--------------- QuickDiag | g3n-h@ckm@n | V3_22.10.17.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 14/12/2017 16:37:14 Updated 22/10/2017 | 08.35 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [Maxime (Administrator)] - [JACK] (S-1-5-21-60461441-1236719898-3972887004-1001) System: Microsoft Windows 10 Famille - - (10.0.15063) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> (1703) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Famille|C:\WINDOWS|\Device\Harddisk0\Partition5 Boot : Normal boot PC: 2182 - LENOVO - IdNumber: 2957963800819 - UUID: 4812025C-9CFC-E111-83C6-B888E3849CC3 Processor : X64 - 2095 Mhz - Intel(R) Pentium(R) CPU B950 @ 2.10GHz 5ECN92WW(V8.04) - en|US|iso8859-1 - LENOVO - S/N: 2957963800819 - 5ECN92WW(V8.04) - LENOVO - 1 CoreTemp : 49 Celsius ----------| Quick ---------- | SoundDevice Son Intel(R) pour écrans - Status: OK - Manufacturer: Intel(R) Corporation - PNPDeviceID: HDAUDIO\FUNC_01&VEN_8086&DEV_2806&SUBSYS_80860101&REV_1000\4&3A3FC0BE&0&0301 Conexant SmartAudio HD - Status: OK - Manufacturer: Conexant - PNPDeviceID: HDAUDIO\FUNC_01&VEN_14F1&DEV_506E&SUBSYS_17AAC025&REV_1000\4&3A3FC0BE&0&0001 ---------- | Video Intel(R) HD Graphics - Resolution: 1600x900 - Colors: 4294967296 - RefreshRate: 60 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: igdumd64.dll,igd10umd64.dll,igd10umd64.dll,igdumd32,igd10umd32,igd10umd32 - PNPDeviceID: PCI\VEN_8086&DEV_0106&SUBSYS_397717AA&REV_09\3&11583659&0&10 - AdapterCompatibility: Intel Corporation - RAM: 1874735104 Inegrated Video Chipset DeviceName: Intel(R) HD Graphics - DriverVersion: 9.17.10.4459 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 28160 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42488 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35760 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35208 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 84992 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 53760 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK ---------- | CPU ---------- | Network Microsoft Kernel Debug Network Adapter - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000 Carte réseau sans fil Qualcomm Atheros AR9485WB-EG - Ethernet 802.3 - Qualcomm Atheros Communications Inc. - Status: - PnPID : PCI\VEN_168C&DEV_0032&SUBSYS_321817AA&REV_01\4&18901DAC&0&00E1 Contrôleur Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet (NDIS 6.30) - Ethernet 802.3 - Qualcomm Atheros - Status: - PnPID : PCI\VEN_1969&DEV_1090&SUBSYS_397917AA&REV_08\4&8F8BD4C&0&00E0 Microsoft Wi-Fi Direct Virtual Adapter - - - Status: - PnPID : Carte virtuelle directe Wi-Fi Microsoft - Ethernet 802.3 - Microsoft - Status: - PnPID : {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_WFD\5&39D39B29&0&01 WAN Miniport (SSTP) - - - Status: - PnPID : WAN Miniport (IKEv2) - - - Status: - PnPID : WAN Miniport (L2TP) - - - Status: - PnPID : WAN Miniport (PPTP) - - - Status: - PnPID : WAN Miniport (PPPOE) - - - Status: - PnPID : WAN Miniport (IP) - - - Status: - PnPID : WAN Miniport (IPv6) - - - Status: - PnPID : WAN Miniport (Network Monitor) - - - Status: - PnPID : ---------- | Memory RAM = Total (MB) : 4055 | Free (MB) : 2146 Pagefile = Total (MB) : 5103 | Free (MB) : 3005 Virtual = Total (MB) : 4194 | Free (MB) : 3920 Physical Memory 0 : Capacity: 4294967296 - DIMM0 - Posit.: 1 - Manufacturer: Unknown - PartNumber: RMT3160ED58E9W1600 - S/N: 4191C078 ---------- | SID Users Administrateur : [S-1-5-21-60461441-1236719898-3972887004-500] DefaultAccount : [S-1-5-21-60461441-1236719898-3972887004-503] HomeGroupUser$ : [S-1-5-21-60461441-1236719898-3972887004-1048] Invité : [S-1-5-21-60461441-1236719898-3972887004-501] Maxime : [S-1-5-21-60461441-1236719898-3972887004-1001] Administrateurs : [S-1-5-32-544] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux dÂévénements : [S-1-5-32-573] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de lÂAnalyseur de performances : [S-1-5-32-558] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] HomeUsers : [S-1-5-21-60461441-1236719898-3972887004-1047] WinRMRemoteWMIUsers__ : [S-1-5-21-60461441-1236719898-3972887004-1000] ---------- | SystemAccounts Name: Tout le monde - SID: S-1-1-0 - SIDType: 5 - Status: OK Name: LOCAL - SID: S-1-2-0 - SIDType: 5 - Status: OK Name: CREATEUR PROPRIETAIRE - SID: S-1-3-0 - SIDType: 5 - Status: OK Name: GROUPE CREATEUR - SID: S-1-3-1 - SIDType: 5 - Status: OK Name: CREATOR OWNER SERVER - SID: S-1-3-2 - SIDType: 5 - Status: OK Name: CREATOR GROUP SERVER - SID: S-1-3-3 - SIDType: 5 - Status: OK Name: DROITS DU PROPRIÃTAIRE - SID: S-1-3-4 - SIDType: 5 - Status: OK Name: LIGNE - SID: S-1-5-1 - SIDType: 5 - Status: OK Name: RESEAU - SID: S-1-5-2 - SIDType: 5 - Status: OK Name: TACHE - SID: S-1-5-3 - SIDType: 5 - Status: OK Name: INTERACTIF - SID: S-1-5-4 - SIDType: 5 - Status: OK Name: SERVICE - SID: S-1-5-6 - SIDType: 5 - Status: OK Name: ANONYMOUS LOGON - SID: S-1-5-7 - SIDType: 5 - Status: OK Name: Proxy - SID: S-1-5-8 - SIDType: 5 - Status: OK Name: Système - SID: S-1-5-18 - SIDType: 5 - Status: OK Name: ENTERPRISE DOMAIN CONTROLLERS - SID: S-1-5-9 - SIDType: 5 - Status: OK Name: SELF - SID: S-1-5-10 - SIDType: 5 - Status: OK Name: Utilisateurs authentifiés - SID: S-1-5-11 - SIDType: 5 - Status: OK Name: RESTRICTED - SID: S-1-5-12 - SIDType: 5 - Status: OK Name: UTILISATEUR TERMINAL SERVER - SID: S-1-5-13 - SIDType: 5 - Status: OK Name: REMOTE INTERACTIVE LOGON - SID: S-1-5-14 - SIDType: 5 - Status: OK Name: IUSR - SID: S-1-5-17 - SIDType: 5 - Status: OK Name: SERVICE LOCAL - SID: S-1-5-19 - SIDType: 5 - Status: OK Name: SERVICE RÃSEAU - SID: S-1-5-20 - SIDType: 5 - Status: OK Name: BUILTIN - SID: S-1-5-32 - SIDType: 3 - Status: OK ---------- | Drives C:\ -> [Fixed] | [Windows8_OS] | Total : 883.74 Go | Free : 437.96 Go -> NTFS [SATA] D:\ -> [Fixed] | [LENOVO] | Total : 25 Go | Free : 24.86 Go -> NTFS [SATA] DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 6 Part. - PnPID : SCSI\DISK&VEN_ATA&PROD_ST1000LM024_HN-M\4&3359EDDD&0&000000 ---------- | Windows updates Test 1 : Windows Is Activated ---------- | Browsers IE : 11.0.15063.608 (© Microsoft Corporation. Tous droits réservés.) FF : 57.0.1.6541 (©Firefox and Mozilla Developers; available under the MPL 2 license.) GC : 63.0.3239.84 (Copyright 2016 Google Inc.) Default : "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "" ---------- | FlashPlayer FlashPlayer ActiveX : 28.0.0.126 FlashPlayer Plugin : 28.0.0.126 ---------- | Security AV : Windows Defender Enabled AS : Windows Defender Enabled FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Manual(3)] = Running AS: Windows Defender [Auto(2)] = Running WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 376 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.15063.0) = C:\Windows\System32\smss.exe [18/03/2017 21:57:38] --> Command Line : 548 | [Owner : Système | Parent : 536() | ?????] - (.Microsoft Corporation - Processus dÂexécution client-serveur.) - (10.0.15063.0) = C:\Windows\System32\csrss.exe [18/03/2017 21:57:38] --> Command Line : 620 | [Owner : Système | Parent : 536() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.15063.502) = C:\Windows\System32\wininit.exe [16/09/2017 07:38:44] --> Command Line : 692 | [Owner : Système | Parent : 620(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.15063.502) = C:\Windows\System32\services.exe [15/09/2017 17:54:08] --> Command Line : 700 | [Owner : Système | Parent : 620(wininit.exe) | 12.69 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.15063.674) = C:\Windows\System32\lsass.exe [11/10/2017 13:55:04] --> Command Line : 820 | [Owner : Système | Parent : 692(services.exe) | 3.47 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 828 | [Owner : UMFD-0 | Parent : 620(wininit.exe) | 2.76 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.15063.608) = C:\Windows\System32\fontdrvhost.exe [16/09/2017 07:59:58] --> Command Line : 936 | [Owner : Système | Parent : 692(services.exe) | 24.62 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 984 | [Owner : SERVICE RÃSEAU | Parent : 692(services.exe) | 11.47 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 64 | [Owner : Système | Parent : 692(services.exe) | 6.07 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1028 | [Owner : Système | Parent : 692(services.exe) | 5.34 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1064 | [Owner : Système | Parent : 692(services.exe) | 8.95 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1084 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 21.55 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1160 | [Owner : Système | Parent : 692(services.exe) | 14.67 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1184 | [Owner : SERVICE LOCAL | Parent : 1028(svchost.exe) | 5.23 Mo] - (.Microsoft Corporation - Windows Driver Foundation - Processus hôte de lÂinfrastructure de pilotes en mode utilisateur.) - (10.0.15063.0) = C:\Windows\System32\WUDFHost.exe [18/03/2017 21:57:38] --> Command Line : 1204 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 7.76 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1288 | [Owner : Système | Parent : 692(services.exe) | 10.12 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1340 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 16.33 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1492 | [Owner : Système | Parent : 692(services.exe) | 5.42 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1504 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 7.52 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1520 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 7.24 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1568 | [Owner : Système | Parent : 692(services.exe) | 7.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1608 | [Owner : Système | Parent : 692(services.exe) | 11.12 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1672 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 6.88 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1708 | [Owner : Système | Parent : 692(services.exe) | 8.08 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1796 | [Owner : Système | Parent : 692(services.exe) | 7.35 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1804 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 7.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1812 | [Owner : SERVICE RÃSEAU | Parent : 692(services.exe) | 11.1 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1948 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 11.06 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1968 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 8.59 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2044 | [Owner : SERVICE RÃSEAU | Parent : 692(services.exe) | 7.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1080 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 5.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1632 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 10.5 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2224 | [Owner : Système | Parent : 692(services.exe) | 12.13 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2292 | [Owner : Système | Parent : 692(services.exe) | 12.78 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2428 | [Owner : Système | Parent : 692(services.exe) | 13.56 Mo] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.15063.608) = C:\Windows\System32\spoolsv.exe [15/09/2017 17:53:54] --> Command Line : 2520 | [Owner : SERVICE RÃSEAU | Parent : 692(services.exe) | 7.31 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2548 | [Owner : Système | Parent : 692(services.exe) | 5.92 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2660 | [Owner : Système | Parent : 692(services.exe) | 6.42 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2724 | [Owner : SERVICE LOCAL | Parent : 2660(svchost.exe) | 8.1 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (10.0.15063.0) = C:\Windows\System32\dasHost.exe [18/03/2017 21:57:46] --> Command Line : 2816 | [Owner : SERVICE RÃSEAU | Parent : 692(services.exe) | 11.66 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2824 | [Owner : Système | Parent : 692(services.exe) | 6.04 Mo] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - (1.824.23.7067) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [19/07/2017 22:50:40] --> Command Line : 2832 | [Owner : Système | Parent : 692(services.exe) | 7.4 Mo] - (.Conexant Systems Inc. - Conexant Audio Message Service.) - (1.12.0.0) = C:\Windows\System32\CxAudMsg64.exe [23/07/2017 13:12:08] --> Command Line : 2852 | [Owner : Système | Parent : 692(services.exe) | 24.3 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2876 | [Owner : Système | Parent : 692(services.exe) | 6.77 Mo] - (.Nuance Communications, Inc. - Dragon NaturallySpeaking Service.) - (11.0.200.90) = C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [12/08/2010 16:06:46] --> Command Line : 2884 | [Owner : Système | Parent : 692(services.exe) | 4.94 Mo] - (.Seiko Epson Corporation - Epson Scanner Service (64bit).) - (1.1.0.1) = C:\Windows\System32\escsvc64.exe [29/05/2014 15:41:49] --> Command Line : 2904 | [Owner : Système | Parent : 692(services.exe) | 6.39 Mo] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Interface.) - (1.24.388.1) = C:\Program Files\Intel\iCLS Client\HeciServer.exe [20/04/2012 13:16:12] --> Command Line : 2912 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 6.16 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2920 | [Owner : Système | Parent : 692(services.exe) | 5.5 Mo] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host Interface.) - (8.1.0.1252) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [25/09/2012 07:55:05] --> Command Line : 2944 | [Owner : Système | Parent : 692(services.exe) | 14.63 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2952 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 24.13 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2984 | [Owner : Système | Parent : 692(services.exe) | 8.27 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3012 | [Owner : Système | Parent : 692(services.exe) | 8.13 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3056 | [Owner : Système | Parent : 692(services.exe) | ?????] - (.Microsoft Corporation - Windows Security Health Service.) - (4.11.15063.674) = C:\Windows\System32\SecurityHealthService.exe [11/10/2017 13:55:50] --> Command Line : 2068 | [Owner : Système | Parent : 692(services.exe) | 7.54 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 2220 | [Owner : Système | Parent : 692(services.exe) | 4.2 Mo] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - (19.0.9.5) = C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [03/06/2015 02:16:46] --> Command Line : 2440 | [Owner : Système | Parent : 692(services.exe) | 8.04 Mo] - (.Reason Software Company Inc. - Unchecky Service.) - (1.1.0.0) = C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [04/10/2017 18:07:43] --> Command Line : 2240 | [Owner : Système | Parent : 692(services.exe) | 36.66 Mo] - (.- SPWindowsService.) - (1.0.0.0) = C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28/10/2017 10:41:39] --> Command Line : 2760 | [Owner : Système | Parent : 692(services.exe) | 6.88 Mo] - (.Atheros - Atheros Coex Service Application.) - (8.0.0.255) = C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [19/08/2012 20:13:26] --> Command Line : 3108 | [Owner : Système | Parent : 692(services.exe) | 18.33 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3116 | [Owner : Système | Parent : 692(services.exe) | 16.96 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3124 | [Owner : Système | Parent : 692(services.exe) | 5.26 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3132 | [Owner : Système | Parent : 692(services.exe) | 41.54 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3140 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 8.12 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3284 | [Owner : Système | Parent : 692(services.exe) | ?????] - (.Microsoft Corporation - Antimalware Service Executable.) - (4.12.17007.17123) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe [12/12/2017 10:02:58] --> Command Line : 3348 | [Owner : Système | Parent : 692(services.exe) | 29.93 Mo] - (.Malwarebytes - Malwarebytes Service.) - (3.1.0.556) = C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [14/09/2017 16:10:27] --> Command Line : 3396 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 4.99 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3596 | [Owner : Système | Parent : 692(services.exe) | 12.53 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3656 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 8.47 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3868 | [Owner : Système | Parent : 692(services.exe) | 6.4 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3960 | [Owner : SERVICE RÃSEAU | Parent : 692(services.exe) | 6.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 4868 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | ?????] - (.Microsoft Corporation - Microsoft Network Realtime Inspection Service.) - (4.12.17007.17123) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe [12/12/2017 10:02:58] --> Command Line : 2036 | [Owner : Système | Parent : 692(services.exe) | 13.93 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 6056 | [Owner : Système | Parent : 692(services.exe) | 5.57 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 6084 | [Owner : Système | Parent : 692(services.exe) | 21.41 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 4944 | [Owner : Système | Parent : 692(services.exe) | 13.52 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3280 | [Owner : Système | Parent : 4648() | 0.09 Mo] - (.Google Inc. - Google Crash Handler.) - (1.3.33.7) = C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe [16/11/2017 18:42:00] --> Command Line : 1640 | [Owner : Système | Parent : 692(services.exe) | 5.7 Mo] - (.Intel Corporation - Local Manageability Service.) - (8.1.0.1252) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [25/09/2012 07:54:39] --> Command Line : 5288 | [Owner : Système | Parent : 4648() | 0.63 Mo] - (.Google Inc. - Google Crash Handler.) - (1.3.33.7) = C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe [16/11/2017 18:42:00] --> Command Line : 3836 | [Owner : Système | Parent : 692(services.exe) | 22.1 Mo] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.15063.413) = C:\Windows\System32\SearchIndexer.exe [23/07/2017 13:44:45] --> Command Line : 6524 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 8.04 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 5672 | [Owner : Système | Parent : 692(services.exe) | 10.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1156 | [Owner : Système | Parent : 692(services.exe) | 16.22 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 6540 | [Owner : Système | Parent : 692(services.exe) | 12.52 Mo] - (.Intel Corporation - User Notification Service.) - (8.1.0.1252) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [25/09/2012 07:55:00] --> Command Line : 3872 | [Owner : Système | Parent : 692(services.exe) | 42.12 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 7820 | [Owner : Système | Parent : 5504() | ?????] - (.Microsoft Corporation - Processus dÂexécution client-serveur.) - (10.0.15063.0) = C:\Windows\System32\csrss.exe [18/03/2017 21:57:38] --> Command Line : 6396 | [Owner : Système | Parent : 5504() | 8.58 Mo] - (.Microsoft Corporation - Application dÂouverture de session Windows.) - (10.0.15063.608) = C:\Windows\System32\winlogon.exe [16/09/2017 07:38:45] --> Command Line : 8696 | [Owner : DWM-2 | Parent : 6396(winlogon.exe) | 39.92 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (10.0.15063.0) = C:\Windows\System32\dwm.exe [18/03/2017 21:58:21] --> Command Line : 5180 | [Owner : UMFD-2 | Parent : 6396(winlogon.exe) | 5.26 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.15063.608) = C:\Windows\System32\fontdrvhost.exe [16/09/2017 07:59:58] --> Command Line : 7756 | [Owner : SERVICE LOCAL | Parent : 692(services.exe) | 6.41 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 7084 | [Owner : Système | Parent : 692(services.exe) | 7.03 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 8616 | [Owner : Maxime | Parent : 3348(MBAMService.exe) | 27.29 Mo] - (.Malwarebytes - Malwarebytes Tray Application.) - (3.0.0.1208) = C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [14/09/2017 16:10:20] --> Command Line : 5476 | [Owner : Maxime | Parent : 2220(SynTPEnhService.exe) | 21.45 Mo] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) - (19.0.9.5) = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [03/06/2015 02:16:46] --> Command Line : 2940 | [Owner : Maxime | Parent : 2440(unchecky_svc.exe) | 8.78 Mo] - (.Reason Software Company Inc. - Unchecky Background Process.) - (1.1.0.0) = C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe [04/10/2017 18:07:43] --> Command Line : 7120 | [Owner : Maxime | Parent : 692(services.exe) | 18.01 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 228 | [Owner : Maxime | Parent : 1568(svchost.exe) | 21.57 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.15063.0) = C:\Windows\System32\sihost.exe [18/03/2017 21:58:10] --> Command Line : 1628 | [Owner : Maxime | Parent : 692(services.exe) | 25.16 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 7504 | [Owner : Maxime | Parent : 6068() | 4.63 Mo] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (19.0.9.5) = C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [03/06/2015 02:16:48] --> Command Line : 1868 | [Owner : Maxime | Parent : 1160(svchost.exe) | 19.28 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.15063.0) = C:\Windows\System32\taskhostw.exe [18/03/2017 21:57:57] --> Command Line : 3740 | [Owner : Maxime | Parent : 4700() | 84.64 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.15063.674) = C:\Windows\explorer.exe [11/10/2017 13:54:19] --> Command Line : 6248 | [Owner : Système | Parent : 692(services.exe) | 18.31 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 9172 | [Owner : Système | Parent : 692(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 8508 | [Owner : Maxime | Parent : 1160(svchost.exe) | 3.01 Mo] - (.CyberLink - YouCam Mirage.) - (1.0.0.629) = C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [27/07/2012 10:52:44] --> Command Line : 4836 | [Owner : Maxime | Parent : 692(services.exe) | 24.38 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 5056 | [Owner : Maxime | Parent : 5948() | 0.59 Mo] - (.Lenovo - Lenovo Solution Center Notifications.) - (1.1.0.0) = C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [07/12/2016 13:00:36] --> Command Line : 1960 | [Owner : Maxime | Parent : 936(svchost.exe) | 13.95 Mo] - (.Microsoft Corporation - InstallAgent.) - (10.0.15063.502) = C:\Windows\System32\InstallAgent.exe [16/09/2017 07:36:42] --> Command Line : 9104 | [Owner : Maxime | Parent : 936(svchost.exe) | 12.18 Mo] - (.Microsoft Corporation - InstallAgentUserBroker.) - (10.0.15063.502) = C:\Windows\System32\InstallAgentUserBroker.exe [16/09/2017 07:36:43] --> Command Line : 7540 | [Owner : Maxime | Parent : 936(svchost.exe) | 88.26 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.15063.332) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe [23/07/2017 13:44:58] --> Command Line : 2996 | [Owner : Maxime | Parent : 936(svchost.exe) | 69.14 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.15063.0) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe [18/03/2017 21:56:41] --> Command Line : 1276 | [Owner : Maxime | Parent : 936(svchost.exe) | 10.21 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.15063.0) = C:\Windows\System32\RuntimeBroker.exe [18/03/2017 21:58:01] --> Command Line : 2092 | [Owner : Maxime | Parent : 936(svchost.exe) | 37.44 Mo] - (.Microsoft Corporation - SmartScreen.) - (10.0.15063.674) = C:\Windows\System32\smartscreen.exe [11/10/2017 13:54:17] --> Command Line : 5880 | [Owner : Système | Parent : 3836(SearchIndexer.exe) | 11.33 Mo] - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) - (7.0.15063.447) = C:\Windows\System32\SearchProtocolHost.exe [23/07/2017 13:56:57] --> Command Line : 5696 | [Owner : SERVICE LOCAL | Parent : 1948(svchost.exe) | 15.7 Mo] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (10.0.15063.447) = C:\Windows\System32\audiodg.exe [23/07/2017 13:57:00] --> Command Line : 6652 | [Owner : Maxime | Parent : 632() | 174.18 Mo] - (.Mozilla Corporation - Firefox.) - (57.0.1.6541) = C:\Program Files (x86)\Mozilla Firefox\firefox.exe [27/05/2014 14:28:44] --> Command Line : 3324 | [Owner : Maxime | Parent : 6652(firefox.exe) | 46.15 Mo] - (.Mozilla Corporation - Firefox.) - (57.0.1.6541) = C:\Program Files (x86)\Mozilla Firefox\firefox.exe [27/05/2014 14:28:44] --> Command Line : 6976 | [Owner : Maxime | Parent : 6652(firefox.exe) | 141.12 Mo] - (.Mozilla Corporation - Firefox.) - (57.0.1.6541) = C:\Program Files (x86)\Mozilla Firefox\firefox.exe [27/05/2014 14:28:44] --> Command Line : 7544 | [Owner : Maxime | Parent : 6652(firefox.exe) | 71.78 Mo] - (.Mozilla Corporation - Firefox.) - (57.0.1.6541) = C:\Program Files (x86)\Mozilla Firefox\firefox.exe [27/05/2014 14:28:44] --> Command Line : 6160 | [Owner : Système | Parent : 692(services.exe) | 5.62 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 1020 | [Owner : Système | Parent : 692(services.exe) | 15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 3148 | [Owner : Maxime | Parent : 1160(svchost.exe) | 6.81 Mo] - (.- LSC.Services.UpdateStatusService.) - (3.4.2.6) = C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.UpdateStatusService.exe [07/12/2016 13:00:56] --> Command Line : 1876 | [Owner : Système | Parent : 692(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe [18/03/2017 21:58:21] --> Command Line : 8884 | [Owner : SERVICE RÃSEAU | Parent : 936(svchost.exe) | 12.23 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.0) = C:\Windows\System32\wbem\WmiPrvSE.exe [18/03/2017 21:58:01] --> Command Line : 6844 | [Owner : Système | Parent : 3836(SearchIndexer.exe) | 8.54 Mo] - (.Microsoft Corporation - Microsoft Windows Search Filter Host.) - (7.0.15063.0) = C:\Windows\System32\SearchFilterHost.exe [18/03/2017 21:58:18] --> Command Line : 2620 | [Owner : Maxime | Parent : 1160(svchost.exe) | 7 Mo] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) - (1.824.23.7067) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [19/07/2017 22:50:40] --> Command Line : 172 | [Owner : Maxime | Parent : 6652(firefox.exe) | 41.79 Mo] - (.SosVirus - QuickDiag.) - (22.10.17.1) = C:\Users\Maxime\Downloads\QuickDiag.exe [14/12/2017 16:34:37] --> Command Line : 1564 | [Owner : Système | Parent : 936(svchost.exe) | 9.06 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.0) = C:\Windows\System32\wbem\WmiPrvSE.exe [18/03/2017 21:58:01] --> Command Line : 5644 | [Owner : SERVICE RÃSEAU | Parent : 936(svchost.exe) | 10 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.0) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [18/03/2017 21:58:50] --> Command Line : ---------- | MD5 [MD5.01078D46C77CE0D7DC584A29062A799D] - [11/10/2017 13:54:19] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4735.3 Ko] - (10.0.15063.674) : C:\WINDOWS\Explorer.exe [MD5.94912C1D73ADE68F2486ED4D8EA82DE6] - [18/03/2017 21:57:50] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [265.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\cmd.exe [MD5.31E45CAA8E7035ECD47E96A7377BE975] - [18/03/2017 21:57:38] - (.© Microsoft Corporation. Tous droits réservés. - Processus dÂexécution client-serveur.) - [17.28 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\csrss.exe [MD5.2D29C0AFCC8225AFF6637F7362C22960] - [18/03/2017 21:58:21] - (.© Microsoft Corporation. - COM Surrogate.) - [20.91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\dllhost.exe [MD5.90224339656D3CFEC43150209B4CD38E] - [23/07/2017 13:44:45] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [692.1 Ko] - (10.0.15063.296) : C:\WINDOWS\System32\Kernel32.dll [MD5.BA909DA3D184EF80F9293AB9E12FF30F] - [11/10/2017 13:55:04] - (.© Microsoft Corporation. - Local Security Authority Process.) - [56.62 Ko] - (10.0.15063.674) : C:\WINDOWS\System32\lsass.exe [MD5.AA7F1C36F5BC779964CFA4F98D224D9F] - [16/09/2017 07:59:56] - (.© Microsoft Corporation. - Distributed COM Services.) - [1060 Ko] - (10.0.15063.608) : C:\WINDOWS\System32\rpcss.dll [MD5.ECB702B8C5650381C0784F1EEABB97BC] - [18/03/2017 21:58:29] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [67 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\rundll32.exe [MD5.C81F9707DEA008EED4071B5A39B7C76E] - [15/09/2017 17:54:08] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [515.6 Ko] - (10.0.15063.502) : C:\WINDOWS\System32\services.exe [MD5.3120B24060924F9B94182A1432B2D7F9] - [18/03/2017 21:58:21] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [46.55 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\svchost.exe [MD5.B074ECE844C671332F89C7544DBFC74A] - [15/11/2017 17:40:44] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de lÂAPI uilisateur de Windows multi-utilisateurs.) - [1314.06 Ko] - (10.0.15063.726) : C:\WINDOWS\System32\user32.dll [MD5.46B72E05D0B9F489CA60DBD7361039B0] - [18/03/2017 21:58:21] - (.© Microsoft Corporation. Tous droits réservés. - Application dÂouverture de session Userinit.) - [31.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\userinit.exe [MD5.0242626678C83AE788C655C1990A3CC3] - [16/09/2017 07:38:44] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [310.77 Ko] - (10.0.15063.502) : C:\WINDOWS\System32\Wininit.exe [MD5.9CDA170849A4F66F4D68B3DBB3AC8394] - [16/09/2017 07:38:45] - (.© Microsoft Corporation. Tous droits réservés. - Application dÂouverture de session Windows.) - [690 Ko] - (10.0.15063.608) : C:\WINDOWS\System32\Winlogon.exe [MD5.5A6D591D56791BA63CE73FCAD60D89A1] - [16/09/2017 07:38:53] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de fonction connexe pour WinSock.) - [596.41 Ko] - (10.0.15063.608) : C:\WINDOWS\System32\Drivers\afd.sys [MD5.01733BEEE02E51F712330D5909BD701C] - [18/03/2017 21:56:26] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [28.41 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\atapi.sys [MD5.71CCAFFF7D5E64E3D07BD96F2B2898EF] - [18/03/2017 21:56:26] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [189.91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\ataport.sys [MD5.B6E5AD7C83A5254DEE9D86023C0E5A81] - [18/03/2017 21:57:39] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\cdfs.sys [MD5.ABE77AD954BC3D72F559CF0C381E50BC] - [18/03/2017 21:56:25] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [156.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\cdrom.sys [MD5.185A4519B7764F4DEF714D890A7A9FD2] - [18/03/2017 21:57:47] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [147 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\dfsc.sys [MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - [23/07/2017 13:56:55] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [84.5 Ko] - (10.0.15063.447) : C:\WINDOWS\System32\Drivers\hdaudbus.sys [MD5.C6C8315E3262FAE460529C6DA2951682] - [18/03/2017 21:56:35] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [112.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\i8042prt.sys [MD5.DCC05E5EAA580C97F13B434FAFACED85] - [18/03/2017 21:58:21] - (.© Microsoft Corporation. - IP Network Address Translator.) - [209.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\ipnat.sys [MD5.F2AD1B72C5A6475FB5FF332E1980DF88] - [18/03/2017 21:57:54] - (.© Microsoft Corporation. Tous droits réservés. - Minirdr SMB Windows NT.) - [456.4 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\mrxsmb.sys [MD5.BC6EB2110C8462FF20E74B2E2A31917E] - [15/11/2017 17:38:56] - (.© Microsoft Corporation. Tous droits réservés. - NDIS (Network Driver Interface Specification).) - [1210.4 Ko] - (10.0.15063.726) : C:\WINDOWS\System32\Drivers\ndis.sys [MD5.BAD3C424788BC071C3EC82CFCDA954D2] - [16/09/2017 08:01:09] - (.© Microsoft Corporation. - MBT Transport driver.) - [298 Ko] - (10.0.15063.608) : C:\WINDOWS\System32\Drivers\netbt.sys [MD5.4FB781DF7C0ED6B989F465A7886583F1] - [15/11/2017 17:39:00] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [2272.9 Ko] - (10.0.15063.726) : C:\WINDOWS\System32\Drivers\ntfs.sys [MD5.2CC6C325B271C7CA60F374F8F868CB45] - [18/03/2017 21:56:26] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [95.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\parport.sys [MD5.5279EC98F6218D29EADDFECCC0D80E9A] - [18/03/2017 21:58:07] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [104.5 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\rasl2tp.sys [MD5.53A01D3FDB701AC5D9DDE4140227E3D9] - [18/03/2017 21:59:55] - (.© Microsoft Corporation. Tous droits réservés. - Redirecteur de périphérique de Microsoft RDP.) - [179 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\rdpdr.sys [MD5.9360DA9E370C1E1483967351C0CB7245] - [11/10/2017 13:55:34] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [2609.4 Ko] - (10.0.15063.674) : C:\WINDOWS\System32\Drivers\tcpip.sys [MD5.D74756DD1518D28A09CDA99696273FA4] - [16/09/2017 07:31:33] - (.© Microsoft Corporation. - TDI Translation Driver.) - [116.91 Ko] - (10.0.15063.540) : C:\WINDOWS\System32\Drivers\tdx.sys [MD5.E3429DBBEA3965BB96E24B16EF4A2551] - [18/03/2017 21:57:39] - (.© Microsoft Corporation. - Volume Shadow Copy driver.) - [387.91 Ko] - (10.0.15063.0) : C:\WINDOWS\System32\Drivers\volsnap.sys ---------- | Locked Applications [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9e93b39-49d1-4179-9848-a5a2896955ea}] - () - (%systemroot%\system32\mrt.exe) ---------- | Explorer.exe component call (Microsoft Files Whitelisted) (.Google.-.Google Drive shell extension.) - (2.34.7529.6838) -- C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (.Dropbox, Inc..-.Dropbox Shell Extension.) - (1.0.0.25) -- C:\Users\Maxime\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (..-..) - (14.0.7109.5000) -- C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf (.Intel Corporation.-.LDDM User Mode Driver for Intel(R) Graphics Technology.) - (9.17.10.4459) -- C:\WINDOWS\SYSTEM32\igd10umd64.dll (..-..) - (4.11.0.0) -- C:\Program Files (x86)\WinRAR\rarext64.dll ---------- | Svchost.exe component call (Microsoft Files Whitelisted) (.http://www.sqlite.org/copyright.html.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.15.2.0) -- C:\WINDOWS\System32\winsqlite3.dll ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE RÃSEAU Dropbox - (C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [Startup]) - User: JACK\Maxime Facebook Update - ("C:\Users\Maxime\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime Google Update - (C:\Users\Maxime\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime GoogleDriveSync - ("C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime EPLTarget\P0000000000000001 - (C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILEE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-412 413 415 Series" [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime ISUSPM - (C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime BingSvc - (C:\Users\Maxime\AppData\Local\Microsoft\BingSvc\BingSvc.exe [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime Spotify Web Helper - ("C:\Users\Maxime\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime Spotify - ("C:\Users\Maxime\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime EPLTarget\P0000000000000002 - (C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILEE.EXE /EPT "EPLTarget\P0000000000000002" /M "XP-412 413 415 Series" [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\...\Run]) - User: JACK\Maxime SecurityHealth - (%ProgramFiles%\Windows Defender\MSASCuiL.exe [HKLM\SOFTWARE\...\Run]) - User: Public IgfxTray - ("C:\WINDOWS\system32\igfxtray.exe" [HKLM\SOFTWARE\...\Run]) - User: Public HotKeysCmds - ("C:\WINDOWS\system32\hkcmd.exe" [HKLM\SOFTWARE\...\Run]) - User: Public Persistence - ("C:\WINDOWS\system32\igfxpers.exe" [HKLM\SOFTWARE\...\Run]) - User: Public cAudioFilterAgent - ("C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [HKLM\SOFTWARE\...\Run]) - User: Public SmartAudio - ("C:\Program Files\CONEXANT\SAII\SACpl.exe" /t [HKLM\SOFTWARE\...\Run]) - User: Public Energy Management - (C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [HKLM\SOFTWARE\...\Run]) - User: Public EnergyUtility - (C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [HKLM\SOFTWARE\...\Run]) - User: Public SynTPEnh - (%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [HKLM\SOFTWARE\...\Run]) - User: Public [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="C:\Users\Maxime\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver "Google Update"=C:\Users\Maxime\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart "EPLTarget\P0000000000000001"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILEE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-412 413 415 Series" "ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler "BingSvc"=C:\Users\Maxime\AppData\Local\Microsoft\BingSvc\BingSvc.exe [24/06/2015 21:27:11] "Spotify Web Helper"="C:\Users\Maxime\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Spotify"="C:\Users\Maxime\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized "EPLTarget\P0000000000000002"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILEE.EXE /EPT "EPLTarget\P0000000000000002" /M "XP-412 413 415 Series" [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "RESTART_STICKY_NOTES"=0x0300000091F110098361D101 "GarminExpressTrayApp"=0x03000000FB57E46EF6DACF01 "Facebook Update"=0x030000004FD7A28CF6DACF01 "Skype"=0x03000000ACA0AC0F2D8BCF01 "StopClope"=0x020000000000000000000000 "Google Update"=0x030000002751618FF6DACF01 "GoogleDriveSync"=0x03000000309038082D8BCF01 "iTunesHelper"=0x020000000000000000000000 "EPLTarget\P0000000000000000"=0x020000000000000000000000 "EPLTarget\P0000000000000001"=0x020000000000000000000000 "EPLTarget\P0000000000000002"=0x020000000000000000000000 "Spotify"=0x03000000CF96F3EB8261D101 "Spotify Web Helper"=0x020000000000000000000000 "BingSvc"=0x020000000000000000000000 "ISUSPM"=0x020000000000000000000000 "OneDrive"=0x020000000000000000000000 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU] "a"=cmd\1 "MRUList"=a [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "Device"=XP-412 413 415 Series(Réseau),winspool,Ne00: "IsMRUEstablished"=1 "LegacyDefaultPrinterMode"=0 [HKLM\Software\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "SecurityHealth"=%ProgramFiles%\Windows Defender\MSASCuiL.exe "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" "Persistence"="C:\WINDOWS\system32\igfxpers.exe" "cAudioFilterAgent"="C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" "SmartAudio"="C:\Program Files\CONEXANT\SAII\SACpl.exe" /t "Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [13/08/2012 08:48:56] "EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [13/08/2012 08:49:28] "SynTPEnh"=%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "SecurityHealth"=0x040000000000000000000000 "SynTPEnh"=0x0700000045158594F6DACF01 "SmartAudio"=0x020000000000000000000000 "cAudioFilterAgent"=0x020000000000000000000000 "BtvStack"=0x020000000000000000000000 "Energy Management"=0x020000000000000000000000 "EnergyUtility"=0x020000000000000000000000 "BtTray"=0x020000000000000000000000 "HotKeysCmds"=0x020000000000000000000000 "IgfxTray"=0x020000000000000000000000 "Persistence"=0x020000000000000000000000 "AvastUI.exe"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32] "331BigDog"=0x040000000000000000000000 "Dolby Advanced Audio v2"=0x020000000000000000000000 "YouCam Mirage"=0x030000001A009A5AF6DACF01 "YouCam Tray"=0x03000000661AE565F6DACF01 "UpdateP2GShortCut"=0x030000004851AB85F6DACF01 "RemoteControl10"=0x0300000011B0A388F6DACF01 "Intel AppUp(SM) center"=0x020000000000000000000000 "BCSSync"=0x030000000DC81A84F6DACF01 "AvastUI.exe"=0x020000000000000000000000 "mobilegeni daemon"=0x020000000000000000000000 "EEventManager"=0x020000000000000000000000 "avast"=0x020000000000000000000000 "332BigDog"=0x03000000A13DEC96F6DACF01 "Adobe ARM"=0x0300000020A1864CBFB3CE01 "SunJavaUpdateSched"=0x03000000006BF94DBFB3CE01 "tuto4pc_fr_41"=0x03000000C01FAD4DBFB3CE01 "20131121"=0x020000000000000000000000 "APSDaemon"=0x020000000000000000000000 "DNS7reminder"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "EnableMitInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=1 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D325FFA9F5E74C [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "331BigDog"="C:\Program Files (x86)\USB Camera\VM331STI.EXE" "YouCam Mirage"="C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe" "YouCam Tray"="C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s "UpdateP2GShortCut"="C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" "RemoteControl10"="C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe" "Intel AppUp(SM) center"="C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4 "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" "DNS7reminder"="C:\Windows\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "EnableMitInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Wininit.ini : [Rename] NUL=C:\WINDOWS\system32\Macromed\Flash\Flash.ocx ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List Adobe Acrobat Update Task Adobe Flash Player Updater EPSON XP-412 413 415 Series Invitation {3C606750-BB97-42A2-AF7C-3BD83A76FF03} EPSON XP-412 413 415 Series Invitation {42F04F6A-FFCF-44A2-BF1F-BF13CC11B6E7} EPSON XP-412 413 415 Series Invitation {602EACDE-32D6-4A04-800C-40473B983AAC} EPSON XP-412 413 415 Series Invitation {FC64140B-E2DA-4554-870A-1A85E0C5C308} EPSON XP-412 413 415 Series Update {3C606750-BB97-42A2-AF7C-3BD83A76FF03} EPSON XP-412 413 415 Series Update {42F04F6A-FFCF-44A2-BF1F-BF13CC11B6E7} EPSON XP-412 413 415 Series Update {602EACDE-32D6-4A04-800C-40473B983AAC} EPSON XP-412 413 415 Series Update {FC64140B-E2DA-4554-870A-1A85E0C5C308} FacebookUpdateTaskUserS-1-5-21-60461441-1236719898-3972887004-1001Core FacebookUpdateTaskUserS-1-5-21-60461441-1236719898-3972887004-1001UA GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA GoogleUpdateTaskUserS-1-5-21-60461441-1236719898-3972887004-1001Core GoogleUpdateTaskUserS-1-5-21-60461441-1236719898-3972887004-1001Core1d35e22e940f17a GoogleUpdateTaskUserS-1-5-21-60461441-1236719898-3972887004-1001UA GoogleUpdateTaskUserS-1-5-21-60461441-1236719898-3972887004-1001UA1d35e22e965ebcc Java Update Scheduler MirageAgent OneDrive Standalone Update Task-S-1-5-21-60461441-1236719898-3972887004-1001 Optimize Start Menu Cache Files-S-1-5-21-60461441-1236719898-3972887004-1001 Programme de mise à jour en ligne de Adobe Synaptics TouchPad Enhancements User_Feed_Synchronization-{705B7F45-E8EE-4A4E-98D3-1F2168150387} {7A763036-D193-4834-8A73-9B2E252F76CD} {A08C5381-A8AA-41F7-80F2-0DFB7EA5C2AD} ---------- | Startings up registry ? Folder ---------- | Control - lsa - SecurityProviders - Session Manager - Terminal Server [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=UsoSvc DeviceInstall gpsvc trustedinstaller "SvcHostSplitThresholdInKB"=3670016 "WaitToKillServiceTimeout"=200 "SystemStartOptions"= NOEXECUTE=OPTIN NOVGA "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(5) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(2) "LastBootSucceeded"=1 "LastBootShutdown"=0 "DirtyShutdownCount"=21 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Notification Packages"=scecli "Authentication Packages"=msv1_0 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "LsaPid"=700 "ProductType"=3 "restrictanonymous"=0 "restrictanonymoussam"=1 "SamConnectedAccountsExist"=1 "SecureBoot"=1 "Security Packages"=kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "ResourceTimeoutCount"=648000 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "AutoChkSkipSystemPartition"=0 [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "InstanceID"=b4b50cc0-7767-45c8-9093-f829e83 "GlassSessionId"=2 ---------- | .LNK with Arguments ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "ScreenSaveActive"=1 "SnapSizing"=1 "TileWallpaper"=0 "WallPaper"=C:\Users\Maxime\Desktop\Album\Portable Mich' 220817\WP_20170225_003.jpg [22/08/2017 11:37:48] "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "MouseMonitorEscapeSpeed"=0 "UserPreferencesMask"=0x9E1E078012000000 "AutoColorization"=1 "MaxVirtualDesktopDimension"=3520 "MaxMonitorDimension"=1920 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC301000E4C1A00200A0000B005000000995AECA28FD20143003A005C00550073006500720073005C004D006100780069006D0065005C004400650073006B0074006F0070005C0041006C00620075006D005C0050006F0072007400610062006C00650020004D00690063006800270020003200320030003800310037005C00570050005F00320030003100370030003200320035005F003000300033002E006A007000670000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ImageColor"=2763234115 "LogPixels"=96 "Win8DpiScaling"=0 "PreferredUILanguages"=fr-FR "DpiScalingVer"=4096 "ScreenSaverIsSecure"=0 "ScreenSaveTimeOut"=18000 "SCRNSAVE.EXE"=C:\WINDOWS\system32\PhotoScreensaver.scr [23/07/2017 13:57:45] "WaitToKillAppTimeout"=200 "HungAppTimeout"=200 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=145 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "ShellState"=0x240000003428000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SlowContextMenuEntries"=0x3673466C8182604E8204430CED96822DA5F001000114020000000000C000000000000046EEDC0100BD0E0C47735D584D9CEDE91E22E23282269600001A58CE57B60C66429CA019364C90A0B37883000060B81DB4E464D2119906E49FADC173CAB5D40000 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "TelemetrySalt"=6 "AppReadinessLogonComplete"=1 "FirstRunTelemetryComplete"=1 "GlobalAssocChangedCounter"=53 "Browse For Folder Width"=347 "Browse For Folder Height"=288 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=2 "ShowCompColor"=1 "HideFileExt"=0 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StartMenuInit"=13 "ReindexedProfile"=1 "ShellViewReentered"=1 "Start_TrackSearchContract"=1 "ApplicationSearchHistory"=1 "Start_TrackShareContractHistory"=1 "Start_ShareContractHistoryCount"=5 "Start_TrackShareContractMFU"=1 "StoreAppsOnTaskbar"=1 "RTStartMenuNotificationDisplayCount"=0 "EnableStartMenu"=1 "TaskbarSizeMove"=1 "DisablePreviewDesktop"=0 "TaskbarGlomLevel"=2 "TaskbarStateLastRun"=0xB3432E5A00000000 "TaskbarAutoHideInTabletMode"=0 "TaskbarSmallIcons"=0 "DontUsePowerShellOnWinX"=0 "TaskbarBadges"=1 "ShowTaskViewButton"=1 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery] "MRUListEx"=0x1500000014000000130000001200000011000000100000000F0000000E000000030000000C0000000D0000000B0000000A000000020000000900000008000000070000000600000005000000040000000100000000000000FFFFFFFF "0"=0x73007200740074007200610069006C002E007400780074000000 "1"=0x65006E007200650067000000 "4"=0x71007500690063006B00740069006D0065000000 "5"=0x530065007400750070002E006D0073000000 "6"=0x73006500690067000000 "7"=0x35003000200061006E0073000000 "8"=0x35003000200061006E00730020006D0069006300680020006D0061006E00750065000000 "9"=0x6C006500200073006500690067000000 "2"=0x530065007400750070002E006D00730069000000 "10"=0x64006F0077006E000000 "11"=0x64006F0077006E006C006F0061006400200077000000 "13"=0x64006F0077006E006C006F00610064000000 "12"=0x64006F0077006E006C006F006100640020006E00610076006900670061000000 "3"=0x730065007400750070000000 "14"=0x610070007000440061000000 "15"=0x63006100700074007500720065000000 "16"=0x6300610070007400750072006500200064002700E9006300720061006E000000 "17"=0x6400E900670072006500760065006D00650074000000 "18"=0x6400E900670072006500760065006D0065006E0074000000 "19"=0x7200690062000000 "20"=0x6D0061006C000000 "21"=0x6D0061006C0077000000 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "DisableCAD"=1 "SoftwareSASGeneration"=1 "ConsentPromptBehaviorAdmin"=5 "EnableLUA"=1 "PromptOnSecureDesktop"=1 "EnableSecureUIAPath"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoRecentDocsHistory"=0 "NoActiveDesktopChanges"=0 "NoActiveDesktop"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "SmartScreenEnabled"=RequireAdmin "GlobalAssocChangedCounter"=87 "AicEnabled"=PreferStore [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableInstallerDetection"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "DisableCAD"=1 "SoftwareSASGeneration"=1 "ConsentPromptBehaviorAdmin"=5 "EnableLUA"=1 "PromptOnSecureDesktop"=1 "EnableSecureUIAPath"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoRecentDocsHistory"=0 "NoActiveDesktopChanges"=0 "NoActiveDesktop"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=28 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=15063 "FirstLogon"=0 "PUUActive"=0x3A3934BC0100150073006A011E5E0900FCD70F00F3C05000D100000002002A00D6DE2112076585000933180006750300DFF0020045980000000000000E611300D82D000007090000F9736B47EE74D3011E5E0900000000000100000000000000 "DP"=0xCE00580091001500780000003A3934BCC9BA200000000000F9736B47EE74D3014BDBEA48E974D301AE8372000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ParseAutoexec"=1 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DefaultDomainName"= "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "LastLogOffEndTimePerfCounter"=38084390508 "ShutdownFlags"=2147483755 "Userinit"=C:\Windows\system32\userinit.exe, "AutoAdminLogon"=0 "DefaultUserName"=MicrosoftAccount\danet.maxime@yahoo.fr "ShutdownWithoutLogon"=0 "scremoveoption"=0 "DisableCad"=1 "EnableFirstLogonAnimation"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "EnableSIHostIntegration"=1 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "Userinit"=C:\WINDOWS\system32\userinit.exe, ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Clients\StartMenuInternet\Google Chrome.3ACIGE7GWDDAYEBV2NW4VK76L4\Shell\open\Command] ""="C:\Users\Maxime\AppData\Local\Google\Chrome\Application\chrome.exe" [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Clients\StartMenuInternet\Google Chrome.3ACIGE7GWDDAYEBV2NW4VK76L4\InstallInfo] "ReinstallCommand"="C:\Users\Maxime\AppData\Local\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [16/09/2017 08:01:13] [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [16/09/2017 08:01:13] [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall ---------- | AppcompatFlags [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Users\Maxime\AppData\Local\Temp\6842BB0C-BAB0-7891-A961-A2869AAA397E\Setup.exe"=1 "C:\Users\Maxime\AppData\Local\Temp\IS1668~1\DeltaTB.exe"=1 "C:\Users\Maxime\AppData\Local\Temp\E142A830-BAB0-7891-A002-3D661AEA382E\Setup.exe"=1 "C:\Users\Maxime\AppData\Local\Temp\__TEMPWEBPLAYER__\DeltaTB.exe"=1 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "SIGN.IE=013C2FA8 Firefox Setup 19.0.2.exe"=0x5341435001000000000000000700000028000000A82F3C0100000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000DD300800000000000100000001000000 "SIGN.IE=06A848B8 avast_free_antivirus_setup.exe"=0x5341435001000000000000000700000028000000B848A80600000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000E38F0200000000000100000001000000 "C:\Users\Maxime\Downloads\Brothersoft_downloader_For_Foobar2000.exe"=0x5341435001000000000000000700000028000000C894060000000000010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000E67C1600000000000100000001000000 "C:\Users\Maxime\Downloads\Brothersoft_downloader_For_Foobar2000(1).exe"=0x5341435001000000000000000700000028000000C894060000000000010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000392D1400000000000100000001000000 "C:\Users\Maxime\Downloads\foobar2000_v1.2.3.exe"=0x534143500100000000000000070000002800000054AA380000000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000C1391300000000000100000001000000 "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe"=0x534143500100000000000000070000002800000070BC02007F1C0300010000000000000000000106712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000008C110500000000000200000002000000 "C:\Users\Maxime\Downloads\pc-decrapifier-2.3.1.exe"=0x5341435001000000000000000700000028000000BD9A190000000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000A69F0100000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR1E70.tmp\Adobe AIR Installer.exe"=0x534143500100000000000000070000002800000068930100705F0200010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000FBD53200000000000100000001000000 "C:\Program Files (x86)\foobar2000\foobar2000.exe"=0x534143500100000000000000070000002800000000481B000FF51B0001000000000000000000010600010000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\Downloads\vlc-2.0.5-win32.exe"=0x5341435001000000000000000700000028000000DEAE5D01F41C0100010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000036E40000000000000100000001000000 "C:\Users\Maxime\Downloads\install_flashplayer11x32_mssd_aih.exe"=0x5341435001000000000000000700000028000000882D0A00D6CF0A00010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000BA110500000000000100000001000000 "C:\Users\Maxime\Downloads\install_flashplayer11x32_mssd_aih [1].exe"=0x534143500100000000000000070000002800000098550F00A8FA0F00010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000006A2E0200000000000100000001000000 "C:\Users\Maxime\Downloads\SoftonicDownloader_pour_winrar.exe"=0x534143500100000000000000070000002800000060FF050000000000010000000000000000000206712000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000005A846501000000000100000001000000 "C:\Program Files (x86)\WinRAR\WinRAR.exe"=0x5341435001000000000000000700000028000000008E11000000000001000000000000000000010600210000E63F486B2AA0D2010000000000000000020000007800000000000000000000000000000000000000000000000000000064D2F80800000000E60000000300000000000000000000400000000000000000000000000000000002BA920B000000003A00000000000000000000000000005000000000000000000000000000000000CCF56C00000000004F00000000000000 "C:\Users\Maxime\AppData\Roaming\Nosibay\Bubble Dock\LBubble Dock.exe"=0x5341435001000000000000000700000028000000582A0A00F6CD0A00010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000F9150000000000000100000001000000 "C:\Users\Maxime\AppData\Roaming\Nosibay\Bubble Dock\Uninstall Bubble Dock.exe"=0x534143500100000000000000070000002800000048610600AEEA0600030000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000041DD0000000000000100000001000000 "C:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exe"=0x534143500100000000000000070000002800000040270D00B9690D00030000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004F2F4800000000000100000001000000 "SIGN.MEDIA=41F10 JM20329 Win98 Driver\Win98 Driver\Setup.exe"=0x534143500100000000000000070000002800000000B0000000000000010000000000000000000105712000002EF6C8A3A56ACD0100000000000000000100000004000000010000000500000010000000000000000000000000030105000800000200000050000000000301050008006000820000000000000080000000000000C70600000000000001000000010000000000000000080040008200000000000000800000000000001D100000000000000100000000000000 "SIGN.MEDIA=41F10 JM20329 Win98 Driver\Win98 Driver\JMUsbMon.exe"=0x534143500100000000000000070000002800000000C0000000000000010000000000000000000105712000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000001F000000000000000300000003000000 "SIGN.MEDIA=2CD3BC PcCloneEx\Setup.exe"=0x53414350010000000000000007000000280000000080D00000000000010000000000000000000006712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000008004000000000000000000000000000000000D027CB00000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE"=0x5341435001000000000000000700000028000000588C4C00345C4D00010000000000000000000106712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000095312300000000000100000001000000 "C:\Program Files\Microsoft Office 15\root\office15\perfboost.exe"=0x5341435001000000000000000700000028000000705A0100B2200200010000000000000000000106710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000100000000000000000000000000000820E0100000000000300000003000000 "C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE"=0x5341435001000000000000000700000028000000503E0E0026DE0E00010000000000000000000106710000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000001000000000000000000000000000004BC52600000000000100000001000000 "C:\Windows\SysWOW64\FlashPlayerApp.exe"=0x534143500100000000000000070000002800000060910A003BB50A00010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000AAEF0100000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR5FFA.tmp\Adobe AIR Installer.exe"=0x53414350010000000000000007000000280000006893010092720200010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000CC820000000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIRC046.tmp\Adobe AIR Installer.exe"=0x53414350010000000000000007000000280000006893010092720200010000000000000000000206712200002EF6C8A3A56ACD010000008000000000020000002800000000000000000000000000000000000000000000000000000075EB0100000000000100000001000000 "C:\Users\Maxime\Downloads\SkypeSetupFull.exe"=0x534143500100000000000000070000002800000068A0D3016838D401010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000016470100000000000200000002000000 "C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE"=0x5341435001000000000000000700000028000000407C8601EC828601010000000000000000000106000100002EF6C8A3A56ACD010000000100000000 "C:\Program Files\Microsoft Office 15\root\office15\POWERPNT.EXE"=0x5341435001000000000000000700000028000000582E1C0015381C00010000000000000000000106000100002EF6C8A3A56ACD010000000100000000 "C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\MSOXMLED.EXE"=0x534143500100000000000000070000002800000048520300006F030001000000000000000000020673220000647CA60EA56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000003F000000000000000100000001000000 "C:\Users\Maxime\Desktop\GoogleSketchUpWFR.exe"=0x5341435001000000000000000700000028000000E0C967023CEC6702010000000000000000000106710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000008004000000000000000000000000000000000D1E10400000000000100000001000000 "C:\Program Files (x86)\Google\Google SketchUp 8\SketchUp.exe"=0x53414350010000000000000007000000280000000070B9005B3EBA000100000000000000000001067120000033504C2B57DFD101000000000000000002000000500000000000000000000040000000000000000000000000000000002B28BB00000000000600000006000000000000000000000000000000000000000000000000000000A55AA400000000001300000000000000 "C:\Users\Maxime\Downloads\Webplayer.exe"=0x5341435001000000000000000700000028000000B04D0B006F540B00010000000000000000000106710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000CC0C0B00000000000200000002000000 "C:\Program Files (x86)\Delta\delta\1.8.10.0\GUninstaller.exe"=0x5341435001000000000000000700000028000000F00506007C9E0600030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B1910000000000000100000001000000 "C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE"=0x534143500100000000000000070000002800000090581D001F831D00010000000000000000000106000100002EF6C8A3A56ACD010000000100000000 "C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"=0x5341435001000000000000000700000028000000B88C1C001E5A1D0003000000000000000000010600010000647CA60EA56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000006ACB0100000000000100000001000000 "C:\Users\Maxime\Downloads\Office Professionnel Plus Finale FR 32 BITS + Activation à vie\Office 2010 Toolkit & EZ-Activator 2.0\Office 2010 Toolkit.exe"=0x53414350010000000000000007000000280000000006D40000000000010000000000000000000106F5220000647CA60EA56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000100000000000000000000000000000D77B0000000000000200000002000000 "C:\Users\Maxime\Downloads\Office Professionnel Plus Finale FR 32 BITS + Activation à vie\Office14\setup.exe"=0x53414350010000000000000007000000280000007815070078530700010000000000000000000106002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000050000000000000000000000000000000005AB53700000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR8DF7.tmp\Adobe AIR Installer.exe"=0x53414350010000000000000007000000280000006893010074890200010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000B73A0000000000000100000001000000 "C:\Users\Maxime\Downloads\install_reader11_fr_mssd_aih.exe"=0x5341435001000000000000000700000028000000A0850F005C131000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000155F0400000000000100000001000000 "C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Eula.exe"=0x5341435001000000000000000700000028000000804E0100CD800100010000000000000000000106712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000060170000000000000100000001000000 "C:\Users\Maxime\Downloads\GarminExpress.exe"=0x5341435001000000000000000700000028000000F065C400CD15C500010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000D6A9D400000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR7B83.tmp\Adobe AIR Installer.exe"=0x53414350010000000000000007000000280000006893010077AE0100010000000000000000000206712200002EF6C8A3A56ACD010000008000000000 "C:\Users\Maxime\AppData\Local\Temp\update_4908475.exe"=0x534143500100000000000000070000002800000038920100129C0100010000000000000000000106000100002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000510A0000000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR80D8.tmp\Adobe AIR Installer.exe"=0x53414350010000000000000007000000280000006893010077AE0100010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000437B2900000000000100000001000000 "C:\Users\Maxime\Downloads\Webplayer(1).exe"=0x5341435001000000000000000700000028000000E8190B00B4DA0B00010000000000000000000106710200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000050780600000000000100000001000000 "C:\Program Files (x86)\Delta\delta\1.8.21.5\GUninstaller.exe"=0x5341435001000000000000000700000028000000F00706004E8E0600030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000D4C70000000000000100000001000000 "C:\Program Files (x86)\DealPly\uninst.exe"=0x534143500100000000000000070000002800000023F906008FC21300030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000C2F90000000000000100000001000000 "C:\Users\Maxime\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe"=0x534143500100000000000000070000002800000000A6070052730800010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000EF5D0000000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR8FBF.tmp\Adobe AIR Installer.exe"=0x534143500100000000000000070000002800000068930100D6D70100010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000D0E70A00000000000100000001000000 "C:\Users\Maxime\Downloads\Dropbox 2.2.3.exe"=0x5341435001000000000000000700000028000000D01315025D041602010000000000000000000106000100002EF6C8A3A56ACD010000000000000000 "C:\Users\Maxime\AppData\Local\Temp\AIR59CF.tmp\Adobe AIR Installer.exe"=0x534143500100000000000000070000002800000068930100D6D70100010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000911F0600000000000100000001000000 "C:\Program Files (x86)\Java\jre7\bin\ssvagent.exe"=0x5341435001000000000000000700000028000000A0BD0000B84B0100010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000480E0000000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Office14\MSPUB.EXE"=0x5341435001000000000000000700000028000000989E9300F9A99300010000000000000000000106000100002EF6C8A3A56ACD010000000100000000 "C:\Users\Maxime\Downloads\28.0.1500.71_chrome_installer.exe"=0x5341435001000000000000000700000028000000600502028BC50202010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000076E0100000000000100000001000000 "C:\Users\Maxime\Desktop\installer_windows_movie_maker_French.exe"=0x5341435001000000000000000700000028000000C889270000000000010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000001E64F900000000000200000002000000 "C:\Program Files (x86)\Accelerer PC\unins000.exe"=0x534143500100000000000000070000002800000028BB1100DA2B1200030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000546F0000000000000100000001000000 "C:\Users\Maxime\AppData\Local\tuto4pc_fr_41\upt4pc_fr_41.exe"=0x5341435001000000000000000700000028000000681F300031E73000010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000AF020000000000000500000005000000 "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe"=0x534143500100000000000000070000002800000000DC010026A5020001000000000000000000020671220000E63F486B2AA0D20100000000000000000200000050000000000000000000001000000000000000000000000000000000CD99EA00000000009C00000001000000000000000000005000000000000000000000000000000000DBAD0500000000000400000000000000 "C:\Users\Maxime\AppData\Roaming\BabSolution\Shared\GUninstaller.exe"=0x5341435001000000000000000700000028000000502E05001FBB0500030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000859B0000000000000100000001000000 "C:\Program Files (x86)\tuto4pc_fr_41\unins000.exe"=0x534143500100000000000000070000002800000033FD0A0000000000030000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000073190000000000000100000001000000 "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe"=0x5341435001000000000000000700000028000000F02F02009B6F020001000000000000000000020671220000975FD891C99ECE01000000000000000002000000500000000000000000000050000000000000000000000000000000004D990100000000000100000001000000000000000000000000000000000000000000000000000000FD2B0100000000000200000000000000 "C:\Windows\Temp\installer.exe"=0x5341435001000000000000000700000028000000C0E33F0000000000010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000000A305200000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIRFD4B.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000689301008FC80100010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000371D2C00000000000100000001000000 "C:\Users\Maxime\Downloads\TuneUpUtilities2014_fr-FR.exe"=0x5341435001000000000000000700000028000000A8F3F7019CE8F801010000000000000000000206712200002EF6C8A3A56ACD010000000000000000 "C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe"=0x534143500100000000000000070000002800000038E106007FA40700010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000007FBA0800000000000100000001000000 "C:\Users\Maxime\AppData\Roaming\File Scout\filescout.exe"=0x534143500100000000000000070000002800000000F60300707C0400010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000001FB22300000000000E0000000E000000 "C:\Windows\System32\GfxUI.exe"=0x534143500100000000000000070000002800000040035A0020BA5A00010000000000000000000106F5200000647CA60EA56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000008C8D0300000000000100000001000000 "C:\Users\Maxime\Downloads\stopclope.exe"=0x5341435001000000000000000700000028000000FF720D0000000000010000000000000000000206412000002EF6C8A3A56ACD0100000000000000000200000028000000000000000008004000000000000000000000000000000000A05D0000000000000100000001000000 "C:\Program Files (x86)\StopClope\bin\StopClope.exe"=0x53414350010000000000000007000000280000000050170000000000010000000000000000000105F12000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000856E0F02000000000F0000000F000000 "C:\Users\Maxime\AppData\Local\Temp\AIR5923.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000689301000AE40100010000000000000000000206712200002EF6C8A3A56ACD010000008000000000020000002800000000000000000000000000000000000000000000000000000048710000000000000100000001000000 "C:\Users\Maxime\Downloads\vlc-2.1.0-win32.exe"=0x534143500100000000000000070000002800000079767201F41C0100010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004CF70100000000000100000001000000 "C:\Users\Maxime\Downloads\jre-7u45-windows-i586.exe"=0x5341435001000000000000000700000028000000A81FBB018D3DBB01010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000040200200000000000100000001000000 "C:\Program Files (x86)\PhotoFiltre 7\PhotoFiltre7.exe"=0x534143500100000000000000070000002800000000FA3400000000000100000000000000000002066120000033504C2B57DFD1010000000000000000020000005000000000000000000000400000000000000000000000000000000057A2810000000000050000000500000000000000000000000000000000000000000000000000000025422F00000000002300000000000000 "C:\Users\Maxime\Downloads\gimp-2.8.6-setup.exe"=0x5341435001000000000000000700000028000000306C5F05F1B25F05010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000DB4E0000000000000100000001000000 "C:\Users\Maxime\Downloads\miniphoto_installation.exe"=0x5341435001000000000000000700000028000000F0CD000000000000010000000000000000000105710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000008004000000000000000000000000000000000B2C50000000000000100000001000000 "C:\Program Files (x86)\Miniphoto\miniphoto.exe"=0x53414350010000000000000007000000280000000070010000000000010000000000000000000105F12000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000040000000000000000000000000000B5890600000000000500000005000000 "C:\Users\Maxime\Downloads\iview_4.36_setup.exe"=0x5341435001000000000000000700000028000000604E1C008FB01C00010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000CC280200000000000100000001000000 "C:\Users\Maxime\Downloads\googledrivesync.exe"=0x5341435001000000000000000700000028000000C07F0C000D920C00010000000000000000000106000100002EF6C8A3A56ACD010000008000000000020000002800000000000000000000000000000000000000000000000000000041600D00000000000200000002000000 "C:\Users\Maxime\Downloads\pf7-setup-fr.exe"=0x5341435001000000000000000700000028000000A87209002B4E0A00010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000037438600000000000100000001000000 "C:\Users\Maxime\Downloads\UsbFix.exe"=0x53414350010000000000000007000000280000007961120000000000010000000000000000000006710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000008004000000000000000000000000000000000511C0A00000000000500000005000000 "C:\Users\Maxime\Downloads\adwcleaner.exe"=0x534143500100000000000000070000002800000012F0100000000000010000000000000000000106710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000BE4E0300000000000100000001000000 "C:\Users\Maxime\Downloads\mbam-setup-1.75.0.1300.exe"=0x5341435001000000000000000700000028000000F0EF9C0071349D00010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000BE3D6400000000000100000001000000 "C:\Users\Maxime\Downloads\ZHPDiag2.exe"=0x5341435001000000000000000700000028000000639C680000000000010000000000000000000206412200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000000210100000000000100000001000000 "C:\Program Files (x86)\ZHPDiag\ZHPhep.exe"=0x534143500100000000000000070000002800000000421D000000000001000000000000000000020671220000975FD891C99ECE0100000000000000000200000050000000000000000000004002000000000000000000000000000000F96E1D00000000000100000001000000000000000000000002000000000000000000000000000000DA551F0000000000020000000000000006000000080000000200000000000000 "C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe"=0x534143500100000000000000070000002800000000421D000000000001000000000000000000020671220000975FD891C99ECE010000000000000000020000005000000000000000000000400000000000000000000000000000000023D602000000000001000000010000000000000000000000000000000000000000000000000000004BD50800000000000200000000000000 "SIGN.IE=0AC9BE delfix.exe"=0x5341435001000000000000000700000028000000BEC90A0000000000010000000000000000000106710200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000069410100000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIRFF6D.tmp\Adobe AIR Installer.exe"=0x53414350010000000000000007000000280000006893010015FA0100010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000A6AC2F00000000000100000001000000 "C:\Program Files (x86)\TuneUp Utilities 2014\UpdateWizard.exe"=0x5341435001000000000000000700000028000000387F0300BAA6030001000000000000000000020600210000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000073D62900000000000C0000000C000000 "C:\Users\Maxime\Desktop\OnlineHD-Chrome-V2.1.exe"=0x534143500100000000000000070000002800000010320700405A0700010000000000000000000106000100002EF6C8A3A56ACD010000000000000000 "C:\Users\Maxime\AppData\Local\BeamriseUninstall\Bootstrapper{1.4BR2gpTP.100}.exe"=0x534143500100000000000000070000002800000048050E003F9F0E00030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000100000004000000010000000500000010000000000000000000000000000106000000000200000050000000000001060000002000008000000000000000800000000000A94C00000000000001000000010000000000000000000000000080000000000000008000000000002287000000000000010000000000000006000000080000000000800000000000 "C:\Program Files (x86)\Miniphoto\uninstall.exe"=0x53414350010000000000000007000000280000005089000000000000030000000000000000000105710000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800000000000000000000000000000000000055A30000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{D0956C11-0F60-43FE-99AD-524E833471BB}\setup.exe"=0x534143500100000000000000070000002800000000B0060000000000030000000000000000000006710200002EF6C8A3A56ACD01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000001000000000000000000000000000004E7D0000000000000100000001000000 "C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe"=0x5341435001000000000000000700000028000000600D21006DD62100030000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000095450000000000000100000001000000 "C:\Program Files (x86)\IrfanView\iv_uninstall.exe"=0x53414350010000000000000007000000280000006094000052360100030000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800000000000000000000000000000000000080170000000000000100000001000000 "C:\Program Files (x86)\Mobogenie\uninst.exe"=0x53414350010000000000000007000000280000000B020200E6C43501030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A5AD0000000000000100000001000000 "C:\Program Files (x86)\OnlineHD V7.0\Uninstall.exe"=0x5341435001000000000000000700000028000000002E010000000000030000000000000000000206712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000095450000000000000100000001000000 "C:\Program Files (x86)\OnlineHD.TV\uninst.exe"=0x534143500100000000000000070000002800000089D90000405A0700030000000000000000000106000100002EF6C8A3A56ACD01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000200000000000000000000000000003A130000000000000100000001000000 "C:\Program Files (x86)\PcCloneEX\Uninstall.exe"=0x5341435001000000000000000700000028000000003A2D0000000000030000000000000000000006710000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800000000000000000000000000000000000092190000000000000100000001000000 "C:\Program Files (x86)\SecretSauce\SecretSauceUninstall.exe"=0x5341435001000000000000000700000028000000BAAE03008ABC0D00030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000F8A70000000000000100000001000000 "C:\Program Files (x86)\SugarSync\uninstall.exe"=0x53414350010000000000000007000000280000002688010018050801030000000000000000000106002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000071240000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}\setup.exe"=0x534143500100000000000000070000002800000069BE0D0000000000030000000000000000000106002100002EF6C8A3A56ACD010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000010800000000000000080000000000075670000000000000100000001000000010000000400000001000000 "C:\Users\Maxime\Downloads\jxpiinstall.exe"=0x5341435001000000000000000700000028000000A80D0E00E44C0E00010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000008B2B0200000000000100000001000000 "C:\Program Files (x86)\Java\jre7\bin\javacpl.exe"=0x5341435001000000000000000700000028000000A805010087960100010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B4790000000000000200000002000000 "C:\Users\Maxime\Downloads\Philip's Large Red Cursors.exe"=0x53414350010000000000000007000000280000007F89070000000000010000000000000000000206412000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800400000000000000000000000000000000021750000000000000100000001000000 "C:\Users\Maxime\Downloads\Civikey-Std-2.6.1.exe"=0x534143500100000000000000070000002800000091B2F90300000000010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000000F290100000000000200000002000000 "C:\Program Files (x86)\Civikey\Std\binaries\CiviKey.exe"=0x534143500100000000000000070000002800000000CA0C0000000000010000000000000000000106800100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B8781E00000000000300000003000000 "C:\Program Files\CONEXANT\SAII\SACpl.exe"=0x5341435001000000000000000700000028000000002419001F881900010000000000000000000106712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A8610000000000000100000001000000 "SIGN.MEDIA=74186F SETUP.EXE"=0x53414350010000000000000007000000280000000022020000000000010000000000000000000105712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800400000000000000000000000000000000073850200000000000100000001000000 "SIGN.MEDIA=6F20F58 SETUP.EXE"=0x534143500100000000000000070000002800000000180100270C0200010000000000000000000105003000002EF6C8A3A56ACD010000000000000000 "SIGN.MEDIA=1DE723 Pirate.exe"=0x534143500100000000000000070000002800000000700B00AB770B00010000000000000000000006712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000019430C00000000000300000003000000 "SIGN.MEDIA=1DE723 setup.exe"=0x5341435001000000000000000700000028000000002E0200DEFF0200010000000000000000000105712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000008004000000000000000000000000000000000AEC30000000000000100000001000000 "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVDLaunchPolicy.exe"=0x534143500100000000000000070000002800000028A5060067C306000100000000000000000001067122000033504C2B57DFD101000000000000000002000000500000000000000080000040000000000000000000000000000000007AF46B0000000000030000000300000000000000800000000000000000000000000000000000000010F82000000000000200000000000000 "C:\Users\Maxime\Desktop\MM26_FR.msi"=0x534143500100000000000000070000002800000000E60100BC93020001000000000000000000010500100000647CA60EA56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B0850200000000000200000002000000 "C:\Users\Maxime\Desktop\videoeditor.exe"=0x534143500100000000000000070000002800000069B7FD0000000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000929E0000000000000100000001000000 "C:\Program Files (x86)\OpoSoft\Video Editor\Video Editor.exe"=0x534143500100000000000000070000002800000000C01D0000000000010000000000000000000006710000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004EBA0200000000000100000001000000 "C:\Users\Maxime\Desktop\VideoSpin_2_0_Setup.exe"=0x5341435001000000000000000700000028000000B018250A4546250A010000000000000000000006710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000835D0300000000000100000001000000 "C:\Program Files (x86)\Pinnacle\VideoSpin\Programs\VideoSpin.exe"=0x534143500100000000000000070000002800000010E55200E0805300010000000000000000000006712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000F6C06B00000000000300000003000000 "C:\Program Files (x86)\TuneUp Utilities 2014\Integrator.exe"=0x5341435001000000000000000700000028000000380B1000D64F100001000000000000000000020600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000031ED7600000000000500000005000000 "SIGN.MEDIA=157EB00 Data\Bin\VisioLaunch.exe"=0x53414350010000000000000007000000280000000010040000000000010000000000000000000006712000002EF6C8A3A56ACD0100000000000000000200000028000000000000008000000000000000000000000000000000000000BB2C1100000000000100000001000000 "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe"=0x534143500100000000000000070000002800000013F001005194020001000000000000000000020661220000E63F486B2AA0D201000000000000000002000000C80000000000000000000010000000000000000000000000000000005DDB5200000000002700000017000000000000000000005000000000000000000000000000000000BC339A0E000000008601000000000000000000008000005000000000000000000000000000000000C8B051000000000004000000000000000000000000000000000000000000000000000000000000006DA86100000000004900000000000000000000008000000000000000000000000000000000000000DCA61100000000000100000000000000 "C:\Users\Maxime\AppData\Local\Temp\{a2c69cba-542a-4a49-af31-b8a49349064d}\.be\GarminExpressInstaller.exe"=0x5341435001000000000000000700000028000000B85F0D0051B90D00010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000BA480800000000000100000001000000 "C:\Users\Maxime\Desktop\GarminExpress.exe"=0x5341435001000000000000000700000028000000281FD6019780D601010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000DFC23200000000000300000003000000 "C:\Users\Maxime\Desktop\CommunicatorPlugin_410.exe"=0x5341435001000000000000000700000028000000C8D71F01F5F11F01010000000000000000000206002100002EF6C8A3A56ACD0100000080000000000200000028000000000000000000004000000000000000000000000000000000CB4A0200000000000200000002000000 "C:\Users\Maxime\AppData\Local\Temp\AIR7194.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A092010044520200010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000F6F67900000000000100000001000000 "C:\Users\Maxime\Desktop\chromeinstall-7u55.exe"=0x5341435001000000000000000700000028000000A80F0E007BD50E00010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000016A40200000000000100000001000000 "SIGN.MEDIA=224802 InstallNavi.exe"=0x53414350010000000000000007000000280000004048220067E62200010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000097E51F00000000000100000001000000 "C:\Windows\twain_32\escndv\escndv.exe"=0x5341435001000000000000000700000028000000A05C03002267030001000000000000000000000671200000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000BE571F000000000014000000080000000000000000000040000000000000000000000000000000001140B600000000006600000000000000 "C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPQuicker.exe"=0x534143500100000000000000070000002800000060EC0D0033720E0001000000000000000000010671200000975FD891C99ECE010000000000000000020000005000000000000000000000400000000000000000000000000000000020970000000000000100000001000000000000000000000000000000000000000000000000000000309C0000000000000100000000000000 "C:\Windows\twain_32\escndv\escfg.exe"=0x5341435001000000000000000700000028000000681E040078E7040001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000083234900000000000700000007000000 "C:\Program Files (x86)\EPSON Software\Epson Manual\Launcher\EPSMLAN.EXE"=0x5341435001000000000000000700000028000000400E090026300900010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000AB4A1600000000000100000001000000 "C:\Windows\twain_32\escndv\estcfg.exe"=0x534143500100000000000000070000002800000000900200720A03000100000000000000000001067120000033504C2B57DFD10100000000000000000200000050000000000000000000004000000000000000000000000000000000990B0000000000005A0000005A0000000000000000000000000000000000000000000000000000002D030000000000002B00000000000000 "C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe"=0x534143500100000000000000070000002800000020450200FA80020001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000071AC0900000000000300000003000000 "C:\Users\Maxime\Desktop\Install_Prezi_Desktop_4.7.5.exe"=0x5341435001000000000000000700000028000000C82C090065A8114A010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000005A470000000000000100000001000000 "C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe"=0x534143500100000000000000070000002800000028442C00D3932C00010000000000000000000206F5220000647CA60EA56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000352E0000000000000200000002000000 "C:\Users\Maxime\AppData\Local\Temp\ICReinstall_Install_Prezi_Desktop_4.7.5.exe"=0x5341435001000000000000000700000028000000C82C090065A8114A010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000614B0000000000000100000001000000 "C:\Users\Maxime\Downloads\Install_Prezi_Desktop_4.7.5 [1].exe"=0x5341435001000000000000000700000028000000089E9D1693B29D16010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000100000000000000000000000000000000048B50300000000000300000003000000 "C:\Program Files (x86)\Prezi Desktop 4\Prezi Desktop.exe"=0x534143500100000000000000070000002800000000700300212D0100010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000C3D36100000000000800000008000000 "C:\Program Files (x86)\MyPC Backup\uninst.exe"=0x5341435001000000000000000700000028000000664C01000AE19E00030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B2B80000000000000100000001000000 "C:\Program Files (x86)\Greener Web\GreenerWebUninstall.exe"=0x534143500100000000000000070000002800000010AC0300B9702000030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000871C0200000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR67FE.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A09201006D870200010000000000000000000206712200002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000EE8F0600000000000100000001000000 "C:\Users\Maxime\Desktop\CommunicatorPlugin_420.exe"=0x534143500100000000000000070000002800000048CA1F018A77200101000000000000000000020600010000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000E7EB0000000000000100000001000000 "C:\Program Files (x86)\Garmin\Express\Express.exe"=0x534143500100000000000000070000002800000058352C0019872C00010000000000000000000306F1220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000003FF4201000000000100000001000000 "C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe"=0x534143500100000000000000050000001000000000000000000000000000000000000000070000002800000080BD0700BE9E080001000000000000000000020671220000E63F486B2AA0D20100000080000000000200000028000000000000000000004000000000000000000000000000000000AD481207000000000800000008000000 "C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe"=0x53414350010000000000000007000000280000002041000035D50000010000000000000000000306F5220000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000001D100000000000000100000001000000 "C:\Users\Maxime\Desktop\adwcleaner_3.310.exe"=0x534143500100000000000000070000002800000023F514000000000001000000000000000000010671020000975FD891C99ECE010000000000000000020000005000000000000000000000400000000000000000000000000000000082150F0000000000010000000100000000000000000000000000000000000000000000000000000064190000000000000100000000000000 "C:\Users\Maxime\Desktop\mbam-setup-2.0.2.1012.exe"=0x5341435001000000000000000700000028000000D8DD0701EB24080101000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000018163800000000000100000001000000 "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"=0x5341435001000000000000000700000028000000385B6A00CC9D6A0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000521C0000000000000200000002000000 "C:\Users\Maxime\Desktop\mbam-setup-2.0.2.1012 (1).exe"=0x5341435001000000000000000700000028000000D8DD0701EB24080101000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000011FC2800000000000200000002000000 "C:\Users\Maxime\Desktop\mbam-setup-1.70.0.1100.exe"=0x534143500100000000000000070000002800000038F99A0046CA9B0001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000112F3E00000000000200000002000000 "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"=0x5341435001000000000000000700000028000000A8930C00859B0C0001000000000000000000010671020000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000084260000000000000100000001000000 "D:\Docs Max\Administratif\Compte Bancaire\RIB et IBAN\ZHPDiag2.exe"=0x5341435001000000000000000700000028000000E8AC68000000000001000000000000000000030641220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009D7D0000000000000100000001000000 "C:\Program Files (x86)\EPSON Software\Download Navigator\EPSDNAVI.EXE"=0x534143500100000000000000070000002800000068012B00E6722B0001000000000000000000030600210000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000BFB7B000000000000900000008000000000000000000004000000000000000000000000000000000D4B1530A000000004B00000000000000 "D:\Docs Max\Administratif\Compte Bancaire\RIB et IBAN\AdsFix.exe"=0x534143500100000000000000070000002800000000F62800AA99290001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000036F85A00000000000100000001000000 "C:\Users\Maxime\Downloads\AdsFix.exe"=0x534143500100000000000000070000002800000000F62800AA99290001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000A6930300000000000100000001000000 "C:\Users\Maxime\Desktop\QuickDiag.exe"=0x534143500100000000000000070000002800000000461500ABCE150001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D00B0800000000000100000001000000 "C:\Users\Maxime\Desktop\OTM.exe"=0x534143500100000000000000070000002800000000F807000E4C080001000000000000000000030641220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E2550300000000000100000001000000 "C:\Users\Maxime\Desktop\Réparation ordi\QuickDiag.exe"=0x534143500100000000000000070000002800000000461500ABCE150001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000A75B1500000000000100000001000000 "C:\Program Files (x86)\TuneUp Utilities 2014\UninstallManager.exe"=0x534143500100000000000000070000002800000038F90300AAF8040001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D31E0000000000000100000001000000 "C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe"=0x53414350010000000000000007000000280000003809200062B1200001000000000000000000020673020000B395E7CF049FCE01000000000000000002000000280000000000000000000040000000000000000000000000000000008C000000000000000200000002000000 "C:\Program Files (x86)\StopClope\unins000.exe"=0x5341435001000000000000000700000028000000F9D309000000000003000000000000000000030641200000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000D4810300000000000100000001000000 "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe"=0x53414350010000000000000007000000280000006A010B000000000001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000010000000000000000000000000F92F0000000000000100000001000000 "C:\Program Files (x86)\Malwarebytes' Anti-Malware\unins000.exe"=0x534143500100000000000000070000002800000068D70A00522B0B0003000000000000000000020600010000975FD891C99ECE010000000000000000 "C:\Program Files (x86)\EPSON Software\Event Manager\EProjManager.exe"=0x534143500100000000000000070000002800000040B612004B2B130001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000011285400000000000300000003000000 "C:\Users\Maxime\Documents\Docs Max\Meulan les Mureaux\Mémoire\Mémoire Tyss\Prezi.exe"=0x534143500100000000000000070000002800000000CA01000000000001000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000890B0000000000000100000001000000 "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4e.exe"=0x5341435001000000000000000700000028000000F09E070068FB0700010000000000000000000106F5220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000200000000000000000000000000CC120000000000000100000001000000 "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4d.exe"=0x5341435001000000000000000700000028000000F008040071DD0400010000000000000000000106F5220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000200000000000000000000000000B7130000000000000100000001000000 "SIGN.MEDIA=1CA00 Meulan les Mureaux\Mémoire\Mémoire Tyss\Prezi.exe"=0x534143500100000000000000070000002800000000CA01000000000001000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000910F0000000000000100000001000000 "C:\Users\Maxime\AppData\Roaming\Dropbox\bin\Dropbox.exe"=0x5341435001000000000000000700000028000000A0A42B0289972C0201000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CC3FB106000000000200000002000000 "C:\Users\Maxime\AppData\Local\Temp\AIRB5D1.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A0920100315F020001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000008120200000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR13EB.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A0920100315F020001000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000CADB2400000000000100000001000000 "C:\Users\Maxime\Desktop\FreeMind-Windows-Installer-1.0.0-max.exe"=0x5341435001000000000000000700000028000000FDE144020000000001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BA920000000000000200000002000000 "C:\Program Files (x86)\FreeMind\FreeMind.exe"=0x5341435001000000000000000700000028000000006601007BBB010001000000000000000000020671000000975FD891C99ECE0100000000000000000200000028000000000000000000004000100000000000000000000000000000840D5F02000000000300000003000000 "C:\Users\Maxime\AppData\Local\Temp\AIR7372.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A09201008CC8010001000000000000000000030671220000975FD891C99ECE01000000800000000002000000280000000000000000000040000000000000000000000000000000008E012600000000000100000001000000 "C:\Users\Maxime\Desktop\SimpleMindPro165TrialSetup.exe"=0x5341435001000000000000000700000028000000329554000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000081F93500000000000400000004000000 "C:\Windows\1.6.5\SimpleMindPro.exe"=0x534143500100000000000000070000002800000000EC13000000000001000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DC6F2901000000000800000008000000 "C:\Users\Maxime\Desktop\Dragon Naturally Speaking pro v11 FR\setup.exe"=0x5341435001000000000000000700000028000000984A1100F86A110001000000000000000000010600210000975FD891C99ECE0100000000000000000200000028000000000000000000005000000000000000000000000000000000BB900900000000000100000001000000 "C:\Users\Maxime\Desktop\Dragon Naturally Speaking pro v11 FR\WindowsInstaller-KB893803-x86.exe"=0x534143500100000000000000070000002800000010712700EC04280001000000000000000000000671000000975FD891C99ECE010000008000000000020000002800000000000000800900400000000000000000000000000000000009230000000000000100000001000000 "C:\Users\Maxime\Desktop\Dragon Naturally Speaking pro v11 FR\Dragon NaturallySpeaking 11.msi"=0x534143500100000000000000070000002800000000FC0000FB41010001000000000000000000010500100000B395E7CF049FCE010000000000000000020000002800000000000000000000400000000000000000000000000000000095710A00000000000200000002000000 "C:\Windows\Program\natspeak.exe"=0x534143500100000000000000070000002800000068D536003EE3360001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000000000000500010000000000000000000000000000068D6C606000000000500000005000000 "C:\Users\Maxime\AppData\Local\Temp\AIR117F.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A09201004A0D020001000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000330E1500000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIRC825.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A09201004CC9010001000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000E1C40100000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\certutil.exe"=0x5341435001000000000000000700000028000000006001000000000001000000000000000000010571000000975FD891C99ECE0100000000000000000200000028000000000000000000004000040000000000000000000000000000E50E0000000000000200000002000000 "C:\Users\Maxime\AppData\Local\Temp\AIR2247.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000A07C05003A6C060001000000000000000000030671220000975FD891C99ECE010000008000000000 "C:\Program Files (x86)\Skype\Phone\Skype.exe"=0x534143500100000000000000070000002800000080082D0355102D0301000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C3952F00000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR694F.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B87C0500D874060001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000021050D00000000000100000001000000 "C:\Users\Maxime\Desktop\DemoTT55_fra.exe"=0x534143500100000000000000070000002800000045809C000000000001000000000000000000000671020000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400002000000000000000000000000000093330000000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\BingSvc\BSvcProcessor.exe"=0x534143500100000000000000070000002800000098101100C837110001000000000000000000030600210000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000A3340200000000008100000046000000000000000000004000000000000000000000000000000000A0F6B00700000000540B000000000000 "C:\Users\Maxime\AppData\Local\Temp\AIRC260.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B87C05009858060001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000090A80400000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE"=0x5341435001000000000000000700000028000000B0FE2000BE48210001000000000000000000010600010000975FD891C99ECE010000000100000000 "C:\Users\Maxime\AppData\Local\Temp\AIRE31F.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B87C05000275060001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000079520600000000000100000001000000 "C:\Users\Maxime\Desktop\Sony Vegas Pro 12 Build 770 (64 bit) (patch-keygen DI)\vegaspro12.0.770.exe"=0x534143500100000000000000070000002800000078FA7C0EEA3A7D0E01000000000000000000010600010000B395E7CF049FCE010000000000000000020000002800000000000000000000400000000000000000000000000000000096CE0100000000000500000005000000 "D:\Sony vegas pro\Sony Vegas Pro 12 Build 770 (64 bit) (patch-keygen DI)\patch - keygen DI\Keygen.exe"=0x534143500100000000000000070000002800000000303900B66E390001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000100000000000000000000000000000ED200500000000000100000001000000 "D:\Sony vegas pro\vegas120.exe"=0x534143500100000000000000070000002800000020BB99016E869A0101000000000000000000010600010000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000A23B0000000000000100000001000000 "C:\Users\Maxime\Desktop\Sony Vegas Pro 12 Build 770 (64 bit) (patch-keygen DI)\patch - keygen DI\Keygen.exe"=0x534143500100000000000000070000002800000000303900B66E390001000000000000000000010600010000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040001000000000000000000000000000000C890C00000000000600000006000000 "C:\Program Files\Sony\Vegas Pro 12.0\vegas120.exe"=0x534143500100000000000000070000002800000020BB99016E869A0101000000000000000000010600010000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000005F5EDD02000000002700000027000000 "C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe"=0x534143500100000000000000070000002800000040D912004791130001000000000000000000030671200000E63F486B2AA0D20100000000000000000200000028000000000000000000005000000000000000000000000000000000F73B0F00000000000F0000000F000000 "C:\Users\Maxime\AppData\Local\Temp\AIRA1EE.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B0880500BD03060001000000000000000000030600210000975FD891C99ECE010000008000000000 "C:\Users\Maxime\AppData\Local\Vistaprint Livres photo\apc.exe"=0x5341435001000000000000000700000028000000D8486C0032246D0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BF049800000000000500000005000000 "C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"=0x5341435001000000000000000700000028000000C8340300A937030001000000000000000000030600010000E78E163C2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000007B81480D000000004F0000004F000000 "C:\Program Files\AVAST Software\Avast\avastui.exe"=0x534143500100000000000000070000002800000050365D0036845D0001000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000001E2AEA01000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C03802000BA5020001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8BA020001D3020001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\Maxime\AppData\Local\Temp\AIR1883.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B0880500E60E060001000000000000000000000A0021000019B4C529E312D1010000008000000000020000002800000000000000000000400000000000000000000000000000000081B14100000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR8A93.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B0880500CEF1050001000000000000000000000A0021000019B4C529E312D1010000008000000000020000002800000000000000000000400000000000000000000000000000000083BD1400000000000100000001000000 "C:\Users\Maxime\AppData\Local\Temp\AIR7580.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B08805009A10060001000000000000000000000A0021000019B4C529E312D10100000080000000000200000028000000000000000000004000000000000000000000000000000000B24D3800000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C0AC02007050030001000000000000000000000A0021000019B4C529E312D1010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C0AC02007050030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Maxime\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe"=0x534143500100000000000000070000002800000000482D00A2D42D000100000000000000000001057120000033504C2B57DFD1010000000000000000 "C:\Users\Maxime\Desktop\Tor Browser\Browser\firefox.exe"=0x534143500100000000000000070000002800000000240500C33A050001000000000000000000000A0001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000069A15700000000000200000002000000 "C:\Program Files (x86)\Google\Drive\googledrivesync.exe"=0x534143500100000000000000070000002800000060AD6401017A65010100000000000000000001067102000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000864A0000000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000E07E03004B44040001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Maxime\AppData\Local\Temp\AIRDF76.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000488C05001503060001000000000000000000000A0021000033504C2B57DFD1010000008000000000020000002800000000000000000000400000000000000000000000000000000055480300000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D87E030025C1030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\PokerStars.FR\PokerStarsUpdate.exe"=0x5341435001000000000000000700000028000000B8211400CD46140001000000000000000000000A0021000033504C2B57DFD10100000080000000000200000028000000000000000000004000000000000000000000000000000000308C0400000000000300000003000000 "C:\Users\Maxime\Desktop\PokerStarsInstallFR.exe"=0x5341435001000000000000000700000028000000E0E2F7040000000001000000000000000000000A7120000033504C2B57DFD101000000000000000005000000100000000000000000000000000000000008000002000000280000000000000000080040000020000000000000002000000000000A350000000000000100000001000000010000000400000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D88003007F30040001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\Windows Media Player\wmplayer.exe"=0x5341435001000000000000000700000028000000008C02001930030001000000010000000000000A7122000033504C2B57DFD1010000000000000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D88203009CF3030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\SketchUp\SketchUp 2015\SketchUp.exe"=0x534143500100000000000000070000002800000000661401D84C150101000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000DEACDA03000000000400000004000000 "C:\Users\Maxime\AppData\Local\Temp\AIRCBA3.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000488C05007B37060001000000000000000000000A0021000033504C2B57DFD10100000080000000000200000028000000000000000000004000000000000000000000000000000000BF633700000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6917.0607_1\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D09A0300AA58040001000000000000000000000A7120000033504C2B57DFD1010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6917.0607_2\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D09A0300AA58040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6943.0625_1\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0960300F48A040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"=0x534143500100000000000000070000002800000060CA11002C5E120001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000A560DF01000000001400000014000000000000000000004000000000000000000000000000000000FA700000000000000400000000000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0B00300CDA9040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\AppData\Local\Temp\AIRA824.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000F08D05007389060001000000000000000000000A00210000E63F486B2AA0D2010000008000000000020000002800000000000000000000400000000000000000000000000000000035B87300000000000100000001000000 "C:\Program Files\AVAST Software\Avast\VisthAux.exe"=0x5341435001000000000000000700000028000000008403007301040001000000000000000000000A00210000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000004000000000000000000000000000000000A60E0000000000000100000001000000 "C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe"=0x5341435001000000000000000700000028000000882A1400619D140001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000500000000000000000000000000000000000000000000000000000005976460D000000004300000043000000000000000000004000000000000000000000000000000000FB999608000000001600000000000000 "C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe"=0x534143500100000000000000070000002800000018AA1700DC95180001000000000000000000010600010000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\Desktop\ZHPCleaner.exe"=0x5341435001000000000000000700000028000000800F2C00033A2C0001000000000000000000030600010000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000EC6A1B00000000000500000005000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000D0A474012679750101000000000000000000000A00210000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0E20300117A040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Program Files\AVAST Software\Avast\Setup\instup.exe"=0x534143500100000000000000070000002800000068DA14000000000001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000000FBB0400000000000200000002000000 "C:\Program Files (x86)\FreeMind\unins000.exe"=0x534143500100000000000000070000002800000021020B000000000001000000000000000000020600010000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000004F6F0100000000000200000002000000 "C:\ProgramData\Package Cache\{bd8bd200-9a60-4969-b267-6b565f36e3da}\GarminExpressInstaller.exe"=0x534143500100000000000000070000002800000078611000B9F0100001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000007A7C0200000000000500000005000000 "C:\Users\Maxime\Desktop\mb3-setup-consumer-3.2.2.2018.exe"=0x5341435001000000000000000700000028000000E860F403E7FEF40301000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000012040100000000000100000001000000 "C:\Users\Maxime\Desktop\Nettoyage ordi\QuickDiag.exe"=0x5341435001000000000000000700000028000000A83D47002252470001000000000000000000000A00210000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000068D12B00000000000200000002000000 "C:\Users\Maxime\Desktop\quicktimeinstaller.exe"=0x534143500100000000000000070000002800000040497F02DDC37F0201000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000041670100000000000100000001000000 "C:\Users\Maxime\Desktop\Windows10Upgrade9252.exe"=0x5341435001000000000000000700000028000000B08862008E56630001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000F3640000000000000100000001000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\OneDrive.exe"=0x5341435001000000000000000700000028000000D0BC19009F9A1A0001000000000000000000000A00210000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\Desktop\Nettoyage ordi\delfix_1.013.exe"=0x5341435001000000000000000700000028000000402C0C00C2D00C0001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000002F710200000000000100000001000000 "C:\Users\Maxime\Desktop\Nettoyage ordi\unchecky_setup.exe"=0x5341435001000000000000000700000028000000D8BA1400593F150001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E2110000000000000100000001000000 "C:\Users\Maxime\Desktop\EPSDNAVI_Temp\Download Navigator\Setup.msi"=0x53414350010000000000000007000000280000000002010013D4010001000000000000000000010500100000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000BA780000000000000100000001000000 "C:\Users\Maxime\Desktop\EPSDNAVI_Temp\Download Navigator\Setup.exe"=0x5341435001000000000000000700000028000000F8C10500C74C060001000000000000000000030600010000E63F486B2AA0D2010000008000000000020000002800000000000000000000400000000000000000000000000000000065EC0300000000000100000001000000 "C:\Users\Maxime\Desktop\pole emploi\uTorrent.exe"=0x5341435001000000000000000700000028000000607A2B0093CA2B0001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000045440500000000000100000001000000 "C:\Users\Maxime\AppData\Roaming\uTorrent\uTorrent.exe"=0x5341435001000000000000000700000028000000C04D1E009D951E0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000EB7E4700000000000A0000000A000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.7074.1023\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C80E0400B6AD040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000C8447B0131B57B0101000000000000000000000A00210000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C80E040067ED040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\AppData\Local\Google\Chrome\Application\chrome.exe"=0x534143500100000000000000070000002800000058BF170046D8170001000000000000000000000A00210000E78E163C2AA0D2010000000100000000 "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE"=0x5341435001000000000000000700000028000000A8DA1500C7D5160001000000000000000000010600010000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\Downloads\Firefox Setup 57.0.1.exe"=0x5341435001000000000000000700000028000000A0A04002A3F6400201000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000004BB10400000000000100000001000000 "C:\Program Files (x86)\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000D0210700B947070001000000000000000000000A00210000E63F486B2AA0D2010000000100000000 "C:\Program Files (x86)\Mozilla Firefox\pingsender.exe"=0x5341435001000000000000000700000028000000D0D70000782C010001000000000000000000000A71200000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000DD0A0000000000000400000004000000 "C:\Users\Maxime\Downloads\mozilla-firefox_57-0-1_fr_11003_32.exe"=0x5341435001000000000000000700000028000000001A290288112A0201000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000C5A41F00000000000200000002000000 "C:\Users\Maxime\Downloads\EIE11_FR-FR_WOL_WIN764.EXE"=0x5341435001000000000000000700000028000000904FA003E899A00301000000000000000000030671020000E63F486B2AA0D2010000000000000000020000002800000000000000800100400000000000000000000000000000000063BF0100000000000100000001000000 "C:\Users\Maxime\Desktop\torbrowser-install-6.0.5_fr.exe"=0x53414350010000000000000007000000280000000057FB02BC4FFC0201000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000C6799700000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE"=0x5341435001000000000000000700000028000000A87C3701F1DC370101000000000000000000010600010000E63F486B2AA0D2010000000100000000 "C:\Users\Maxime\Desktop\Nettoyage ordi\ZHPCleaner.exe"=0x5341435001000000000000000700000028000000809F2D0016CD2D0001000000000000000000030600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000061FDAD00000000000200000002000000 "C:\Users\Maxime\AppData\Roaming\ZHP\ZHPCleaner.exe"=0x5341435001000000000000000700000028000000809F2D0016CD2D0001000000000000000000030600010000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000003915600000000000200000002000000 "C:\Users\Maxime\Downloads\QuickDiag.exe"=0x5341435001000000000000000700000028000000A8C73C0092F63C0001000000000000000000000A00210000E63F486B2AA0D2010000000000000000 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"=0x5341435001000000000000000700000028000000584D180031CA180001000000000000000000000A00210000E78E163C2AA0D2010000000100000000 "C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\Installer\setup.exe"=0x5341435001000000000000000700000028000000587F1D0054331E0003000000000000000000000A00210000E78E163C2AA0D2010000000000000000 "C:\Users\Maxime\AppData\Local\Google\Chrome\Application\62.0.3202.94\Installer\setup.exe"=0x5341435001000000000000000700000028000000582F1D007AD31D0003000000000000000000000A00210000E78E163C2AA0D2010000000000000000 ---------- | IFEO ---------- | Mountpoints2 ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=131452885027793743 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "DisableAntiSpyware"=0 "ProductType"=2 "ManagedDefenderProductType"=0 "ProductStatus"=0 "InstallTime"=0x07F2E37DE99ACD01 "DisableAntiVirus"=0 "InstallLocation"=C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\ "LastEnabledTime"=0xEC498E80E96CD301 "OneTimeSqmDataSent"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts # unchecky_begin # These rules were added by the Unchecky program in order to block advertising software modules 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com [64] More lines ---------- | Ping Envoi d'une requ?te 'ping' sur google.com [172.217.22.142] avec 32 octets de donn?es?: R?ponse de 172.217.22.142?: octets=32 temps=22 ms TTL=53 R?ponse de 172.217.22.142?: octets=32 temps=23 ms TTL=53 R?ponse de 172.217.22.142?: octets=32 temps=23 ms TTL=53 R?ponse de 172.217.22.142?: octets=32 temps=23 ms TTL=53 Statistiques Ping pour 172.217.22.142: Paquets?: envoy?s = 4, re?us = 4, perdus = 0 (perte 0%), Dur?e approximative des boucles en millisecondes : Minimum = 22ms, Maximum = 23ms, Moyenne = 22ms ---------- | @ [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "Cache_Update_Frequency"=Once_Per_Session "Local Page"=C:\WINDOWS\SysWOW64\blank.htm "NoUpdateCheck"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Start Page"=www.google.com "Default_Page_URL"=http://lenovo13.msn.com "DisableFirstRunCustomize"=3 "Default_Secondary_Page_URL"=http://www.lenovo.com "OperationalData"=13 "FullScreen"=no "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0x150A3C75A8A1D201 "IconCache"=2b1zkjn "CompatibilityFlags"=0 "Window_Placement"=0x2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000000000000E80300003A020000 "ApplicationTileImmersiveActivation"=0 "AssociationActivationMode"=2 "Use FormSuggest"=yes "DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFB0010000960000003004000076020000 "AutoHide"=yes "ImageStoreRandomFolder"=323snl3 "Start Default_Page_URL"=http://www.google.com/ "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "CustomizeSearch"=http://www.google.com/ "EdgeSwitchingOSBuildNumber"=10586.th2_release.160906-1759 "Secondary Start Pages"=http://www.msn.com/?pc=U453&ocid=U453DHP&osmkt=fr-fr "Start Page_TIMESTAMP"=0x3A8558954AE3D201 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"=0x0100000038000000773629A736E3F3D093FFF19FBF67DC8B18E233A9ED08741F4D95AD4547C2DF06F09D3D12DB8DED1E5C5E513AB6BB89D77815618BF8AA7597020000000E00000052456E36357A33336B6677253364 "NotifyDownloadComplete"=yes "First Home Page"=http://g.msn.com/1me10IE11FRFR/WOL_WCP [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"=http://www.google.com/ "Search Bar"=http://www.google.com/ "Start Page"=http://www.google.com/ "Start Default_Page_URL"=http://www.google.com/ "Local Page"=C:\WINDOWS\SysWOW64\blank.htm "Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157 "CustomizeSearch"=http://www.google.com/ [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Internet Explorer\SearchURL] "Default"=http://www.google.com/ [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Internet Explorer\AboutURLs] "Tabs"=http://www.google.com/ [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "CertificateRevocation"=1 "EnableNegotiate"=1 "MigrateProxy"=1 "ProxyEnable"=0 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "ZonesSecurityUpgrade"=0x56AA10C9CF2FD301 "EmailName"=User@ "AutoConfigProxy"=wininet.dll "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "WarnOnPost"=0x01000000 "UseSchannelDirectly"=0x01000000 "EnableHttp1_1"=1 "UrlEncoding"=0 "WarnonZoneCrossing"=0 "GlobalUserOffline"=0 "EnableAutodial"=0 "NoNetAutodial"=0 [HKLM\Software\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "Local Page"=C:\WINDOWS\SysWOW64\blank.htm "TabProcGrowth"=Medium "Print_Background"=0 "AlwaysShowMenus"=0 "StatusBarWeb"=1 "DoNotTrack"=1 "Search Bar"=http://www.google.com/ "Start Default_Page_URL"=http://www.google.com/ "CustomizeSearch"=http://www.google.com/ [HKLM\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"=http://www.google.com/ "Search Bar"=http://www.google.com/ "Start Page"=http://www.google.com/ "Start Default_Page_URL"=http://www.google.com/ "Local Page"=C:\WINDOWS\SysWOW64\blank.htm "Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157 "CustomizeSearch"=http://www.google.com/ [HKLM\Software\Microsoft\Internet Explorer\SearchURL] "Default"=http://www.google.com/ [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\SysWOW64\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 ---------- | Proxy ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] : igfxdev.dll ---------- | Execution FileExts ---------- | SIOI | SEH | URLSH [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ GoogleDriveBlacklisted] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} -- C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [10/11/2017 10:52:10] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ GoogleDriveSynced] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} -- C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [10/11/2017 10:52:10] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ GoogleDriveSyncing] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} -- C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [10/11/2017 10:52:10] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt1"] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt2"] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt3"] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt4"] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt5"] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt6"] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt7"] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt8"] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw] - {472083B0-C522-11CF-8763-00608CC02F24} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast] - {472083B0-C522-11CF-8763-00608CC02F24} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [18/03/2017 21:57:23] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7} -- C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:44:34] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} -- C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:44:34] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399} -- C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:44:34] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619} -- C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:44:34] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} -- C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:44:34] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp] - {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} -- C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending] - {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} -- C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot] - {A759AFF6-5851-457D-A540-F4ECED148351} -- C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared] - {1574C9EF-7D58-488F-B358-8B78C1538F51} -- C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt1"] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt2"] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt3"] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt4"] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt5"] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt6"] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt7"] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt8"] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7} -- C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} -- C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399} -- C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619} -- C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} -- C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=Groove GFS Stub Execution Hook [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=Groove GFS Stub Execution Hook ---------- | Toolbar [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser] "ITBar7Layout"=0x13000000000000000000000020000000100000001500000001000000800600005E010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={AA1D8799-6AF9-4999-A437-C975155F764A} "KnownProvidersUpgradeTime"=0x32FAC90C6965D101 "Version"=4 "UpgradeTime"=0x5C51210E6965D101 "DownloadRetries"=6 "DefaultPackCorrection"=1 "DefaultPackNTCorrection"=1 [HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}"= "{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}"=avast! Online Security "{9421DD08-935F-4701-A9CA-22DF90AC4EA6}"=EPTBL [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Toolbar] "{201CF130-E29C-4E5C-A73F-CD197DEFA6AE}"=E-Web Print [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} ---------- | Extensions [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (&Envoyer à OneNote) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] : (Lync Click to Call) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (Notes &liées OneNote) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (&Envoyer à OneNote) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (Notes &liées OneNote) - [] ---------- | SearchScopes [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA1D8799-6AF9-4999-A437-C975155F764A}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA1D8799-6AF9-4999-A437-C975155F764A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{AA1D8799-6AF9-4999-A437-C975155F764A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS : ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] -> (Groove GFS Browser Helper) : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] -> (Office Document Cache Handler) : C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [06/03/2013 07:37:48] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201CF130-E29C-4E5C-A73F-CD197DEFA6AE}] -> (E-Web Print) : C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] -> (Groove GFS Browser Helper) : C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [19/12/2013 00:41:02] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> (Java(tm) Plug-In SSV Helper) : C:\Program Files (x86)\Java\jre7\bin\ssv.dll [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] -> (Office Document Cache Handler) : C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [06/03/2013 07:37:48] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> (Java(tm) Plug-In 2 SSV Helper) : C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll ---------- | Chrome C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\aohghmighlieiainnegkcijnfilokake = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\apdfllckaahabafndbhieahigkjlhalf = : Google & co - https://drive.google.com/?usp=chrome_app - Google & co - [http://docs.google.com/http://drive.google.com/https://docs.google.com/https://drive.google.com/] - https://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\blakpkgjpemejpbmfiglncklihnhjkij = : __MSG_extIntDesc__ - __MSG_extName__ - https://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co - http://www.youtube.com - http://www.youtube.com - Google & co - http://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\coobgpohoikkiipiblmjeljniedjpjpf = : Google & co - http://www.google.com/webhp?source=search_app - Google & co - [*://www.google.com/search*://www.google.com/webhp*://www.google.com/imgres] - http://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi = : __MSG_extDesc__ - __MSG_extName__ - https://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\gighmmpiobklfepjocnamgkkbiglidom = : __MSG_description__ - short_name: __MSG_name__ - permissions:[tabs\u003Call_urls>contextMenuswebRequestwebRequestBlockingwebNavigationstorageunlimitedStoragenotificationsidlealarms] - https://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co - https://mail.google.com/mail/ca - Google & co - [*://mail.google.com/mail/ca] - http://clients2.google.com/service/update2/crx C:\Users\Maxime\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm = : Provider for discovery and services for mirroring of Chrome Media Router - Chrome Media Router - 919648714761-55j965o0km033psv3i9qls5mo3qtdrb0.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl] ---------- | Opera ---------- | Firefox [HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions] "e-webprint@epson.com"=C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin] - (Facebook Video Calling Plugin) : C:\Users\Maxime\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Users\Maxime\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [HKU\S-1-5-21-60461441-1236719898-3972887004-1001\Software\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Users\Maxime\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 28.0.0.126 Plugin) : C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] - (Office Authorization plug-in for NPAPI browsers) : C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 28.0.0.126 Plugin) : C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42] - (Intel IPT WebApi plugin) : C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater] - (This plugin updates Intel WebAPI component) : C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.55.2] - (Java Deployment Toolkit) : C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2] - (Oracle® Next Generation Java Plug-In) : C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] - (Office Authorization plug-in for NPAPI browsers) : C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.0] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\Adobe Reader] - (Handles PDFs in-place in Firefox) : C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll C:\Users\Maxime\AppData\Roaming\Mozilla\Firefox\Profiles\g8ckada9.default\Prefs.js C:\Users\Maxime\AppData\Roaming\Mozilla\Firefox\Profiles\owmdd1yo.default-1369816259357\Prefs.js user_pref("browser.newtab.url", "http://www.bing.com/?pc=COSP&ptag=D102817-A9FCDBB39EF&form=CONMHP&conlogo=CT3335799"); user_pref("browser.search.defaultenginename", "Bing®"); user_pref("browser.search.selectedEngine", "Bing®"); user_pref("browser.startup.homepage", "https://www.qwant.com/"); user_pref("browser.startup.homepage_override.buildID", "20171128222554"); user_pref("browser.startup.homepage_override.mstone", "57.0.1"); user_pref("browser.uiCustomization.state", "{\"placements\":{\"widget-overflow-fixed-list\":[],\"PersonalToolbar\":[\"personal-bookmarks\"],\"nav-bar\":[\"back-button\",\"forward-button\",\"stop-reload-button\",\"home-button\",\"unified-back-forward-button\",\"customizableui-special-spring1\",\"urlbar-container\",\"downloads-button\",\"reload-button\",\"stop-button\",\"search-container\",\"customizableui-special-spring2\",\"webrtc-status-button\",\"library-button\",\"wrc-toolbar-button\",\"window-controls\",\"social-share-button\",\"button--skype_ff_extensionjetpack-c2c-options-button\",\"sidebar-button\",\"jid1-16aeif9oqirkxa_jetpack-browser-action\"],\"TabsToolbar\":[\"tabbrowser-tabs\",\"new-tab-button\",\"alltabs-button\",\"tabs-closebutton\"],\"toolbar-menubar\":[\"menubar-items\"],\"addon-bar\":[\"addonbar-closebutton\",\"status-bar\"]},\"seen\":[\"button--skype_ff_extensionjetpack-c2c-options-button\",\"jid1-16aeif9oqirkxa_jetpack-browser-action\",\"developer-button\",\"webide-button\"],\"dirtyAreaCache\":[\"PersonalToolbar\",\"nav-bar\",\"TabsToolbar\",\"toolbar-menubar\",\"PanelUI-contents\",\"addon-bar\"],\"currentVersion\":12,\"newElementCount\":2}"); user_pref("e10s.rollout.cohort", "webextensions-multiBucket4"); user_pref("extensions.a217e8200a3b343dfb9518ec01d483d7fb98c68091f3f41a1bb1c692cf84781e9com27096.27096.plugins.plugin_4.code", "var jQuery = $jquery_171 = $jquery = null;\n\nif (document && typeof document.getElementById !== \"undefined\") {\n\n/*! jQuery v1.7.1 jquery.com | jquery.org/license */\n(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(\"<\"+a+\">\").appendTo(b),e=d.css(\"display\");d.remove();if(e===\"none\"||e===\"\"){cl||(cl=c.createElement(\"iframe\"),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===\"CSS1Compat\"?\"\":\"\")+\"
\"),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,\"display\"),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(\"Microsoft.XMLHTTP\")}catch(b){}}function ci(){try{return new a.XMLHttpRequest}catch(b){}}function cc(a,c){a.dataFilter&&(c=a.dataFilter(c,a.dataType));var d=a.dataTypes,e={},g,h,i=d.length,j,k=d[0],l,m,n,o,p;for(g=1;g0){if(c!==\"border\")for(;gt |