--------------- QuickScript | g3n-h@ckm@n | V4_27.04.18.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 30/04/2018 09:26:16 Updated 27/04/2018 | 14.15 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris Registry saved : C:\QuickDiag\Save\Registry [30.04.2018 @ 09_26_16] Task HP AR Program Upload - 4ba89dd2808145be9d415a1b82b2d4c59d7a2adb9e264a46961bacc5917ba472 Not Found ! Task HP AR Program Upload - 7295639e1a004599bcffec441ede2c5798bcf81e62644a03b6b591401e723d1b Not Found ! Task HP AR Program Upload - 96b43d4ae8474ca5a8ff25a3650ca34b45bfb6d4fe2b4a54aeaf95b319742780 Not Found ! Task HP AR Program Upload - 9ea29ba2ad7345eba2699d268bf2df89266c0c46bd1a4e7f9ca478333e472aac Not Found ! Task {B90BE772-893A-4871-BAB2-FF70C4B45845} Not Found ! Key : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw] Deleted Successfully Key : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8E9AEB09-3658-4FA2-B85B-40B932D0F5B3}] Deleted Successfully Key : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}] Deleted Successfully Key : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{8E9AEB09-3658-4FA2-B85B-40B932D0F5B3}] Deleted Successfully Key : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}] Deleted Successfully Key : [HKLM\Software\McAfee.com] Deleted Successfully Key : [HKLM\Software\WOW6432Node\AVAST Software] Deleted Successfully Key : [HKLM\Software\WOW6432Node\McAfee] Deleted Successfully C:\Windows.old Moved Successfully C:\WINDOWS\Temp\_avast_ Moved Successfully C:\Users\Patrick\SkyDrive.old Moved Successfully C:\Users\Patrick\AppData\Roaming\GlarySoft Moved Successfully C:\ProgramData\AVAST Software Moved Successfully C:\Program Files (x86)\Temp Moved Successfully C:\Program Files\ReviverSoft Moved Successfully C:\Program Files\Common files\AVAST Software Moved Successfully C:\WINDOWS\System32\Tasks\HP AR Program Upload - 4ba89dd2808145be9d415a1b82b2d4c59d7a2adb9e264a46961bacc5917ba472 Moved Successfully C:\WINDOWS\System32\Tasks\HP AR Program Upload - 7295639e1a004599bcffec441ede2c5798bcf81e62644a03b6b591401e723d1b Moved Successfully C:\WINDOWS\System32\Tasks\HP AR Program Upload - 96b43d4ae8474ca5a8ff25a3650ca34b45bfb6d4fe2b4a54aeaf95b319742780 Moved Successfully C:\WINDOWS\System32\Tasks\HP AR Program Upload - 9ea29ba2ad7345eba2699d268bf2df89266c0c46bd1a4e7f9ca478333e472aac Moved Successfully C:\WINDOWS\System32\Tasks\{B90BE772-893A-4871-BAB2-FF70C4B45845} Moved Successfully Line : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Prefs.js : user_pref("extensions.Deal Keeper.asul", "1406371082643"); -> Deleted Successfully Line : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Prefs.js : user_pref("extensions.Deal Keeper.aul", "1406370768837"); -> Deleted Successfully Line : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Prefs.js : user_pref("extensions.Deal Keeper.irl", true); -> Deleted Successfully Line : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Prefs.js : user_pref("extensions.Deal Keeper.is", "isgiwhFR"); -> Deleted Successfully Line : C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Prefs.js : user_pref("extensions.Deal Keeper.ug", "927B4C28-BD34-4527-A36F-B874A9CC4041"); -> Deleted Successfully -------------- | RegRead [HKEY_CURRENT_USER\Software\7-Zip] "Lang"=fr [HKEY_CURRENT_USER\Software\AvastAdSDK] "LastOffer"=1524473788 [HKEY_CURRENT_USER\Software\BookService] "18"=0x9F6BA72A412B9DF6D3AD2EC9101B196C732AD2E6FF63115550DD950DEDE6B5145830E1A8A6246CB3F6E17CC60F24107E696CAD7759DCF730DBC4E3EB3EB83B791186379063783E28F56DD5485B92DDFB8BF5B150C31CF695AA810B9A3AA01AAEE2E0AAB1606E5CF8B2187277809C17B5AC0060EFD419B9D155CB2BE30B32FE6F982B8905D925BC40726142F97E5D02FDB14959CFFFC2045751C80E6C804ABE40F8F6814F010F4AA7980226915E37FDEAB289D13154ACF7DE5EEB6DCAE83A93ADA7B19C8A97368FF8A51157A36A39B02EC812F93CDD12D7E25E2AC7705935543A052AC0827C11E554E7B7816CBBFCB42897FFFF4661F1A20FA6A449268410C00E44DDD8DECD0435B4E4794AE6 [HKEY_CURRENT_USER\Software\Browser Cleanup] "cl"=3 "AvExts"={"chrome":{"aos2":{"s":0},"asg2":{"s":0},"asp2":{"s":0},"ast2":{"s":0},"hon2":{"s":0},"pam2":{"s":0},"sp2":{"s":0},"wkb2":{"s":0},"wtu2":{"s":0},"wtu32":{"s":0}},"firefox":{"aos2":{"s":0},"asg2":{"s":0},"asp2":{"s":0},"ast2":{"s":0},"hon2":{"s":0},"pam2":{"s":0},"sp2":{"s":0},"sp22":{"s":0},"wtu2":{"s":0},"wtu32":{"s":0}},"iexplorer":{"aos2":{"s":0},"pam2":{"s":0},"sp2":{"s":0},"wtu2":{"s":0}},"system":{"wtustat":0}} "BrowserState"={"ed":{"def":0,"m":0,"r":1,"sp":"","version":"11.0.16299.371"},"ff":{"def":0,"m":0,"r":0,"sp":"","version":"57.0 (x64 fr)"},"gc":{"def":1,"m":1,"r":472,"sp":"","version":"65.0.3325.181"},"ie":{"def":0,"m":0,"r":0,"sp":"","version":"9.11.16299.0"},"op":{"def":0,"m":0,"r":0,"sp":"","version":""}} [HKEY_CURRENT_USER\Software\Bsd Concept] "Planète Généalogie"=C:\Program Files (x86)\BSD Concept\Planète Généalogie\PlaneteGenealogie.exe [HKEY_CURRENT_USER\Software\Bubble Noise] "19"=0x9E6AA72A412B9DF6D3AD2EC9101B196C732AC6F2F572456E6DE39D14EFB98F26280FF1BBBB2371D485E17CC60F24107E696CAD7759DCF730DBC4E3EB3EB83B791186379063783E28F56DD5485B92DDFB8BF5B150C31CF695AA810B9A3AA01AAEE2E0AAB1606E5CF8B2187277809C17B5AC0060EFD419B9D155CB2BE30B32FE6F982B8905D925BC40726142F97E5D02FDB14959CFFFC2045751C80E6C804ABE40F8F6814F010F4AA7980226915E37FDEAB289D13154ACF7DE5EEB6DCAE83A93ADA7B19C8A97368FF8A51157A36A39B02EC812F93CDD12D7E25E2AC7705935543A052AC0827C11E554E7B7816CBBFCB42897FFFF4661F1A20FA6A449268410C00E44DDD8DECD0435B416794AE6 [HKEY_CURRENT_USER\Software\CMMs] "20"=0x996DA72A412B9DF6D3AD2EC9101B196C7329DDECEE65175550DD9608AA8D900F0C0684DCD24D02D485E17CC60F24107E696CAD7759DCF730DBC4E3EB3EB83B791186379063783E28F56DD5485B92DDFB8BF5B150C31CF695AA810B9A3AA01AAEE2E0AAB1606E5CF8B2187277809C17B5AC0060EFD419B9D155CB2BE30B32FE6F982B8905D925BC40726142F97E5D02FDB14959CFFFC2045751C80E6C804ABE40F8F6814F010F4AA7980226915E37FDEAB289D13154ACF7DE5EEB6DCAE83A93ADA7B19C8A97368FF8A51157A36A39B02EC812F93CDD12D7E25E2AC7705935543A052AC0827C11E554E7B7816CBBFCB42897FFFF4661F1A20FA6A449268410C00E44DDD8DECD0435B4637B4AE6 [HKEY_CURRENT_USER\Software\Dropbox] "InfPatchComplete"=1 [HKEY_CURRENT_USER\Software\IM Providers] "DefaultIMApp"=Skype [HKEY_CURRENT_USER\Software\Licenses] "{0392473B9566735D8}"=0x563EA80E0BA2A7A6410653989EA944A36022916ED8B605A199E8099B1FB15A23DBF9A639E2D8EA6951B3A04BD6F7D069C1E41A5F619504B6E627CC6B243C9515B6D4648E2ABDD72D8E1402A87A5D718F010EAFD1E1BA57D18B7997390E93485D6EA7E3CF3E037794F1FD99BCBF366895EDF2B0705E698210E08603FB [HKEY_CURRENT_USER\Software\Malwarebytes] "TimerRT"=0 "AEDisabledByUser"=false "RTPDisabledByUser"=false "MWACDisabledByUser"=false "ARWDisabledByUser"=false "FirstRun"=true [HKEY_CURRENT_USER\Software\Malwarebytes' Anti-Malware] "alwaysscanfiles"=1 "alwaysscanheuristics"=1 "alwaysscanmemory"=1 "alwaysscanregistry"=1 "alwaysscanstartups"=1 "openlog"=1 "defaultscan"=0 "terminateie"=0 "selectedrives"=C:\|D:\| [HKEY_CURRENT_USER\Software\Myfree Codec] "path"=C:\Program Files (x86)\MyFree Codec\1.0b beta "Last Version"=1.0.2013.822 "Version Number"=20130822 [HKEY_CURRENT_USER\Software\Opera Software] "Last Stable Install Path"=C:\Program Files (x86)\Opera\ "Previous Default Browser"="C:\WINDOWS\system32\LaunchWinApp.exe" "%1" "ATTEMPTS"=5 "UUID"=0d267922-dd2e-49f3-a854-c449ac260d07 "LUT"=1475836912 [HKEY_CURRENT_USER\Software\ProtectedStorage] "0"=0x01000000D08C9DDF0115D1118C7A00C04FC297EB0100000085411F54890DF348957AFAB6D4B4A84D00000000020000000000106600000001000020000000BA56081D2DE65FD9542AA0F564E900F603EB978816C67A6877240B5B4CE3D440000000000E800000000200002000000022C870320DA9209C76DF713A2ACE3A310B81C87451BEB0246E535B2CB62439895000000055EE76E3D6A4F8EB528B25D3837E14454AC17F2A673628820D8554A38B04BD4E4BEC5FD600F56399F137A5D7768F8C9E4AF051F2CFC3B7A8831D11F1983E4B501271F167F0B40120ABFCE77467B3951440000000B41ABA19B7FE4B196258FF59934CAF5537A4D9CDB0C8F193AC044F5D978212DF35FAEE3489248C2C38E7F1459EFA057D3B635799CB3D525A2AC3F90B6C9DE214 "1"=0x01000000D08C9DDF0115D1118C7A00C04FC297EB0100000085411F54890DF348957AFAB6D4B4A84D000000000200000000001066000000010000200000003A5996736902847812764EDA3164D6EA6BD2CBF914DF7BD7BE08A8AE1C75CF89000000000E800000000200002000000069DC7EDA11C525A240A2F4CAD3EF9417C42DF1358EC0D62D29957DFC5C9EFE2C500000004ADF7592761A6655713A0BB8411F7572F0994D42E805E7FB52785666F19D991F14E2C8A564C657D96364092CADBAD0F188F1E0D469B8E4946F139CA85F3935C4C9581DA5C97E49C3B290DC7D052FB9B140000000BBBC30313A8325224E9FC74641C47CF79CA20BF134E92D2C7A80E3E8DC8FA9FD895CB14F569C305953B393EEB7F92AF3EB73313B952A582F23C568D0EFCF3B3E [HKEY_CURRENT_USER\Software\Redemption] "A95116F2"= [HKEY_CURRENT_USER\Software\RegisteredApplications] "AppXtxcr3sbqvbg05kkv4f2fnq0s0k00ar0d"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\WildTangentGames.-GamesApp-_1.0.3.28_x86__qt5r5pa5dyg8m\WTGames\Capabilities "AppXbm2263aw4p1z4rr7ge1vv6vnkfq7737m"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsReadingList_6.3.9654.21234_x64__8wekyb3d8bbwe\Microsoft.WindowsReadingList\Capabilities "AppXsb1w0yr9y5pz6rnqgg320bm7bk31nhdb"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe\AppexTravel\Capabilities "AppX77rj1xf748zh1ym4w6dnw3ch25299q48"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe\AppexHealthAndFitness\Capabilities "AppX7wh31rvx950vt1t0mhkdw2z1mdn5x9qe"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe\AppexFoodAndDrink\Capabilities "AppX1r65q4mawwwbjbw312gs413ycbhfyyw2"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\eBayInc.eBay_1.6.0.34_neutral__1618n3s9xq8tw\App\Capabilities "AppXv8v7mgnr1rpv57v3vwms7ymgzs353xsh"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\AD2F1837.HPRegistration_1.2.1.166_neutral__v10z8vjag6ke6\App\Capabilities "AppXdt7d90g57d51s6tek5x6y04n3xj4z01c"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\AD2F1837.HPConnectedPhotopoweredbySnapfish_6.0.588.0_x86__v10z8vjag6ke6\App\Capabilities "AppXjr5adfwqybzrd1pbxt98herxvke60cx0"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\AD2F1837.HPScanandCapture_40.0.245.0_x64__v10z8vjag6ke6\App\Capabilities "AppXtthjenkbbvakzbe95dck5q79ykaec624"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\OrangeFrance.TVdOrange_6.2.0.0_x64__3nekra66ya1hy\App\Capabilities "AppXf5mavwz6cmcs1aw0szmxwwb6ejx0h7zp"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Office.Sway_18.1711.50601.0_x64__8wekyb3d8bbwe\Microsoft.Sway\Capabilities "AppXx6bjgb0ga1g7dx9dez2eg9hrn32c2r74"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.DesktopAppInstaller_1.0.12894.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXrtp3qc7f6evy7hzdhmnwxwjxxee5my92"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.CommsPhone_3.34.12002.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXwwfp195gacb8y7gcky8v2q3q0mvfp72n"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.XboxGameOverlay_1.24.5001.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXveh2ktf0zxzfhebt0a4dk2gt25zs2zpn"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.XboxSpeechToTextOverlay_1.21.13002.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXjwz74rmbwq2vmvvtjr9zw8xneptepdrj"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.MicrosoftSolitaireCollection_3.18.12091.0_x64__8wekyb3d8bbwe\App\Capabilities "Rocket.PAWKGCIKH5MUTP7NN4MHVGZSRA"=Software\Clients\StartMenuInternet\Rocket.PAWKGCIKH5MUTP7NN4MHVGZSRA\Capabilities "Firefox"=Software\Clients\StartMenuInternet\FIREFOX.EXE\Capabilities "FIREFOX.EXE"=Software\Clients\StartMenuInternet\FIREFOX.EXE\Capabilities "AppXjs1j2g7y637hgs5prgqmkstfxazwy289"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.AAD.BrokerPlugin_1000.16299.15.0_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXz8g3g23babxsemaah61xebqfd07m2a56"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppX41dnhjtckhbse790zajcb72bsxj7a5k5"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.MicrosoftOfficeHub_17.8830.7600.0_x64__8wekyb3d8bbwe\Microsoft.MicrosoftOfficeHub\Capabilities "AppXmgj48ewmzzwt11zq319t7591v59qteen"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.XboxGameCallableUI_1000.16299.15.0_neutral_neutral_cw5n1h2txyewy\Microsoft.XboxGameCallableUI\Capabilities "AppX58hjgn2bg726g1kw5yg1p7s9vq3wvx6f"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.ParentalControls_1000.16299.15.0_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXvm0yz6wexnbg6gyakreksfh23d2f560e"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_10.0.16299.15_neutral__cw5n1h2txyewy\App\Capabilities "AppXe8aeeqgj209qp5yf2pmkny5jegf5yzej"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_10.0.16299.15_neutral__cw5n1h2txyewy\App\Capabilities "AppXant3e4c766njgz07zg5semb238b1nvse"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.HolographicFirstRun_10.0.16299.125_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXwxvnpdbw9c10hhrvdzzdqn2p2jej368v"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.Apprep.ChxApp_1000.16299.15.0_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXzdj9rvz13tf0rsetc7tkq2npy124s69y"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.PPIProjection_10.0.16299.15_neutral_neutral_cw5n1h2txyewy\Microsoft.PPIProjection\Capabilities "AppX5zjesx7qzfc49qr8sz790v9hnabbqnqp"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_10.0.16299.15_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXvm0aw4rghzevpacct7b8z2fgrtzgrdya"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Xbox.TCUI_1.11.29001.0_x64__8wekyb3d8bbwe\Microsoft.Xbox.TCUI\Capabilities "AppXa7cwdstqqq9qvk8vq491bcgrzxcgkfck"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\AD2F1837.HPPrinterControl_80.1.349.0_x64__v10z8vjag6ke6\AD2F1837.HPPrinterControl\Capabilities "AppXv7cc1xn48p290tq4aenjb2gs6gn1b8a7"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Messaging_3.37.23004.0_x64__8wekyb3d8bbwe\x27e26f40ye031y48a6yb130yd1f20388991ax\Capabilities "AppXhxp18zcdh6pc3r75383t1b4p8qvgya2k"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsPhone_10.1802.311.0_x64__8wekyb3d8bbwe\CompanionApp.App\Capabilities "AppXq2z9e41te1jknqf4bnnkb94g2xwpa3p9"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.Cortana_1.9.6.16299_neutral_neutral_cw5n1h2txyewy\CortanaUI\Capabilities "AppXtxkavz1xd01zpr5qaywp1yhtt6n57snp"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Reader_10.1802.463.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXg8kv16cxtcrr81sghnfnhvvve9nysgxq"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\InputApp_1000.16299.251.0_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXajqvg2qr08dvq02qs8xd1jwvmvm95krm"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Print3D_2.0.10611.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXd96mmf0hh056wm25vqx4kn62hc29xehf"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.XboxApp_39.39.21002.0_x64__8wekyb3d8bbwe\Microsoft.XboxApp\Capabilities "AppX23wdrrt1e8bqb24apk8h1xp25v5j3shw"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_4.23.10923.0_x64__8wekyb3d8bbwe\AppexNews\Capabilities "AppX7pqgewmem2x43rwpzsn9bb9p5gmmrwab"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingFinance_4.23.10923.0_x64__8wekyb3d8bbwe\AppexFinance\Capabilities "AppXez3zvqjz5xs06tjbrhfk3x1wc3j68a6k"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingSports_4.23.10923.0_x64__8wekyb3d8bbwe\AppexSports\Capabilities "AppXs8qqpf5j0k74179h9dgj2sxstq50z0kh"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingWeather_4.23.10923.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXxxfy8gnn2wftbx6m7wnwdnr5ct013wwv"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\9E2F88E3.Twitter_5.8.1.1000_x86__wgeqdkkx372wm\x554f661dyd360y462cy8743yf8a99b7d41dbx\Capabilities "AppX6mb377y5ebcqscn230dx0wtz8mcz9t81"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.3DBuilder_15.2.10821.1000_x64__8wekyb3d8bbwe\App\Capabilities "AppXzyvbnkt2grc73q4mfkvw49cg62k1ejc1"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsFeedbackHub_1.1712.811.1000_x64__8wekyb3d8bbwe\App\Capabilities "AppXmbhcmwyx43k9n02y3tgzfn6jw2xh3qwt"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.ZuneMusic_10.18011.13411.1000_x64__8wekyb3d8bbwe\Microsoft.ZuneMusic\Capabilities "AppXpgsecytcqptn67hhh6n1nvs3kzjh936g"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsAlarms_10.1803.614.1000_x64__8wekyb3d8bbwe\App\Capabilities "AppX9zv9ez0pagp2tsyasmmb8vq4wq7tt1eb"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\Microsoft.ZuneVideo\Capabilities "AppX83g3wajb0za3ry5gr1bem9kgh7wx0dee"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsCamera_2018.227.30.1000_x64__8wekyb3d8bbwe\App\Capabilities "AppXvmz1wydba08k0dtc17x5w4x18vc5m9fc"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsSoundRecorder_10.1803.613.1000_x64__8wekyb3d8bbwe\App\Capabilities "AppXta9nfg0kcy5btjkttt5p404arf663mx4"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsCalculator_10.1803.711.1000_x64__8wekyb3d8bbwe\App\Capabilities "AppXhqzk5h0nnh99t2qcynef90vayf76e91j"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.People_10.3.3472.1000_x64__8wekyb3d8bbwe\x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x\Capabilities "AppXtx7951wr3cvqpxqq8qqsx4bcv1haag4p"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.ShellExperienceHost_10.0.16299.371_neutral_neutral_cw5n1h2txyewy\App\Capabilities "AppXx3tdzb3g356fta8gg68yd48vr8g5bgqm"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.MicrosoftEdge_41.16299.371.0_neutral__8wekyb3d8bbwe\MicrosoftEdge\Capabilities "AppXph0xfa2zn61v58k8bcrq4tx3x9my1tpd"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.SecHealthUI_10.0.16299.334_neutral__cw5n1h2txyewy\SecHealthUI\Capabilities "AppX0zj22msywt494cc752ma77bdnq148vkx"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Office.OneNote_17.9226.20641.0_x64__8wekyb3d8bbwe\microsoft.onenoteim\Capabilities "AppXnexk0a3r7xkm5r8k8w3qgjnhmxwaxzbr"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.MSPaint_4.1804.13047.0_x64__8wekyb3d8bbwe\Microsoft.MSPaint\Capabilities "AppX4c003het03sd65b60hc68n4nqqag3en0"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.GetHelp_10.1706.10952.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXmsreqytweazgcg8t017kxkky7ew3ps26"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\App\Capabilities "AppX823zqr5hb89wnp3bve09dvfa918ydz20"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXzk5k1m288fx2cgz4k11h4rxjvpx4357d"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.WindowsStore_11803.1001.9.0_x64__8wekyb3d8bbwe\App\Capabilities "AppXdx7z7v43r22m49eex5j3w1hp3fmw0ssv"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Microsoft3DViewer_4.1804.19012.0_x64__8wekyb3d8bbwe\Microsoft.Microsoft3DViewer\Capabilities "AppXsej1t6qtbfvq59w79faqphxhcfvazb25"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\microsoft.windowscommunicationsapps_17.9126.21785.0_x64__8wekyb3d8bbwe\microsoft.windowslive.manageaccounts\Capabilities "AppXw0r4z2qkanxqpgftxa1pj18eba7rb6dk"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\microsoft.windowscommunicationsapps_17.9126.21785.0_x64__8wekyb3d8bbwe\microsoft.windowslive.calendar\Capabilities "AppX755p1k4qtt5sgm19dx4kmv4xgmz5m21g"=Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\microsoft.windowscommunicationsapps_17.9126.21785.0_x64__8wekyb3d8bbwe\microsoft.windowslive.mail\Capabilities [HKEY_CURRENT_USER\Software\Rocket] "name"=Rocket "oopcrashes"=1 "lang"=fr "pv"=31.0.1650.23 [HKEY_CURRENT_USER\Software\{3E130920-7C40-4938-9222-4C357069EC21}] "LatestLaunchDate"=0xE10701000300190007002F001A004901 "Trial"=0xE0070A00040006000600310016008A02 "Spend"=0x00000000000000000000030027000000 "Live"=0x00000000 "Launch_Times"=2 "TrialRunBefore"=0x01000000 [HKEY_CURRENT_USER\Software\Classes] "EditFlags"=0x00000000 -------------- | File information : c:\windows\system32\launchwinapp.exe MD5 : 4538B3D12C95D45EC491DA3158F0BB8F - c:\windows\system32\launchwinapp.exe ProductName = Microsoft® Windows® Operating System Version = 10.0.16299.334 CompanyName = Microsoft Corporation LegalCopyright = © Microsoft Corporation. All rights reserved. LegalTrademarks = ProductVersion = 10.0.16299.334 FileDescription = Launch Windows App PrivateBuild = FileVersion = 10.0.16299.334 (WinBuild.160101.0800) OriginalFilename = LaunchWinApp.exe SpecialBuild = DefaultLangCodepage = 040904B0 Size = 41 Ko Creation = 10/04/2018 22:15:25 Modification = 13/03/2018 07:38:27 Last Access = 10/04/2018 22:15:25 -------------- | CleanDisk : FreeSpace : 306572 Cleaning....... FreeSpace : 306676 ----------(EOF)----------