuelle\AppData\Local\Chromium\Application\chrome.exe|Name=Chromium (mDNS-In)|Desc=Règle de trafic entrant pour Chromium autorisant le trafic mDNS|EmbedCtxt=Chromium| "{69BEC53B-37CA-4AB8-8AA0-39FEC9A48975}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{MAGIX.MusicMakerJam_2.3.1054.0_x64__a2t3txkz9j1jw?ms-resource://MAGIX.MusicMakerJam/Resources/app_name}|Desc=@{MAGIX.MusicMakerJam_2.3.1054.0_x64__a2t3txkz9j1jw?ms-resource://MAGIX.MusicMakerJam/Resources/app_name}|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-914775309-424825794-3355368112-487557154-2084386389-537045334-2498513562|EmbedCtxt=@{MAGIX.MusicMakerJam_2.3.1054.0_x64__a2t3txkz9j1jw?ms-resource://MAGIX.MusicMakerJam/Resources/app_name}|Platform=2:6:2|Platform2=GTEQ| "{87BD174A-4383-40B0-919B-3D3EC819CE2A}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{MAGIX.MusicMakerJam_2.3.1054.0_x64__a2t3txkz9j1jw?ms-resource://MAGIX.MusicMakerJam/Resources/app_name}|Desc=@{MAGIX.MusicMakerJam_2.3.1054.0_x64__a2t3txkz9j1jw?ms-resource://MAGIX.MusicMakerJam/Resources/app_name}|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-914775309-424825794-3355368112-487557154-2084386389-537045334-2498513562|EmbedCtxt=@{MAGIX.MusicMakerJam_2.3.1054.0_x64__a2t3txkz9j1jw?ms-resource://MAGIX.MusicMakerJam/Resources/app_name}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{0D7907B5-7ABF-4B04-B7C7-C91E2D8FD939}"=v2.26|Action=Allow|Active=TRUE|Dir=In|RA4=169.254.0.0/255.255.0.0|RA4=244.0.0.251|App=C:\Program Files (x86)\LeapFrog\LeapFrog Connect\LeapfrogConnect.exe|Name=LeapFrog Connect| "{DCF32A5F-E067-4A62-B35A-6A82E1655698}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Sticky Notes|Desc=Microsoft Sticky Notes|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-3539788797-2700867667-1432428195-1581642-2885308443-3834444517-2495346167|EmbedCtxt=Microsoft Sticky Notes|Platform=2:6:2|Platform2=GTEQ| "{503BF424-1CA4-4072-AA23-5B0992E16F7C}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Sticky Notes|Desc=Microsoft Sticky Notes|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-3539788797-2700867667-1432428195-1581642-2885308443-3834444517-2495346167|EmbedCtxt=Microsoft Sticky Notes|Platform=2:6:2|Platform2=GTEQ| "{C9ABB5DD-28D2-463C-85ED-E2E911215735}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{EE3F83D0-B074-4426-90CD-F60D3173ABA7}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{CD8752F6-4BA2-464C-89BF-45172250C5D4}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Netflix|Desc=Netflix|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-444797119-353723001-3522112724-563070080-1809981734-922308773-1844997097|EmbedCtxt=Netflix|Platform=2:6:2|Platform2=GTEQ| "{E6BB6233-4456-4577-8750-6272D879D893}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Netflix|Desc=Netflix|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-444797119-353723001-3522112724-563070080-1809981734-922308773-1844997097|EmbedCtxt=Netflix|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{8FED4342-42ED-4BEB-8A7F-D3D8C1858F43}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Twitter|Desc=Twitter|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-1063257880-1914585122-1954150059-946145533-116938067-416079064-1690466945|EmbedCtxt=Twitter|Platform=2:6:2|Platform2=GTEQ| "{319BF555-497C-400F-8611-DD24F6BDF724}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Candy Crush Soda Saga|Desc=Candy Crush Soda Saga|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-3055884410-2067824683-223899546-422323478-2359388318-2114876276-1379654078|EmbedCtxt=Candy Crush Soda Saga|Platform=2:6:2|Platform2=GTEQ| "{A7E6669C-13D5-4E83-AD42-808C63AE035C}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox|Desc=Xbox|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-4153522205-3718366397-1353898457-1332184198-1210887116-3116787857-2103916698|EmbedCtxt=Xbox|Platform=2:6:2|Platform2=GTEQ| "{11EF26B9-D688-406A-AE9A-F0158E7A2760}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox|Desc=Xbox|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-4153522205-3718366397-1353898457-1332184198-1210887116-3116787857-2103916698|EmbedCtxt=Xbox|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{2FF2E049-C894-4873-AC4F-7C783069AE10}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{DF3C4E45-51AE-4E37-A9F6-A72548C9C092}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2395831268-3694815761-1612603451-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (Security Accelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @%SystemRoot%\System32\DispCI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs) [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{78A1C341-4539-11D3-B88D-00C04FAD5171}] : (mfesapsn) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{81C87465-DE07-4EFC-9D93-61E891D52FD2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9d6d66a6-0b0c-4563-9077-a0e9a7955ae4}] : (Ramdisk) [] -> @ramdisk.inf,%ClassName%;RAM Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A73C93F1-9727-4D1D-ACE1-0E333BA4E7DB}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [20/01/2017 10:07:50] - (15.6.0.1220) - (McAfee, Inc. - McAfee Link Driver) - C:\WINDOWS\system32\drivers\mfehidk.sys [17/02/2015 23:36:18] - (15.6.0.1220) - (McAfee, Inc. - Anti-Virus Mini-Firewall Driver) - C:\WINDOWS\system32\drivers\mfewfpk.sys [16/07/2016 13:41:54] - (4.0.2.217) - (Qualcomm Atheros, Inc. - Qualcomm Atheros Extensible Wireless LAN device driver) - C:\WINDOWS\System32\drivers\Qcamain10x64.sys [17/01/2017 06:56:20] - (21.21.13.7654) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 376.54) - C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvlddmkm.sys [19/03/2016 18:27:18] - (1.2.30.0) - (NVIDIA Corporation - NVIDIA Virtual Audio Driver) - C:\WINDOWS\system32\drivers\nvvad64v.sys [04/09/2015 20:51:58] - (8.0.0.1) - (Acer Incorporated - LMDriver) - C:\WINDOWS\System32\drivers\LMDriver.sys [04/09/2015 20:52:00] - (8.0.0.1) - (Acer Incorporated - RadioShim) - C:\WINDOWS\System32\drivers\RadioShim.sys [02/09/2015 11:46:03] - (19.0.7.34) - (Synaptics Incorporated - Synaptics I2C Driver) - C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [23/10/2016 10:35:12] - (10.0.0.256) - (Qualcomm Atheros - Qualcomm Atheros BtFilter Driver) - C:\WINDOWS\system32\DRIVERS\btfilter.sys [22/08/2016 23:46:19] - (10.0.10125.31214) - (Realsil Semiconductor Corporation - RTS USB READER Driver) - C:\WINDOWS\system32\Drivers\RtsUer.sys [17/02/2015 23:38:48] - (15.6.0.1220) - (McAfee, Inc. - McAfee Arbitrary Access Control Driver) - C:\WINDOWS\system32\drivers\mfeaack.sys [17/02/2015 23:33:10] - (15.6.0.1220) - (McAfee, Inc. - Anti-Virus File System Filter Driver) - C:\WINDOWS\system32\drivers\mfeavfk.sys [17/02/2015 23:33:54] - (15.6.0.1220) - (McAfee, Inc. - McAfee Core Firewall Engine Driver) - C:\WINDOWS\system32\drivers\mfefirek.sys [31/03/2017 21:03:28] - (1.5.0.1983) - (McAfee, Inc. - Event Driver) - C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [09/09/2016 18:54:04] - (15.6.0.1220) - (McAfee, Inc. - AAC Protected Launch Plugin Driver) - C:\WINDOWS\system32\drivers\mfeplk.sys [17/02/2015 23:38:12] - (15.6.0.1220) - (McAfee, Inc. - McAfee Personal Firewall IDS Plugin) - C:\WINDOWS\system32\drivers\cfwids.sys [19/05/2017 18:42:38] - (1.0.0.111) - (McAfee, Inc. - McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [19/03/2016 18:29:26] - (4.1.1966.5192) - (NVIDIA Corporation - Nvidia Streaming Kernel Service) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service S0 - [Kernel Driver] - 3ware () -> System32\drivers\3ware.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ADP80XX () -> System32\drivers\ADP80XX.SYS - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsata () -> System32\drivers\amdsata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsbs () -> System32\drivers\amdsbs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdxata () -> System32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD) -> System32\drivers\bxvbda.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - disk (@disk.inf,%disk_ServiceDesc%;Disk Driver) -> System32\drivers\disk.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - EhStorTcgDrv (@EhStorTcgDrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys - AcceptPause: False - AcceptStop: False R0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - HpSAMD () -> System32\drivers\HpSAMD.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - iaStorA () -> System32\drivers\iaStorA.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - iaStorAV (@iastorav.inf,%iaStorAV.DeviceDesc%;Intel(R) SATA RAID Controller Windows) -> System32\drivers\iaStorAV.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - intelide () -> System32\drivers\intelide.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - iorate (@%SystemRoot%\system32\drivers\iorate.sys,-100) -> system32\drivers\iorate.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - isapnp () -> System32\drivers\isapnp.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - LSI_SAS () -> System32\drivers\lsi_sas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SSS () -> System32\drivers\lsi_sss.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas () -> System32\drivers\megasas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas2i () -> System32\drivers\MegaSas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasr () -> System32\drivers\megasr.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - mfeelamk (McAfee Inc. mfeelamk) -> system32\drivers\mfeelamk.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - mfehidk (McAfee Inc. mfehidk) -> system32\drivers\mfehidk.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - mfewfpk (McAfee Inc. mfewfpk) -> system32\drivers\mfewfpk.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - msisadrv () -> System32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - mvumis () -> System32\drivers\mvumis.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - nvraid () -> System32\drivers\nvraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - nvstor () -> System32\drivers\nvstor.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pci (@pci.inf,%pci_svcdesc%;Pilote de bus PCI) -> System32\drivers\pci.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - pciide () -> System32\drivers\pciide.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - pcmcia () -> System32\drivers\pcmcia.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - percsas2i () -> System32\drivers\percsas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - percsas3i () -> System32\drivers\percsas3i.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - scmbus (@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver) -> System32\drivers\scmbus.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SiSRaid2 () -> System32\drivers\SiSRaid2.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SiSRaid4 () -> System32\drivers\sisraid4.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - stexstor () -> System32\drivers\stexstor.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storvsc () -> System32\drivers\storvsc.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volsnap (@%SystemRoot%\system32\drivers\volsnap.sys,-100) -> System32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volume (@volume.inf,%VolumeServiceDesc%;Volume driver) -> System32\drivers\volume.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vsmraid () -> System32\drivers\vsmraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicDisplay () -> \SystemRoot\System32\drivers\BasicDisplay.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicRender () -> \SystemRoot\System32\drivers\BasicRender.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys - AcceptPause: False - AcceptStop: True S1 - [Kernel Driver] - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys - AcceptPause: False - AcceptStop: False R1 - [File System Driver] - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - clreg (@%SystemRoot%\system32\drivers\registry.sys,-100) -> \SystemRoot\System32\drivers\registry.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - wanarp (@%systemroot%\system32\mprmsg.dll,-32011) -> System32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - wcifs (@%systemroot%\system32\drivers\wcifs.sys,-100) -> \SystemRoot\system32\drivers\wcifs.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - wcnfs (@%systemroot%\system32\drivers\wcnfs.sys,-100) -> \SystemRoot\system32\drivers\wcnfs.sys - AcceptPause: False - AcceptStop: True ---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted) ---------- | Uninstall [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\3079e7c6e0aecc7bd5742b03dfda0350] : (.-.) -> [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Dashlane] : (Dashlane.-.Dashlane, Inc.) -> C:\Users\Emmanuelle\AppData\Roaming\Dashlane\4.8.5.35155\bin\DashlaneUninstall.exe [HKU\S-1-5-21-2395831268-3694815761-1612603451-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Host App Service] : (App Explorer.-.SweetLabs) -> "C:\Users\Emmanuelle\AppData\Local\Host App Service\Uninstall.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D] : (Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012).-.Leapfrog) -> C:\PROGRA~1\DIFX\B60D1297D6D5E54C\DPInst64.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\leapfrog-02-03-05-012-1373324.inf_amd64_8d32ba055a076abd\leapfrog-02-03-05-012-1373324.inf [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\VulkanRT1.0.26.0] : (Vulkan Run Time Libraries 1.0.26.0.-.LunarG, Inc.) -> C:\Program Files (x86)\VulkanRT\1.0.26.0\UninstallVulkanRT.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{06F2A7C5-19F0-4962-B8D2-A495B7DD2A30}] : (Intel(R) Management Engine Components.-.Intel Corporation) -> MsiExec.exe /I{06F2A7C5-19F0-4962-B8D2-A495B7DD2A30} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{12A718F2-2357-4D41-9E1F-18583A4745F7}] : (Acer UEIP Framework.-.Acer Incorporated) -> MsiExec.exe /i {12A718F2-2357-4D41-9E1F-18583A4745F7} PRODUCTNAME="Acer UEIP Framework" BRANDNAME="Acer" BOOTSTRATOR=1 [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1AF41E84-3408-499A-8C93-8891F0612719}] : (Acer Care Center.-.Acer Incorporated) -> Msiexec.exe /i {1AF41E84-3408-499A-8C93-8891F0612719} ACER=1 PRODUCTNAME="Acer Care Center" REMOVEUSEC=1 BOOTSTRATOR=1 [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1CEAC85D-2590-4760-800F-8DE5E91F3700}] : (Intel(R) Management Engine Components.-.Intel Corporation) -> "C:\ProgramData\Intel\Package Cache\{1CEAC85D-2590-4760-800F-8DE5E91F3700}\Setup.exe" -uninstall ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{205AE40D-8AD7-4F29-A430-DD2168DA562D}] : (Intel(R) Rapid Storage Technology.-.Intel Corporation) -> MsiExec.exe /I{205AE40D-8AD7-4F29-A430-DD2168DA562D} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}] : ( DriverSetupUtility.-.Acer Incorporated) -> Msiexec.exe /i {2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6} ACER=1 PRODUCTNAME=" DriverSetupUtility" REMOVEUSEC=1 BOOTSTRATOR=1 [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1] : (Avast SecureLine.-.AVAST Software) -> "C:\Program Files\AVAST Software\SecureLine\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3241744A-BA36-41F0-B4AA-EF3946D00632}] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{409CB30E-E457-4008-9B1A-ED1B9EA21140}] : (Intel(R) Rapid Storage Technology.-.Intel Corporation) -> "C:\ProgramData\Intel\Package Cache\{409CB30E-E457-4008-9B1A-ED1B9EA21140}\Setup.exe" -uninstall [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}] : (Acer Explorer Agent.-.Acer Incorporated) -> Msiexec.exe /i {4D0F42CF-1693-43D9-BDC8-19141D023EE0} ACER=1 PRODUCTNAME="Acer Explorer Agent" REMOVEUSEC=1 BOOTSTRATOR=1 ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{7D84E343-A23D-451C-B123-0195B2D903A6}] : (Intel® Trusted Connect Service Client.-.Intel Corporation) -> MsiExec.exe /I{7D84E343-A23D-451C-B123-0195B2D903A6} ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{8C91A5EB-2C62-4A6D-8802-CC79FD2ED390}] : (Intel(R) Chipset Device Software.-.Intel Corporation) -> MsiExec.exe /I{8C91A5EB-2C62-4A6D-8802-CC79FD2ED390} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{91F52DE4-B789-42B0-9311-A349F10E5479}] : (Acer Power Management.-.Acer Incorporated) -> MsiExec.exe /i {91F52DE4-B789-42B0-9311-A349F10E5479} PRODUCTNAME="Acer Power Management" BRANDNAME="Acer" NEWUPGRADE=0 BOOTSTRATOR=1 ISDT=0 [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}] : (Intel(R) Serial IO.-.Intel Corporation) -> "C:\ProgramData\Intel\Package Cache\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}\Setup.exe" -uninstall ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel] : (Panneau de configuration NVIDIA 376.54.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver] : (NVIDIA Pilote graphique 376.54.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.Driver [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience] : (NVIDIA GeForce Experience 2.5.11.45.-.NVIDIA Corporation) -> "C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.GFExperience ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus] : (NVIDIA Optimus Update 2.5.11.45.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX] : (NVIDIA Logiciel système PhysX 9.15.0428.-.NVIDIA Corporation) -> "C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.PhysX ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update] : (Mises à jour NVIDIA 2.5.11.45.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer] : (NVIDIA LED Visualizer 1.0.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv] : (SHIELD Streaming.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService] : (NVIDIA GeForce Experience Service.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service] : (NVIDIA Network Service.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer] : (NVIDIA Display Container.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS] : (NVIDIA Display Container LS.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay] : (NVIDIA ShadowPlay 2.5.11.45.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController] : (SHIELD Wireless Controller Driver.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core] : (NVIDIA Update Core.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver] : (NVIDIA Virtual Audio 1.2.30.-.NVIDIA Corporation) -> ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B4FF8C31-F307-4873-A244-BBC0233CAD4B}] : (Intel(R) Management Engine Components.-.Intel Corporation) -> MsiExec.exe /I{B4FF8C31-F307-4873-A244-BBC0233CAD4B} ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{CBD9BDB2-3126-4756-A03A-621CCF87C188}] : (Intel(R) Serial IO.-.Intel Corporation) -> MsiExec.exe /I{CBD9BDB2-3126-4756-A03A-621CCF87C188} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E3678E72-78E3-4F91-A9FB-913876FF6DA2}] : (Acer Quick Access.-.Acer Incorporated) -> MsiExec.exe /i {E3678E72-78E3-4F91-A9FB-913876FF6DA2} BOOTSTRATOR=1 GPRODUCTNAME="Acer Quick Access" BRANDNAME="Acer" ISDT=0 ##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{FD37351B-3074-4652-8188-1B3FB784EC4E}] : (Intel(R) ME UninstallLegacy.-.Intel Corporation) -> MsiExec.exe /I{FD37351B-3074-4652-8188-1B3FB784EC4E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Dashlane Upgrade Service] : (Dashlane Upgrade Service.-.Dashlane SAS) -> "C:\ProgramData\{6C65EBE1-72AC-48E2-A6B6-76C310D3B83A}\DashlaneUpgradeInstaller.exe" REMOVE=TRUE MODIFY=FALSE [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}] : (CyberLink PowerDVD 12.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\LeapPadExplorerPlugin] : (Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapReader Plugin).-.LeapFrog) -> MsiExec.exe /X{0BAE3575-4157-4059-BD93-0ACAD1758B30} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Mozilla Firefox 55.0.2 (x86 en-US)] : (Mozilla Firefox 55.0.2 (x86 en-US).-.Mozilla) -> "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MozillaMaintenanceService] : (Mozilla Maintenance Service.-.Mozilla) -> "C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MSC] : (McAfee LiveSafe.-.McAfee, Inc.) -> C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Picasa 3] : (Picasa 3.-.Google, Inc.) -> "C:\Program Files (x86)\Google\Picasa3\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\UPCShell] : (LeapFrog Connect (French).-.LeapFrog) -> C:\Program Files (x86)\LeapFrog\LeapFrog Connect\uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VLC media player] : (VLC media player.-.VideoLAN) -> C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangent wildgames Master Uninstall] : (WildTangent Games.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGameProvider-acer-genres] : (Game Explorer Categories - genres.-.WildTangent, Inc.) -> "C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - genres\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGameProvider-acer-main] : (Game Explorer Categories - main.-.WildTangent, Inc.) -> "C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - main\Uninstall.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-acer-vegasworld] : (Vegas World.-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\Web Link - Vegas World\Uninstall.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-acer-villagersandheroes] : (Villagers and Heroes.-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\Web Link - Villagers and Heroes\Uninstall.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-4527bc60-c537-4ef8-8c87-cc9539bb1241] : (Runefall.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Runefall\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-4c57b906-a5ca-4c03-9798-68e13f3261f1] : (Magic Academy.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Magic Academy\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-679326c7-f13f-4d56-ae2e-6a7fee2304c7] : (Jewel Match 3.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Jewel Match 3\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-6e35cc10-c9f5-48e9-baf9-e03aec7ff14d] : (Rory's Restaurant.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Rorys Restaurant\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-8d9b4f73-bb47-4fea-917d-c50dd2ffed5c] : (12 Labours of Hercules III: Girl Power.-.WildTangent) -> "C:\Program Files (x86)\WildGames\12 Labours of Hercules III Girl Power\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-ad853ef4-00ea-4eae-8b6e-18dee9cd5722] : (Jewel Match Snowscapes.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Jewel Match Snowscapes\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-d421feba-0407-4288-b40c-de6252d31e83] : (Polar Bowler 1st Frame.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Polar Bowler 1st Frame\uninstall\uninstaller.exe" ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-ff512562-ab4b-4aae-9e8c-1d09bd47ac58] : (Home Makeover.-.WildTangent) -> "C:\Program Files (x86)\WildGames\Home Makeover\uninstall\uninstaller.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{065E406C-5309-4CE8-9935-189A1EAE1004}] : (Amazon Assistant.-.Amazon) -> ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0BAE3575-4157-4059-BD93-0ACAD1758B30}] : (LeapFrog LeapReader Plugin.-.LeapFrog) -> MsiExec.exe /I{0BAE3575-4157-4059-BD93-0ACAD1758B30} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{13885028-098C-4799-9B71-27DAC96502D5}] : (abFiles.-.Acer Incorporated) -> C:\Program Files (x86)\Acer\abFiles\abFilesSetup.exe -uninstall ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App] : (Update Installer for WildTangent Games App.-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\App\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3241744A-BA36-41F0-B4AA-EF3946D00632}] : (Qualcomm Atheros QCA9377 Wireless LAN & Bluetooth Installer.-.Qualcomm Atheros) -> "C:\Program Files (x86)\InstallShield Installation Information\{3241744A-BA36-41F0-B4AA-EF3946D00632}\setup.exe" -runfromtemp -l0x040c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}] : (McAfee WebAdvisor.-.McAfee, Inc.) -> C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3C2F27D2-67A9-4B2A-AA2B-4A09553B3489}] : (LeapFrog Connect.-.LeapFrog) -> MsiExec.exe /X{3C2F27D2-67A9-4B2A-AA2B-4A09553B3489} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3DC26EA7-03E3-4353-9424-EEB7A34A7504}] : (eBay Worldwide.-.OEM) -> MsiExec.exe /I{3DC26EA7-03E3-4353-9424-EEB7A34A7504} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A37A114-702F-4055-A4B6-16571D4A5353}] : (AOP Framework.-.Acer Incorporated) -> C:\Program Files (x86)\Acer\AOP Framework\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4B230374-6475-4A73-BA6E-41015E9C5013}] : (Intel® Security Assist.-.Intel Corporation) -> MsiExec.exe /I{4B230374-6475-4A73-BA6E-41015E9C5013} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}] : (Realtek Card Reader.-.Realtek Semiconductor Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}\setup.exe" -runfromtemp -removeonly ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60c073df-e736-4210-9c3a-5fc2b651cef3}] : (Logiciel pour périphérique à chipset Intel®.-.Intel(R) Corporation) -> "C:\ProgramData\Package Cache\{60c073df-e736-4210-9c3a-5fc2b651cef3}\SetupChipset.exe" /uninstall ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer] : (WildTangent Games App.-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\Touchpoints\acer\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{710C99CC-218C-484C-900C-38CC408CEB4C}] : (Chromium.-.) -> "C:\Users\Emmanuelle\AppData\Local\{0DC33B9F-296B-5727-44F3-72CF609B8E57}\uninst.exe" -FN="C:\Users\Emmanuelle\AppData\Local\UpdateTask\Sync.exe"-P=/Uninstall /s /noun /DelSelfDir [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}] : (Realtek Ethernet Controller Driver.-.Realtek) -> C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A26EA9EF-0420-4657-AD7F-A4C9D67B63B6}] : (.-.) -> C:\ProgramData\{6C65EBE1-72AC-48E2-A6B6-76C310D3B83A}\DashlaneUpgradeInstaller.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A4023BDF-82D5-412D-9D58-8C2819EBFE2E}] : (Foxit PhantomPDF.-.Foxit Software Inc.) -> MsiExec.exe /X{A4023BDF-82D5-412D-9D58-8C2819EBFE2E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}] : (Acer Portal.-.Acer Incorporated) -> C:\Program Files (x86)\Acer\Acer Portal\uninstall.exe ##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}] : (CyberLink PowerDVD 12.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B5AD89F2-03D3-4206-8487-018298007DD0}] : (abPhoto.-.Acer Incorporated) -> C:\Program Files (x86)\Acer\abPhoto\abPhotoSetup.exe -uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}] : (Intel(R) Processor Graphics.-.Intel Corporation) -> "C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe" -uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}] : (Realtek High Definition Audio Driver.-.Realtek Semiconductor Corp.) -> C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709 [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FC965A47-4839-40CA-B618-18F486F042C6}] : (Skype™ 7.30.-.Skype Technologies S.A.) -> MsiExec.exe /X{FC965A47-4839-40CA-B618-18F486F042C6} ---------- | Ports ---------- | Installer [HKCR\Installer\Products\00006109C80000000000000000F01FEC] : Office 16 Click-to-Run Extensibility Component [HKCR\Installer\Products\00006109C800C0400000000000F01FEC] : Office 16 Click-to-Run Localization Component [HKCR\Installer\Products\00006109DD0000000100000000F01FEC] : Office 16 Click-to-Run Extensibility Component 64-bit Registration [HKCR\Installer\Products\00006109F80000000100000000F01FEC] : Office 16 Click-to-Run Licensing Component [HKCR\Installer\Products\13C8FF4B703F37842A44BB0C32C3DAB4] : Intel(R) Management Engine Components [HKCR\Installer\Products\27E8763E3E8719F49ABF198367FFD62A] : Acer Quick Access [HKCR\Installer\Products\2BDB9DBC621365740AA326C1FC781C88] : Intel(R) Serial IO [HKCR\Installer\Products\2D72F2C39A76A2B4AAB2A49055B34398] : LeapFrog Connect [HKCR\Installer\Products\2F817A21753214D4E9F18185A374547F] : Acer UEIP Framework -> C:\Windows\Installer\{12A718F2-2357-4D41-9E1F-18583A4745F7}\ProductIconIco [HKCR\Installer\Products\2F98DA5B3D306024487810288900D70D] : abPhoto -> C:\Windows\Installer\{B5AD89F2-03D3-4206-8487-018298007DD0}\icon.ico [HKCR\Installer\Products\343E48D7D32AC1541B3210592B9D306A] : Intel® Trusted Connect Service Client [HKCR\Installer\Products\411A73A4F20755044A6B6175D1A43535] : AOP Framework -> C:\Windows\Installer\{4A37A114-702F-4055-A4B6-16571D4A5353}\icon.ico [HKCR\Installer\Products\473032B4574637A4ABE61410E5C90531] : Intel® Security Assist -> C:\Windows\Installer\{4B230374-6475-4A73-BA6E-41015E9C5013}\isa.ico [HKCR\Installer\Products\48E14FA18043A994C83988190F167291] : Care Center -> C:\Windows\Installer\{1AF41E84-3408-499A-8C93-8891F0612719}\icon.ico [HKCR\Installer\Products\4B8898265AF36AE4AB3AAD46F07681DB] : -> C:\Windows\Installer\{628988B4-3FA5-4EA6-BAA3-DA640F6718BD}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4ED25F19987B0B2439113A941FE04597] : Acer Power Management [HKCR\Installer\Products\5753EAB075149504DB39A0AC1D57B803] : LeapFrog LeapReader Plugin [HKCR\Installer\Products\5C7A2F600F9126948B2D4A597BDDA203] : Intel(R) Management Engine Components [HKCR\Installer\Products\63AEB64B17B0E4A4EA1478426134AFA0] : PowerDVD -> C:\Windows\Installer\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}\ARPPRODUCTICON.exe [HKCR\Installer\Products\71B0DA5AD43FEB941A758C3B5DA2DC31] : Acer Portal -> C:\Windows\Installer\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}\icon.ico [HKCR\Installer\Products\74A569CF9384AC046B81814F680F246C] : Skype™ 7.30 -> C:\WINDOWS\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe [HKCR\Installer\Products\75B373813CF4A1B4593B7A5ECD5A777F] : Qualcomm Atheros Setup -> C:\Windows\Installer\{18373B57-4FC3-4B1A-95B3-A7E5DCA577F7}\ARPPRODUCTICON.exe [HKCR\Installer\Products\7AE62CD33E3035344942EE7B3AA45740] : eBay Worldwide -> c:\Windows\Installer\{3DC26EA7-03E3-4353-9424-EEB7A34A7504}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\818DCFD4A63092246AD7FC71CD64D129] : Windows 10 Update and Privacy Settings [HKCR\Installer\Products\82058831C8909974B91772AD9C56205D] : abFiles -> C:\Windows\Installer\{13885028-098C-4799-9B71-27DAC96502D5}\icon.ico [HKCR\Installer\Products\93941D9F2971BA44C8352F8035C45284] : UpdateAssistant [HKCR\Installer\Products\99E80CA9B0328e74791254777B1F42AE] : [HKCR\Installer\Products\A38C15B2D5649AE4C9CDE19DE50DA96C] : DriverSetupUtility -> C:\Windows\Installer\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}\Bitmaps\Registration.ico [HKCR\Installer\Products\A98660DE7B3353D4F867638AC20D4360] : KB4023057 [HKCR\Installer\Products\B15373DF470325641888B1F37B48CEE4] : Intel(R) ME UninstallLegacy [HKCR\Installer\Products\BE5A19C826C2D6A48820CC97DFE23D09] : Intel(R) Chipset Device Software [HKCR\Installer\Products\C604E56090358EC4995381A9E1EA0140] : Amazon Assistant -> C:\WINDOWS\Installer\{065E406C-5309-4CE8-9935-189A1EAE1004}\installIcon.exe [HKCR\Installer\Products\D04EA5027DA892F44A03DD1286AD65D2] : Intel(R) Rapid Storage Technology [HKCR\Installer\Products\FC24F0D439619D34DB8C9141D120E30E] : Explorer Agent -> C:\Windows\Installer\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}\Bitmaps\Registration.ico [HKCR\Installer\Products\FDB3204A5D28D214D985C88291BEEFE2] : Foxit PhantomPDF -> C:\Windows\Installer\{A4023BDF-82D5-412D-9D58-8C2819EBFE2E}\IconName.exe ---------- | ADS ---------- | Drives Disk: 0 Size=954G Pos MBRndx Type/Name Size Active Hide Start Sector Sectors --- ------ ---------- ---- ------ ---- ------------ ------------ 0 0 EE-UNKNWN 21.0T No No 1 294,967,295 ---------- | MBR Windows Version: Windows Information: (build 9200), 64-bit Base Board Manufacturer: Acer BIOS Manufacturer: Insyde Corp. System Manufacturer: Acer System Product Name: Aspire E5-573G Logical Drives Mask: 0x0000000c Analysis of file "C:\QuickDiag\MBR.bin": Unknown MBR code 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog Le programme QuickDiag.exe version 1.7.17.1 a cessé d'interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l'historique du problème dans le panneau de configuration Sécurité et maintenance. ID de processus : 2b3c Heure de début : 01d31f729d358bf5 Heure de fin : 4294967295 Chemin d'accès de l'application : C:\Users\Emmanuelle\Desktop\QuickDiag.exe ID de rapport : c48d00f8-8b67-11e7-9bde-54ab3a5dc86f Nom complet du package défaillant : ID de l'application relative au package défaillant : ------------ ------------ Échec de la procédure d’ouverture pour le service « .NETFramework » dans la DLL « C:\WINDOWS\system32\mscoree.dll ». Les données de performance de ce service ne seront pas disponibles. Le premier mot (DWORD) de la section Données contient le code d’erreur. ------------ Échec de la procédure d’ouverture pour le service « .NETFramework » dans la DLL « C:\WINDOWS\system32\mscoree.dll ». Les données de performance de ce service ne seront pas disponibles. Le premier mot (DWORD) de la section Données contient le code d’erreur. ------------ ------------ Le package Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue. ------------ Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Protocole LLDP (Link Layer Discovery Protocol) Microsoft. System Error: Accès refusé. . ------------ Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Protocole LLDP (Link Layer Discovery Protocol) Microsoft. System Error: Accès refusé. . ------------ Nom de l’application défaillante firefox.exe, version : 54.0.1.6388, horodatage : 0x591d55d1 Nom du module défaillant : xul.dll, version : 54.0.1.6388, horodatage : 0x591d59fb Code d’exception : 0xc0000005 Décalage d’erreur : 0x00218d0e ID du processus défaillant : 0x3788 Heure de début de l’application défaillante : 0x01d31ddbd279c252 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Mozilla Firefox\firefox.exe Chemin d’accès du module défaillant: C:\Program Files (x86)\Mozilla Firefox\xul.dll ID de rapport : 9d34218e-68ae-4a8d-a63e-ec33bf061d7b Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Nom de l’application défaillante MicrosoftEdge.exe, version : 11.0.14393.1066, horodatage : 0x58d9f0a2 Nom du module défaillant : eModel.dll, version : 11.0.14393.1066, horodatage : 0x58d9f20b Code d’exception : 0xc0000409 Décalage d’erreur : 0x00000000000d4800 ID du processus défaillant : 0x3ac Heure de début de l’application défaillante : 0x01d2fcc9db0f048f Chemin d’accès de l’application défaillante : C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe Chemin d’accès du module défaillant: C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll ID de rapport : 50297496-325e-4373-9639-ac519dc7ad2d Nom complet du package défaillant : Microsoft.MicrosoftEdge_38.14393.1066.0_neutral__8wekyb3d8bbwe ID de l’application relative au package défaillant : MicrosoftEdge ------------ Le package Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue. ------------ Nom de l’application défaillante svchost.exe_MapsBroker, version : 10.0.14393.0, horodatage : 0x57899b1c Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0x8400000e Décalage d’erreur : 0x0000000000000000 ID du processus défaillant : 0x1d90 Heure de début de l’application défaillante : 0x01d2fcc823afa72a Chemin d’accès de l’application défaillante : C:\WINDOWS\System32\svchost.exe Chemin d’accès du module défaillant: unknown ID de rapport : a260142a-d0dc-4ded-b048-6166611e2923 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Le package Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue. ------------ Le package Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue. ------------ Le package Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy+CortanaUI a été interrompu, car sa suspension a été trop longue. ------------ Nom de l’application défaillante NvStreamNetworkService.exe, version : 4.1.1974.1729, horodatage : 0x559bb830 Nom du module défaillant : ntdll.dll, version : 10.0.14393.479, horodatage : 0x5825887f Code d’exception : 0xc0000005 Décalage d’erreur : 0x0000000000030bdd ID du processus défaillant : 0x3098 Heure de début de l’application défaillante : 0x01d2c9bed8030e75 Chemin d’accès de l’application défaillante : C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : a97dc60a-dbee-4182-90b0-bc9b3d98b2b2 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Nom de l’application défaillante svchost.exe_ProfSvc, version : 10.0.14393.0, horodatage : 0x57899b1c Nom du module défaillant : combase.dll, version : 10.0.14393.576, horodatage : 0x584a7796 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00000000000b071c ID du processus défaillant : 0x308 Heure de début de l’application défaillante : 0x01d2c57bf3209f4c Chemin d’accès de l’application défaillante : C:\WINDOWS\system32\svchost.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\combase.dll ID de rapport : 83139ef7-5b22-4681-9b0f-abbc784d0056 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Nom de l’application défaillante mcshield.exe, version : 1.5.0.2512, horodatage : 0x587cd5e2 Nom du module défaillant : mcshield.exe, version : 1.5.0.2512, horodatage : 0x587cd5e2 Code d’exception : 0xc0000005 Décalage d’erreur : 0x0000000000039530 ID du processus défaillant : 0xba0 Heure de début de l’application défaillante : 0x01d2c57c1e9a3f0f Chemin d’accès de l’application défaillante : C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe Chemin d’accès du module défaillant: C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe ID de rapport : 69f5a735-4f06-41e7-afd6-ff3b2c6ff656 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ McShield crashed. Error Code:c0000005 ------------ ----------( EOF)---------- - 6270 | 23:02:54