--------------- QuickDiag | g3n-h@ckm@n | V5_01.11.19.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 26/12/2019 16:28:27 Updated 01/11/2019 | 14:35 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [Ben (Administrator)] - [BEN-PC] (S-1-5-21-2392155067-2275373385-2186660377-1002) System: Microsoft Windows 10 Famille - - (10.0.17763) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> (1809) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Famille|C:\WINDOWS|\Device\Harddisk0\Partition2 Boot : Normal boot PC: MS-7728 - MEDIONPC - IdNumber: To be filled by O.E.M. - UUID: 00000000-0000-0000-0000-8C89A5A0577D Processor : X64 - 3392 Mhz - Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz BIOS Date: 12/22/11 11:15:27 Ver: 04.06.04 - eng - American Megatrends Inc. - S/N: To be filled by O.E.M. - E7728MLN.209 - MEDION - 7292010 CoreTemp : ? Celsius ----------| Quick ---------- | SoundDevice Realtek High Definition Audio - Status: OK - Manufacturer: Realtek - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_14627728&REV_1003\4&14ADA4A4&0&0001 NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001\5&39FD3295&0&0001 NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001\5&39FD3295&0&0101 NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001\5&39FD3295&0&0201 NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001\5&39FD3295&0&0301 NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: ROOT\UNNAMED_DEVICE\0000 ---------- | Video NVIDIA GeForce GTX 560 - Resolution: 1920x1080 - Colors: 4294967296 - RefreshRate: 59 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvldumdx.dll - PNPDeviceID: PCI\VEN_10DE&DEV_1084&SUBSYS_25721462&REV_A1\4&1093365&0&0008 - AdapterCompatibility: NVIDIA - RAM: 1342177280 Windows Live Display Driver - Resolution: 1920x1080 - Colors: 4294967296 - RefreshRate: 59 - 32 Bits Per Pixel - DeviceID: VideoController2 - Drivers: - PNPDeviceID: ROOT\*RDPDISP_DISPLAY\0000 - AdapterCompatibility: Microsoft - RAM: Inegrated Video Chipset DeviceName: NVIDIA GeForce GTX 560 - DriverVersion: 23.21.13.9135 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 54272 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 92672 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25824 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 36680 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 39424 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 27648 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34800 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42904 - Manufacturer: Microsoft Corporation - Status: OK ---------- | Memory Pagefile = Total (MB) : 16758 | Free (MB) : 12161 Virtual = Total (MB) : 4194 | Free (MB) : 3897 Physical Memory (MB) -------------------- Total: 8173 Available: 4019 Cached: 4169 Free: 666 Kernel Memory (MB) ------------------ Paged: 423 Nonpaged: 243 System ------ Handles: 83172 Processes: 199 Threads: 2719 ---------- | SID Users Admin123 : [S-1-5-21-2392155067-2275373385-2186660377-1275] Administrateur : [S-1-5-21-2392155067-2275373385-2186660377-500] Ben : [S-1-5-21-2392155067-2275373385-2186660377-1002] DefaultAccount : [S-1-5-21-2392155067-2275373385-2186660377-503] HomeGroupUser$ : [S-1-5-21-2392155067-2275373385-2186660377-1274] Invité : [S-1-5-21-2392155067-2275373385-2186660377-501] WDAGUtilityAccount : [S-1-5-21-2392155067-2275373385-2186660377-504] Administrateurs : [S-1-5-32-544] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] HomeUsers : [S-1-5-21-2392155067-2275373385-2186660377-1273] ---------- | Drives C:\ -> [Fixed] | [Boot] | Total : 1821.92 Go | Free : 757.02 Go -> NTFS [SATA] E:\ -> [Fixed] | [Recover] | Total : 40 Go | Free : 21.55 Go -> NTFS [SATA] Drive: 0 Cylinders: 243201 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 2000398934016 bytes ---------- | Windows updates - Activation - License W.A.T : :) Test 1 : Windows Is Activated Volume License ---------- | Browsers IE : 11.0.17763.771 (© Microsoft Corporation. Tous droits réservés.) FF : 56.0.0.6478 (©Firefox and Mozilla Developers; available under the MPL 2 license.) GC : 79.0.3945.88 (Copyright 2019 Google LLC.) Default : "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "" ---------- | FlashPlayer FlashPlayer ActiveX : 32.0.0.255 FlashPlayer Plugin : 32.0.0.303 ---------- | Security AV : Windows Defender Disabled FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Auto(2)] = Running AS: Windows Defender [Manual(3)] = stopped WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 560 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.17763.292) = C:\Windows\System32\smss.exe [27/06/2019 14:36:38] CPU Usage:0 % 736 | [Owner : Système | Parent : 716() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.17763.1) = C:\Windows\System32\csrss.exe [15/09/2018 08:28:45] CPU Usage:0 % 824 | [Owner : Système | Parent : 716() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.17763.1) = C:\Windows\System32\wininit.exe [15/09/2018 08:28:45] CPU Usage:0 % 836 | [Owner : Système | Parent : 816() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.17763.1) = C:\Windows\System32\csrss.exe [15/09/2018 08:28:45] CPU Usage:0 % 896 | [Owner : Système | Parent : 824(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.17763.914) = C:\Windows\System32\services.exe [12/12/2019 18:41:49] CPU Usage:0 % 904 | [Owner : Système | Parent : 824(wininit.exe) | 18.06 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.17763.1) = C:\Windows\System32\lsass.exe [15/09/2018 08:28:46] CPU Usage:0 % 988 | [Owner : Système | Parent : 816() | 10.81 Mo] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.17763.802) = C:\Windows\System32\winlogon.exe [11/10/2019 10:36:28] CPU Usage:0 % 460 | [Owner : Système | Parent : 896(services.exe) | 3.56 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 488 | [Owner : UMFD-1 | Parent : 988(winlogon.exe) | 9.56 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.17763.864) = C:\Windows\System32\fontdrvhost.exe [13/11/2019 20:44:43] CPU Usage:0 % 516 | [Owner : UMFD-0 | Parent : 824(wininit.exe) | 3.19 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.17763.864) = C:\Windows\System32\fontdrvhost.exe [13/11/2019 20:44:43] CPU Usage:0 % 496 | [Owner : Système | Parent : 896(services.exe) | 28.31 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 84 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 16.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1068 | [Owner : Système | Parent : 896(services.exe) | 7.74 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1156 | [Owner : DWM-1 | Parent : 988(winlogon.exe) | 60.94 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (10.0.17763.831) = C:\Windows\System32\dwm.exe [13/11/2019 20:44:39] CPU Usage:0 % 1312 | [Owner : Système | Parent : 896(services.exe) | 9.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1320 | [Owner : Système | Parent : 896(services.exe) | 16.03 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1392 | [Owner : Système | Parent : 896(services.exe) | 5.68 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1448 | [Owner : Système | Parent : 896(services.exe) | 11.43 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1508 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.95 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1504 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.19 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1520 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 11.99 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1528 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 16.53 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1736 | [Owner : Système | Parent : 896(services.exe) | 10.42 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1792 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.5 Mo] - (.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes en mode utilisateur.) - (10.0.17763.1) = C:\Windows\System32\WUDFHost.exe [15/09/2018 08:28:52] CPU Usage:0 % 1808 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.43 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1932 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.3 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1940 | [Owner : Système | Parent : 896(services.exe) | 11.96 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.2.0.0) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [27/06/2019 14:03:14] CPU Usage:0 % 1268 | [Owner : Système | Parent : 896(services.exe) | 5.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1656 | [Owner : Système | Parent : 896(services.exe) | 106.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1896 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.68 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1992 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 10.78 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2056 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.AVAST Software - Avast Antivirus remediation exe.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [11/10/2019 09:18:44] CPU Usage:0 % 2204 | [Owner : Système | Parent : 896(services.exe) | 9.2 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2312 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 8.53 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2404 | [Owner : Système | Parent : 896(services.exe) | 12.23 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2424 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 8.93 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2560 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2672 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 9.11 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2692 | [Owner : Système | Parent : 1940(NVDisplay.Container.exe) | 23.36 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.2.0.0) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [27/06/2019 14:03:14] CPU Usage:0 % 2700 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 6.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2792 | [Owner : Système | Parent : 896(services.exe) | 7.8 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2800 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 8.7 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2944 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 9.55 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3008 | [Owner : Système | Parent : 896(services.exe) | 16.18 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2876 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 17.05 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3168 | [Owner : Système | Parent : 896(services.exe) | 14.61 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3192 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.92 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3200 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 8.8 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3228 | [Owner : Système | Parent : 896(services.exe) | 8.3 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3340 | [Owner : Système | Parent : 896(services.exe) | 13.01 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3388 | [Owner : Système | Parent : 896(services.exe) | 6.67 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3396 | [Owner : Système | Parent : 896(services.exe) | 6.16 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3468 | [Owner : Système | Parent : 896(services.exe) | 12.07 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3476 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.AVAST Software - Avast Antivirus Service.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\AvastSvc.exe [11/10/2019 09:18:44] CPU Usage:0 % 3488 | [Owner : SERVICE LOCAL | Parent : 3396(svchost.exe) | 12.3 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (10.0.17763.1) = C:\Windows\System32\dasHost.exe [15/09/2018 08:28:36] CPU Usage:0 % 3796 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.67 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3856 | [Owner : Système | Parent : 896(services.exe) | 13.42 Mo] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.17763.831) = C:\Windows\System32\spoolsv.exe [13/11/2019 20:43:51] CPU Usage:0 % 3892 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 17.36 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3992 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 8.09 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3728 | [Owner : Système | Parent : 896(services.exe) | 6.13 Mo] - (.Adobe Systems - Adobe Acrobat Update Service.) - (1.824.35.289) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [10/09/2019 22:16:22] CPU Usage:0 % 4108 | [Owner : Système | Parent : 896(services.exe) | 9.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4124 | [Owner : Système | Parent : 896(services.exe) | 6.99 Mo] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Interface.) - (1.24.738.1) = C:\Program Files\Intel\iCLS Client\HeciServer.exe [19/06/2012 19:10:34] CPU Usage:0 % 4168 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.Malwarebytes - Malwarebytes Service.) - (3.2.0.874) = C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [09/07/2019 10:27:12] CPU Usage:0 % 4224 | [Owner : Système | Parent : 896(services.exe) | 10.02 Mo] - (.NVIDIA - NVIDIA Performance Service.) - (6.5.26.5) = C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [22/03/2010 09:17:24] CPU Usage:0 % 4256 | [Owner : Système | Parent : 896(services.exe) | 31.6 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.19.2734.4859) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [17/11/2019 20:51:21] CPU Usage:0 % 4300 | [Owner : Système | Parent : 896(services.exe) | 6.27 Mo] - (.Sony Corporation - Device Information Provider.) - (7.0.0.11271) = C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [27/11/2012 21:12:44] CPU Usage:0 % 4344 | [Owner : Système | Parent : 896(services.exe) | 4.19 Mo] - (.Thrustmaster® - Thrustmaster® General Accessory Service.) - (1.0.4.0) = C:\Program Files (x86)\Thrustmaster\Thrustmaster FFB Driver\64bits\tmGAInstall.exe [12/11/2016 21:59:42] CPU Usage:0 % 4352 | [Owner : Système | Parent : 896(services.exe) | 6.7 Mo] - (.NVIDIA - NVIDIA Update Center Service.) - (6.5.10.5) = C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe [06/11/2009 13:24:54] CPU Usage:0 % 4360 | [Owner : Système | Parent : 896(services.exe) | 9.84 Mo] - (.Microsoft Corporation - Windows Live Mesh Remote Desktop Service.) - (15.4.5722.2) = C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [22/09/2010 17:10:10] CPU Usage:0 % 4368 | [Owner : Système | Parent : 896(services.exe) | 6.02 Mo] - (.-.) - (0.0.0.0) = C:\Windows\System32\PnkBstrA.exe [25/10/2016 17:15:58] CPU Usage:0 % 4376 | [Owner : Système | Parent : 896(services.exe) | 7.01 Mo] - (.CrypKey (Canada) Ltd. - CrypKey License Service.) - (1.1.0.2) = C:\Windows\System32\Crypserv.exe [26/11/2013 22:13:31] CPU Usage:0 % 4388 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 20.94 Mo] - (.Microsoft Corporation - SMSvcHost.exe.) - (4.8.3761.0) = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [22/09/2019 14:46:33] CPU Usage:0 % 4464 | [Owner : Système | Parent : 896(services.exe) | 7.73 Mo] - (.Microsoft Corporation - Service SNMP.) - (10.0.17763.1) = C:\Windows\System32\snmp.exe [27/06/2019 14:27:35] CPU Usage:0 % 4472 | [Owner : Système | Parent : 896(services.exe) | 7.48 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4480 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 7.38 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4492 | [Owner : Système | Parent : 896(services.exe) | 10.42 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4504 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.68 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4512 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.43 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4536 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 5.87 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4560 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4572 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 13.56 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4628 | [Owner : Système | Parent : 896(services.exe) | 6.7 Mo] - (.Microsoft Corporation - Microsoft Application Virtualization Virtual Service Agent.) - (4.6.3.25281) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [08/10/2014 17:18:56] CPU Usage:0 % 4636 | [Owner : Système | Parent : 896(services.exe) | 24.61 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4644 | [Owner : Système | Parent : 896(services.exe) | 10.98 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4704 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.26 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4712 | [Owner : Système | Parent : 896(services.exe) | 5.39 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4800 | [Owner : Système | Parent : 896(services.exe) | 19.46 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4808 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 6.22 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4824 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 33.72 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4872 | [Owner : Système | Parent : 896(services.exe) | 10.59 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4896 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 11.47 Mo] - (.Microsoft Corporation - Message Queuing Service.) - (5.0.1.1) = C:\Windows\System32\mqsvc.exe [15/09/2018 08:38:22] CPU Usage:0 % 5712 | [Owner : Système | Parent : 896(services.exe) | 14.71 Mo] - (.Microsoft Corporation - Microsoft Application Virtualization Client Service.) - (4.6.3.25281) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [08/10/2014 17:18:50] CPU Usage:0 % 5956 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 5.26 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 6180 | [Owner : Système | Parent : 896(services.exe) | 11.31 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 6400 | [Owner : Système | Parent : 4256(nvcontainer.exe) | 7.84 Mo] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) - (10.0.17763.1) = C:\Windows\System32\rundll32.exe [15/09/2018 08:28:57] CPU Usage:0 % 6744 | [Owner : Système | Parent : 896(services.exe) | 7.08 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 6752 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 7.15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 7340 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 16.46 Mo] - (.Microsoft Corporation - SMSvcHost.exe.) - (4.8.3761.0) = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [22/09/2019 14:46:33] CPU Usage:0 % 7368 | [Owner : Système | Parent : 896(services.exe) | 10.94 Mo] - (.Microsoft Corporation - Microsoft Office Client Virtualization Service.) - (14.0.7147.5000) = C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [18/03/2015 18:51:28] CPU Usage:0 % 7940 | [Owner : Ben | Parent : 4256(nvcontainer.exe) | 30.32 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.19.2734.4859) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [17/11/2019 20:51:21] CPU Usage:0 % 4688 | [Owner : Ben | Parent : 1736(svchost.exe) | 31.23 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.17763.1) = C:\Windows\System32\sihost.exe [15/09/2018 08:28:34] CPU Usage:0 % 2500 | [Owner : Ben | Parent : 896(services.exe) | 21.09 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 8324 | [Owner : Ben | Parent : 896(services.exe) | 29.82 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 8360 | [Owner : Système | Parent : 896(services.exe) | 14.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 8400 | [Owner : Ben | Parent : 1320(svchost.exe) | 17.24 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.17763.831) = C:\Windows\System32\taskhostw.exe [13/11/2019 20:44:37] CPU Usage:0 % 8516 | [Owner : Ben | Parent : 1320(svchost.exe) | 2.5 Mo] - (.Microsoft Corporation - IPoint.exe.) - (2.3.188.0) = C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [19/03/2014 14:23:16] CPU Usage:0 % 8656 | [Owner : Ben | Parent : 1320(svchost.exe) | 2.4 Mo] - (.Microsoft Corporation - IType.exe.) - (2.3.188.0) = C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [19/03/2014 14:23:16] CPU Usage:0 % 8680 | [Owner : Ben | Parent : 4224(nTuneService.exe) | 9.55 Mo] - (.NVIDIA - NVIDIA nTune Command.) - (6.5.26.5) = C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [22/03/2010 09:17:22] CPU Usage:0 % 8744 | [Owner : Système | Parent : 896(services.exe) | 7.72 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 8820 | [Owner : Ben | Parent : 8744(svchost.exe) | 16.75 Mo] - (.Microsoft Corporation - Chargeur CTF.) - (10.0.17763.1) = C:\Windows\System32\ctfmon.exe [15/09/2018 08:28:45] CPU Usage:0 % 9156 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 17.66 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 3148 | [Owner : Système | Parent : 896(services.exe) | 7.27 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2904 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 9.18 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 6432 | [Owner : Ben | Parent : 4168(MBAMService.exe) | 30.93 Mo] - (.Malwarebytes - Malwarebytes Tray Application.) - (4.0.0.457) = C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [09/07/2019 10:27:10] CPU Usage:0 % 8916 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 5940 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.Microsoft Corporation - Windows Security Health Service.) - (4.18.1807.16384) = C:\Windows\System32\SecurityHealthService.exe [14/08/2019 16:32:06] CPU Usage:0 % 5300 | [Owner : Ben | Parent : 8196() | 149.26 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.17763.831) = C:\Windows\explorer.exe [13/11/2019 20:43:52] CPU Usage:0 % 8340 | [Owner : Ben | Parent : 896(services.exe) | 16.34 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 8500 | [Owner : Système | Parent : 896(services.exe) | 16.75 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1308 | [Owner : Ben | Parent : 496(svchost.exe) | 93.41 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.17763.864) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe [13/11/2019 20:44:15] CPU Usage:0 % 8896 | [Owner : Ben | Parent : 896(services.exe) | 30.37 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 1092 | [Owner : Ben | Parent : 496(svchost.exe) | 147.33 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.17763.719) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe [11/09/2019 17:28:14] CPU Usage:0 % 7336 | [Owner : Ben | Parent : 496(svchost.exe) | 29.31 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 5572 | [Owner : Ben | Parent : 496(svchost.exe) | 25.05 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 8552 | [Owner : Ben | Parent : 496(svchost.exe) | 49.95 Mo] - (.Microsoft Corporation - Application Frame Host.) - (10.0.17763.1) = C:\Windows\System32\ApplicationFrameHost.exe [15/09/2018 08:28:39] CPU Usage:0 % 8540 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 13.29 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 5624 | [Owner : Ben | Parent : 496(svchost.exe) | 207.46 Mo] - (.Microsoft Corporation - SkypeApp.) - (8.55.0.131) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeApp.exe [12/12/2019 19:35:16] CPU Usage:0 % 9224 | [Owner : Ben | Parent : 496(svchost.exe) | 10.41 Mo] - (.-.) - (8.55.0.131) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe [12/12/2019 19:35:16] CPU Usage:0 % 9476 | [Owner : Ben | Parent : 496(svchost.exe) | 36.84 Mo] - (.-.) - (1.19112.111.0) = C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19112.111.0_x64__8wekyb3d8bbwe\YourPhone.exe [21/12/2019 18:20:47] CPU Usage:0 % 9652 | [Owner : Système | Parent : 896(services.exe) | 35.54 Mo] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.17763.831) = C:\Windows\System32\SearchIndexer.exe [13/11/2019 20:44:07] CPU Usage:0 % 9948 | [Owner : Ben | Parent : 496(svchost.exe) | 20.53 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 10368 | [Owner : Ben | Parent : 496(svchost.exe) | 3.86 Mo] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.17763.615) = C:\Windows\System32\SettingSyncHost.exe [10/07/2019 11:25:26] CPU Usage:0 % 10860 | [Owner : Ben | Parent : 496(svchost.exe) | 42.44 Mo] - (.Microsoft Corporation - Windows Defender SmartScreen.) - (10.0.17763.529) = C:\Windows\System32\smartscreen.exe [29/06/2019 12:48:55] CPU Usage:0 % 11072 | [Owner : Système | Parent : 896(services.exe) | 5.72 Mo] - (.Intel Corporation - Local Manageability Service.) - (8.1.0.1281) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [15/07/2011 20:53:32] CPU Usage:0 % 11100 | [Owner : Système | Parent : 8408() | 0.15 Mo] - (.Google LLC - Google Crash Handler.) - (1.3.35.421) = C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe [14/12/2019 15:44:19] CPU Usage:0 % 11248 | [Owner : Ben | Parent : 496(svchost.exe) | 25.27 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 8928 | [Owner : Ben | Parent : 496(svchost.exe) | 35.39 Mo] - (.-.) - (10.19101.1071.0) = C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19101.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe [29/10/2019 20:03:04] CPU Usage:0 % 5092 | [Owner : Système | Parent : 8416() | 0.16 Mo] - (.AVAST Software - Avast Browser Update.) - (1.4.136.333) = C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe [29/04/2018 14:58:52] CPU Usage:0 % 10512 | [Owner : Ben | Parent : 4132() | 27.74 Mo] - (.IObit - UninstallerMonitor.) - (8.0.2.1640) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe [03/12/2018 11:07:51] CPU Usage:0 % 10832 | [Owner : Ben | Parent : 496(svchost.exe) | 15.81 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 11592 | [Owner : Système | Parent : 8408() | 0.12 Mo] - (.Google LLC - Google Crash Handler.) - (1.3.35.421) = C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe [14/12/2019 15:44:19] CPU Usage:0 % 11628 | [Owner : Ben | Parent : 11016() | 20.46 Mo] - (.AVAST Software - Avast Antivirus.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\AvastUI.exe [11/10/2019 09:19:40] CPU Usage:0 % 11712 | [Owner : Système | Parent : 8416() | 0.13 Mo] - (.AVAST Software - Avast Browser Update.) - (1.4.136.333) = C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe [29/04/2018 14:58:52] CPU Usage:0 % 11760 | [Owner : Système | Parent : 896(services.exe) | 7.74 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 11868 | [Owner : Ben | Parent : 8544() | 1.54 Mo] - (.Node.js - NVIDIA Web Helper Service.) - (11.13.0.0) = C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [03/12/2018 15:40:29] CPU Usage:0 % 9164 | [Owner : Ben | Parent : 496(svchost.exe) | 8.75 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 12468 | [Owner : Ben | Parent : 496(svchost.exe) | 6.72 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 13224 | [Owner : SERVICE RÉSEAU | Parent : 896(services.exe) | 9.88 Mo] - (.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) - (2001.12.10941.16384) = C:\Windows\System32\msdtc.exe [15/09/2018 08:29:16] CPU Usage:0 % 10888 | [Owner : Ben | Parent : 11868(NVIDIA Web Helper.exe) | 0.3 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.17763.404) = C:\Windows\System32\conhost.exe [29/06/2019 12:48:19] CPU Usage:0 % 9704 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.Microsoft Corporation - Service Broker du moniteur d'exécution System Guard.) - (10.0.17763.404) = C:\Windows\System32\SgrmBroker.exe [29/06/2019 12:48:34] CPU Usage:0 % 9892 | [Owner : Système | Parent : 896(services.exe) | 21.35 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 13044 | [Owner : Système | Parent : 896(services.exe) | 6.23 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 7380 | [Owner : Système | Parent : 896(services.exe) | 13.77 Mo] - (.Intel Corporation - User Notification Service.) - (8.1.0.1281) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [15/07/2011 20:53:32] CPU Usage:0 % 10472 | [Owner : Système | Parent : 496(svchost.exe) | 10.46 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.17763.1) = C:\Windows\System32\dllhost.exe [15/09/2018 08:28:45] CPU Usage:0 % 5208 | [Owner : Ben | Parent : 11248(RuntimeBroker.exe) | 59.28 Mo] - (.Microsoft Corporation - SkypeBridge.) - (8.55.0.131) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe [12/12/2019 19:35:16] CPU Usage:0 % 11024 | [Owner : Système | Parent : 896(services.exe) | 8.5 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 13776 | [Owner : Système | Parent : 896(services.exe) | 11.03 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 9420 | [Owner : Ben | Parent : 496(svchost.exe) | 0.16 Mo] - (.Microsoft Corporation - Store.) - (11912.1001.1.0) = C:\Program Files\WindowsApps\Microsoft.WindowsStore_11912.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe [18/12/2019 17:53:36] CPU Usage:0 % 12968 | [Owner : Ben | Parent : 496(svchost.exe) | 20.02 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 6580 | [Owner : Ben | Parent : 496(svchost.exe) | 66.09 Mo] - (.Microsoft Corporation - Paramètres.) - (10.0.17763.1) = C:\Windows\ImmersiveControlPanel\SystemSettings.exe [15/09/2018 08:29:46] CPU Usage:0 % 13464 | [Owner : Ben | Parent : 11628(AvastUI.exe) | 32.79 Mo] - (.AVAST Software - Avast Antivirus.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\AvastUI.exe [11/10/2019 09:19:40] CPU Usage:0 % 12664 | [Owner : Ben | Parent : 496(svchost.exe) | 61.52 Mo] - (.Microsoft Corporation - Windows My People.) - (10.0.17763.1) = C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\PeopleExperienceHost.exe [15/09/2018 08:28:40] CPU Usage:0 % 14108 | [Owner : Ben | Parent : 496(svchost.exe) | 10.44 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 10464 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 8.69 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 13576 | [Owner : SERVICE LOCAL | Parent : 896(services.exe) | 10.76 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 11492 | [Owner : Ben | Parent : 496(svchost.exe) | 12.09 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.17763.1) = C:\Windows\System32\dllhost.exe [15/09/2018 08:28:45] CPU Usage:0 % 12780 | [Owner : Ben | Parent : 496(svchost.exe) | 66.56 Mo] - (.Microsoft Corporation - Microsoft Edge.) - (11.0.17763.831) = C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe [13/11/2019 20:45:25] CPU Usage:0 % 12248 | [Owner : Ben | Parent : 496(svchost.exe) | 14.16 Mo] - (.Microsoft Corporation - Browser_Broker.) - (11.0.17763.316) = C:\Windows\System32\browser_broker.exe [27/06/2019 14:36:01] CPU Usage:0 % 11436 | [Owner : Ben | Parent : 9948(RuntimeBroker.exe) | 13.74 Mo] - (.Microsoft Corporation - Microsoft Edge Web Platform.) - (11.0.17763.1) = C:\Windows\System32\MicrosoftEdgeSH.exe [15/09/2018 08:28:32] CPU Usage:0 % 8904 | [Owner : Ben | Parent : 496(svchost.exe) | 26.44 Mo] - (.Microsoft Corporation - Microsoft Edge Content Process.) - (11.0.17763.1) = C:\Windows\System32\MicrosoftEdgeCP.exe [15/09/2018 08:28:50] CPU Usage:0 % 11188 | [Owner : Ben | Parent : 496(svchost.exe) | 45.8 Mo] - (.-.) - (2019.19081.22010.0) = C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19081.22010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe [14/12/2019 15:09:54] CPU Usage:0 % 2848 | [Owner : Ben | Parent : 496(svchost.exe) | 29.9 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17763.1) = C:\Windows\System32\RuntimeBroker.exe [15/09/2018 08:28:29] CPU Usage:0 % 4004 | [Owner : Système | Parent : 896(services.exe) | 6.03 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 10596 | [Owner : Ben | Parent : 5300(explorer.exe) | 305.36 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:0 % 404 | [Owner : Ben | Parent : 10596(firefox.exe) | 82.09 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:0 % 12692 | [Owner : Ben | Parent : 10596(firefox.exe) | 63.32 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:0 % 7016 | [Owner : Ben | Parent : 10596(firefox.exe) | 294.21 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:0 % 12364 | [Owner : Ben | Parent : 10596(firefox.exe) | 216.89 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:0 % 13204 | [Owner : Ben | Parent : 10596(firefox.exe) | 251.08 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:1 % 13472 | [Owner : Ben | Parent : 496(svchost.exe) | 50.42 Mo] - (.Microsoft Corporation - WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe.) - (10.0.17763.802) = C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe [11/10/2019 10:36:17] CPU Usage:0 % 12536 | [Owner : Ben | Parent : 10596(firefox.exe) | 43.59 Mo] - (.Mozilla Corporation - Firefox.) - (71.0.0.7275) = C:\Program Files\Mozilla Firefox\firefox.exe [06/12/2019 18:38:30] CPU Usage:0 % 7728 | [Owner : Système | Parent : 896(services.exe) | 7.87 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 12460 | [Owner : SERVICE LOCAL | Parent : 2876(svchost.exe) | 15.14 Mo] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (10.0.17763.831) = C:\Windows\System32\audiodg.exe [13/11/2019 20:43:35] CPU Usage:0 % 468 | [Owner : Système | Parent : 896(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 9016 | [Owner : Système | Parent : 896(services.exe) | 18.05 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 8452 | [Owner : Système | Parent : 896(services.exe) | 10.11 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 2964 | [Owner : Système | Parent : 896(services.exe) | 6.82 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.17763.1) = C:\Windows\System32\svchost.exe [15/09/2018 08:28:45] CPU Usage:0 % 4816 | [Owner : Ben | Parent : 496(svchost.exe) | 10.34 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.17763.1) = C:\Windows\System32\dllhost.exe [15/09/2018 08:28:45] CPU Usage:0 % 6392 | [Owner : Ben | Parent : 5300(explorer.exe) | 64.85 Mo] - (.SosVirus - QuickDiag.) - (1.11.19.1) = C:\Users\Ben\Downloads\QuickDiag.exe [26/12/2019 16:23:58] CPU Usage:0 % 4320 | [Owner : Système | Parent : 496(svchost.exe) | 8.61 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.17763.1) = C:\Windows\System32\wbem\WmiPrvSE.exe [15/09/2018 08:28:29] CPU Usage:0 % 12152 | [Owner : SERVICE RÉSEAU | Parent : 496(svchost.exe) | 9.99 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.17763.1) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [15/09/2018 08:29:00] CPU Usage:0 % ---------- | Locked Applications [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9e93b39-49d1-4179-9848-a5a2896955ea}] - () - (%systemroot%\system32\mrt.exe) ---------- | Policy Restrictions ---------- | Explorer.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\Windows\System32\InputHost.dll (.NVIDIA Corporation.-.NVIDIA Driver Loader, Version 391.35.) - (23.21.13.9135) -- C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvldumdx.dll (.NVIDIA Corporation.-.NVIDIA D3D10 Driver, Version 391.35.) - (23.21.13.9135) -- C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvwgf2umx_cfg.dll (.AVAST Software.-.Avast Antivirus Shell Extension.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\ashShell.dll (..-..) - (0.0.0.0) -- C:\Windows\ShellExperiences\TileControl.dll (..-..) - (0.0.0.0) -- C:\Windows\ShellComponents\TaskFlowUI.dll (..-..) - (0.9.0.0) -- C:\Program Files\RogueKiller\roguekillershell.dll (.Alexander Roshal.-.WinRAR shell extension.) - (5.70.0.0) -- C:\Program Files\WinRAR\rarext.dll (.AVAST Software.-.Avast Antivirus AAVM Remote Procedure Call Library.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\AavmRpch.dll (.IObit.-.IUMenuRightExtension.) - (1.2.0.2) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll (.NVIDIA Corporation.-.NVIDIA Shell Extensions.) - (6.14.13.9135) -- C:\WINDOWS\system32\nv3dappshext.dll (.NVIDIA Corporation.-.NVIDIA NVAPI Library, Version 391.35.) - (23.21.13.9135) -- C:\WINDOWS\system32\nvapi64.dll (.IObit.-.Uninstall for explorer.) - (1.0.7.16) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll ---------- | Winlogon.exe Modules (Microsoft Files Whitelisted) ---------- | svchost.exe Modules (Microsoft Files Whitelisted) (.Hewlett-Packard.-.Dot4Net Module.) - (12.2.3.21) -- c:\windows\system32\hpzinw12.dll (.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.23.2.0) -- c:\windows\system32\winsqlite3.dll (.Hewlett-Packard.-.PmlDrv Module.) - (12.2.3.21) -- c:\windows\system32\hpzipm12.dll (.AVAST Software.-.Hook Library.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\aswhook.dll ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE LOCAL OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE RÉSEAU uTorrent - ("C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\...\Run]) - User: BEN-PC\Ben Gadwin PrintScreen Pro (64-bit) - ("C:\Program Files\Gadwin\Gadwin PrintScreenPro\PrintScreenPro64.exe" /nosplash [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\...\Run]) - User: BEN-PC\Ben DAEMON Tools Lite Automount - ("C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\...\Run]) - User: BEN-PC\Ben EADM - ("C:\Program Files (x86)\Origin\Origin.exe" -AutoStart [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\...\Run]) - User: BEN-PC\Ben CCleaner Smart Cleaning - ("C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\...\Run]) - User: BEN-PC\Ben SecurityHealth - (%windir%\system32\SecurityHealthSystray.exe [HKLM\SOFTWARE\...\Run]) - User: Public RTHDVCPL - ("C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [HKLM\SOFTWARE\...\Run]) - User: Public AvastUI.exe - ("C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui [HKLM\SOFTWARE\...\Run]) - User: Public [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 "AutoRun"=@mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist ( start /MIN "" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit) [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED "Gadwin PrintScreen Pro (64-bit)"="C:\Program Files\Gadwin\Gadwin PrintScreenPro\PrintScreenPro64.exe" /nosplash "DAEMON Tools Lite Automount"="C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun "EADM"="C:\Program Files (x86)\Origin\Origin.exe" -AutoStart "CCleaner Smart Cleaning"="C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "uTorrent"=0x03000000A1D9BC73B0DED001 "CCleaner Monitoring"=0x03000000F57B7F75B0DED001 "DAEMON Tools Lite"=0x020000000000000000000000 "Gadwin PrintScreen Pro (64-bit)"=0x03000000C7F99D7BB0DED001 "E09FXLRD_17379010"=0x030000000694587EB0DED001 "OneDrive"=0x0300000038E80C80B0DED001 "Skype"=0x03000000573E8381B0DED001 "cacaoweb"=0x0300000072D107BBCC67D101 "DAEMON Tools Lite Automount"=0x030000000908BB5E171FD301 "Steam"=0x0300000090F85161171FD301 "OneDriveSetup"=0x020000000000000000000000 "CCleaner Smart Cleaning"=0x020000000000000000000000 "EADM"=0x020000000000000000000000 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "Device"=HP DeskJet 2600 series,winspool,Ne05: "IsMRUEstablished"=1 "LegacyDefaultPrinterMode"=0 [HKLM\Software\Microsoft\Command Processor] "DefaultColor"=0 "EnableExtensions"=1 "CompletionChar"=64 "PathCompletionChar"=64 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "SecurityHealth"=%windir%\system32\SecurityHealthSystray.exe "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "SecurityHealth"=0x0700000068981781D335D301 "RTHDVCPL"=0x07000000228E4D82D335D301 "NvBackend"=0x020000000000000000000000 "ShadowPlay"=0x0300000058D29183D335D301 "emsisoft anti-malware"=0x020000000000000000000000 "AvastUI.exe"=0x020000000000000000000000 "iTunesHelper"=0x020000000000000000000000 "WindowsDefender"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32] "AvastUI.exe"=0x020000000000000000000000 "IAStorIcon"=0x03000000A7957979B0DED001 "emsisoft anti-malware"=0x020000000000000000000000 "PMBVolumeWatcher"=0x03000000BBE01D65171FD301 "NUSB3MON"=0x0300000039125285D335D301 "SunJavaUpdateSched"=0x03000000775B597AD335D301 "KiesTrayAgent"=0x03000000515CC86D171FD301 [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D52E70A57C4208 [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "PMBVolumeWatcher"=C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [27/11/2012 21:08:28] "NUSB3MON"="C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List Adobe Acrobat Update Task Adobe Flash Player NPAPI Notifier Adobe Flash Player Updater Avast Emergency Update Avast Secure Browser Heartbeat Task (Hourly) Avast Secure Browser Heartbeat Task (Logon) AvastUpdateTaskMachineCore AvastUpdateTaskMachineUA CCleaner Update CCleanerSkipUAC CreateChoiceProcessTask GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Microsoft_Hardware_Launch_ipoint_exe Microsoft_Hardware_Launch_itype_exe Microsoft_Hardware_Launch_mousekeyboardcenter_exe Microsoft_MKC_Logon_Task_ipoint.exe Microsoft_MKC_Logon_Task_itype.exe NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} OneDrive Standalone Update Task-S-1-5-21-2392155067-2275373385-2186660377-1002 Programme de mise à jour en ligne de Adobe Programme de mise à jour en ligne de HP. Programme de mise à jour en ligne de Real Player RealPlayerRealUpgradeLogonTaskS-1-5-21-2392155067-2275373385-2186660377-1002 RealPlayerRealUpgradeScheduledTaskS-1-5-21-2392155067-2275373385-2186660377-1002 RealUpgradeLogonTaskS-1-5-21-2392155067-2275373385-2186660377-1002 RealUpgradeScheduledTaskS-1-5-21-2392155067-2275373385-2186660377-1002 Uninstaller_SkipUac_Ben User_Feed_Synchronization-{F62D63AA-DC6A-4080-B91B-E2A98B496DF3} {0060CF01-458B-48D6-877E-2A0F76EA32B8} {0E63F5AE-60DF-4FDD-BC23-459DDD855757} {122BD959-CBC5-4A49-9A5F-1DB03181C927} {280CEF13-C2D5-47D6-BE94-63A13B650753} {2BF96D00-FBE4-4A3A-A187-D14D4A901C25} {30C6BFAD-84CD-47D6-981F-B0393D501FB6} {361E0C10-EFFD-4152-ADD9-0D84E52601EC} {38FE8D0B-8DE0-455A-994B-BBCD6337BEBA} {3B1E1D3E-DCD7-4DDA-96B6-E893B38AAC1B} {3BF4CEB5-AB8C-451D-8112-8464DD2BB071} {3D746C14-220D-4313-B550-F9869C9B246C} {47307A01-660C-4813-8EAD-2B72B8568751} {476E79E6-981D-4B4A-8150-AF36F5144AB1} {48E2B34E-BDE8-4F49-A525-D2A936C79F52} {538FA2C7-B5F1-4690-BEFC-F700CF5D0ACB} {55C9975E-E85F-4E00-9BAB-B67196C75C11} {5BD1E956-63FE-438D-9681-8BDDA5BCCD4F} {68BF5EE7-AAC1-49F4-819D-3A2E274C2291} {6A6E7CFB-C72E-4E90-A19F-E96A8CED9255} {6AC0402B-3CD2-4242-BFBE-27C473178239} {6D06B9D7-84E2-4153-975E-E117D130EE8A} {70DBCF58-B074-43FE-87CE-33F93F92ACF2} {72E2A08B-A816-4604-ABCA-0C9215AD03AC} {79283870-4C40-47F0-87B8-1A9DC658C43A} {80410DAF-89C3-4995-B368-94BF9687E4D2} {962DEF4A-AF10-4AA8-8F70-413A26701031} {98F7C016-4BAF-479C-9A18-EC9D88A24ACB} {9C228003-0E75-4F61-A472-172FCF168F58} {9EFC5413-2EA8-4578-8097-9F8FBA12986C} {9FBBDCEE-E1C3-41A5-A9C3-377E0ABF954B} {A321CCB5-ABB2-4CD3-BA9E-B5CD8B24B788} {A59CE86E-1230-441F-942F-D8975AF6E3D1} {CA707A14-78B7-4275-9983-F4AD935FEC40} {CC04710E-F0E9-453E-A323-97164C8FE8B1} {CF1EA5D5-C7A7-4EEE-B30C-EA19E56D8F5F} {D1E469FF-2B22-4AFB-B668-13D20B61412C} {D5188470-FB6E-49C6-926F-5ECB16B4A4D4} {E40316F6-1B67-480F-A1F7-083641FB8C8B} {E428843A-4077-4107-B11D-50358203D2E6} {EA8560A2-0927-4153-B6DE-2E90416285AA} {EC5012F7-569F-490D-8B1B-5F6BC808D9EB} {EE5B3511-029A-477D-9EE2-2D6EC726F865} {F3004A9D-A3B5-47A5-A0C1-4F34023FEFD4} {F94BDF2B-DC67-4B78-8C00-EFEA60640E6F} ---------- | Startings up registry ¦ Folder [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe] : C:\ProgramData\Adobe\682B646.vbe [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] : "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CANAL+ CANALSAT A LA DEMANDE] : "C:\Program Files (x86)\Canal+\CANAL+ CANALSAT A LA DEMANDE\Launcher.exe" [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CLMLServer] : "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IAStorIcon] : C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MedionReminder] : C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [26/05/2011 00:32:46] [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC] : "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PWRISOVM.EXE] : C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuotationCafe Search Scope Monitor] : "C:\Program Files (x86)\QUOTAT~2\bar\1.bin\45srchmn.exe" /m=2 /w /h [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuotationCafe_45 Browser Plugin Loader] : C:\Program Files (x86)\QUOTAT~2\bar\1.bin\45brmon.exe [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ROC_ROC_NT] : "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RTHDVCPL] : C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe] : "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent] : "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED ---------- | Control - lsa - SecurityProviders - Session Manager - Terminal Server [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=DeviceInstall UsoSvc gpsvc trustedinstaller "SvcHostSplitThresholdInKB"=3670016 "WaitToKillServiceTimeout"=2000 "SystemStartOptions"= NOEXECUTE=OPTIN "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(2) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=16 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Notification Packages"=scecli "Authentication Packages"=msv1_0 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "LsaPid"=904 "ProductType"=3 "restrictanonymous"=0 "restrictanonymoussam"=1 "SamConnectedAccountsExist"=1 "SecureBoot"=1 "Security Packages"=kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "GlobalFlag2"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "AutoChkSkipSystemPartition"=0 "ResourceTimeoutCount"=648000 "PendingFileRenameOperations"=\??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\a\asdk.dll \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\a\ \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\p\pfAP.dll \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\p\pfBL.dll \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\p\ \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\ui\pfUI.dll \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\ui\ \??\C:\Users\Ben\AppData\Local\Temp\nsoC450.tmp\ [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "InstanceID"=2ee56682-bdf3-4fe4-b5dc-11b0127 "GlassSessionId"=1 ---------- | .LNK with Arguments ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretTimeout"=5000 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "ScreenSaveActive"=1 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "FocusBorderHeight"=2 "FocusBorderWidth"=2 "WallPaper"=c:\windows\web\wallpaper\theme1\img1.jpg [15/09/2018 08:29:25] "UserPreferencesMask"=0x9E1E078012000000 "Pattern Upgrade"=TRUE "Win8DpiScaling"=0 "DpiScalingVer"=4096 "MaxVirtualDesktopDimension"=3840 "MaxMonitorDimension"=1920 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC30100038F090080070000B0040000FAEC92D4C54CD40163003A005C00770069006E0064006F00770073005C007700650062005C00770061006C006C00700061007000650072005C007400680065006D00650031005C0069006D00670031002E006A0070006700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "PreferredUILanguages"=fr-FR "WaitToKillAppTimeout"=2000 "LockScreenAutoLockActive"=1 "DelayLockInterval"=0 "LogPixels"=168 "EnablePerProcessSystemDPI"=1 "HungAppTimeout"=2000 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableLockWorkstation"=0 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=145 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer] "EdgeDesktopShortcutCreated"=1 "ShellState"=0x2400000037A8000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SlowContextMenuEntries"=0xD3D4D98FF540E846B3F1416F1A5F4EC7F2380000AF75193DC6488E4FA182BE0E08FA86A961FC0000550F3DCB2CBC1A4C85ED23ED75B5106B8C2200000114020000000000C000000000000046844D00006024B221EA3A6910A2DC08002B30309DB5230000 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "GlobalAssocChangedCounter"=536 "TelemetrySalt"=6 "AppReadinessLogonComplete"=1 "FirstRunTelemetryComplete"=1 "PostAppInstallTasksCompleted"=1 "link"=0x16000000 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=1 "ShowCompColor"=1 "HideFileExt"=0 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "SuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StartMenuInit"=13 "TaskbarSizeMove"=1 "DisablePreviewDesktop"=0 "TaskbarSmallIcons"=1 "TaskbarGlomLevel"=1 "ShowSuperHidden"=1 "ShowStatusBar"=1 "StoreAppsOnTaskbar"=1 "EnableStartMenu"=1 "ReindexedProfile"=1 "DontUsePowerShellOnWinX"=0 "ShowTaskViewButton"=0 "TaskbarStateLastRun"=0xD951FE5D00000000 [HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers] "authenticodeenabled"=0 "DefaultLevel"=262144 "TransparentEnabled"=1 "PolicyScope"=0 "ExecutableTypes"=ADE ADP BAS BAT CHM CMD COM CPL CRT EXE HLP HTA INF INS ISP LNK MDB MDE MSC MSI MSP MST OCX PCD PIF REG SCR SHS URL VB WSC [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableFullTrustStartupTasks"=2 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableUwpStartupTasks"=2 "EnableVirtualization"=1 "SupportFullTrustStartupTasks"=1 "SupportUwpStartupTasks"=1 "ValidateAdminCodeSignatures"=0 "PromptOnSecureDesktop"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "SoftwareSASGeneration"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 "HideSCAHealth"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "SmartScreenEnabled"=RequireAdmin [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers] "authenticodeenabled"=0 "DefaultLevel"=262144 "TransparentEnabled"=1 "PolicyScope"=0 "ExecutableTypes"=ADE ADP BAS BAT CHM CMD COM CPL CRT EXE HLP HTA INF INS ISP LNK MDB MDE MSC MSI MSP MST OCX PCD PIF REG SCR SHS URL VB WSC [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableFullTrustStartupTasks"=2 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableUwpStartupTasks"=2 "EnableVirtualization"=1 "SupportFullTrustStartupTasks"=1 "SupportUwpStartupTasks"=1 "ValidateAdminCodeSignatures"=0 "PromptOnSecureDesktop"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "SoftwareSASGeneration"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 "HideSCAHealth"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=3 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=17763 "FirstLogon"=0 "PUUActive"=0x5B98CD3F01000C00CE00290260990B00893F0D00893F0D00D2000000020026006754725878C2DD007C6E4000980D06000D1305003FD50000000000002BFC3E00D72C0000AC0700007190848600BCD50160990B00000000000100000060990B0063450000E125000076562F0100000000 "DP"=0xD200E8000C010C00D00000005B98CD3F564FF20000000000DCEA0BBCF5BBD501658FCDC9D0BBD501D55579000000000000000000794E01000000000000000000A4233E000000000000000000000000000000000000000000000000000000F03F80510100EF7700C0AB60150CEB60174C08BE008054080108D418050ACD190000494025604D402560B5D100800A34215F0A74215FC33600000400E6120400E612C8B900C069C0002869E0022C385700802460072025E007321D1601402808C0212808C06316D8008044428159C44289596AFB00C000924034009A4034696A00801A8240461A824046 "ParseAutoexec"=1 "Shell"=%comspec% [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "scremoveoption"=0 "LastLogOffEndTimePerfCounter"=15877881728 "ShutdownFlags"=2147483815 "Userinit"=C:\Windows\system32\userinit.exe, "ShutdownWithoutLogon"=0 "DisableCad"=1 "EnableFirstLogonAnimation"=1 "AutoLogonSID"=S-1-5-21-2392155067-2275373385-2186660377-1002 "LastUsedUsername"=Ben [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "EnableSIHostIntegration"=1 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "AppUserModelID"=Microsoft.Windows.Explorer "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "AppUserModelID"=Microsoft.Windows.Explorer "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files\Mozilla Firefox\firefox.exe" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\Avast Secure Browser\Shell\open\Command] ""="C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" [HKLM\Software\Clients\StartMenuInternet\Avast Secure Browser\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files\Mozilla Firefox\firefox.exe" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [04/10/2019 17:23:57] [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Avast Secure Browser\Shell\open\Command] ""="C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Avast Secure Browser\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [04/10/2019 17:23:57] [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall ---------- | AppcompatFlags [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "SIGN.MEDIA=BBD713C3 setup.exe"=1 "SIGN.MEDIA=2B7EA0 setup.exe"=1 "SIGN.MEDIA=2B7EA0 Autorun.exe"=1 "SIGN.MEDIA=A75F9741 Setup.exe"=1 "SIGN.MEDIA=3585B05A Autorun.exe"=1 "SIGN.MEDIA=D65A972B HCSetup.exe"=1 "SIGN.MEDIA=729C85D0 setup.exe"=1 "SIGN.MEDIA=B44DACDF Autorun.exe"=1 "SIGN.MEDIA=70A3C0BC Setup.exe"=1 "SIGN.MEDIA=EA05B1D setup.exe"=1 "SIGN.MEDIA=30907C3F Setup.exe"=1 "SIGN.MEDIA=3D787E0 autorun.exe"=1 "SIGN.IE=065E7E20 moviestudio90b.exe"=1 "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe"=1 "SIGN.MEDIA=966634DD setup.exe"=1 "SIGN.MEDIA=11921C6 autorun.exe"=1 "SIGN.MEDIA=6E18922A setup.exe"=1 "SIGN.MEDIA=911439A3 Launcher.exe"=1 "SIGN.MEDIA=4126CFE0 Autorun.exe"=1 "SIGN.MEDIA=B101F067 Setup.exe"=1 "SIGN.MEDIA=1F2CA14 setup\rsrc\Autorun.exe"=1 "SIGN.MEDIA=5796AAA Combined-Community-Codec-Pack-2011-11-11.exe"=1 "SIGN.MEDIA=12CF358 setup.exe"=1 "SIGN.MEDIA=7850E69 setup.exe"=1 "SIGN.MEDIA=24F46A9 win\CDSplash.exe"=1 "SIGN.MEDIA=43C2197 Setup.exe"=1 "SIGN.MEDIA=21E4A4 Installer.exe"=1 "SIGN.MEDIA=6E167A0 Autorun.exe"=1 "SIGN.MEDIA=47BAD2 OriginInstaller.exe"=1 "SIGN.MEDIA=8A9F504C Setup.exe"=1 "SIGN.MEDIA=0 OriginInstaller.exe"=1 "SIGN.MEDIA=A09EFB90 Setup.exe"=1 "C:\Program Files (x86)\Activision\Call of Duty Black Ops II\redist\vcredist_x86.exe"=1 "SIGN.MEDIA=D3AB4262 autorun.exe"=1 "SIGN.MEDIA=116C0A38 autorun.exe"=1 "SIGN.MEDIA=1297930 UPDATE\assassins_creed_2_1.01_us.exe"=1 "SIGN.MEDIA=646726AB autorun.exe"=1 "SIGN.MEDIA=52FE43F3 SETUP.EXE"=1 "SIGN.MEDIA=1C84350 SETUP.EXE"=1 "SIGN.MEDIA=1B49C4 setup.exe"=1 "SIGN.MEDIA=503818 Install.exe"=1 "C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe"=33 "C:\Program Files (x86)\Realtek\NICDRV_8169\RTINSTALLER64.EXE"=1 "SIGN.MEDIA=12A1B1EA Fairlight\Installer.exe"=1 "C:\Program Files (x86)\ffdshow\unins000.exe"=1 "C:\Program Files (x86)\HP\Digital Imaging\{B61ED343-0B14-4241-999C-490CB1A20DA4}\hpzstub.exe"=1 "SIGN.MEDIA=86BE47EC Setup.exe"=1 "SIGN.MEDIA=E60C5 OriginInstaller.exe"=1 "SIGN.MEDIA=541BC50B setup.exe"=1 ""=1 "SIGN.MEDIA=C2222AC setup.EXE"=1 "SIGN.MEDIA=94F09C11 Setup.exe"=1 "SIGN.MEDIA=B07650B6 setup.exe"=1 "SIGN.MEDIA=C607FC82 Ace Combat Assault Horizon Enhanced Edition (2013) [PCDVD][MULTi5][WwW.LoKoTorrents.CoM]\setup.exe"=1 "SIGN.MEDIA=517528AF autorun.exe"=1 "SIGN.MEDIA=2403C14F setup.exe"=1 "SIGN.MEDIA=448BDB3A setup.exe"=1 "C:\Program Files (x86)\Battlefield 4\unins000.exe"=1 "C:\Games\Call of Duty - Ghosts\GameUpdater.exe"=1 "SIGN.MEDIA=7278C92 setup.exe"=1 "SIGN.MEDIA=B3043A8E setup.exe"=1 "C:\Program Files (x86)\Total War ROME II\unins000.exe"=1 "SIGN.MEDIA=9C94DBE8 setup.exe"=1 "SIGN.MEDIA=177BBE1B setup.exe"=1 "SIGN.MEDIA=2F773726 setup.exe"=1 "SIGN.MEDIA=6D8E8049 Setup.exe"=1 "SIGN.MEDIA=69B5E05D setup.exe"=1 "C:\Program Files\i2p\i2p.exe"=2 "SIGN.MEDIA=96DEC1C7 setup.exe"=1 "SIGN.MEDIA=B28CF7AD setup.exe"=1 "SIGN.MEDIA=CDBF3AB1 setup.exe"=1 "SIGN.MEDIA=8D1861F2 setup.exe"=1 "SIGN.MEDIA=68AF0A52 setup.exe"=1 "SIGN.MEDIA=27E5870 Autorun.exe"=1 "C:\Program Files (x86)\Rockstar Games\EFLC\Update\setup.exe"=1 "SIGN.MEDIA=68404D0B setup.exe"=1 "SIGN.MEDIA=E210A538 setup.exe"=1 "SIGN.MEDIA=3744F82B setup.exe"=1 "SIGN.MEDIA=CD7E205B Setup.exe"=1 "SIGN.MEDIA=6888614B setup.exe"=1 "SIGN.MEDIA=DFEAC1C3 setup.exe"=1 "SIGN.MEDIA=1FE45FF4 Autorun.exe"=1 "SIGN.MEDIA=6FBE4E0B setup.exe"=1 "SIGN.MEDIA=6857DB0B setup.exe"=1 "C:\Users\Ben\Downloads\OriginThinSetup.exe"=1 "C:\Users\Ben\Downloads\clipgrab-3.4.7.exe"=1 "SIGN.MEDIA=E9744D8 Assistant_Setup.exe"=1 "C:\Program Files\AVAST Software\Avast\BrowserCleanup.exe"=1 "C:\Users\Ben\Desktop\Assistant Installer\Assistant_Setup.exe"=1 "C:\Program Files (x86)\MEDION GoPal Assistant\GoPal_Assistant.exe"=1 "SIGN.MEDIA=68A6900B setup.exe"=1 "C:\Program Files (x86)\Common Files\Metaboli\Core\yummy.installer.exe"=32 "SIGN.MEDIA=2C034DB9 setup.exe"=1 "SIGN.MEDIA=E9744D8 Assistant_SetupBootstrapper.exe"=1 "C:\Medion\MEDION_GoPal_Assistant_6.2.0.12196_full.exe"=1 "C:\Medion\USB3.0\Renesas driver V_2.1.25.0\RENESAS-USB3-Host-Driver-21250-setup.exe"=1 "C:\Program Files (x86)\AC Dead Kings\ÓÎÏÀÍøNETSHOW.exe"=2 "C:\Users\Ben\Downloads\Saitek_Cyborg3D_Force_SD6_64.exe"=1 "C:\Users\Ben\Downloads\Smart Technology 7_0_27_13 64Bit.exe"=1 "SIGN.MEDIA=514DB08F setup.exe"=1 "SIGN.MEDIA=B7AE4ACA Setup.exe"=1 "C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\setup.exe"=1 "C:\Users\Ben\Downloads\siw-system-info_2011_build_1029_francais_14288.exe"=1 "C:\Users\Ben\Downloads\flashplayer17_ha_install.exe"=1 "C:\Users\Ben\Downloads\flashplayer17_ha_install(1).exe"=1 "C:\Users\Ben\Downloads\crystaldiskinfo_6-3-2_fr_306038.exe"=1 "C:\Users\Ben\Downloads\readerdc_fr_ha_install.exe"=1 "SIGN.MEDIA=898E1F3E setup.exe"=1 "C:\Users\Ben\AppData\Roaming\istartsurf\UninstallManager.exe"=32 "C:\Program Files (x86)\Lavasoft\Web Companion\Application\Installer.exe"=1 "C:\Users\Ben\Desktop\logiciels\Firefox Setup 21.0.exe"=1 "C:\Users\Ben\Downloads\EmsisoftAntiMalwareSetup.exe"=1 "C:\Users\Ben\Downloads\pixpsetup.exe"=1 "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=32 "C:\Users\Ben\AppData\Local\Temp\Rar$EXa0.882\Install_Win10_1003_07282015\setup.exe"=1 "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"=32 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files\Gadwin\Gadwin PrintScreenPro\PrintScreenPro64.exe"=0x5341435001000000000000000500000010000000000000000000000000000000000000000700000028000000A864EF004164F00001000000000000000000030673020000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000C897A302000000000D0000000D000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C03802000BA5020001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8380200FDD8020001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\OneDrive.exe"=0x5341435001000000000000000700000028000000C824060017F1060001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Program Files (x86)\Origin Games\FIFA 15\fifa15.exe"=0x5341435001000000000000000700000028000000D09D3305C677340501000000000000000000000A7322000067077CBAC54CD40100000000000000000200000018010000000000001000003000000000000000000000000000000000320A000000000000010000000100000000000000100000600000000000000000000000000000000085B3340600000000340000000000000000000000100000200000000000000000000000000000000095062201000000001E000000000000000000000000000040000000000000000000000000000000007C7551030000000005000000000000000000000000000000000000000000000000000000000000008DF04902000000001000000000000000000001060000002000000000000000000000000000000000414CC202000000000600000000000000000001060000006000000000000000000000000000000000E70B0000000000000100000000000000 "C:\Program Files (x86)\The Witcher 3 Wild Hunt\bin\x64\witcher3.exe"=0x53414350010000000000000007000000280000005074B3024055B40201000000000000000000000A73200000D5B3B31A57DFD10100000000000000000200000050000000000000001000006000000000000000000000000000000000645B0C0000000000010000000100000000000000100000200000000000000000000000000000000045B00000000000000100000000000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000604002005E58020001000000000000000000000A002100000261329FFFBAD0010000000100000000 "C:\Users\Ben\Desktop\Bureau\LOGICIELS\StellarPhoenixWindowsDataRecovery-Home_01NET.exe"=0x5341435001000000000000000700000028000000F8B43F00DE824000010000000000000000000206000100000261329FFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000B8540000000000000200000002000000 "C:\Users\Ben\Desktop\Bureau\LOGICIELS\PirateBrowser 0.6b\Start PirateBrowser.exe"=0x53414350010000000000000007000000280000000E8000009DD10000010000000000000000000206712000000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000009FAE0000000000000100000001000000 "C:\Users\Ben\Desktop\Bureau\LOGICIELS\WindowsActivationUpdate.exe"=0x5341435001000000000000000700000028000000A86D0200B9DB0200010000000000000000000106710200000261329FFFBAD00100000080000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000305B0000000000000100000001000000 "C:\Program Files (x86)\Microsoft Application Virtualization Client\sftdde.exe"=0x5341435001000000000000000700000028000000A89E04008DF004000100000000000000000003060001000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000096A12A01000000001900000019000000 "C:\Users\Ben\Downloads\MaConfigx64_4_6_0_1.exe"=0x534143500100000000000000070000002800000080AB4200DB5B4300010000000000000000000006710000000261329FFFBAD0010000000000000000020000002800000000000000000800400000000000000000000000000000000048D40000000000000200000002000000 "C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe"=0x534143500100000000000000070000002800000010F90600E821070001000000000000000000030673000000078CBF8EFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000A9292900000000000400000004000000 "C:\Program Files (x86)\Ubisoft\Trials Fusion - Fault One Zero\datapack\trials_fusion.exe"=0x5341435001000000000000000700000028000000D87AB600A8EBB60001000000000000000000000A7122000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000AD930500000000000200000002000000 "C:\Windows\SysWOW64\FlashPlayerApp.exe"=0x5341435001000000000000000700000028000000E81D0C00067F0C0001000000000000000000000A712200000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000005F2C0000000000000100000001000000 "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe"=0x5341435001000000000000000700000028000000C01702006E31020001000000000000000000000A6122000019B4C529E312D1010000000000000000020000002800000000000000000000100000000000000000000000000000000070E3EF00000000007400000074000000 "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe"=0x5341435001000000000000000700000028000000600E3800AC9038000100000000000000000002067122000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000BF150900000000002D0000002D000000 "SIGN.MEDIA=30966AA OriginSetup.exe"=0x534143500100000000000000070000002800000000AE61000000000001000000000000000000000A612000000261329FFFBAD0010000000000000000020000002800000000000000000800400000000000000000000000000000000056BE3B02000000000100000001000000 "C:\Program Files (x86)\BFH\BFHWebHelper.exe"=0x5341435001000000000000000500000010000000000000000000000000000000000000000700000028000000009E0C00A2D90C0001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000010000000000000000000000A63F1B00000000000A000000020000000000000000000040000000000000000000000000000000007877A000000000001200000000000000 "C:\Users\Ben\Downloads\bttlfldhrdlnpfrpartrar__15047_i1620337365_il1715505.exe"=0x5341435001000000000000000700000028000000B0040C00CBBB0C00010000000000000000000206000100000261329FFFBAD0010000000000000000 "C:\Users\Ben\AppData\Local\Temp\20150903091821\I\QQBrowser.exe"=0x53414350010000000000000007000000280000003802020000E10200010000000000000000000206710200000261329FFFBAD00100000000000000000200000028000000000000000008000000000000000000000000000000000000841DB300000000000200000002000000 "C:\Program Files (x86)\gmsd_fr_005010078\gamesdesktop_widget.exe"=0x534143500100000000000000070000002800000090989D00B37B9E0001000000000000000000000A712200000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000A9CB0400000000000200000002000000 "C:\ProgramData\TVTime\Uninstall.exe"=0x5341435001000000000000000700000028000000E03908006077080001000000000000000000000A712200000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000056DE0100000000000200000002000000 "C:\Program Files (x86)\mbot_fr_014010078\unins000.exe"=0x5341435001000000000000000700000028000000F0C70A00D25F0B00010000000000000000000306000100000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000074160700000000000100000001000000 "C:\Program Files\WebBar\unins000.exe"=0x5341435001000000000000000700000028000000C3440B0000000000010000000000000000000306000100000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000001B340100000000000100000001000000 "C:\Program Files (x86)\PhraseProfessor_1.10.0.22\Uninstall.exe"=0x5341435001000000000000000700000028000000A8D4040036850500010000000000000000000106000100000261329FFFBAD001000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000009B3C0000000000000100000001000000 "C:\Program Files (x86)\MovieDea\uninst.exe"=0x5341435001000000000000000700000028000000C486020000000000010000000000000000000106000100000261329FFFBAD0010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000043360000000000000200000002000000 "C:\Users\Ben\AppData\Roaming\ASPackage\Uninstall.exe"=0x5341435001000000000000000700000028000000790B010000000000010000000000000000000106000100000261329FFFBAD0010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000074040000000000000100000001000000 "C:\Program Files\BubbleSound\Uninstall.exe"=0x53414350010000000000000007000000280000006E05010000000000010000000000000000000106000100000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000051040100000000000100000001000000 "C:\Program Files (x86)\gmsd_fr_005010078\unins000.exe"=0x5341435001000000000000000700000028000000F0C70A00D25F0B00010000000000000000000306000100000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000083940600000000000100000001000000 "C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe"=0x534143500100000000000000070000002800000018604B0033A84B00010000000000000000000306000100000261329FFFBAD00100000000000000000200000028000000000000000000000000100000000000000000000000000000D1242700000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\20150903135535\I\QQBrowser.exe"=0x53414350010000000000000007000000280000003802020000E10200010000000000000000000206710200000261329FFFBAD0010000000000000000020000002800000000000000000800400000000000000000000000000000000046EFCB00000000000200000002000000 "C:\Users\Ben\AppData\Local\Temp\WIZZTEMP\newversion.exe"=0x53414350010000000000000007000000280000000AEC4E0000000000010000000000000000000306000100000261329FFFBAD0010000000000000000020000002800000000000000000800400000000000000000000000000000000055071D00000000000100000001000000 "C:\Users\Ben\AppData\Local\DailyPcClean Support\updpcc_en_009010079.exe"=0x5341435001000000000000000700000028000000908C32000D62330001000000000000000000000A712200000261329FFFBAD001000000000000000002000000280000000000000000080040000000000000000000000000000000003F000000000000000200000002000000 "C:\Program Files (x86)\DailyPcClean Support\unins000.exe"=0x5341435001000000000000000700000028000000F0C70A00D25F0B00010000000000000000000306000100000261329FFFBAD0010000000000000000020000002800000000000000000000400010000000000000000000000000000020B61400000000000300000003000000 "C:\Program Files (x86)\WordSurfer_1.10.0.19\Uninstall.exe"=0x534143500100000000000000070000002800000000CA0400BD060500010000000000000000000106000100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000603E0000000000000100000001000000 "C:\Program Files (x86)\SpaceSondPro\uninstall.exe"=0x53414350010000000000000007000000280000008549060000000000010000000000000000000306000100000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000009C630000000000000100000001000000 "C:\Program Files (x86)\gmsd_fr_005010079\unins000.exe"=0x5341435001000000000000000700000028000000F0C70A00D25F0B00010000000000000000000306000100000261329FFFBAD00100000000000000000200000050000000000000000000000000000000000000000000000000000000ED5109000000000002000000020000000000000000000040001000000000000000000000000000005AD51200000000000100000000000000 "C:\Users\Ben\Downloads\RogueKiller.exe"=0x5341435001000000000000000700000028000000487C1E0115F91E0101000000000000000000000A002100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000C1C03C02000000000500000005000000 "C:\Users\Ben\AppData\Local\Temp\20150903185808\I\QQBrowser.exe"=0x53414350010000000000000007000000280000003802020000E10200010000000000000000000206710200000261329FFFBAD00100000000000000000200000028000000000000000008000000000000000000000000000000000000C6C23400000000000100000001000000 "C:\Users\Ben\Downloads\adwcleaner_5-005_fr_430277.exe"=0x5341435001000000000000000700000028000000003E190000000000010000000000000000000306000100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000B5520300000000000200000002000000 "C:\Users\Ben\AppData\Local\Temp\20150903202939\I\QQBrowser.exe"=0x53414350010000000000000007000000280000003802020000E10200010000000000000000000206710200000261329FFFBAD00100000000000000000200000028000000000000000008000000000000000000000000000000000000E3FC0C00000000000200000002000000 "C:\Users\Ben\AppData\Local\gmsd_fr_005010079\upgmsd_fr_005010079.exe"=0x534143500100000000000000070000002800000090883200D609330001000000000000000000000A712200000261329FFFBAD0010000000000000000020000002800000000000000000800000000000000000000000000000000000013020000000000000300000003000000 "C:\Program Files (x86)\WindeskWinsearch\Windesk Winsearch.exe"=0x5341435001000000000000000700000028000000883110004DB3100001000000000000000000000AF5220000078CBF8EFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000007BFD0000000000000100000001000000 "C:\Users\Ben\AppData\Roaming\Nosibay\Bubble Dock\LBubble Dock.exe"=0x5341435001000000000000000700000028000000102B0A00954A0A00010000000000000000000306710000000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000C6640300000000000100000001000000 "C:\Users\Ben\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe"=0x5341435001000000000000000700000028000000105B1700E954180001000000000000000000000A712000000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000006D100300000000000100000001000000 "C:\Program Files (x86)\BFH\Uninstall.exe"=0x534143500100000000000000070000002800000064B90100185F020001000000000000000000000A612200000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000E5B20000000000000200000002000000 "C:\Users\Ben\AppData\Local\Temp\20150903225520\I\QQBrowser.exe"=0x53414350010000000000000007000000280000003802020000E10200010000000000000000000206710200000261329FFFBAD0010000000000000000020000002800000000000000000800000000000000000000000000000000000044100F00000000000100000001000000 "C:\Users\Ben\Downloads\SpyHunter-Installer.exe"=0x534143500100000000000000070000002800000080653100C543320001000000000000000000000A002100000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000001E9AD301000000000200000002000000 "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe"=0x534143500100000000000000070000002800000080497E00A5ED7E0001000000000000000000000A00210000078CBF8EFFBAD001000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000002F000000000000000100000001000000 "C:\Users\Ben\AppData\Roaming\Enigma Software Group\sh_installer.exe"=0x534143500100000000000000070000002800000080653100C543320001000000000000000000000A002100000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000078390800000000000400000004000000 "C:\Users\Ben\Downloads\mbam-setup-2.1.8.1057.exe"=0x5341435001000000000000000700000028000000107D7301D31B7401010000000000000000000206000100000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000A5562A02000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE"=0x5341435001000000000000000700000028000000A88C4C0056604D00010000000000000000000206712000000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000670E0000000000000300000003000000 "C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE"=0x5341435001000000000000000700000028000000E0F2300097E9310001000000000000000000010600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000099FBD200000000000300000003000000 "SIGN.MEDIA=B67CE395 autorun.exe"=0x534143500100000000000000070000002800000010156E002D2D6E00010000000000000000000006712000000261329FFFBAD001000000000000000002000000280000000000000080000000000000000000000000000000000000000BDE5900000000000100000001000000 "C:\Program Files (x86)\Notepad++\notepad++.exe"=0x534143500100000000000000070000002800000000B02400632922000100000000000000000003067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000927F5200000000000E0000000E000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's H.A.W.X\Support\GameUpdater\GU_DX9\gu.exe"=0x534143500100000000000000070000002800000000600900B6E80900010000000000000000000006712200000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000006C960500000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's H.A.W.X\HAWX.exe"=0x53414350010000000000000005000000100000000000000000000000000000000000000007000000280000005085A7006AB3A7000100000000000000000000067120000019B4C529E312D10100000000000000000200000050000000000000000000000000000000000000000000000000000000DA6E1D00000000000100000001000000000000000000004000000000000000000000000000000000ECF20D00000000000100000000000000 "C:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe"=0x534143500100000000000000070000002800000028953200B334330001000000000000000000010671220000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000010000000000000000000000000E9712D000000000003000000020000000000000080000000000002100000000000000000000000009A3CB302000000000300000000000000 "C:\Program Files (x86)\Common Files\EAInstaller\Titanfall\Cleanup.exe"=0x5341435001000000000000000700000028000000400B0D00B98B0D00010000000000000000000206000100000261329FFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000662B0000000000000100000001000000 "C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe"=0x5341435001000000000000000700000028000000604A0B00BC960B0001000000000000000000010671020000E63F486B2AA0D20100000000000000000200000028000000000000008000000000000000000000000000000000000000553D6300000000002900000029000000 "C:\Program Files (x86)\WRC 4 FIA World Rally Championship\unins000.exe"=0x5341435001000000000000000700000028000000A1940C0000000000010000000000000000000206000100000261329FFFBAD00100000000000000000200000028000000000000000000004000020000000000000000000000000000D50E0000000000000100000001000000 "C:\Program Files (x86)\Enemy Front PROPER\unins000.exe"=0x53414350010000000000000007000000280000007121170000000000010000000000000000000106000100000261329FFFBAD0010000000000000000020000002800000000000000000000400002000000000000000000000000000072140000000000000100000001000000 "C:\Program Files (x86)\Common Files\EAInstaller\Battlefield 4\Cleanup.exe"=0x534143500100000000000000070000002800000040070D00DAC10D00010000000000000000000206000100000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000087350000000000000100000001000000 "C:\Program Files (x86)\Eugen Systems\Wargame - Airland Battle\unins000.exe"=0x5341435001000000000000000700000028000000C95B120000000000010000000000000000000306000100000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000002A200000000000000100000001000000 "C:\Program Files (x86)\Company of Heroes 2\unins000.exe"=0x5341435001000000000000000700000028000000A1060B0000000000010000000000000000000206000100000261329FFFBAD00100000000000000000200000028000000000000000000004000020000000000000000000000000000A9180000000000000100000001000000 "C:\Program Files (x86)\BleachBit\uninstall.exe"=0x534143500100000000000000070000002800000008570100398E6100010000000000000000000106000100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000C3110000000000000100000001000000 "C:\Games\Need for Speed The Run\Need For Speed The Run.exe"=0x5341435001000000000000000700000028000000007C4302A85D440201000000000000000000010671220000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000023E71400000000000300000003000000 "C:\Program Files (x86)\ACE COMBAT ASSAULT HORIZON Enhanced Edition\Ace Combat_AH.exe"=0x534143500100000000000000070000002800000000AA9000A89697000100000000000000000001067102000019B4C529E312D1010000000000000000010000000400000001000000020000005000000000000000100000200000000000000000000000000000000053F4000000000000020000000200000000000000000000400000000001000000000000000100000096CA5500000000000200000000000000 "SIGN.MEDIA=CF7F46F3 SETUPTOPGUN.EXE"=0x53414350010000000000000007000000280000000000E02E00000000010000000000000000000106412200000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000009F907500000000000300000003000000 "C:\Program Files (x86)\TopGun - Hardlock\TopGun.exe"=0x534143500100000000000000070000002800000000EE4B0000000000010000000000000000000106712200000261329FFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000462B00000000000005000000050000000000000000000000000000000000000000000000000000000A280000000000000200000000000000 "C:\Program Files (x86)\TopGun - Hardlock\Uninstall.exe"=0x5341435001000000000000000700000028000000BF2812000000000001000000000000000000000A412200000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000054420100000000000200000002000000 "C:\Program Files (x86)\TopGun - Hardlock\binary\TopGun.exe"=0x534143500100000000000000070000002800000000EE4B0000000000010000000000000000000106710200000261329FFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004010000000000000000000000000000000AE460000000000000200000002000000 "C:\Program Files (x86)\Top Gun - Hard Lock\binary\TopGun.exe"=0x534143500100000000000000070000002800000000EE4B0000000000010000000000000000000106710200000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000EEE20000000000000100000001000000 "C:\Program Files (x86)\Top Gun - Hard Lock\GameUpdater.exe"=0x53414350010000000000000007000000280000000068100000000000010000000000000000000106710200000261329FFFBAD001000000800000000002000000280000000000000000000000000000000000000000000000000000006B1D0000000000000100000001000000 "SIGN.MEDIA=916C353C setup.exe"=0x5341435001000000000000000700000028000000B88D230000000000010000000000000000000306000100000261329FFFBAD00100000000000000000200000028000000000000008000000000000000000000000000000000000000E8421D00000000000100000001000000 "C:\Program Files\WRC 5 FIA World Rally Championship\WRC5.exe"=0x534143500100000000000000050000001000000000000000000000000000000010000000070000002800000000844100F84C420001000000000000000000000A7122000019B4C529E312D101000000000000000002000000A00000000000000010000060000000000000000000000000000000006A5E1100000000000400000004000000000000000000004000000000010000000000000000000000CEC60600000000000200000000000000000000001000002000000000000000000000000000000000155003000000000001000000000000000000000000000000000000000000000000000000000000008D000000000000000100000000000000 "C:\Users\Ben\Desktop\Bureau\LOGICIELS\2009_FFD_1.exe"=0x534143500100000000000000070000002800000010DBA6006AD6A700010000000000000000000006710200000261329FFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000100200000000000000000000000000343B0000000000000100000001000000 "C:\Games\Need for Speed Most Wanted\NFS13.exe"=0x53414350010000000000000007000000280000000090DB004FC6CE0001000000000000000000010671020000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000000000000000000000000000D807A600000000000200000001000000000000000000004000000000000000000000000000000000CD420F00000000000200000000000000 "SIGN.MEDIA=A3795F15 setup.exe"=0x5341435001000000000000000700000028000000FF5F340000000000010000000000000000000106000100000261329FFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000097A90800000000000200000002000000 "E:\Games\Act of Aggression\ActOfAggression.exe"=0x534143500100000000000000070000002800000090D3350299D6350201000000000000000000000A712200000261329FFFBAD00100000000000000000500000010000000000000000000000000000000200000000200000028000000000000002000006000000000000000000000000000000000BC0D0000000000000100000001000000 "C:\Games\Act of Aggression\ActOfAggression.exe"=0x534143500100000000000000050000001000000000000000000000000000000020000000070000002800000090D3350299D6350201000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000020000060000000000000000000000000000000006C49D600000000003500000035000000 "C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe"=0x5341435001000000000000000100000004000000010000000700000028000000002601000000000001000000000000000000010671020000DB80FDAC2839D301000000000000000002000000500000000000000000000000000000000000000000000000000000005AB58600000000000200000002000000000000000000004000000000010000000000000001000000571F5E00000000000200000000000000 "C:\Program Files (x86)\Windows Live\Mail\wlmail.exe"=0x5341435001000000000000000700000028000000786701001AAB01000100000000000000000001067122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000A0C80000000000000200000002000000 "SIGN.MEDIA=2EE3022A Autorun.exe"=0x5341435001000000000000000700000028000000D81E3F00C8643F0001000000000000000000000A712200000261329FFFBAD001000000000000000002000000280000000000000080000000000000000000000000000000000000000C5B2F00000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Assassin's Creed Rogue\ACC.exe"=0x5341435001000000000000000700000028000000D85A0B042D9B0B0401000000000000000000000A73220000078CBF8EFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000004C8E0200000000000100000001000000 "SIGN.MEDIA=ECA2990A setup.exe"=0x5341435001000000000000000700000028000000DCDA28000000000001000000000000000000000A002100000261329FFFBAD00100000000000000000200000028000000000000008000000000000000000000000000000000000000A77F5400000000000400000004000000 "C:\Program Files\Call of Duty Black Ops III\BlackOps3.exe"=0x5341435001000000000000000700000028000000E8896F0238956F0201000000000000000000000A73220000078CBF8EFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000899D8A00000000000500000005000000000000000000000000000000000000000000000000000000AE870000000000000100000000000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe"=0x53414350010000000000000007000000280000002057480051D9480001000000000000000000000AF12200000261329FFFBAD00100000000000000000200000028000000000000000000000000000000000000000000000000000000DF020000000000000200000002000000 "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"=0x53414350010000000000000007000000280000002085280024E2280001000000000000000000000A002100000261329FFFBAD0010000000000000000020000002800000000000000000000000000000000000000000000000000000048260600000000000200000002000000 "C:\Program Files (x86)\7-Zip\7zG.exe"=0x534143500100000000000000070000002800000000A6030000000000010000000000000000000106712000000261329FFFBAD00100000000000000000200000028000000000000000000000000020200000000000000000000000000F9080000000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver\setup.exe"=0x534143500100000000000000070000002800000078500600B87D060001000000000000000000000A002100000261329FFFBAD001000000000000000002000000280000000000000080000040000000000000000000000000000000000C200D00000000000100000001000000 "C:\Users\Ben\Desktop\Bureau\LOGICIELS\crystaldiskinfo_6-3-2_fr_306038 [1].exe"=0x5341435001000000000000000700000028000000E8032E0096412E000100000000000000000003060001000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000005612F200000000000500000005000000 "C:\Users\Ben\AppData\Local\Temp\AIR5340.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B87C05000275060001000000000000000000000A712200000261329FFFBAD00100000080000000000200000028000000000000000000000000000000000000000000000000000000DA2F0000000000000100000001000000 "C:\Users\Ben\Desktop\Bureau\LOGICIELS\mbam-setup-2.0.3.1025.exe"=0x5341435001000000000000000700000028000000988E2E01C5382F01010000000000000000000206000100000261329FFFBAD0010000000000000000020000002800000000000000000000000000000000000000000000000000000096AF2602000000000200000002000000 "C:\Users\Ben\Downloads\JRT.exe"=0x534143500100000000000000070000002800000068671800656F18000100000000000000000001067102000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000005000000000000000000000000000000000000000000000000000000097220100000000000100000001000000000000000000004000000000000000000000000000000000F4AE0200000000000300000000000000 "C:\Program Files (x86)\Emsisoft Anti-Malware\unins000.exe"=0x5341435001000000000000000700000028000000F01A120016DD1200010000000000000000000206000100000261329FFFBAD0010000000000000000020000002800000000000000000000400410000000000000000000000000000094B70400000000000100000001000000 "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins001.exe"=0x53414350010000000000000007000000280000006A090B000000000001000000000000000000000A002100000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000009AE30000000000000100000001000000 "C:\Users\Ben\Downloads\mbam-setup-2.2.0.1024.exe"=0x5341435001000000000000000700000028000000D88F5D01B6275E0101000000000000000000000A002100000261329FFFBAD0010000000000000000020000002800000000000000000000000000000000000000000000000000000070320200000000000100000001000000 "C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\Installer\setup.exe"=0x534143500100000000000000070000002800000048390F00836C0F0001000000000000000000000A002100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000FB460000000000000100000001000000 "C:\Program Files (x86)\CrystalDiskInfo\DiskInfo.exe"=0x534143500100000000000000050000001000000000000000000000000000000000000000070000002800000078642400E593240001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000E2E40000000000000A0000000A000000 "C:\Program Files (x86)\Lucky Bright\Uninstaller.exe"=0x5341435001000000000000000700000028000000C80C0500FD330500010000000000000000000106000100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000D6760000000000000100000001000000 "C:\Program Files (x86)\SearchMoreKnow\Uninstaller.exe"=0x5341435001000000000000000700000028000000400C0500F1C30500010000000000000000000106000100000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000000EFD0000000000000200000002000000 "C:\Users\Ben\Downloads\RogueKiller(1).exe"=0x534143500100000000000000070000002800000048C83D0162513E0101000000000000000000000A002100000261329FFFBAD001000000000000000002000000280000000000000000000040000000000000000000000000000000000AF2E501000000000100000001000000 "C:\Users\Ben\Downloads\EmsisoftAntiMalwareSetup(3).exe"=0x5341435001000000000000000700000028000000807C3F0C26DE3F0C01000000000000000000000A002100000261329FFFBAD001000000000000000002000000280000000000000000000000000000000000000000000000000000006589C901000000000100000001000000 "C:\Program Files (x86)\METAL GEAR RISING REVENGEANCE\METAL GEAR RISING REVENGEANCE.exe"=0x5341435001000000000000000700000028000000000290010000000001000000000000000000020671000000DB80FDAC2839D301000000000000000002000000A000000000000000100000600000000000000000000000000000000090020000000000000100000001000000000000001000002000000000000000000000000000000000DF02000000000000020000000000000000000000000000000000000001000000000000000000000082070000000000000200000000000000000000000000004000000000000000000000000000000000CBB50500000000000700000000000000 "C:\Program Files (x86)\Call of Duty Black Ops III\BO3 Offline Modes Launcher.exe"=0x5341435001000000000000000700000028000000002205000000000001000000000000000000000AF12200000261329FFFBAD0010000000000000000050000001000000000000000000000000000000080000000020000005000000000000000800000000000000000000000000000000000000039F40200000000000400000001000000000000008000004000000000000000000000000000000000A4820200000000000400000000000000 "C:\Program Files (x86)\Call of Duty Black Ops III\BlackOps3.exe"=0x5341435001000000000000000500000010000000000000000000000000000000000000000B0000000802000042006C00610063006B004F0070007300330020002D00200052006100630063006F00750072006300690000006C006E006B0000006500750078005C00430061006C006C0020006F006600200044007500740079005C0042006C00610063006B004F0070007300330020002D00200052006100630063006F0075007200630069002E006C006E006B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000700000028000000E8AF720292F3720201000000000000000000000A73220000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000000000000000000000000000286F8300000000000500000001000000000000000000004000000000000000000000000000000000E0BD8700000000000F00000000000000 "SIGN.MEDIA=A98D6CBE Autorun.exe"=0x534143500100000000000000070000002800000010650600C3900600010000000000000000000006710000000261329FFFBAD001000000000000000002000000280000000000000080000000000000000000000000000000000000000C8F1800000000000100000001000000 "C:\Users\Ben\Downloads\Mad Max [FitGirl Ultra Repack]\setup-multi9.exe"=0x53414350010000000000000007000000280000005D555D0000000000010000000000000000000106000100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000D6C7ED01000000000200000002000000 "C:\Program Files (x86)\Mad Max\MadMax.exe"=0x53414350010000000000000006000000080000001000000000000000050000001000000000000000000000000000000000000000070000002800000000C6140598B3150501000000000000000000000A7322000059193B14E312D10100000000000000000200000078000000000000000000004010000000000000000000000000000000952B000000000000090000000500000000000000200000600000000000000000000000000000000010340000000000000200000000000000000000000000000010000000000000000000000000000000EA1A0000000000000100000000000000 "C:\Program Files (x86)\Mad Max\Launcher.bat"=0x5341435001000000000000000700000028000000008C030022EE030001000000000000000000010500100000078CBF8EFFBAD0010000000000000000 "C:\Program Files (x86)\Mad Max\unins000.exe"=0x53414350010000000000000007000000280000007121170000000000010000000000000000000106000100000261329FFFBAD001000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000009411000000000000010000000100000000000000000000000002020000000000000000000000000066160000000000000200000000000000 "C:\Program Files (x86)\BFH\bfh.exe"=0x5341435001000000000000000700000028000000009CE404B905E50401000000000000000000000A73220000078CBF8EFFBAD0010000000000000000020000002800000000000000000000400000000000000000000000000000000022C20100000000000100000001000000 "SIGN.MEDIA=E4A3BAD0 setup.exe"=0x5341435001000000000000000700000028000000AD62470000000000010000000000000000000106000100000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000F7B03000000000000100000001000000 "C:\Games\Mortal kombat\Mortal Kombat Komplete Edition\DiscContentPC\MKKE.exe"=0x534143500100000000000000070000002800000000DAB100AE2EB200010000000000000000000206712200000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000F6BC1400000000000100000001000000 "SIGN.MEDIA=158DF76 SETUP.EXE"=0x534143500100000000000000070000002800000080030300C86203000100000000000000000002060021000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000B0D02700000000000200000002000000 "C:\Program Files (x86)\Avanquest\Architect 3D Ultimate\PunchHomeNGAS.exe"=0x53414350010000000000000007000000280000003811050028060600010000000000000000000206710200000261329FFFBAD00100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000B80B00000000000001000000010000000000000000000040000000000000000000000000000000004DD50100000000000200000000000000 "C:\Program Files (x86)\SIW\siw.exe"=0x5341435001000000000000000700000028000000006A2D000D372E000100000000000000000002060001000019B4C529E312D1010000000000000000020000002800000000000000000000400010000000000000000000000000000040F90100000000000200000002000000 "C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe"=0x5341435001000000000000000700000028000000C8DA08000FFA080001000000000000000000000A712200000261329FFFBAD00100000000000000000200000028000000000000000000004000000000000000000000000000000000A32B0A00000000000100000001000000 "C:\Program Files (x86)\MSI Afterburner\Uninstall.exe"=0x534143500100000000000000070000002800000026600100038449020100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000F3930000000000000300000003000000 "C:\Program Files (x86)\RivaTuner Statistics Server\Uninstall.exe"=0x53414350010000000000000007000000280000000C5E0100755C53010100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000C13C0200000000000200000002000000 "C:\Program Files (x86)\InstallShield Installation Information\{649C3DB6-B295-4ff7-8A04-3786D8CF36E8}\ISAdmin.exe"=0x534143500100000000000000070000002800000038670C00530A0D000100000000000000000002060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000062D40B00000000000200000002000000 "C:\Users\Ben\Downloads\6.06_nvidia_system_tools.exe"=0x534143500100000000000000070000002800000000288B0502BF8B05010000000000000000000105710000000261329FFFBAD00100000000000000000200000028000000000000000008004000000000000000000000000000000000724B0300000000000200000002000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA System Monitor\NVMonitor.exe"=0x534143500100000000000000070000002800000068BE1200D51A130001000000000000000000010673220000D5B3B31A57DFD10100000000000000000200000028000000000000000000000010100000000000000000000000000000509D0200000000000600000006000000 "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"=0x534143500100000000000000070000002800000038099600CD0E960001000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000009AC32F00000000000200000002000000 "C:\Users\Ben\Downloads\msi-afterburner.exe"=0x5341435001000000000000000700000028000000204F0E001A3D6AF30100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000BABB0100000000000100000001000000 "C:\Program Files (x86)\Far Cry 4\bin\FarCry4.exe"=0x5341435001000000000000000700000028000000D8620100E71002000100000000000000000003067300000059193B14E312D1010000000000000000050000001000000000000000000000000000000000000000020000005000000000000000100000600000000000000000000000000000000003903300000000000100000001000000000000000000004000000000010000000000000000000000ACB43100000000000100000000000000 "C:\Users\Ben\Downloads\JRT(1).exe"=0x534143500100000000000000070000002800000068671800656F18000100000000000000000001067102000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000000F881000000000000100000001000000 "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe"=0x53414350010000000000000007000000280000006A090B000000000001000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000004360000000000000300000003000000 "C:\Users\Ben\Downloads\JRT(2).exe"=0x534143500100000000000000070000002800000068671800656F18000100000000000000000001067102000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000074C40100000000000200000002000000 "C:\Users\Ben\Downloads\mbam-setup-org-2.2.0.1024.exe"=0x5341435001000000000000000700000028000000D88F5D01B6275E0101000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000005B8ADD00000000000200000002000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver361.43\setup.exe"=0x5341435001000000000000000700000028000000305106002A9B060001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000008000004000000000000000000000000000000000C8DF0200000000000100000001000000 "C:\Program Files (x86)\Farming Simulator 15\FarmingSimulator2015.exe"=0x5341435001000000000000000700000028000000B0C80600EC5F07000100000000000000000000067102000019B4C529E312D10100000000000000000200000050000000000000000000004000000000000000000000000000000000A7130000000000000100000001000000000000000000000000000000000000000000000000000000F9150000000000000100000000000000 "C:\Users\Ben\Downloads\mbam-setup-org-2.2.0.1024(2).exe"=0x5341435001000000000000000700000028000000D88F5D01B6275E0101000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000C4C18201000000000100000001000000 "C:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\Autorun\Exe\Autorun.exe"=0x534143500100000000000000070000002800000070D90000CBBF0100010000000000000000000106F100000019B4C529E312D10100000000000000000200000028000000000000008000004000100000000000000000000000000000D0D07301000000000100000001000000 "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"=0x534143500100000000000000070000002800000028E50E007D120F000100000000000000000003060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000025190000000000000100000001000000 "C:\Users\Ben\Downloads\Firefox Setup Stub 43.0.2.exe"=0x5341435001000000000000000700000028000000E8CB0300D7C604000100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000FDDA1400000000000100000001000000 "C:\Users\Ben\Downloads\adwcleaner_5.026.exe"=0x5341435001000000000000000700000028000000009A1A00000000000100000000000000000003060001000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400010000000000000000000000000000065DDAA00000000000900000009000000 "C:\Program Files\RogueKiller\unins000.exe"=0x534143500100000000000000070000002800000048180C0029780C000100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000000000004000020000000000000000000000000000CE170000000000000100000001000000 "H:\Mad Max [FitGirl Ultra Repack]\setup-multi9.exe"=0x53414350010000000000000007000000280000005D555D00000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000BBA72700000000000100000001000000 "C:\Program Files (x86)\Assassins Creed Syndicate\ACS.exe"=0x5341435001000000000000000700000028000000E89E07020729080201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000002000006000000000000000000000000000000000210E9900000000000A0000000A000000 "C:\Users\Ben\Downloads\EmsisoftAntiMalwareSetup_13088567.exe"=0x53414350010000000000000007000000280000000851550C9391550C01000000000000000000000A0021000019B4C529E312D1010000000000000000 "C:\ProgramData\Malwarebytes Anti-Malware\mbam.exe"=0x534143500100000000000000070000002800000038099600CD0E960001000000000000000000000A7122000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000A3BB3700000000000200000002000000 "C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe"=0x53414350010000000000000007000000280000007862C2003B3DC30001000000000000000000000A7322000059193B14E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000024A81100000000000400000004000000 "C:\Users\Ben\Downloads\bio7728.exe"=0x53414350010000000000000007000000280000003E2F1800000000000100000000000000000000067102000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000B0570100000000000500000005000000 "C:\Users\Ben\Downloads\bio7728(1).exe"=0x53414350010000000000000007000000280000003E2F1800000000000100000000000000000000067102000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000066450000000000000300000003000000 "C:\Users\Ben\Desktop\medion\medion bios\2.09\flash.bat"=0x534143500100000000000000070000002800000000920300914704000100000000000000000001050010000059193B14E312D1010000000000000000 "C:\Users\Ben\Desktop\medion\medion bios\2.09\afuwinx64.exe"=0x5341435001000000000000000700000028000000903407009B8E07000100000000000000000001067322000059193B14E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000D4370100000000000500000005000000 "C:\Users\Ben\Downloads\chpintel_inf9x.exe"=0x5341435001000000000000000700000028000000614E4600000000000100000000000000000000067102000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000086440100000000000200000002000000 "C:\Users\Ben\Desktop\medion\medion bios\01. Intel Chipset\9.4.0.1026\infinst_autol.exe"=0x5341435001000000000000000700000028000000F81C5E0054F25E000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000033E70000000000000200000002000000 "SIGN.MEDIA=E036341B setup.exe"=0x5341435001000000000000000700000028000000CA624700000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000059F71200000000000200000002000000 "C:\Games\Euro Fishing\WindowsNoEditor\FishingGame\Binaries\Win64\FishingGame-Win64-Shipping.exe"=0x534143500100000000000000070000002800000000DADC02AAB4D60201000000000000000000000A7320000059193B14E312D10100000000000000000500000010000000000000000000000000000000200000000200000028000000000000002000006000000000000000000000000000000000F4D04A00000000000400000004000000 "C:\Games\Euro Fishing\WindowsNoEditor\FishingGame.exe"=0x534143500100000000000000070000002800000000DA1100E603020001000000000000000000000A7320000059193B14E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000000D84200000000000300000003000000 "C:\Games\Euro Fishing\unins000.exe"=0x534143500100000000000000070000002800000071251800000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000084190000000000000100000001000000 "C:\Program Files (x86)\MEDION GoPal Assistant\Assistant_Starter.exe"=0x534143500100000000000000070000002800000000FA030000000000010000000000000000000306F102000019B4C529E312D10100000000000000000200000028000000000000000000000010100000000000000000000000000000E4810300000000000100000001000000 "C:\Program Files (x86)\MEDION GoPal Assistant\GoPal_Assistant.exe"=0x534143500100000000000000070000002800000000C0020000000000010000000000000000000306F102000019B4C529E312D10100000000000000000200000028000000000000000000000010100000000000000000000000000000F93C0000000000000400000004000000 "C:\Users\Ben\Downloads\MEDION_GoPal_Assistant_6.2.0.12196_full.exe"=0x5341435001000000000000000700000028000000A00159065C8959060100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000008000000000000000000000000000000000000000B5240200000000000200000002000000 "C:\Users\Ben\Downloads\Pro Cycling Manager 2015 [FitGirl Repack]\setup-multi10.exe"=0x53414350010000000000000007000000280000004EE26400000000000100000000000000000001060001000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000000B700100000000000100000001000000 "SIGN.MEDIA=AF27B8E0 autorun.exe"=0x534143500100000000000000070000002800000088922B0084752C000100000000000000000000067102000019B4C529E312D10100000000000000000200000028000000000000008000000000000000000000000000000000000000FFE30500000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Assassin's Creed II\Play_ASC2.exe"=0x534143500100000000000000070000002800000016270D00000000000100000000000000000001060021000019B4C529E312D101000000000000000002000000280000000000000080000040000000000000000000000000000000009E730900000000000100000001000000 "G:\autres\gta_san_andreas\setup.exe"=0x5341435001000000000000000700000028000000D0CF0100E3EE01000100000000000000000001057100000019B4C529E312D101000000000000000002000000280000000000000000080040000000000000000000000000000000004B900300000000000100000001000000 "C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe"=0x534143500100000000000000070000002800000000D0DB00000000000100000000000000000001057120000019B4C529E312D101000000C00000000002000000280000000000000000000050000000000000000000000000000000002D5E0000000000000100000001000000 "C:\Games\Activision\Call of Duty - World at War\CoDWaW.exe"=0x534143500100000000000000050000001000000000000000000000000000000000000000070000002800000000C053001FBF6E0001000000000000000000000671220000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000010000000000000001000000134B00000000000001000000010000000000000000000040000000000000000000000000000000005BEE0600000000000100000000000000010000000400000001000000 "C:\Users\Ben\Downloads\Star.Wars.Battlefront.II-GOG\setup_sw_battlefront2_2.0.0.5.exe"=0x534143500100000000000000070000002800000018A6D001ECE5D0010100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000E51A0B00000000000100000001000000 "C:\GOG Games\Star Wars - Battlefront 2\GameData\BattlefrontII.exe"=0x534143500100000000000000070000002800000000504600F76146000100000000000000000001057100000019B4C529E312D1010000000000000000050000001000000000000000000000000000000010000000020000002800000000000000100000600024000000000000000000000000000002620400000000000100000001000000 "SIGN.MEDIA=AE8C0204 setup.exe"=0x534143500100000000000000070000002800000098624700000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000A3441200000000000100000001000000 "E:\Games\Tom Clancys Rainbow Six Siege\RainbowSix.exe"=0x5341435001000000000000000700000028000000E8B245022018460201000000000000000000000A7322000059193B14E312D101000000000000000005000000100000000000000000000000000000002000000002000000500000000000000030000060000000000000000000000000000000006E20EF00000000000D0000000D000000000000002000006000000000010000000000000000000000AA307C00000000000800000000000000 "C:\Users\Ben\Downloads\UserBenchMark.exe"=0x5341435001000000000000000700000028000000A9FB5300000000000100000000000000000001060001000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000006DE40800000000000100000001000000 "C:\Users\Ben\Downloads\cpu-z_1-74-0_en_11090.exe"=0x5341435001000000000000000700000028000000301F1900241C1A000100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000A13B0000000000000100000001000000 "C:\Program Files\Internet Explorer\iexplore.exe"=0x5341435001000000000000000700000028000000C0720C009F7D0C0001000000010000000000000A0021000059193B14E312D1010000000000000000 "C:\Program Files\CPUID\CPU-Z\cpuz.exe"=0x5341435001000000000000000700000028000000B8BA3200C391330001000000000000000000000A0021000059193B14E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000F7DA1200000000000300000003000000 "C:\Users\Ben\Downloads\biosagentplus_1218.exe"=0x5341435001000000000000000700000028000000D8200A0016190B000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000907F0000000000000100000001000000 "C:\Users\Ben\Downloads\biosagentplus_1218 (1).exe"=0x5341435001000000000000000700000028000000D8200A0016190B000100000000000000000001060001000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000003A2D0000000000000100000001000000 "C:\Users\Ben\Downloads\UserBenchMark(1).exe"=0x5341435001000000000000000700000028000000A9FB5300000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000CD360700000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe"=0x5341435001000000000000000700000028000000B079090072140A000100000000000000000000067102000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000000F850D00000000000100000001000000 "C:\Program Files (x86)\Rockstar Games\EFLC\LaunchEFLCc.exe"=0x534143500100000000000000070000002800000000400100000000000100000000000000000000067102000019B4C529E312D10100000000000000000200000028000000000000008000000010000000000000000000000000000000810F0000000000000200000002000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe"=0x5341435001000000000000000700000028000000B0AD1C015A0D1D010100000000000000000001067122000033504C2B57DFD101000000000000000005000000100000000000000000000000000301050000000002000000280000000003010500000060101200000000000000000000000000001E6B0000000000000700000007000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Launcher.exe"=0x5341435001000000000000000700000028000000B06B06006C5807000100000000000000000001067122000019B4C529E312D1010000000000000000050000001000000000000000000000000000000080000000020000002800000000000000800000400002020000000000000000000000000053070000000000000100000001000000 "C:\Program Files (x86)\SIW\unins000.exe"=0x534143500100000000000000070000002800000045EA0A00000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000020000000000000000000000000000711C0000000000000100000001000000 "C:\GOG Games\Star Wars - Battlefront 2\unins000.exe"=0x534143500100000000000000070000002800000038031300363613000100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000000000004000020000000000000000000000000000291B0000000000000100000001000000 "C:\Program Files (x86)\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exe"=0x53414350010000000000000007000000280000000054A201000000000100000000000000000001066122000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000072090E00000000000100000001000000 "SIGN.MEDIA=341B487B setup.exe"=0x53414350010000000000000007000000280000004E624700000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000055B70B00000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe"=0x5341435001000000000000000700000028000000B073090054040A000100000000000000000000067122000019B4C529E312D101000000000000000002000000280000000000000080000000000000000000000000000000000000007E956F00000000000200000002000000 "C:\Users\Ben\Downloads\bio7728(2).exe"=0x53414350010000000000000007000000280000003E2F1800000000000100000000000000000000067102000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000342E0000000000000200000002000000 "C:\Users\Ben\Downloads\biosagentplus_1218 (3).exe"=0x5341435001000000000000000700000028000000D8200A0016190B000100000000000000000001060001000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000001D800000000000000100000001000000 "C:\Users\Ben\Downloads\MSKLC.exe"=0x5341435001000000000000000700000028000000A0B5A10095EAA1000100000000000000000001057100000019B4C529E312D101000000000000000002000000280000000000000080080040000000000000000000000000000000000C6E0000000000000200000002000000 "C:\Program Files (x86)\Microsoft Keyboard Layout Creator 1.4\MSKLC.exe"=0x534143500100000000000000070000002800000090850F003E3D1000010000000000000000000006F5200000D5B3B31A57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000057F80400000000000400000004000000 "C:\Users\Ben\Downloads\DriversCloudx64_8_0_3_1.exe"=0x5341435001000000000000000700000028000000F88856008ADB56000100000000000000000001067100000019B4C529E312D10100000000000000000200000028000000000000000008004000000000000000000000000000000000FB1A0000000000000200000002000000 "C:\Program Files\DriversCloud.com\MCDetection.exe"=0x534143500100000000000000050000001000000000000000000000000000000000000000070000002800000088BC21004B9A220001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000068B20000000000000A0000000A000000 "C:\Users\Ben\Downloads\VirtualGeoGP-Windows-installer.exe"=0x5341435001000000000000000700000028000000E8261203397C12030100000000000000000001060001000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000074CB0200000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver361.75\setup.exe"=0x534143500100000000000000070000002800000038720600CD8A060001000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000800000400000000000000000000000000000000058D60400000000000100000001000000 "C:\Program Files (x86)\CyberLink\PowerDVD Copy\PowerDVDCopy.exe"=0x5341435001000000000000000700000028000000285506007BED06000100000000000000000001067122000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000C14F0100000000000100000001000000 "C:\Program Files (x86)\CyberLink\Power2Go\IsoViewer.exe"=0x534143500100000000000000070000002800000028951B00FAE81B000100000000000000000001067122000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000001E2F0000000000000100000001000000 "C:\Users\Ben\Downloads\youtube_downloader_hd_setup-2.9.9.23.exe"=0x5341435001000000000000000700000028000000E90C9A00000000000100000000000000000001060001000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000D3131B00000000000300000003000000 "SIGN.MEDIA=21A70D27 setup.exe"=0x5341435001000000000000000700000028000000F5624700000000000100000000000000000001060001000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000005F791F00000000000100000001000000 "C:\Games\Homeworld Deserts of Kharak\Win32\DesertsOfKharak32.exe"=0x53414350010000000000000007000000280000007814FD00CC24FD0001000000000000000000000A0021000019B4C529E312D10100000000000000000500000010000000000000000000000000000000200000000200000028000000000000002000006000000000000000000000000000000000FD0A0000000000000300000003000000 "C:\Games\Homeworld Deserts of Kharak\Win64\DesertsOfKharak64.exe"=0x534143500100000000000000050000001000000000000000000000000000000000000000070000002800000000003D01655D2F0101000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000500000000000000000000000000000000000000000000000000000003BC403000000000003000000010000000000000000000040000000000000000000000000000000005CC25100000000000300000000000000 "C:\Games\LIGHTNING RETURNS FINAL FANTASY XIII\LRFF13.exe"=0x5341435001000000000000000700000028000000008C060233EE060201000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000200000600000000000000000000000000000000016C60F00000000000500000005000000 "C:\Users\Ben\Downloads\JavaSetup8u73.exe"=0x534143500100000000000000070000002800000060380B00B7750B0001000000000000000000000A7122000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000007620300000000000200000002000000 "C:\Program Files (x86)\WRC 5 FIA World Rally Championship\WRC5.exe"=0x534143500100000000000000070000002800000000844100F84C420001000000000000000000000A71220000DB80FDAC2839D3010000000000000000020000007800000000000000100000200000000000000000000000000000000001E5000000000000010000000100000000000000100000600000000000000000000000000000000016E31200000000000100000000000000000000000000004000000000010000000000000000000000D6190900000000000100000000000000 "C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe"=0x5341435001000000000000000700000028000000B40104002E86B8010100000000000000000001060001000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000009C220000000000000100000001000000 "C:\Users\Ben\Downloads\vlc-2.2.2-win64.exe"=0x5341435001000000000000000700000028000000C59FDE014ACB01000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000086B40100000000000100000001000000 "C:\Program Files\Emsisoft Anti-Malware\a2start.exe"=0x5341435001000000000000000700000028000000C83CC900380BCA0001000000000000000000000A0021000059193B14E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000011460000000000000100000001000000 "C:\Users\Ben\Downloads\cacaoweb.exe"=0x5341435001000000000000000700000028000000307508008B65090001000000000000000000000A7120000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000B49D3200000000000200000002000000 "C:\Program Files (x86)\Pro Evolution Soccer 2016\PES2016.exe"=0x53414350010000000000000005000000100000000000000000000000000000000000000007000000280000007013590291F9590201000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000500000000000000000000040000000000100000000000000000000009F045D00000000001B000000010000000000000000000000000000000000000000000000000000006938E601000000000500000000000000 "C:\Users\Ben\Downloads\Extraction.2015.1080p.FR.EN.x264.AC3-mHDgz-www.Zone-Telechargement.com.part4.rar.exe"=0x5341435001000000000000000700000028000000A83601002B8B01000100000000000000000003067100000019B4C529E312D101000000000000000005000000100000000000000000000000000000000008000002000000280000000000000000080000000000000000000000000000000000003AB13900000000000100000001000000 "C:\Program Files (x86)\DAEMON Tools Lite\uninst.exe"=0x534143500100000000000000070000002800000058D3230089D024000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000C05D0000000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver361.91\setup.exe"=0x5341435001000000000000000700000028000000C06B06007750070001000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000800000400000000000000000000000000000000012DE0200000000000100000001000000 "C:\Users\Ben\Downloads\daemon-tools-lite_10-2-0-0112_fr_10729.exe"=0x5341435001000000000000000700000028000000E0161A009A3F1A000100000000000000000001067100000019B4C529E312D1010000000000000000020000002800000000000000000800400000000000000000000000000000000070865A00000000000100000001000000 "C:\Program Files\DAEMON Tools Lite\DTHelper.exe"=0x5341435001000000000000000700000028000000781B04002F16050001000000000000000000000A7322000059193B14E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000D7EB0000000000000200000002000000 "C:\Program Files\DAEMON Tools Lite\DTAgent.exe"=0x534143500100000000000000070000002800000078BF3F0046FB3F0001000000000000000000000A7322000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000AED22C01000000001700000017000000 "C:\Program Files\DAEMON Tools Lite\DTLauncher.exe"=0x534143500100000000000000070000002800000078852E004D482F0001000000000000000000000A7322000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000071EE4D00000000000B0000000B000000 "C:\Program Files (x86)\Middle Earth Shadow of Mordor\x64\ShadowOfMordor.exe"=0x5341435001000000000000000700000028000000003AA501E588A70101000000000000000000030673020000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000010000000000000000000000675E0100000000000100000001000000000000000000004000000000000000000000000000000000FDC12D00000000000100000000000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_game.exe"=0x534143500100000000000000070000002800000010F0E902ABB9EA020100000000000000000002067120000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000DD17000000000000010000000100000000000000000000000000000000000000000000000000000004070000000000000100000000000000 "SIGN.MEDIA=18ADE037 Crack\blacklist_patch_v1_01.exe"=0x5341435001000000000000000700000028000000183E796D7B297A6D0100000000000000000002060021000019B4C529E312D1010000008000000000020000002800000000000000000000400000000000000000000000000000000071810E00000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe"=0x53414350010000000000000007000000280000001044010082F001000100000000000000000002067122000019B4C529E312D1010000000000000000020000002800000000000000800000400000000000000000000000000000000024290300000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_DX11_game.exe"=0x53414350010000000000000007000000280000001046EF021325F0020100000000000000000002067120000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000922E0000000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\blacklist_patch_v1_01.exe"=0x5341435001000000000000000700000028000000183E796D7B297A6D0100000000000000000002060021000019B4C529E312D10100000080000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000EF6A0000000000000100000001000000 "SIGN.MEDIA=18ADE037 Crack\Blacklist_game.exe"=0x534143500100000000000000070000002800000010F0E902ABB9EA020100000000000000000002067120000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000003F0D0000000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe"=0x534143500100000000000000070000002800000010F0E902ABB9EA0201000000000000000000020671200000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000010000000000000000000000386C9400000000000700000001000000000000000000004000000000000000000000000000000000EC4DC000000000001700000000000000 "C:\Program Files (x86)\Common Files\Metaboli\Core\yummy.installer.exe"=0x534143500100000000000000070000002800000078E50C0066090D00010000000000000000000206F1220000DB80FDAC2839D30100000000000000000200000028000000000000060000006000100000000000000000000000000000BF8E0100000000000300000003000000 "C:\Program Files (x86)\Total War ROME II\unins000.exe"=0x5341435001000000000000000700000028000000A1700F00000000000100000000000000000002060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000027450000000000000100000001000000 "C:\Program Files (x86)\AviSynth 2.5\Uninstall.exe"=0x5341435001000000000000000700000028000000708A0000000000000100000000000000000000067100000019B4C529E312D101000000000000000002000000280000000000000000080040000000000000000000000000000000008D630000000000000100000001000000 "C:\Program Files (x86)\AutoGK\uninst.exe"=0x534143500100000000000000070000002800000008E50000000000000100000000000000000000067102000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000006A180000000000000100000001000000 "C:\Users\Ben\Downloads\HPSupportSolutionsFramework-12.0.30.473(3).exe"=0x5341435001000000000000000700000028000000786A3900DD513A000100000000000000000000067102000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000BF3E0000000000000100000001000000 "C:\Users\Ben\Desktop\LOGICIELS\PirateBrowser 0.6b\Start PirateBrowser.exe"=0x53414350010000000000000007000000280000000E8000009DD100000100000000000000000002067120000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000C7B70000000000000100000001000000 "C:\Users\Ben\Desktop\LOGICIELS\Stellar.Phoenix.Windows.Data.Recovery.v6.0.Technical.Edition-NGEN\StellarPhoenixWindowsDataRecovery-Technical.exe"=0x534143500100000000000000070000002800000058BE6900CEF369000100000000000000000002060001000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000070870000000000000100000001000000 "C:\Users\Ben\Desktop\LOGICIELS\WindowsActivationUpdate.exe"=0x5341435001000000000000000700000028000000A86D0200B9DB02000100000000000000000001067102000019B4C529E312D1010000008000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000025480000000000000200000002000000 "C:\Users\Ben\Downloads\Windows Loader v2.1.7-Daz Final\Windows Loader v2.1.7-Daz Final.exe"=0x5341435001000000000000000700000028000000964B3A00000000000100000000000000000000067102000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000100000000000000000000000000000331C0000000000000100000001000000 "SIGN.MEDIA=2E5D9662 setup.exe"=0x5341435001000000000000000700000028000000152C45000000000001000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000085380D00000000000100000001000000 "C:\Program Files (x86)\Street Fighter V\StreetFighterV.exe"=0x5341435001000000000000000500000010000000000000000000000000000000000000000700000028000000006A0200C29D010001000000000000000000000A73200000DB80FDAC2839D30100000000000000000200000050000000000000000000000010000000000000000000000000000000660900000000000002000000020000000000000000000040000000000100000000000000000000003FB91A00000000000100000000000000 "SIGN.MEDIA=1EA47F09 setup.exe"=0x53414350010000000000000007000000280000000D603400000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000085F80E00000000000100000001000000 "C:\Users\Ben\Downloads\Way.of.the.Samurai.4.Update.v1.01-CODEX\Update\setup.exe"=0x534143500100000000000000070000002800000056C63800000000000100000000000000000001060001000019B4C529E312D10100000080000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000FE2B0400000000000100000001000000 "E:\Games\Way of the Samurai 4\WayOfTheSamurai4.exe"=0x534143500100000000000000070000002800000000F06800C684690001000000000000000000000A6122000019B4C529E312D101000000000000000002000000280000000000000020000060000000000000000000000000000000005CC61400000000000100000001000000 "E:\Games\Way of the Samurai 4\unins000.exe"=0x534143500100000000000000070000002800000071251800000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000964A0000000000000100000001000000 "SIGN.MEDIA=3E7C5D0C autorun.exe"=0x534143500100000000000000070000002800000088822E00D1982E000100000000000000000000067102000019B4C529E312D1010000000000000000020000002800000000000000800000000000000000000000000000000000000061810400000000000400000004000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver364.47\setup.exe"=0x534143500100000000000000070000002800000038720600CC1B070001000000000000000000000A0021000019B4C529E312D1010000000000000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver364.47d09be3ee-d762-4b30-9355-a502e3158bcd\setup.exe"=0x534143500100000000000000070000002800000038720600CC1B070001000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000080000040000000000000000000000000000000002BC40000000000000100000001000000 "SIGN.MEDIA=3E7C5D0C setup.exe"=0x534143500100000000000000070000002800000088C2050064EF05000100000000000000000000067102000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000013615400000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver364.472288042f-6387-474c-b801-74ff29dbe8e4\setup.exe"=0x534143500100000000000000070000002800000038720600CC1B070001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000008000004000000000000000000000000000000000EE8C0000000000000100000001000000 "C:\Program Files (x86)\Sony\Vegas Movie Studio HD Platinum 11.0\VegasMovieStudioPE110.exe"=0x534143500100000000000000070000002800000058B103014A1004010100000000000000000001060021000033504C2B57DFD10100000000000000000200000078000000000001060000002000100000000000000000000000000000BB7000000000000003000000030000000000000000000040000000000000000000000000000000003E2F00000000000003000000000000000000000000000000000000000000000000000000000000003E360100000000000A00000000000000 "C:\Program Files (x86)\Windows Media Player\wmplayer.exe"=0x5341435001000000000000000700000028000000008C0200DEDE020001000000010000000000000A7122000019B4C529E312D1010000000000000000 "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe"=0x534143500100000000000000070000002800000070B30100A75F02000100000000000000000001067122000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000009E9C0000000000000400000004000000 "C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe"=0x5341435001000000000000000700000028000000A0C3FF003792000101000000000000000000010671200000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000010000000000000001000000E127020000000000020000000200000000000000000000400000000000000000000000000000000050532100000000000100000000000000010000000400000001000000 "C:\Users\Ben\AppData\Local\Temp\NVIDIA\DisplayDriver\GeForceGameReadyDriver364.51\setup.exe"=0x534143500100000000000000070000002800000038720600ADD7060001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000008000004000000000000000000000000000000000684B0500000000000100000001000000 "C:\Program Files (x86)\MXGP\MXGP.exe"=0x53414350010000000000000007000000280000000020D1006649D1000100000000000000000003067122000019B4C529E312D101000000000000000002000000500000000000000000000040000000000000000000000000000000009C2F0000000000000300000003000000000000000000000000020200000000000000000000000000510A0000000000000100000000000000 "C:\Program Files (x86)\Batman Arkham Origins Cold Cold Heart\SinglePlayer\Binaries\Win32\BatmanOrigins.exe"=0x534143500100000000000000070000002800000000AA6801EBBA71010100000000000000000002067102000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000DE1C00000000000003000000030000000000000000000000101000000000000000000000000000005C510000000000000200000000000000 "C:\Program Files (x86)\Sniper Elite 3\bin\SniperElite3.exe"=0x5341435001000000000000000700000028000000008C9F000000000001000000000000000000030671020000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000E5010000000000000600000006000000 "C:\Program Files (x86)\Street Fighter V\StreetFighterV\Binaries\Win64\StreetFighterV.exe"=0x534143500100000000000000070000002800000000F0A6024F96320301000000000000000000000A73200000DB80FDAC2839D3010000000000000000020000005000000000000000100000201000000001000000000000000000000012271000000000000500000002000000000000001000006000000000000000000000000000000000BFE21700000000000100000000000000 "C:\Program Files (x86)\Batman Arkham Origins Cold Cold Heart\unins000.exe"=0x534143500100000000000000070000002800000071211700000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000182B0000000000000100000001000000 "C:\Games\LIGHTNING RETURNS FINAL FANTASY XIII\unins000.exe"=0x534143500100000000000000070000002800000071251800000000000100000000000000000001060001000019B4C529E312D10100000000000000000200000028000000000000000000004000020000000000000000000000000000FB120000000000000100000001000000 "C:\Users\Ben\Downloads\ccsetup516.exe"=0x5341435001000000000000000700000028000000C0CE6800490F69000100000000000000000001060001000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000008C0C1500000000000100000001000000 "C:\Program Files (x86)\MEDION GoPal Assistant\Assistant_Uninstaller.exe"=0x53414350010000000000000007000000280000000010020000000000010000000000000000000106F102000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000EFF40000000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\jre-8u77-windows-au.exe"=0x5341435001000000000000000700000028000000403C0B00344E0B0001000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000009D1E0800000000000100000001000000 "C:\Program Files\AVAST Software\Avast\BrowserCleanup.exe"=0x5341435001000000000000000700000028000000705C1700EA3818000100000000000000000003067102000019B4C529E312D101000000000000000002000000280000000000000600000020000000000000000000000000000000007CC70200000000000100000001000000 "SIGN.MEDIA=E60C5 OriginInstaller.exe"=0x534143500100000000000000070000002800000000DC080000000000010000000000000000000106F122000019B4C529E312D101000000000000000002000000500000000000000000000000000000000000000000000000000000004824190000000000010000000100000000000000800000000000020000000000000000000000000031154B00000000000100000000000000 "C:\Users\Ben\AppData\Local\Temp\jre-8u91-windows-au.exe"=0x5341435001000000000000000700000028000000404A0B0014980B0001000000000000000000000A7122000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000046770600000000000100000001000000 "SIGN.MEDIA=817ED016 Game\GameFiles.part01.exe"=0x5341435001000000000000000700000028000000F3E6CE1D000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000800000000000000000000000000000000000000024FB1800000000000400000004000000 "C:\Program Files (x86)\Crysis 3\Bin32\Crysis3.exe"=0x53414350010000000000000007000000280000000076F8010000000001000000000000000000000A6122000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000001C3F000000000000020000000100000000000000000000400000000000000000000000000000000002460000000000000300000000000000 "C:\Games\Crysis 3\Bin32\Crysis3.exe"=0x534143500100000000000000070000002800000008CDF801D34CF9010100000000000000000002066122000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000911C0000000000000100000001000000 "C:\Users\Ben\Downloads\GRID.Autosport.Update.v1.0.100.5260-RELOADED\Update\setup.exe"=0x5341435001000000000000000700000028000000751D0A00000000000100000000000000000003060001000019B4C529E312D10100000080000000000200000028000000000000000000000000000000000000000000000000000000A10E0100000000000100000001000000 "C:\Program Files (x86)\GRID Autosport\GRIDAutosport.exe"=0x534143500100000000000000070000002800000000A80A01000000000100000000000000000003067102000019B4C529E312D101000000000000000005000000100000000000000000000000000002060000000002000000280000000000020600000060000000000000000000000000000000000C650800000000000300000003000000 "C:\Program Files (x86)\GRID Autosport\GRIDAutosport_avx.exe"=0x534143500100000000000000070000002800000000C00B01000000000100000000000000000003067102000019B4C529E312D101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000003E720E00000000000100000001000000 "C:\Program Files (x86)\THQ\MX vs ATV Reflex\MXReflex.exe"=0x5341435001000000000000000700000028000000004C6500000000000100000000000000000001067122000019B4C529E312D101000000000000000002000000280000000000000000000040101000000000000000000000000000000FC80400000000000200000002000000 "C:\Users\Ben\Desktop\Mes jeux\Crysis3.exe"=0x53414350010000000000000007000000280000000076F8010000000001000000000000000000000A6122000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000960E0000000000000100000001000000 "C:\Program Files (x86)\MXGP\unins000.exe"=0x5341435001000000000000000700000028000000A1A60D00000000000100000000000000000002060001000019B4C529E312D101000000000000000002000000280000000000000000000000000200000000000000000000000000000E1D0000000000000100000001000000 "C:\Users\Ben\Downloads\SteamSetup.exe"=0x5341435001000000000000000700000028000000681115002116150001000000000000000000000A0021000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000693A0000000000000100000001000000 "C:\Program Files (x86)\DEAD OR ALIVE 5 Last Round\game.exe"=0x534143500100000000000000070000002800000030DFE400CAFAE40001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000000000000000000000000000A3690E000000000002000000020000000000000000000040000000000000000000000000000000008B510D00000000000200000000000000 "C:\Program Files (x86)\Gas Guzzlers Extreme\Bin32\GasGuzzlers.exe"=0x5341435001000000000000000700000028000000001C07000000000001000000000000000000020671020000DB80FDAC2839D30100000000000000000200000050000000000000000000004000000000000000000000000000000000387720000000000004000000010000000000000000000000000000000000000000000000000000009E6A3200000000000600000000000000 "C:\Program Files (x86)\Gas Guzzlers Extreme\Bin32\GGDedicatedServerLauncher.exe"=0x534143500100000000000000070000002800000000CE0700852F080001000000000000000000020671020000DB80FDAC2839D30100000000000000000200000050000000000000008000000010000000000000000000000000000000C25A0000000000000100000001000000000000008000004000000000000000000000000000000000D72D0000000000000100000000000000 "C:\Program Files (x86)\Gas Guzzlers Extreme\Bin32\GGDedicatedServer.exe"=0x534143500100000000000000070000002800000000340300984A03000100000000000000000002067102000019B4C529E312D1010000000000000000020000002800000000000000000000400000000000000000000000000000000082070000000000000100000001000000 "C:\Users\Ben\Desktop\Mes jeux\Assassin Creed\GasGuzzlers.exe"=0x5341435001000000000000000700000028000000001C0700000000000100000000000000000002067102000019B4C529E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000FC170000000000000100000001000000 "SIGN.MEDIA=CC55DAE2 setup.exe"=0x534143500100000000000000070000002800000000566100590A62000100000000000000000003067100000019B4C529E312D10100000000000000000200000028000000000000000008004000000000000000000000000000000000A7C0DB00000000000200000002000000 "H:\TOSHIBA\Launcher\start.exe"=0x53414350010000000000000007000000280000003815AA00F159AA000100000000000000000001060021000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000007B100000000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe"=0x5341435001000000000000000700000028000000C0411000C50711000100000000000000000003060001000019B4C529E312D10100000000000000000200000028000000000000008000000000000000000000000000000000000000CD904700000000000100000001000000 "SIGN.MEDIA=B4040F7D autorun.exe"=0x534143500100000000000000070000002800000088C22E00DFC02F000100000000000000000000067122000019B4C529E312D1010000000000000000020000002800000000000000800000000000000000000000000000000000000063612C00000000000300000003000000 "C:\Users\Ben\Downloads\kon-bootv2.5.exe"=0x5341435001000000000000000700000028000000AA211100000000000100000000000000000001060001000019B4C529E312D1010000000000000000020000002800000000000000800000400000000000000000000000000000000087640000000000000200000002000000 "C:\Users\Ben\Downloads\kon-bootV2.5\KonBootInstaller.exe"=0x5341435001000000000000000700000028000000000A03000000000001000000000000000000000A7122000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000369E0300000000000400000004000000 "C:\Users\Jeux\Documents\kon-bootV2.5\KonBootInstaller.exe"=0x5341435001000000000000000700000028000000000A03000000000001000000000000000000000A7122000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000005F40000000000000100000001000000 "SIGN.MEDIA=1BB468C konexec32.exe"=0x5341435001000000000000000700000028000000008402005902030001000000000000000000000A7122000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000115B0000000000000100000001000000 "C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe"=0x534143500100000000000000070000002800000000B041008449420001000000010000000000000A7122000019B4C529E312D1010000000000000000 "C:\Program Files (x86)\Focus Home Interactive\Pro Cycling Manager 2016\Database\PCM.exe"=0x5341435001000000000000000700000028000000309DAD00643CAE0001000000000000000000000A7122000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000004D080000000000000100000001000000 "C:\Program Files (x86)\Focus Home Interactive\Pro Cycling Manager 2016\language.changer.exe"=0x534143500100000000000000070000002800000000C205000000000001000000000000000000000AF122000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000254F0100000000000C000000050000000000000000000040000000000000000000000000000000008E050000000000000100000000000000 "C:\Program Files (x86)\Focus Home Interactive\Pro Cycling Manager 2016\PCM.exe"=0x534143500100000000000000050000001000000000000000000000000000000000000000070000002800000070A1AD00C286AE0001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000DB2DE6010000000005000000010000000000000000000040000000000000000000000000000000006B3CD600000000000B00000000000000 "C:\Program Files (x86)\Konami Digital Entertainment\UEFA Euro 2016 France\PES2016.exe"=0x534143500100000000000000070000002800000000408D021264580201000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000050000000000000000000004000000000010000000000000000000000B09C3E00000000000600000001000000000000000000000000000000000000000000000000000000E4EE2100000000000200000000000000 "C:\Users\Ben\AppData\Local\Temp\jre-8u101-windows-au.exe"=0x534143500100000000000000070000002800000040500B0095370C0001000000000000000000000A7122000019B4C529E312D10100000000000000000200000028000000000000000000004000000000000000000000000000000000ADCC0200000000000100000001000000 "C:\Program Files\AVAST Software\SZBrowser\launcher.exe"=0x5341435001000000000000000700000028000000F8390B00EB1A0C0001000000000000000000000A0021000019B4C529E312D1010000000000000000 "C:\Program Files (x86)\Company of Heroes 2 Master Collection\RelicCoH2.exe"=0x53414350010000000000000007000000280000000818890289F5890201000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000020000060000000000000000000000000000000005DF46400000000000300000003000000 "C:\Program Files (x86)\Company of Heroes 2 Master Collection\language.changer.exe"=0x534143500100000000000000070000002800000000F605000000000001000000000000000000000AF122000019B4C529E312D1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000099036600000000000100000001000000 "C:\Program Files (x86)\Bin32\Crysis3.exe"=0x534143500100000000000000070000002800000008CDF801D34CF9010100000000000000000002066122000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000391B0000000000000100000001000000 "C:\Users\Ben\Downloads\UplayInstaller(1).exe"=0x5341435001000000000000000700000028000000D0F4B1036411B20301000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000001F1E0500000000000200000002000000 "C:\Users\Ben\Desktop\Mes jeux\RelicCoH2.exe"=0x53414350010000000000000007000000280000000818890289F5890201000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000083260000000000000100000001000000 "C:\Program Files (x86)\Company of Heroes 2 Master Collection\$RTUMXSN.exe"=0x53414350010000000000000007000000280000000818890289F5890201000000000000000000000A0021000019B4C529E312D101000000000000000002000000500000000000000000000040000000000000000000000000000000009B8F56000000000001000000010000000000000000000000000000000000000000000000000000007AFE0200000000000100000000000000 "C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\setup.exe"=0x5341435001000000000000000700000028000000C06B0600CD75060001000000000000000000000A0021000019B4C529E312D101000000000000000002000000280000000000000080000040000000000000000000000000000000009F23E100000000000100000001000000 "C:\Users\Ben\Downloads\GhostReconPhantoms_Setup(EU).exe"=0x5341435001000000000000000700000028000000281E45008C3F45000100000000000000000001060001000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000F4B40100000000000200000002000000 "C:\Users\Ben\Downloads\GhostReconPhantoms_Setup(EU) (1).exe"=0x5341435001000000000000000700000028000000281E45008C3F45000100000000000000000001060001000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000DC330100000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\OFFICE11\WORDVIEW.EXE"=0x5341435001000000000000000700000028000000A07A86008365870001000000000000000000000A7120000019B4C529E312D101000000000000000002000000280000000000000000000000000000000000000000000000000000006B0A0100000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C0BA02005C1F030001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000C8F0890013408A0001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C8BA020001D3020001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\PDFCreator\PDFCreator.exe"=0x534143500100000000000000070000002800000000403000252331000100000000000000000001067100000033504C2B57DFD1010000000000000000020000002800000000000000000000000010000000000000000000000000000072210000000000000100000001000000 "C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe"=0x5341435001000000000000000700000028000000C02C1E004D081F0001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000A7C23106000000000500000005000000 "SIGN.MEDIA=AB8E6615 setup.exe"=0x534143500100000000000000070000002800000072980F00000000000100000000000000000002060001000033504C2B57DFD1010000000000000000020000002800000000000000800000000000000000000000000000000000000032582100000000000100000001000000 "C:\Program Files (x86)\Batman Arkham Knight\Binaries\Win64\BatmanAK.exe"=0x53414350010000000000000007000000280000000074D3058527DB0501000000000000000000000A73220000D5B3B31A57DFD101000000000000000002000000500000000000000000000000000000000000000000000000000000009B6B00000000000002000000010000000000000000000040000000000000000000000000000000002BEE3E00000000000300000000000000 "C:\Users\Ben\AppData\Local\Temp\jre-8u111-windows-au.exe"=0x534143500100000000000000070000002800000040420B0047080C0001000000000000000000000A7122000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000D0DD0600000000000100000001000000 "C:\Users\Ben\Desktop\Nouveau dossier (2)\BatArkhmKni_pfr\Batman Arkham Knight-Patch FR.exe"=0x53414350010000000000000007000000280000000000401FBDFC040001000000000000000000000A6122000033504C2B57DFD1010000008000000000020000002800000000000000000000400000000000000000000000000000000014710100000000000100000001000000 "C:\Program Files (x86)\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000C8C507006234080001000000000000000000000A0021000033504C2B57DFD1010000000100000000 "C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe"=0x534143500100000000000000070000002800000048B278001405790001000000000000000000000671020000DB80FDAC2839D30100000000000000000200000050000000000000000000000000000000010000000000000001000000913D01000000000002000000010000000000000000000040000000000000000000000000000000001D688100000000000200000000000000010000000400000001000000 "C:\Program Files (x86)\Origin Games\FIFA 17 DEMO\fifa17_demo.exe"=0x5341435001000000000000000700000028000000B00D1D0809BE1D0801000000000000000000000A73220000E78E163C2AA0D2010000000000000000020000005000000000000000000000400000000000000000000000000000000089A10A09000000000700000002000000000000000000000000000000000000000000000000000000168E6300000000000800000000000000 "C:\Program Files (x86)\Ubisoft\Assassin's Creed Liberation HD\unins000.exe"=0x53414350010000000000000007000000280000005ABF0A00000000000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400002000000000000000000000000000038160000000000000100000001000000 "C:\Program Files (x86)\Assassin's Creed Unity\unins000.exe"=0x5341435001000000000000000700000028000000694A1200000000000100000000000000000003060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400002000000000000000000000000000072140000000000000100000001000000 "C:\Program Files (x86)\Call of Duty Advanced Warfare\unins000.exe"=0x534143500100000000000000070000002800000071211700000000000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000993F0000000000000100000001000000 "C:\Program Files (x86)\Call of Duty Advanced Warfare\unins001.exe"=0x5341435001000000000000000700000028000000694A1200000000000100000000000000000003060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000007D220000000000000100000001000000 "C:\Program Files (x86)\Farming Simulator 15\unins000.exe"=0x534143500100000000000000070000002800000071211700000000000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000014990000000000000100000001000000 "C:\Program Files (x86)\GRID Autosport\unins000.exe"=0x5341435001000000000000000700000028000000C94A1200000000000100000000000000000003060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000BB140100000000000100000001000000 "C:\Users\Ben\AppData\Local\Apps\2.0\MED0DMDJ.AAJ\1Y066TEM.KPP\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\Uninstaller.exe"=0x534143500100000000000000070000002800000028E21200F5C813000300000000000000000001068001000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000008000000000000000800000000000D2740000000000000100000001000000010000000400000001000000 "C:\Program Files (x86)\Yahoo!\yset\{2A77530F-5F9F-6F42-A59D-214421826E83}\unset.exe"=0x5341435001000000000000000700000028000000A8160100E71302000300000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000022170000000000000100000001000000 "C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe"=0x534143500100000000000000070000002800000018C34A02E27C4B0201000000000000000000000A73220000D5B3B31A57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000097F72900000000000700000007000000 "C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe"=0x534143500100000000000000070000002800000008BDA301C811A40101000000000000000000020671020000DB80FDAC2839D301000000000000000002000000A0000000000000001000002000000000000000000000000000000000D87D0700000000000100000001000000000000001000006000000000000000000000000000000000CE56620000000000010000000000000000000000000000000000000000000000000000000000000019C67100000000000200000000000000000000000000004000000000000000000000000000000000AD58F502000000000400000000000000 "C:\Program Files (x86)\NVIDIA Corporation\System Update\SysTray.exe"=0x534143500100000000000000070000002800000068BE0000C761010001000000000000000000000673020000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000E2E80800000000000200000002000000 "C:\Users\Ben\Downloads\GeForce_Experience_v3.0.7.34.exe"=0x534143500100000000000000070000002800000028573C041CD73C040100000000000000000002060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000092150200000000000100000001000000 "C:\Program Files (x86)\Common Files\EAInstaller\Crysis 3\Cleanup.exe"=0x534143500100000000000000070000002800000088C90C0048E30C000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000003580000000000000100000001000000 "C:\Program Files\Emsisoft Anti-Malware\unins000.exe"=0x5341435001000000000000000700000028000000603A12004128130001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000057DB0100000000000100000001000000 "C:\Users\Ben\Downloads\375.63-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000907E5A12790D5B120100000000000000000002060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000007A551C00000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\MP3_Launcher_1_36_0_0.exe"=0x5341435001000000000000000700000028000000F06711009D8B11000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000800000400000000000000000000000000000000099CA0C00000000000100000001000000 "C:\Users\Ben\Downloads\Firefox Setup 49.0.2.exe"=0x534143500100000000000000070000002800000038A4BC02602ABD0201000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000001C033500000000000100000001000000 "C:\Program Files (x86)\Batman Arkham Knight\Uninstall.exe"=0x534143500100000000000000070000002800000075B90100185F020001000000000000000000000A6122000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000002F8A0000000000000100000001000000 "C:\Program Files (x86)\Batman Arkham Knight\unins000.exe"=0x5341435001000000000000000700000028000000C9341200000000000100000000000000000002060001000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000BF720000000000000100000001000000 "C:\Users\Ben\AppData\Roaming\Dragon Age Inquisition\Uninstall\unins000.exe"=0x5341435001000000000000000700000028000000CA1E0E00000000000100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000004A760000000000000100000001000000 "C:\Program Files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe"=0x534143500100000000000000070000002800000021680500B1311C000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000095230000000000000100000001000000 "C:\Users\Ben\Downloads\2016_FFD_4.exe"=0x5341435001000000000000000700000028000000205D1E014A981E0101000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000003DD50100000000000100000001000000 "C:\Users\Ben\Downloads\XTU-Setup-exe.exe"=0x534143500100000000000000070000002800000058E5A3022AF6A3020100000000000000000001060001000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000004CA70000000000000100000001000000 "C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Client\XtuUiLauncher.exe"=0x534143500100000000000000070000002800000038750100E33002000100000000000000000001068001000033504C2B57DFD1010000000000000000020000002800000000000000800000000400000000000000000000000000000041500700000000000100000001000000 "C:\Program Files (x86)\Pro Evolution Soccer 2016\Settings.exe"=0x5341435001000000000000000700000028000000B07711007CEB110001000000000000000000000AF122000033504C2B57DFD101000000000000000002000000500000000000000000000000000000000000000000000000000000001CD100000000000009000000030000000000000000000040000000000000000000000000000000002F000000000000000100000000000000 "C:\Users\Ben\Downloads\UplayInstaller.exe"=0x5341435001000000000000000700000028000000E89DC50394EAC50301000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000CE270600000000000100000001000000 "C:\Program Files (x86)\Tom Clancys Rainbow Six Siege\RainbowSix.exe"=0x5341435001000000000000000700000028000000E8B245022018460201000000000000000000000A73220000D5B3B31A57DFD101000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000004E200900000000000100000001000000 "C:\Program Files\AVAST Software\Avast\VisthAux.exe"=0x534143500100000000000000070000002800000010F5040074CE050001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000B0070000000000000100000001000000 "C:\Users\Ben\Downloads\HPPSdr.exe"=0x53414350010000000000000007000000280000008083A400D4A0A4000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000071090100000000000100000001000000 "C:\Program Files (x86)\HP\Diagnostics\PSDR\HPPSDr.exe"=0x53414350010000000000000007000000280000008083A400D4A0A4000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000025BC1F00000000000100000001000000 "C:\Program Files (x86)\Sony\PlayMemories Home\PMB3DPlayer.exe"=0x534143500100000000000000070000002800000060D20900577A0A000100000000000000000001067102000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000BA150000000000000200000002000000 "C:\Program Files (x86)\Sony\PlayMemories Home\PMBBrowser.exe"=0x534143500100000000000000070000002800000060303401202B35010100000000000000000001067102000033504C2B57DFD101000000000000000002000000500000000000000000000000100000000000000000000000000000005E611300000000000300000001000000000000000000004000000000000000000000000000000000AE600000000000000100000000000000 "C:\Users\Ben\Desktop\Bureau\Videos\Camescope\moviestudiope11.0.295.dvda.exe"=0x5341435001000000000000000700000028000000F0717F1393997F130100000000000000000001060001000033504C2B57DFD10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000200000000000000000000000000D0430000000000000100000001000000 "C:\Program Files (x86)\Sony\Vegas Movie Studio HD Platinum 11.0\vidcap60.exe"=0x5341435001000000000000000700000028000000583D41009BB741000100000000000000000000067100000033504C2B57DFD10100000000000000000200000028000000000000000000004000100200000000000000000000000000ED170000000000000100000001000000 "C:\Program Files (x86)\Sony\DVD Architect Studio 5.0\dvdarchst50.exe"=0x5341435001000000000000000700000028000000588FBA008975BB000100000000000000000001067120000033504C2B57DFD10100000000000000000200000028000000000000000000000000100000000000000000000000000000290E0000000000000100000001000000 "C:\Users\Ben\Downloads\190x6fb_00_scs_eng.exe"=0x5341435001000000000000000700000028000000B7F13100000000000100000000000000000001057100000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000003C773300000000000100000001000000 "SIGN.MEDIA=F1E1B64B Setup.exe"=0x534143500100000000000000070000002800000000B71A0057EE1A000100000000000000000001060001000033504C2B57DFD10100000000000000000200000028000000000000008000000000000000000000000000000000000000CE18B700000000000300000003000000 "C:\Program Files (x86)\Steam\bin\steamservice.exe"=0x5341435001000000000000000700000028000000205716001292160001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000004000000000000000000000000000000000766E0400000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\bb1f596a67afbe9225dee8c86302692c\GeForce_Experience_Update_v3.3.0.95.exe"=0x534143500100000000000000070000002800000088C6AF04F07CB0040100000000000000000002060001000033504C2B57DFD10100000080000000000200000028000000000000000000004000000000000000000000000000000000FBE00300000000000200000002000000 "C:\Users\Ben\AppData\Local\Temp\6df5b790-a325-48f8-882d-f51332d1dc56\setup.exe"=0x5341435001000000000000000700000028000000387806001026070001000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000008000004000000000000000000000000000000000DBC60D00000000000100000001000000 "C:\Users\Ben\Downloads\LibreOffice_5.3.0_Win_x86_helppack_fr.msi"=0x534143500100000000000000070000002800000000FE00009EC4010001000000000000000000010500100000D5B3B31A57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000058080100000000000200000002000000 "C:\Users\Ben\Downloads\projectlibre-1.6.msi"=0x534143500100000000000000070000002800000000FE00009EC4010001000000000000000000010500100000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000BE170000000000000100000001000000 "C:\Program Files (x86)\ProjectLibre\projectlibre.exe"=0x5341435001000000000000000700000028000000F5920100000000000100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000010000000000000000000000000000026420400000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\AIRF3C1.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000488C05007B37060001000000000000000000000A0021000033504C2B57DFD1010000008000000000020000002800000000000000000000000000000000000000000000000000000032990000000000000100000001000000 "C:\Windows\SysWOW64\Macromed\Temp\{F06C9FA8-4748-42C3-8637-DCC0DDC99D34}\InstallFlashPlayer.exe"=0x534143500100000000000000070000002800000058609E007EA49E0001000000000000000000000A00210000D5B3B31A57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000005E1A0000000000000100000001000000 "C:\Windows\System32\UNPUXWorker.exe"=0x534143500100000000000000070000002800000060570100B8B0010001000000000000000000000A73220000D5B3B31A57DFD101000000000000000002000000280000000000000000000040000000000000000000000000000000005E000000000000000200000002000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000787C03003765040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000 "C:\Users\Ben\AppData\Local\Temp\b73b31a6-1fbd-4176-b528-fe99c7865629\setup.exe"=0x5341435001000000000000000700000028000000C07106006FD6060001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000800000400000000000000000000000000000000067EA9600000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\latest\setup.exe"=0x5341435001000000000000000700000028000000787206005A80060001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000060D20400000000000200000002000000 "C:\Program Files\NVIDIA Corporation\Display\nvtray.exe"=0x5341435001000000000000000700000028000000787E2500FDDF250001000000000000000000000A73220000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000006DC89800000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.6943.0625\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0960300F48A040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\ProgramData\NVIDIA Corporation\Downloader\d20b0c765978b18fcd06bf8de3657f6c\GeForce_Experience_Update_v3.9.0.61.exe"=0x53414350010000000000000007000000280000005072FF04EB09000501000000000000000000020600010000E63F486B2AA0D2010000008000000000020000002800000000000000000000000000000000000000000000000000000025450700000000000100000001000000 "C:\Program Files\CPUID\CPU-Z\unins000.exe"=0x5341435001000000000000000700000028000000A1FA0A000000000001000000000000000000030600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000020000000000000000000000000000BD120000000000000100000001000000 "C:\Program Files (x86)\CrystalDiskInfo\unins000.exe"=0x5341435001000000000000000700000028000000F36213000000000001000000000000000000030600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000020000000000000000000000000000391B0000000000000100000001000000 "C:\Program Files\Common Files\EAInstaller\FIFA 17 DEMO\Cleanup.exe"=0x5341435001000000000000000700000028000000E0630E00AB690E0001000000000000000000020600010000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E31E0000000000000100000001000000 "C:\ProgramData\Package Cache\{281badd0-7e11-494b-bdf7-34d6a2615c3c}\xtu-setup-exe.exe"=0x5341435001000000000000000700000028000000684407002738080001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000200000000000000000000000000BCC00400000000000300000003000000 "C:\Program Files (x86)\myphotobook.fr\Supprime myphotobook.fr.exe"=0x53414350010000000000000007000000280000001DD60100C4A3CD0301000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000777E0000000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=0x5341435001000000000000000700000028000000C8CA06002252070001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000008AA90100000000000100000001000000 "C:\Program Files (x86)\Common Files\EAInstaller\Mass Effect 2\Cleanup.exe"=0x534143500100000000000000070000002800000040070D0085CA0D0001000000000000000000020600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000ED870000000000000100000001000000 "C:\Program Files (x86)\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\ENCARTA.EXE"=0x534143500100000000000000070000002800000018EB300050AF310001000000000000000000010571000000E63F486B2AA0D2010000008000000000020000002800000000000000000000000000000000000000000000000000000067A10200000000000100000001000000 "C:\Users\Ben\Downloads\samsung-smart-switch_4-1-17054-16_en_432673.exe"=0x5341435001000000000000000700000028000000A04C5F022445600201000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000F5A39300000000000200000002000000 "C:\Users\Ben\Downloads\KiesSetup.exe"=0x5341435001000000000000000700000028000000B0F84A048ECF4B0401000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001EA85E00000000000100000001000000 "C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe"=0x5341435001000000000000000700000028000000B0A808006D40090001000000000000000000020671020000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000D7031400000000000300000003000000 "C:\Users\Ben\AppData\Local\Temp\jre-8u144-windows-au.exe"=0x5341435001000000000000000700000028000000404C0B001FB30B0001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000006F240A00000000000100000001000000 "C:\Users\Ben\Downloads\dotNetFx40_Full_setup.exe"=0x534143500100000000000000070000002800000048920D0061380E0001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000443B0000000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\3f9da9e5-75e3-42c3-bb12-ea48a74b921a\setup.exe"=0x5341435001000000000000000700000028000000787406006B5B070001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000800000400000000000000000000000000000000093F50500000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{758C8301-2696-4855-AF45-534B1200980A}\setup.exe"=0x5341435001000000000000000700000028000000003812007936120001000000000000000000020600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000026A0400000000000200000002000000 "C:\Program Files (x86)\Samsung\USB Drivers\Uninstall.exe"=0x534143500100000000000000070000002800000060681700204E180001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000D0000000000000000000000000000000000E740500000000000100000001000000 "C:\Games\Act of Aggression\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000982D0000000000000100000001000000 "C:\Program Files (x86)\Far Cry 4\unins000.exe"=0x5341435001000000000000000700000028000000713525000000000001000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000070240000000000000100000001000000 "C:\Program Files (x86)\Yahoo!\yset\{384867CC-E1D7-3E4B-9B19-794F0B732A3B}\unset.exe"=0x53414350010000000000000007000000280000006015010054AE010001000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000043C00000000000000100000001000000 "C:\Windows\SysWOW64\MASetupCleaner.exe"=0x5341435001000000000000000700000028000000006000000000000001000000000000000000010571000000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000000000000000000000000000000000B9030000000000000100000001000000 "C:\Users\Ben\Downloads\ccsetup533.exe"=0x5341435001000000000000000700000028000000486995001FC5950001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000788A7B06000000000200000002000000000000000000004000000000000000000000000000000000D7503300000000000200000000000000 "C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe"=0x5341435001000000000000000700000028000000B07794003906950001000000000000000000010571000000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000A2070000000000000100000001000000 "C:\Program Files (x86)\Origin\vcredist_x64_vs2015.exe"=0x53414350010000000000000007000000280000004881E90078EAE90001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000084540100000000000100000001000000 "C:\Program Files (x86)\Origin\vcredist_x86_vs2015.exe"=0x5341435001000000000000000700000028000000A09DDC007BEADC0001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000004E0E0200000000000100000001000000 "C:\Program Files (x86)\Origin\Origin.exe"=0x534143500100000000000000070000002800000040492F000B29300001000000000000000000000A00210000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000007D155200000000000100000001000000000000000000004000000000000000000000000000000000EB750000000000000100000000000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0B00300CDA9040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0E20300117A040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.8414.5925.0_x64__8wekyb3d8bbwe\Office16\OfficeHubWin32.exe"=0x5341435001000000000000000700000028000000C0961F004C33200001000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001AED0100000000000100000001000000 "C:\Program Files\Mozilla Firefox\minidump-analyzer.exe"=0x5341435001000000000000000700000028000000D05F0900B65F0A0001000000000000000000000A73200000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000000E080000000000000100000001000000 "C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe"=0x534143500100000000000000070000002800000000700700F348080001000000000000000000010671200000E63F486B2AA0D2010000000000000000020000002800000000030105000000600000000000000000000000000000000052C6BE00000000000200000002000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.7074.1023\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C80E0400B6AD040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C80E040067ED040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\ProgramData\NVIDIA Corporation\Downloader\a50344aae9f3f44da37094b3e01fbb44\GeForce_Experience_Update_v3.10.0.95.exe"=0x53414350010000000000000007000000280000003092DB04497FDC0401000000000000000000020600010000E63F486B2AA0D2010000008000000000020000002800000000000000000000000000000000000000000000000000000073600900000000000100000001000000 "C:\Users\Ben\Downloads\DriversCloud_Win.exe"=0x534143500100000000000000070000002800000030B503009AE5030001000000000000000000000671000000E63F486B2AA0D20100000000000000000200000028000000000000000008004000000000000000000000000000000000C4860000000000000100000001000000 "C:\Program Files\DriversCloud.com\DriversCloud.exe"=0x5341435001000000000000000700000028000000B892690089306A0001000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001C610000000000000300000003000000 "C:\Users\Ben\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\Drivers_Ben-PC.exe"=0x5341435001000000000000000700000028000000E8ED1E00A96E1F0001000000000000000000000A00210000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000009AB40000000000000100000001000000 "C:\Users\Ben\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\388.43-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000A094961BD97E971B01000000000000000000020600010000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000007E0D0300000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\6a1d7cd5e76af7addd60d6ebe31401c3\GeForce_Experience_Update_v3.11.0.73_official_BF82FA.exe"=0x534143500100000000000000070000002800000088D6F0046C52F10401000000000000000000020600010000E63F486B2AA0D201000000800000000002000000280000000000000000000000000000000000000000000000000000006BDD0100000000000200000002000000 "C:\Users\Ben\Downloads\iTunes64Setup.exe"=0x53414350010000000000000007000000280000004881C10FBF18C20F01000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000506A0400000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\IXP718.TMP\SetupAdmin.exe"=0x5341435001000000000000000700000028000000480D02006093020001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000F6410100000000000100000001000000 "C:\Program Files\iTunes\iTunes.exe"=0x534143500100000000000000070000002800000038176402F30C650201000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000010000000000000000000000000000000006F480202000000000700000007000000 "C:\Users\Ben\Downloads\STEEP.exe"=0x5341435001000000000000000700000028000000C6E28F005A51020001000000000000000000000A63200000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000008D8D8402000000000200000002000000 "C:\Users\Ben\Downloads\STEEP(1).exe"=0x5341435001000000000000000700000028000000C6E28F005A51020001000000000000000000000A63200000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000068707C02000000000200000002000000 "C:\Users\Ben\Downloads\STEEP(3).exe"=0x5341435001000000000000000700000028000000C6E28F005A51020001000000000000000000000A63200000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000BE7F7B02000000000100000001000000 "C:\Users\Ben\Downloads\STEEP(4).exe"=0x5341435001000000000000000700000028000000C6E28F005A51020001000000000000000000000A63200000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001F1A7B02000000000100000001000000 "C:\Users\Ben\AppData\Local\Temp\dc37ad48-0cec-4b94-bcae-a8388a682cd1\setup.exe"=0x5341435001000000000000000700000028000000C07B06000C7D060001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000008000004000000000000000000000000000000000FA5D1800000000000100000001000000 "SIGN.MEDIA=68D0510F stp-fifa18.exe"=0x53414350010000000000000007000000280000000623CC000000000001000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000013812500000000000100000001000000 "C:\Program Files\FIFA18\FIFA18.exe"=0x53414350010000000000000005000000100000000000000000000000000000001000000007000000280000004893DF0A7B40E00A01000000000000000000000A0021000067077CBAC54CD401000000000000000002000000A00000000000000010000020000000000000000000000000000000003B1BAE00000000001B0000001400000000000000100000600000000000000000000000000000000041F6CA00000000000B00000000000000000000000000004000000000000000000000000000000000C3107B00000000001100000000000000000000000000000000000000000000000000000000000000656D5B00000000000500000000000000 "C:\Users\Ben\AppData\Local\Temp\96758ff4-a261-44ab-ba22-9edc61ff3820\setup.exe"=0x5341435001000000000000000700000028000000C07B06000C7D060001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000008000004000000000000000000000000000000000ED4A0800000000000100000001000000 "C:\Program Files\Mozilla Firefox\pingsender.exe"=0x5341435001000000000000000700000028000000D0F7000096B9010001000000000000000000000A73200000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000810F0000000000000A0000000A000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C89C0300B381040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0A203006855040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\ProgramData\NVIDIA Corporation\Downloader\df4195c155410738f3135e2f37c0a859\GeForce_Experience_Update_v3.12.0.84_Official_D74701.exe"=0x5341435001000000000000000700000028000000A0C8030599F2030501000000000000000000020600010000E63F486B2AA0D2010000008000000000020000005000000000000000000000000000000000000000000000000000000068673400000000000100000001000000000000000000004000000000000000000000000000000000922B0700000000000100000000000000 "C:\Program Files\FIFA18\FIFASetup\fifaconfig.exe"=0x5341435001000000000000000700000028000000481F0300968C030001000000000000000000010680010000E78E163C2AA0D2010000000000000000020000005000000000000000000000400000000001000000000000000100000028585100000000000100000001000000000000000000000010000000000000000000000000000000FFB20100000000000400000000000000010000000400000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.025.0204.0009\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0AE0300F24D040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000 "C:\ProgramData\NVIDIA Corporation\Downloader\9ea5f785c6c51bd4074453f93cd9d725\GeForce_Experience_Update_v3.13.1.30_Official_8540CC.exe"=0x534143500100000000000000070000002800000050A66F0510EF6F0501000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000FD250200000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"=0x5341435001000000000000000700000028000000C0951F0098D41F0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D3F95901000000000400000004000000 "C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.8830.7600.0_x64__8wekyb3d8bbwe\Office16\OfficeHubWin32.exe"=0x5341435001000000000000000700000028000000A8381E0089FB1E0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D0C00000000000000100000001000000 "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe"=0x5341435001000000000000000700000028000000B0D117003266180001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000A89C0100000000000100000001000000 "C:\Program Files (x86)\Google\Google Earth Pro\client\googleearth.exe"=0x534143500100000000000000070000002800000078621000D356110001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000001000000000000000000000000000000000E6D10000000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.065.0329.0002\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0E00300017A040001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Program Files (x86)\7-Zip\Uninstall.exe"=0x534143500100000000000000070000002800000045E500000000000001000000000000000000000671000000DB80FDAC2839D30100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000000000000000000000000000000000D50E0000000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A80204003EA4040001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.151.0729.0006\FileSyncConfig.exe"=0x534143500100000000000000070000002800000020F80300EE6C040001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileSyncConfig.exe"=0x534143500100000000000000070000002800000020F30300A795040001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Users\Ben\Downloads\OriginThinSetup(1).exe"=0x5341435001000000000000000700000028000000B028C60399AFC60301000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000F8AA4201000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.172.0826.0010\FileSyncConfig.exe"=0x53414350010000000000000007000000280000006010040082C7040001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Program Files (x86)\InstallShield Installation Information\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}\setup.exe"=0x5341435001000000000000000700000028000000003812007936120001000000000000000000020600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000004FFF2B00000000000100000001000000 "C:\Program Files (x86)\Assassins Creed Syndicate\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000001000000000000000000010600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000049200000000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060340400A607050001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "SIGN.MEDIA=2BF648C autorun.exe"=0x5341435001000000000000000700000028000000B04F0500403A060001000000000000000000010671220000DB80FDAC2839D3010000000000000000020000002800000000000000800000000000000000000000000000000000000033966300000000000B0000000B000000 "SIGN.MEDIA=2BF648C Setup.exe"=0x5341435001000000000000000700000028000000B0CD0200DB78030001000000000000000000010671220000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000BF3E0000000000000200000002000000 "C:\Program Files\AVAST Software\Avast\AvastUI.exe"=0x5341435001000000000000000700000028000000D804AD003444AD0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D0070000000000000100000001000000 "C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\settings.exe"=0x5341435001000000000000000700000028000000B08911006018120001000000000000000000010671220000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000009D410000000000000200000002000000 "C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\pes2013.exe"=0x5341435001000000000000000700000028000000B06FC201EB43C30101000000000000000000010671220000DB80FDAC2839D301000000000000000002000000500000000000000010000070000000000000000000000000000000008A030000000000000200000002000000000000001000003000100000000000000000000000000000A1E10100000000000200000000000000 "C:\Program Files (x86)\THQ\MX vs ATV Reflex\MXSettings.exe"=0x5341435001000000000000000700000028000000008A00000000000001000000000000000000010671220000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000000F2F0000000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\9b5f9291927a0ab07ce007a29243f05f\GeForce_Experience_Update_v3.16.0.122_Official_689B18.exe"=0x534143500100000000000000070000002800000088D1CE0610E1CE0601000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000A16B0200000000000200000002000000 "C:\Program Files\CCleaner\CCleaner64.exe"=0x5341435001000000000000000700000028000000A8451C01C00D1D0101000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000077010000000000000100000001000000 "C:\Users\Ben\Downloads\GeForce_Experience_v3.15.0.186(1).exe"=0x5341435001000000000000000700000028000000E01266058ED7660501000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000052E20000000000000100000001000000 "C:\Users\Ben\Downloads\iobit-uninstaller_8-2-0_fr_322480.exe"=0x5341435001000000000000000700000028000000A85AFE006312FF0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000002F04BD00000000000100000001000000 "C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe"=0x534143500100000000000000070000002800000010855000B9E1500001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000000E100000000000000600000006000000 "C:\Users\Ben\Downloads\GeForce_Experience_v3.16.0.122.exe"=0x5341435001000000000000000700000028000000902ACC062565CC0601000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000007880100000000000100000001000000 "C:\Users\Ben\Downloads\malwarebytes_3-5-1-2522_fr_215092.exe"=0x5341435001000000000000000700000028000000A8EC95043596960401000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000009CCE0300000000000100000001000000 "C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.6.1.2711-1.0.463-1.0.7123.exe"=0x53414350010000000000000007000000280000002086D0047C5FD10401000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000001E8C0100000000000100000001000000 "C:\Program Files (x86)\IObit\IObit Uninstaller\AUpdate.exe"=0x53414350010000000000000005000000100000000000000000000000000000000000000007000000280000001081020089E9020001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000CC270000000000000700000007000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.212.1021.0008\FileSyncConfig.exe"=0x53414350010000000000000007000000280000002031040026BC040001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Users\Ben\Downloads\GeForce_Experience_v3.16.0.122(1).exe"=0x5341435001000000000000000700000028000000902ACC062565CC0601000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000087A21100000000000200000002000000 "C:\Program Files (x86)\Steam\Steam.exe"=0x534143500100000000000000070000002800000020BB2E006E9F2F0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000085A0300000000000500000005000000 "C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\Advanced SystemCare_IU.exe"=0x534143500100000000000000070000002800000060DB6802150C690201000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000024F40000000000000100000001000000 "C:\Program Files\Malwarebytes\Anti-Malware\MbamPt.exe"=0x5341435001000000000000000700000028000000001800000000000001000000000000000000000A73220000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000000000000000000000200000002000000 "C:\Games\Activision\Call of Duty - Black Ops\BlackOps.exe"=0x5341435001000000000000000700000028000000002C7900F39E790001000000000000000000010671200000DB80FDAC2839D30100000000000000000200000028000000000000000000009000000000000000000000000000000000119C0000000000000100000001000000 "C:\Games\Call of Duty - Ghosts\GameUpdater.exe"=0x534143500100000000000000070000002800000000841D000000000001000000000000000000020671020000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000C50E0000000000000100000001000000 "C:\Games\Activision\Modern Warfare 2\iw4sp.exe"=0x5341435001000000000000000700000028000000589E35008F62360001000000000000000000000671000000DB80FDAC2839D3010000000000000000020000002800000000000000000000900000000000000000000000000000000038640000000000000100000001000000 "C:\Program Files (x86)\Activision\Call of Duty Black Ops II\t6sp.exe"=0x53414350010000000000000007000000280000009874B10062ECB10001000000000000000000010671000000DB80FDAC2839D301000000000000000005000000100000000000000000000000000201050000000002000000280000000002010500000060000000000000000000000000000000001E080000000000000100000001000000 "C:\Program Files (x86)\Ubisoft\Assassins Creed III\AC3SP.exe"=0x534143500100000000000000070000002800000050523D02952B3E0201000000000000000000010671020000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000100000000000000010000005B800000000000000100000001000000010000000400000001000000 "C:\Program Files (x86)\Assassins Creed Chronicles China\Binaries\Win32\ACCGame-Win32-Shipping.exe"=0x534143500100000000000000070000002800000058B6CA01BB69CB0101000000000000000000000671020000DB80FDAC2839D301000000000000000002000000280000000000000020000060000000000100000000000000010000002FE00000000000000100000001000000010000000400000001000000 "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"=0x5341435001000000000000000700000028000000C83E8000A554800001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000755F0000000000000100000001000000 "C:\Program Files (x86)\Capcom\Street Fighter X Tekken\SFTK.exe"=0x534143500100000000000000070000002800000068FDD3007B6DD40001000000000000000000010671220000DB80FDAC2839D30100000000000000000200000028000000000000000000000000100000000000000000000000000000BD920600000000000100000001000000 "C:\Games\Activision\Prototype\prototypef.exe"=0x534143500100000000000000070000002800000010257C0085D17C0001000000000000000000000671220000DB80FDAC2839D30100000000000000000200000028000000000000000000001000100000000000000000000000000000F81D0000000000000100000001000000 "C:\Program Files\Mozilla Firefox\updater.exe"=0x5341435001000000000000000700000028000000D0CB050095FD050001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000969C0500000000000700000007000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.222.1104.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000020570400F14C050001000000000000000000000A00210000DB80FDAC2839D3010000000100000000 "C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe"=0x5341435001000000000000000700000028000000F8687D0007FD7D0001000000000000000000000A71220000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000AE38B300000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x5341435001000000000000000700000028000000006208000000000001000000000000000000000A73200000BFA2139DEDD1D30100000000000000000200000028000000000000000000001000000000000000000000000000000000A673FE00000000000200000002000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.38.138.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x5341435001000000000000000700000028000000008008000000000001000000000000000000000A73200000BFA2139DEDD1D301000000000000000002000000280000000000000000000010000000000000000000000000000000006D49E300000000000500000005000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\18.240.1202.0004\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000386B0400903D050001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.002.0107.0008\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000308104006ACC040001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Program Files\WinRAR\Uninstall.exe"=0x5341435001000000000000000700000028000000D8FC0500551D060001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000A0020000000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.40.70.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x5341435001000000000000000700000028000000008008000000000001000000000000000000000A73200000BFA2139DEDD1D301000000000000000002000000280000000000000000000010000000000000000000000000000000005FFB8200000000000400000004000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.012.0121.0011\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000308D04008E97040001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.41.54.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x5341435001000000000000000700000028000000008008000000000001000000000000000000000A73200000BFA2139DEDD1D3010000000000000000020000002800000000000000000000100000000000000000000000000000000041278D00000000000300000003000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.033.0218.0011\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060AA0400777F050001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x5341435001000000000000000700000028000000007E08000000000001000000000000000000000A73200000BFA2139DEDD1D30100000000000000000200000028000000000000000000001000000000000000000000000000000000661DF501000000000400000004000000 "C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_18.1903.1152.0_x64__8wekyb3d8bbwe\LocalBridge.exe"=0x534143500100000000000000070000002800000048B600006317010001000000000000000000000A7322000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000AE040100000000000500000005000000 "C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.7.1.2839-1.0.538-1.0.9074.exe"=0x53414350010000000000000007000000280000004047D5031683D50301000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000001FA81C00000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.043.0304.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000030AF0400A4BA040001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Users\Ben\Downloads\MediaCreationTool1809.exe"=0x5341435001000000000000000700000028000000E86925014527260101000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000000CEBCC00000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.44.40.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000EA08000000000001000000000000000000000A73200000BFA2139DEDD1D3010000000000000000020000002800000000000000000000100000000000000000000000000000000039B44E03000000001100000011000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060BC0400AE33050001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Program Files\WinRAR\WinRAR.exe"=0x5341435001000000000000000700000028000000D8BC2200844A230001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000080995900000000001500000015000000 "C:\Program Files\Google\Google Earth Pro\client\googleearth.exe"=0x5341435001000000000000000700000028000000F0B51B005F241C0001000000000000000000000A73220000BFA2139DEDD1D3010000000000000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.070.0410.0005\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060BC04002A69050001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.44.40.1000_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000EA08000000000001000000000000000000000A73200000BFA2139DEDD1D3010000000000000000020000002800000000000000000000100000000000000000000000000000000026474A01000000000300000003000000 "C:\Program Files (x86)\Microsoft Office\Office14\PPTVIEW.EXE"=0x5341435001000000000000000700000028000000A0D27900F6AD7A000100000000000000000001060001000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000001F27BF00000000000600000006000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.46.60.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000EA08000000000001000000000000000000000A7320000067077CBAC54CD40100000000000000000200000028000000000000000000001000000000000000000000000000000000DD640003000000001C0000001C000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.070.0410.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060BC0400100C050001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncConfig.exe"=0x534143500100000000000000070000002800000038C904002188050001000000000000000000000A00210000BFA2139DEDD1D3010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000EA08000000000001000000000000000000000A7320000067077CBAC54CD401000000000000000002000000280000000000000000000010000000000000000000000000000000003F0AF502000000002100000021000000 "C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11270.exe"=0x5341435001000000000000000700000028000000E8A7D5039381D60301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000EDE71E00000000000200000002000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.103.0527.0003\FileSyncConfig.exe"=0x534143500100000000000000070000002800000078D404009BC1050001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.50.38.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000EA08000000000001000000000000000000000A7320000067077CBAC54CD4010000000000000000020000002800000000000000000000100000000000000000000000000000000001140903000000001500000015000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.123.0624.0005\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000788C05000898050001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.51.72.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000E60C000000000001000000000000000000000A7320000067077CBAC54CD4010000000000000000020000002800000000000000000000100000000000000000000000000000000046FC0103000000002800000028000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.152.0801.0007\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000789405000CF3050001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.152.0801.0008\FileSyncConfig.exe"=0x534143500100000000000000070000002800000078940500FFAD050001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.52.138.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000E60C000000000001000000000000000000000A7320000067077CBAC54CD4010000000000000000020000002800000000000000000000100000000000000000000000000000000064FC9802000000001300000013000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000789C05007343060001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Users\Ben\Downloads\ExcelViewer2003SP3-KB934737-FullFile-FRA.exe"=0x5341435001000000000000000700000028000000B0FB9E00CB319F000100000000000000000001057100000067077CBAC54CD40100000000000000000100000004000000010000000500000010000000000000000000000000030105800900000200000050000000000301058009007000060000000000000000000000000000C219000000000000010000000100000000000000800900500000200000000000000020000000000011F20000000000000100000000000000 "C:\Users\Ben\Downloads\Apache_OpenOffice_4.1.7_Win_x86_install_fr.exe"=0x53414350010000000000000007000000280000003E3CEB070000000001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000B2240600000000000100000001000000 "C:\Program Files (x86)\OpenOffice 4\program\soffice.exe"=0x534143500100000000000000070000002800000000AAA8005B07A90001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000001000000000000000000000000000000000828C4800000000000100000001000000 "C:\Program Files\VideoLAN\VLC\vlc.exe"=0x5341435001000000000000000700000028000000C80A0F00C3970F000100000000000000000000060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000B1BC0500000000000300000003000000 "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe"=0x534143500100000000000000070000002800000088771B00C3C41B0001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000CC4E0000000000000100000001000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.152.0927.0012\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000809C05005ADD050001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.85.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000E60C000000000001000000000000000000000A7320000067077CBAC54CD401000000000000000002000000280000000000000000000010000000000000000000000000000000008035A702000000000500000005000000 "C:\ProgramData\NVIDIA Corporation\Downloader\PostProcessing\GFE\6ea36c069dfdb7d15bfc40aa40869bdb\setup.exe"=0x534143500100000000000000070000002800000028D207002C15080001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000DA950600000000000200000002000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.174.0902.0013\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000789E0500CD91060001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.54.85.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000E60C000000000001000000000000000000000A7320000067077CBAC54CD401000000000000000002000000280000000000000000000010000000000000000000000000000000005B5C9E01000000000400000004000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.54.91.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000E60C000000000001000000000000000000000A7320000067077CBAC54CD4010000000000000000020000002800000000000000000000100000000000000000000000000000000079337D02000000001800000018000000 "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.34.15002.0_x64__8wekyb3d8bbwe\GameBarFT.exe"=0x534143500100000000000000070000002800000000C602000000000001000000000000000000000A7322000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000000A133800000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\a38c26e8cedf16bc38244aa77febc13a\GeForce_Experience_Update_v3.20.1.57_Official_B09EB8.exe"=0x5341435001000000000000000700000028000000C80A4507806E45070100000000000000000002060001000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000003060500000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe"=0x534143500100000000000000070000002800000028FA090076DD0A0001000000000000000000000A7120000067077CBAC54CD40100000000000000000200000028000000000000008000000000000000000000000000000000000000D83F0000000000000100000001000000 "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"=0x534143500100000000000000070000002800000028623200313E330001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000019916500000000000400000004000000 "C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_18.1910.1283.0_x64__8wekyb3d8bbwe\LocalBridge.exe"=0x534143500100000000000000070000002800000050C40100F110020001000000000000000000000A7322000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000439E000000000000EC010000EC010000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000685F170268B1170201000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Users\Ben\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000688F05001F71060001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\Program Files\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000C8A608006C11090001000000000000000000000A0021000067077CBAC54CD4010000000100000000 "C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\MBSetup.exe"=0x534143500100000000000000070000002800000078601D005B4A1E0001000000000000000000000A0021000067077CBAC54CD4010000000000000000 "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.35.14003.0_x64__8wekyb3d8bbwe\GameBarFT.exe"=0x534143500100000000000000070000002800000000C602000000000001000000000000000000000A7322000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000062ED3700000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe"=0x534143500100000000000000070000002800000000E60C000000000001000000000000000000000A7320000067077CBAC54CD4010000000000000000020000002800000000000000000000100000000000000000000000000000000045CC3D02000000001300000013000000 "C:\Users\Ben\Downloads\OriginThinSetup.exe"=0x5341435001000000000000000700000028000000E05DCD03798CCD0301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000B7E62400000000000100000001000000 "C:\Program Files (x86)\Origin\legacyPM\OriginLegacyCLI.exe"=0x534143500100000000000000070000002800000038930C00A8070D000100000000000000000001060001000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000007D000000000000000200000002000000 "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.36.6003.0_x64__8wekyb3d8bbwe\GameBarFT.exe"=0x534143500100000000000000070000002800000000C602000000000001000000000000000000000A7322000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000026FD3600000000000100000001000000 "C:\ProgramData\Origin\SelfUpdate\Staged\OriginThinSetupInternal.exe"=0x534143500100000000000000070000002800000028755801A82E590101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000083241D00000000000100000001000000 "C:\Program Files (x86)\Origin\OriginClientService.exe"=0x534143500100000000000000070000002800000030C52500DD22260001000000000000000000000A0021000067077CBAC54CD401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000004C030000000000000100000001000000 "C:\Program Files (x86)\Origin\OriginWebHelperService.exe"=0x534143500100000000000000070000002800000038273300178933000100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000DE020000000000000100000001000000 "SIGN.MEDIA=19FF3CD6 Setup.exe"=0x5341435001000000000000000700000028000000ED86A4000000000001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000D6E14800000000000200000002000000 "C:\Program Files (x86)\FIFA 19\FIFA19.exe"=0x5341435001000000000000000700000028000000003075116103761101000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000FB55AC00000000000500000005000000 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"=0x5341435001000000000000000700000028000000F0031A00B6E01A0001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000006E8A0000000000000100000001000000 "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe"=0x5341435001000000000000000700000028000000304E28001CAB280001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000100000000000000000000000000000000073190000000000000200000002000000 "C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe"=0x5341435001000000000000000700000028000000A802100035F5100001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000A3040000000000000100000001000000 "C:\Users\Ben\Downloads\setup.exe"=0x534143500100000000000000070000002800000020D4C1024691C20201000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000095B50000000000000100000001000000 "C:\Program Files\RogueKiller\RogueKiller64.exe"=0x534143500100000000000000070000002800000038F434024795350201000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000A3040000000000000100000001000000 "C:\Users\Ben\Downloads\ZHPDiag3.exe"=0x534143500100000000000000070000002800000080A131002071320001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000AE4B2100000000000100000001000000 "C:\Users\Ben\Downloads\ZHPCleaner.exe"=0x534143500100000000000000070000002800000080C132000082330001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000078831700000000000100000001000000 "C:\Users\Ben\Downloads\adwcleaner_8.0.1(2).exe"=0x5341435001000000000000000700000028000000B0B27D00B1907E0001000000000000000000000A0021000067077CBAC54CD40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000C91E0200000000000100000001000000 "C:\Users\Ben\Downloads\FRST64-2.1.exe"=0x534143500100000000000000070000002800000000AA2200C5E0220001000000000000000000000A0021000067077CBAC54CD40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000B1480000000000000100000001000000 "C:\Users\Ben\Downloads\winupdatefix_1.3.exe"=0x5341435001000000000000000700000028000000A65F0800000000000100000000000000000000067102000067077CBAC54CD401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000000FBA0200000000000100000001000000 "C:\Users\Ben\Downloads\QuickDiag.exe"=0x534143500100000000000000070000002800000098315100875E510001000000000000000000000A0021000067077CBAC54CD4010000000000000000 ---------- | IFEO ---------- | Mountpoints2 ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=132061160749302078 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "DisableAntiSpyware"=1 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "ProductType"=2 "ManagedDefenderProductType"=0 "ProductStatus"=0 "InstallTime"=0x4F8DBE0685D4D001 "DisableAntiVirus"=1 "InstallLocation"=C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\ "OOBEInstallTime"=0xC24CF0CAED2CD501 "LastEnabledTime"=0xD27C62AB06AED501 "BackupLocation"=C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioEndpointBuilder] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioSrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudAddService.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudBus.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SerCx2.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\usbaudio.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts # pour Windows. 127.0.0.1 localhost [44] More lines ---------- | Ping Envoi d'une requ?te 'ping' sur google.com [172.217.18.206] avec 32 octets de donn?es?: R?ponse de 172.217.18.206?: octets=32 temps=35 ms TTL=55 R?ponse de 172.217.18.206?: octets=32 temps=34 ms TTL=55 R?ponse de 172.217.18.206?: octets=32 temps=35 ms TTL=55 R?ponse de 172.217.18.206?: octets=32 temps=35 ms TTL=55 Statistiques Ping pour 172.217.18.206: Paquets?: envoy?s = 4, re?us = 4, perdus = 0 (perte 0%), Dur?e approximative des boucles en millisecondes : Minimum = 34ms, Maximum = 35ms, Moyenne = 34ms ---------- | @ [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "Cache_Update_Frequency"=Once_Per_Session "Local Page"=C:\Windows\system32\blank.htm "NoUpdateCheck"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Start Page"=https://fr.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset "SearchDefaultBranded"=1 "CompatibilityFlags"=0 "FullScreen"=no "Window_Placement"=0x2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF330200001E010000B3040000FE020000 "IE9RunOncePerInstallCompleted"=1 "IE9RunOnceCompletionTime"=0xCA44B2A813FBCC01 "IE9TourShown"=1 "IE9TourShownTime"=0xCA44B2A813FBCC01 "IconCache"=snwip3p "DownloadWindowPlacement"=0x2C00000000000000000000000083FFFF0083FFFFFFFFFFFFFFFFFFFFD4000000650000005403000045020000 "Use FormSuggest"=no "AutoHide"=yes "Use Search Asst"=no "ApplicationTileImmersiveActivation"=0 "AssociationActivationMode"=2 "Error Dlg Displayed On Every Error"=no "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0x5E258AEB4D3ED101 "IE10TourShown"=1 "IE10TourShownTime"=0x046B4F76D637D501 "OperationalData"=13 "NotifyDownloadComplete"=yes "ImageStoreRandomFolder"=ee4asot "IE10RunOnceLastShown"=1 "IE10RunOnceLastShown_TIMESTAMP"=0x78542E83E772D501 "Search Bar"=http://www.msn.com/?pc=AV01 "Default_Page_URL"=www.google.com "EdgeSwitchingOSBuildNumber"=10586.th2_release.160802-1857 "SearchBandMigrationVersion"=1 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "SecureProtocols"=2688 "CertificateRevocation"=1 "PrivacyAdvanced"=0 "EnableNegotiate"=1 "MigrateProxy"=1 "ProxyEnable"=0 "ReceiveTimeOut"=600000 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EmailName"=User@ "PrivDiscUiShown"=1 "EnableHttp1_1"=1 "WarnOnIntranet"=1 "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "AutoConfigProxy"=wininet.dll "UseSchannelDirectly"=0x01000000 "WarnOnPost"=0x01000000 "UrlEncoding"=0 "ZonesSecurityUpgrade"=0x046B4F76D637D501 "WarnonZoneCrossing"=0 "EnableAutodial"= "GlobalUserOffline"=0 "LockDatabase"=132197868450856546 [HKLM\Software\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "DisableRandomFlighting"=0 "EnableLegacyEdgeSwitching"=1 "Default_Search_URL"=www.google.com "Default_Page_URL"=www.google.com "Start Page"=http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130948634903606914&GUID=1C02DD11-D136-4FC7-B75D-68BE95E84A20 "Search Page"=www.google.com "FrameAuto"=1 [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings] "CallLegacyWCMPolicies"=0 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\SysWOW64\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings] "CallLegacyWCMPolicies"=0 ---------- | Proxy ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | Execution FileExts [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kml] "Application"=googleearth.exe [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kmz] "Application"=googleearth.exe [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qcp] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmm] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi] "Application"= [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil] "Application"= ---------- | SIOI | SEH | URLSH [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7] - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw] - {472083B0-C522-11CF-8763-00608CC02F24} -- C:\Program Files\AVAST Software\Avast\ashShell.dll [11/10/2019 09:18:53] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast] - {472083B0-C522-11CF-8763-00608CC02F24} -- C:\Program Files\AVAST Software\Avast\ashShell.dll [11/10/2019 09:18:53] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [15/09/2018 08:28:50] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7] - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} -- [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= "{6ab96dd7-6e0c-4a7f-93e0-a8a47a685d81}"= ---------- | Toolbar [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser] "ITBar7Layout"=0x13000000000000000000000020000000100008003600000001000000000700005E010000090000000101000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B1C218236549D4119B18009027A5CD4F0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ITBar7Height"=31 [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "Version"=5 "KnownProvidersUpgradeTime"=0x4635958960D5D001 "DownloadRetries"=0 "PrevScope"={9BB47C17-9C68-4BB3-B188-DD9AF0FD21} "UpgradeTime"=0x4635958960D5D001 "DefaultPackCorrection"=1 "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}"= "{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}"=avast! Online Security [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} "PrevScope"={9BB47C17-9C68-4BB3-B188-DD9AF0FD21} ---------- | Extensions [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA}] : (eBay.fr) - [] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B205A35E-1FC4-4CE3-818B-899DBBB3388C}] : () - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{0000036B-C524-4050-81A0-243669A86B9F}] : () - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}] : (@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003) - [] ---------- | SearchScopes [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch] - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 : [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3E0252E5-EF27-4F89-B53F-C910A1D46C82}] - (Yahoo Search) - https://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A9A7ABF-249E-FC0F-893B-5B8FDB0D7E64}] - (Google) - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}] - (Microsoft (Bing)) - http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{73D0D660-594C-BA59-BFCC-31595F1EF984}] - (Google) - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 : ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> (Java(tm) Plug-In SSV Helper) : C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [27/08/2017 10:20:52] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> (Java(tm) Plug-In 2 SSV Helper) : C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [27/08/2017 10:20:51] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> (Java(tm) Plug-In SSV Helper) : C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [27/08/2017 10:20:52] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] -> (Windows Live Messenger Companion Helper) : C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [08/03/2012 17:14:38] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> (Java(tm) Plug-In 2 SSV Helper) : C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [27/08/2017 10:20:51] ---------- | Chrome C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\aapocclcgogkmnckokdopfmhonfmgoek = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\aohghmighlieiainnegkcijnfilokake = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\apdfllckaahabafndbhieahigkjlhalf = : Google & co - https://drive.google.com/?usp=chrome_app - Google & co - [http://docs.google.com/http://drive.google.com/https://docs.google.com/https://drive.google.com/] - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co - http://www.youtube.com - http://www.youtube.com - Google & co - http://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\fabhkdeopjkcpkmofliimbjckmocfiom = : __MSG_newtab_chrome_extension_description__ - __MSG_newtab_chrome_extension_name__ - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\felcaaldnbdncclmgdcncolpebgiejap = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi = : __MSG_extDesc__ - __MSG_extName__ - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\gomekmidlodglbbmalcneegieacbdmki = : Avast Browser Security and Web Reputation Plugin. - Avast Online Security - matches:[\u003Call_urls>] - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\njpedbdniajflhgfoipnjkednnlkngbj = : __MSG_newtab_chrome_extension_description__ - __MSG_newtab_chrome_extension_name__ - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co - https://mail.google.com/mail - Google & co - [*://mail.google.com/mail] - https://clients2.google.com/service/update2/crx C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm = : Provider for discovery and services for mirroring of Chrome Media Router - Chrome Media Router - 919648714761-55j965o0km033psv3i9qls5mo3qtdrb0.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\njpedbdniajflhgfoipnjkednnlkngbj] ---------- | Opera ---------- | Firefox [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\MozillaPlugins\ubisoft.com/uplaypc] - () : C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 32.0.0.303 Plugin) : C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_303.dll [HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.6.2] - () : C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39] - () : C:\Windows\system32\npdeployJava1.dll [HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.2] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.8] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 32.0.0.303 Plugin) : C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_303.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4] - (ESN Sonar browser plugin) : C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0] - () : C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@esn/npbattlelog,version=2.6.2] - () : C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.144.2] - (Java™ Deployment Toolkit) : C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.144.2] - (Oracle® Next Generation Java™ Plug-In) : C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@nvidia.com/3DVision] - (NVIDIA stereo images plugin for Mozilla browsers) : C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming] - (NVIDIA 3D Vision Streaming plugin for Mozilla browsers) : C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@protectdisc.com/NPMPDRM] - (MPDRM License Acquisition Plugin) : C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14] - (RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In) : C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14] - (RealPlayer(tm) HTML5VideoShim Plug-In) : C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.8] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\Adobe Reader] - (Handles PDFs in-place in Firefox) : C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll C:\Users\Admin123\AppData\Roaming\Mozilla\Firefox\Profiles\wzx6vxf2.default\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20160502172042"); user_pref("browser.startup.homepage_override.mstone", "46.0.1"); user_pref("extensions.blocklist.pingCountVersion", -1); user_pref("extensions.bootstrappedAddons", "{\"loop@mozilla.org\":{\"version\":\"1.2.6\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\loop@mozilla.org.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":true},\"e10srollout@mozilla.org\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\e10srollout@mozilla.org.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":true},\"firefox@getpocket.com\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\firefox@getpocket.com.xpi\",\"multiprocessCompatible\":false,\"runInSafeMode\":true}}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.e10sBlockedByAddons", false); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:46.0.1"); user_pref("extensions.getAddons.cache.lastUpdate", 1462645956); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.lastAppVersion", "46.0.1"); user_pref("extensions.lastPlatformVersion", "46.0.1"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-system-defaults\":{\"e10srollout@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\e10srollout@mozilla.org.xpi\",\"e\":true,\"v\":\"1.0\",\"st\":1462382528255},\"firefox@getpocket.com\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\firefox@getpocket.com.xpi\",\"e\":true,\"v\":\"1.0\",\"st\":1462382528243},\"loop@mozilla.org\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\features\\\\loop@mozilla.org.xpi\",\"e\":true,\"v\":\"1.2.6\",\"st\":1461783097962}},\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi\",\"e\":true,\"v\":\"46.0.1\",\"st\":1462382528257}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}}}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\2j82kuaz.default-1451429313446\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20151221130713"); user_pref("browser.startup.homepage_override.mstone", "43.0.2"); user_pref("extensions.blocklist.pingCountVersion", 0); user_pref("extensions.bootstrappedAddons", "{}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.2"); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.lastAppVersion", "43.0.2"); user_pref("extensions.lastPlatformVersion", "43.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"e\":true,\"v\":\"43.0.2\",\"st\":1451210176948,\"mt\":1450741745000}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}}}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\80ub9qff.default-1352891836923\Prefs.js user_pref("app.normandy.startupRolloutPrefs.extensions.fxmonitor.enabled", true); user_pref("browser.search.defaultengine", "Google (avast)"); user_pref("browser.search.defaultenginename", "Google (avast)"); user_pref("browser.search.order.1", "Google (avast)"); user_pref("browser.startup.homepage", "moz-extension://8d0567c8-dfcb-482b-83d7-af5c478bc1ef/dynamicHomePage.html"); user_pref("browser.startup.homepage_override.buildID", "20191202093317"); user_pref("browser.startup.homepage_override.mstone", "71.0"); user_pref("devtools.webextensions.{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.enabled", true); user_pref("e10s.rollout.cohort", "webextensions-multiBucket4"); user_pref("extensions.activeThemeID", "default-theme@mozilla.org"); user_pref("extensions.adblockplus.currentVersion", "2.9.1"); user_pref("extensions.adblockplus.hideContributeButton", true); user_pref("extensions.adblockplus.notificationdata", "{\"lastCheck\":1510408356110,\"softExpiration\":1510477888992,\"hardExpiration\":1510581158244,\"data\":{\"notifications\":[],\"version\":\"201711111351-3/0\"},\"lastError\":0,\"downloadStatus\":\"synchronize_ok\",\"downloadCount\":239,\"shown\":{\"antiadblock\":1502724191560}}"); user_pref("extensions.blocklist.pingCountTotal", 540); user_pref("extensions.blocklist.pingCountVersion", 18); user_pref("extensions.blocklist.url", "http://google.com"); user_pref("extensions.databaseSchema", 31); user_pref("extensions.e10s.rollout.blocklist", ""); user_pref("extensions.e10s.rollout.hasAddon", true); user_pref("extensions.e10s.rollout.policy", "50allmpc"); user_pref("extensions.e10sBlockedByAddons", false); user_pref("extensions.e10sMultiBlockedByAddons", false); user_pref("extensions.etp_search_volume_study.channel_cohort_prefix", "t"); user_pref("extensions.followonsearch.cohortSample", "0.952964"); user_pref("extensions.fxmonitor.firstAlertShown", true); user_pref("extensions.getAddons.cache.lastUpdate", 1577306637); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20170302.01"); user_pref("extensions.incognito.migrated", true); user_pref("extensions.lastAppBuildId", "20191202093317"); user_pref("extensions.lastAppVersion", "71.0"); user_pref("extensions.lastPlatformVersion", "71.0"); user_pref("extensions.pendingOperations", false); user_pref("extensions.pocket.settings.test.panelSignUp", "v1"); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.signer.hotfixed", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.experiment.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/extension"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.webcompat.perform_injections", true); user_pref("extensions.webcompat.perform_ua_overrides", true); user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.screenshots@mozilla.org", true); user_pref("extensions.webextensions.uuids", "{\"{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\":\"cb78138b-51f5-426c-b968-4cc50291b839\",\"firefox@ghostery.com\":\"3b03b4b8-add0-45ca-b17d-74b24fdcab6e\",\"screenshots@mozilla.org\":\"accbeeee-06a6-450b-ad4d-a06ed0b14891\",\"sp@avast.com\":\"dc0b8c10-97e6-4393-ac3a-e34ae5212b2e\",\"wrc@avast.com\":\"4dcacdda-29f2-4bd4-9f66-2416e8260564\",\"jid1-16aeif9OQIRKxA@jetpack\":\"4047b9ea-b6c3-4e40-9486-82595f657df6\",\"abb@amazon.com\":\"95d6caef-1700-4886-8c93-2efd9325c73f\",\"webcompat@mozilla.org\":\"9ea02cf4-b26e-4498-985a-0974be2b3464\",\"formautofill@mozilla.org\":\"94fbb93c-bd71-40f5-b24c-5553c79c2d81\",\"_ceMembers_@free.easypdfcombine.com\":\"8d0567c8-dfcb-482b-83d7-af5c478bc1ef\",\"webcompat-reporter@mozilla.org\":\"3b4a36dc-e263-4d49-bfb2-fffa9a63b8ad\",\"baidu-code-update@mozillaonline.com\":\"e34a2fa1-100a-47c6-b300-3fd9c0eee26a\",\"fxmonitor@mozilla.org\":\"2d66bb31-6149-42b9-9d49-9ea7785224a4\",\"default-theme@mozilla.org\":\"7d2372a2-6066-4a8f-b7d2-9ec8ab5497be\",\"google@search.mozilla.org\":\"fbf3c2ed-7a0d-4310-af50-412046853807\",\"bing@search.mozilla.org\":\"7898e88e-4fd9-4dfa-9f3d-49bbad065f42\",\"amazon@search.mozilla.org\":\"3fdbe14d-5494-430a-bf7d-ccef6c2a61b0\",\"ddg@search.mozilla.org\":\"37e1a126-ace2-4736-b7ca-f37dac58bc20\",\"ebay@search.mozilla.org\":\"e03e21f2-a5c7-43f2-9cd9-be705ef33172\",\"qwant@search.mozilla.org\":\"cbeb97ca-c107-4e95-987b-12435ceff35f\",\"wikipedia@search.mozilla.org\":\"be93778f-92c0-4ad4-8539-953d8ad1e0af\"}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\9si17p10.default-1451503659014\Prefs.js user_pref("browser.startup.homepage", "https://google/|https://www.google.fr/?gws_rd=ssl#cns=0&gws_rd=ssl|about:preferences"); user_pref("browser.startup.homepage_override.buildID", "20151221130713"); user_pref("browser.startup.homepage_override.mstone", "43.0.2"); user_pref("extensions.blocklist.pingCountTotal", 2); user_pref("extensions.blocklist.pingCountVersion", 2); user_pref("extensions.bootstrappedAddons", "{}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.2"); user_pref("extensions.getAddons.cache.lastUpdate", 1451504271); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20151223.01"); user_pref("extensions.lastAppVersion", "43.0.2"); user_pref("extensions.lastPlatformVersion", "43.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"e\":true,\"v\":\"43.0.2\",\"st\":1451210176948,\"mt\":1450741745000}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}}}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\n1b9ngch.default-1451427169902\Prefs.js user_pref("browser.startup.homepage", "google.fr"); user_pref("browser.startup.homepage_override.buildID", "20151221130713"); user_pref("browser.startup.homepage_override.mstone", "43.0.2"); user_pref("extensions.blocklist.pingCountVersion", 0); user_pref("extensions.bootstrappedAddons", "{\"firefox-hotfix@mozilla.org\":{\"version\":\"20151223.01\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Ben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\n1b9ngch.default-1451427169902\\\\extensions\\\\firefox-hotfix@mozilla.org.xpi\",\"multiprocessCompatible\":false}}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.2"); user_pref("extensions.getAddons.cache.lastUpdate", 1451427780); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20151223.01"); user_pref("extensions.lastAppVersion", "43.0.2"); user_pref("extensions.lastPlatformVersion", "43.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"e\":true,\"v\":\"43.0.2\",\"st\":1451210176948,\"mt\":1450741745000}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}},\"app-profile\":{\"firefox-hotfix@mozilla.org\":{\"d\":\"C:\\\\Users\\\\Ben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\n1b9ngch.default-1451427169902\\\\extensions\\\\firefox-hotfix@mozilla.org.xpi\",\"e\":true,\"v\":\"20151223.01\",\"st\":1451427783008}}}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\nyxpybk1.default-1451573893047\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20151221130713"); user_pref("browser.startup.homepage_override.mstone", "43.0.2"); user_pref("extensions.blocklist.pingCountTotal", 2); user_pref("extensions.blocklist.pingCountVersion", 2); user_pref("extensions.bootstrappedAddons", "{}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.2"); user_pref("extensions.getAddons.cache.lastUpdate", 1451574521); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20151223.01"); user_pref("extensions.lastAppVersion", "43.0.2"); user_pref("extensions.lastPlatformVersion", "43.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"e\":true,\"v\":\"43.0.2\",\"st\":1451210176948,\"mt\":1450741745000}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}}}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\qiqd7d9r.default-1451853004150\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20151221130713"); user_pref("browser.startup.homepage_override.mstone", "43.0.2"); user_pref("extensions.blocklist.pingCountTotal", 2); user_pref("extensions.blocklist.pingCountVersion", 2); user_pref("extensions.bootstrappedAddons", "{}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.2"); user_pref("extensions.getAddons.cache.lastUpdate", 1451853620); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20151223.01"); user_pref("extensions.lastAppVersion", "43.0.2"); user_pref("extensions.lastPlatformVersion", "43.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"e\":true,\"v\":\"43.0.2\",\"st\":1451210176948,\"mt\":1450741745000}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}}}"); C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\voqi35ew.default-1451854052743\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20151221130713"); user_pref("browser.startup.homepage_override.mstone", "43.0.2"); user_pref("extensions.blocklist.pingCountTotal", 2); user_pref("extensions.blocklist.pingCountVersion", 2); user_pref("extensions.bootstrappedAddons", "{}"); user_pref("extensions.databaseSchema", 17); user_pref("extensions.enabledAddons", "%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.2"); user_pref("extensions.getAddons.cache.lastUpdate", 1451854659); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20151223.01"); user_pref("extensions.lastAppVersion", "43.0.2"); user_pref("extensions.lastPlatformVersion", "43.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.xpiState", "{\"app-global\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"d\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"e\":true,\"v\":\"43.0.2\",\"st\":1451210176948,\"mt\":1450741745000}},\"winreg-app-global\":{\"wrc@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"st\":1450371628478},\"sp@avast.com\":{\"d\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\SafePrice\\\\FF\",\"e\":false,\"v\":\"10.3.5.13\",\"st\":1450371629041,\"mt\":1450371570069}}}"); [Profile0] - Name=default -> Profiles/wzx6vxf2.default [Profile4] - Name=default-1451573893047 -> Profiles/nyxpybk1.default-1451573893047 ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{65eda36b-5013-4df9-8e41-5865502f9473}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{65eda36b-5013-4df9-8e41-5865502f9473}] "DhcpNameServer"=192.168.1.1 ---------- | Applications [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\7zFM.exe] : "C:\Program Files (x86)\7-Zip\7zFM.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\7zG.exe] : "C:\Program Files (x86)\7-Zip\7zG.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\DivX Player.exe] : "C:\Program Files (x86)\DivX\DivX Player\DivX Player.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\DTLite.exe] : "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\notepad++.exe] : "C:\Program Files (x86)\Notepad++\notepad++.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\PMB3DPlayer.exe] : "C:\Program Files (x86)\Sony\PlayMemories Home\PMB3DPlayer.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\PMBAVCHDPlayer.exe] : "C:\Program Files (x86)\Sony\PlayMemories Home\PMBAVCHDPlayer.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\PMBDownloader.exe] : "C:\Program Files (x86)\Sony\PlayMemories Home\PMBDownloader.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\uTorrent.exe] : "C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\VegasMovieStudioPE110.exe] : "C:\Program Files (x86)\Sony\Vegas Movie Studio HD Platinum 11.0\VegasMovieStudioPE110.exe" "%1" [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Classes\Applications\WinRAR.exe] : "C:\Program Files\WinRAR\WinRAR.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\Classes\Applications\pixillion.exe] : "C:\Program Files (x86)\NCH Software\Pixillion\pixillion.exe" "%L" [HKLM\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen [HKLM\SOFTWARE\Classes\Applications\vlc.exe] : "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\Classes\Applications\wordview.exe] : "C:\Program Files (x86)\Microsoft Office\OFFICE11\WORDVIEW.EXE" /n /dde [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\pixillion.exe] : "C:\Program Files (x86)\NCH Software\Pixillion\pixillion.exe" "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vlc.exe] : "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordview.exe] : "C:\Program Files (x86)\Microsoft Office\OFFICE11\WORDVIEW.EXE" /n /dde ---------- | SvcHost (Whitelist) [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=Power LSM BrokerInfrastructure PlugPlay DcomLaunch SystemEventsBroker DeviceInstall "rdxgroup"=RetailDemo "Camera"=FrameS "LocalServiceNoNetworkFirewall"=BFE mpssvc "diagnostics"=DiagSvc "PrintWorkflow"=PrintWorkflowUserSvc "wusvcs"=WaaSMedicSvc "BcastDVRUserService"=BcastDVRUserService "GraphicsPerfSvcGroup"=GraphicsPerfSvc "ClipboardSvcGroup"=cbdhsvc "BthAppGroup"=BluetoothUserService "smbsvcs"=lanmanserver browser "DevicesFlow"=DevicesFlowUserSvc ConsentUxUserSvc DevicePickerUserSvc "iissvcs"=w3svc was "HPZ12"=Pml Driver HPZ12 Net Driver HPZ12 "osrss"=osrss [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=DcomLaunch DeviceInstall "PrintWorkflow"=PrintWorkflowUserSvc "smbsvcs"=lanmanserver "iissvcs"=w3svc was ---------- | SvcHost - Netsvcs (Whitelist) ---------- | Software [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\(null)] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\0JCYjqIoIDkRscGx2Dt9JzXi] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\2K Sports] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\4kdownload.com] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\AC3Filter] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\ACE Compression Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Activision] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Adlice Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Adobe] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Ahead] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\AlterGeo] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\American Megatrends, Inc.] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\AOL] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\AppDataLow] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Apple Computer, Inc.] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Apple Inc.] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Arkane] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Aspyr Media] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\AVAST Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Badoo] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Bigben Interactive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\BitTorrent] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Blackbird Interactive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\BlueRippleSound] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Bohemia Interactive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Browser Cleanup] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\BugSplat] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\CDDB] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Chromium] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\CI Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\City Interactive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Clients] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Clubic] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\corel] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\CoreVorbis] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Crystal Dynamics] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Cyanide] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\CyberLink] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\DamienBT] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\DirectShow] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Disc Soft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\DivXNetworks] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\DivXplayer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\DSS] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\DT Soft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\EA Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\ej-technologies] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Electronic Arts] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\EMU] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\eMule] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Epic Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\eXtremeMovieManager] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\FLT] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Gabest] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Gadwin] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Gadwin Systems] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Game Updater] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Gamepires] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\GameSpy] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\GNU] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\GOG.com] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Google] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Haali] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Hewlett-Packard] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\HotSwap!] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\HTS] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Icaros] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\IGA] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\IM Providers] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\JavaSoft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\JEDI-VCL] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\JoyvyGameCenter] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\kde.org] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Leadertech] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Lenovo] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\LexmarkInkjet] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Licenses] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Macromedia] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Malwarebytes] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Malwarebytes' Anti-Malware] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Matrix Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Matroska Pack] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\MCAFEE] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Mine] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\MOHWSplash] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\mozilla] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\MozillaPlugins] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\NCH Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\NeoCore Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Netscape] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\NVIDIA Corporation] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\OpenOffice] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Opera Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Panasonic] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\PartyFrance] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\PCTuneUp] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\PDFCreator] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\perforce] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Philipp Schmieder] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Piriform] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Policies] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Protect Software GmbH] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Protexis] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\QtProject] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\RealNetworks] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Realtek] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\RegisteredApplications] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Relic] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Samsung] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\SecuROM] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Skype] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\SOG] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Sony Corporation] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Sony Creative Software] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Stellar information Systems ltd.] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Telltale Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\The Creative Assembly] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\THEGFW] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\THQ] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Trolltech] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\TuneUp] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Ubisoft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Unity] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Unwinder] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\V9ceZZL] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Valve] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\VirginMega] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\VUPlayer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\WinRAR] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\WinRAR SFX] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Wow6432Node] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\WSysInfo] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Xilisoft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Yahoo] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Yummy Interactive, Inc.] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\ZHP] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\{B2CB09FF-2453-4f85-9F40-21C05BE4CBA8}] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\AppDataLow\Software\JavaSoft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\AppDataLow\Software\Yahoo] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Active Setup] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\ActiveMovie] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\ActiveSync] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Assistance] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\AuthCookies] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Avalon.Graphics] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Calc] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\CalcPlus] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\CalendarRT] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Clipboard] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Command Processor] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\CommsAPHost] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Connection Manager] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\ContactsRT] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\CTF] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Device Center] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\DeviceDirectory] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\DirectInput] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\DirectX Diagnostic Tool] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\DVR] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Ease of Access] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\EventSystem] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\F12] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\FamilyStore] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Fax] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Feeds] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\FTP] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\GameBar] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\GameBarApi] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\IAM] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\IdentityCRL] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Ieak] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\IME] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\IMEJP] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Input] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\InputMethod] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\InputPersonalization] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\IntelliPoint] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\IntelliType Pro] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Connection Wizard] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Internet Explorer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Java VM] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Keyboard] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Keyboard Layout Creator 1.4] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\LanguageOverlay] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Learning Essentials] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\MediaPlayer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Messaging] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Microsoft DVD Wizard Settings] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Microsoft Games] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Microsoft Management Console] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Microsoft Reference] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\MicrosoftEdge] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\MPEG2Demultiplexer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\MS Design Tools] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\MSF] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\MSNMessenger] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Multimedia] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Narrator] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Notepad] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Office] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\OneDrive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Osk] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Payment] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\PeerNet] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Personalization] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Phone] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Pim] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\PlayToReceiver] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Poom] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\PowerPoint Viewer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\RAS AutoDial] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\RAS Phonebook] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Remote Assistance] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\RPM] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\SBE] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\ScreenMagnifier] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Scrunch] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Search Enhancement Pack] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Sensors] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Shared] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Shared Tools] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\SideShow] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Silverlight] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Siuf] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\SkyDrive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\SoftGrid] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Speech] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Speech Virtual] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Speech_OneCore] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Spelling] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\SQMClient] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\StorageLibrary] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\SystemCertificates] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\TabletTip] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\TelemetryClient] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Terminal Server Client] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\TPG] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\UCCPlatform] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Unified Store] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Unistore] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\UNP] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\UserData] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\UserDataService] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Visual Basic] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\WAB] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\WcmSvc] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Web Service Providers] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\wfs] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Genuine Advantage] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Live] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Live Mail] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows NT] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Photo Viewer] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Script] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Script Host] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Search] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Security Health] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Windows Sidebar] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\Wisp] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\XAML] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\XboxLive] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\AssignedAccessConfiguration] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\PrivacySettingsBeforeCreatorsUpdate] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\AGEIA Technologies] [HKLM\Software\AMI] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\ATI Technologies] [HKLM\Software\AVAST Software] [HKLM\Software\BrowserChoice] [HKLM\Software\CBSTEST] [HKLM\Software\Clients] [HKLM\Software\cybelsoft] [HKLM\Software\DefaultUserEnvironment] [HKLM\Software\Dell] [HKLM\Software\Disc Soft] [HKLM\Software\Dolby] [HKLM\Software\DTS] [HKLM\Software\EA Games] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\GEAR Software] [HKLM\Software\Google] [HKLM\Software\HaaliMkx] [HKLM\Software\Hewlett-Packard] [HKLM\Software\Intel] [HKLM\Software\Khronos] [HKLM\Software\Knowles] [HKLM\Software\Lenovo] [HKLM\Software\LexmarkInkjet] [HKLM\Software\Macromedia] [HKLM\Software\Malwarebytes] [HKLM\Software\Microsoft] [HKLM\Software\Mozilla] [HKLM\Software\mozilla.org] [HKLM\Software\MozillaPlugins] [HKLM\Software\Nahimic] [HKLM\Software\Nuance] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\Partner] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\Respawn] [HKLM\Software\RTLSetup] [HKLM\Software\SAMSUNG] [HKLM\Software\Sonic] [HKLM\Software\SonicFocus] [HKLM\Software\SoundResearch] [HKLM\Software\SRS Labs] [HKLM\Software\Thrustmaster] [HKLM\Software\TuneUp] [HKLM\Software\VideoLAN] [HKLM\Software\Waves Audio] [HKLM\Software\Windows] [HKLM\Software\WinRAR] [HKLM\Software\WOW6432Node] [HKLM\Software\Yamaha APO] [HKLM\Software\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}] [HKLM\SOFTWARE\Microsoft\.NETFramework] [HKLM\SOFTWARE\Microsoft\AccountsControl] [HKLM\SOFTWARE\Microsoft\Active Setup] [HKLM\SOFTWARE\Microsoft\ActiveSync] [HKLM\SOFTWARE\Microsoft\ADs] [HKLM\SOFTWARE\Microsoft\Advanced INF Setup] [HKLM\SOFTWARE\Microsoft\ALG] [HKLM\SOFTWARE\Microsoft\AllUserInstallAgent] [HKLM\SOFTWARE\Microsoft\AMSI] [HKLM\SOFTWARE\Microsoft\Analog] [HKLM\SOFTWARE\Microsoft\AppServiceProtocols] [HKLM\SOFTWARE\Microsoft\ASP.NET] [HKLM\SOFTWARE\Microsoft\Assistance] [HKLM\SOFTWARE\Microsoft\AuthHost] [HKLM\SOFTWARE\Microsoft\BidInterface] [HKLM\SOFTWARE\Microsoft\BitLockerCsp] [HKLM\SOFTWARE\Microsoft\CallAndMessagingEnhancement] [HKLM\SOFTWARE\Microsoft\Cellular] [HKLM\SOFTWARE\Microsoft\Chkdsk] [HKLM\SOFTWARE\Microsoft\Clipboard] [HKLM\SOFTWARE\Microsoft\ClipboardServer] [HKLM\SOFTWARE\Microsoft\Code Store Database] [HKLM\SOFTWARE\Microsoft\COM3] [HKLM\SOFTWARE\Microsoft\Command Processor] [HKLM\SOFTWARE\Microsoft\CommsAPHost] [HKLM\SOFTWARE\Microsoft\Composition] [HKLM\SOFTWARE\Microsoft\CoreShell] [HKLM\SOFTWARE\Microsoft\Cryptography] [HKLM\SOFTWARE\Microsoft\CTF] [HKLM\SOFTWARE\Microsoft\DataAccess] [HKLM\SOFTWARE\Microsoft\DataCollection] [HKLM\SOFTWARE\Microsoft\DataMarketplace] [HKLM\SOFTWARE\Microsoft\DataSharing] [HKLM\SOFTWARE\Microsoft\DDDS] [HKLM\SOFTWARE\Microsoft\DevDiv] [HKLM\SOFTWARE\Microsoft\Device Association Framework] [HKLM\SOFTWARE\Microsoft\Device Center] [HKLM\SOFTWARE\Microsoft\DeviceReg] [HKLM\SOFTWARE\Microsoft\Dfrg] [HKLM\SOFTWARE\Microsoft\DFS] [HKLM\SOFTWARE\Microsoft\DiagnosticLogCSP] [HKLM\SOFTWARE\Microsoft\DirectDraw] [HKLM\SOFTWARE\Microsoft\DirectInput] [HKLM\SOFTWARE\Microsoft\DirectMusic] [HKLM\SOFTWARE\Microsoft\DirectPlay8] [HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp] [HKLM\SOFTWARE\Microsoft\DirectShow] [HKLM\SOFTWARE\Microsoft\DirectX] [HKLM\SOFTWARE\Microsoft\dot3svc] [HKLM\SOFTWARE\Microsoft\DownloadManager] [HKLM\SOFTWARE\Microsoft\Driver Signing] [HKLM\SOFTWARE\Microsoft\DRM] [HKLM\SOFTWARE\Microsoft\DusmSvc] [HKLM\SOFTWARE\Microsoft\DVDNavigator] [HKLM\SOFTWARE\Microsoft\DVR] [HKLM\SOFTWARE\Microsoft\DXP] [HKLM\SOFTWARE\Microsoft\EAPSIMMethods] [HKLM\SOFTWARE\Microsoft\Enrollment] [HKLM\SOFTWARE\Microsoft\Enrollments] [HKLM\SOFTWARE\Microsoft\EnterpriseCertificates] [HKLM\SOFTWARE\Microsoft\EnterpriseDataProtection] [HKLM\SOFTWARE\Microsoft\EnterpriseResourceManager] [HKLM\SOFTWARE\Microsoft\EventSounds] [HKLM\SOFTWARE\Microsoft\EventSystem] [HKLM\SOFTWARE\Microsoft\Exchange] [HKLM\SOFTWARE\Microsoft\F12] [HKLM\SOFTWARE\Microsoft\FamilyStore] [HKLM\SOFTWARE\Microsoft\Fax] [HKLM\SOFTWARE\Microsoft\FaxServer] [HKLM\SOFTWARE\Microsoft\Feeds] [HKLM\SOFTWARE\Microsoft\FilePicker] [HKLM\SOFTWARE\Microsoft\FilterDS] [HKLM\SOFTWARE\Microsoft\FingerKB] [HKLM\SOFTWARE\Microsoft\FlashConfig] [HKLM\SOFTWARE\Microsoft\FTH] [HKLM\SOFTWARE\Microsoft\Function Discovery] [HKLM\SOFTWARE\Microsoft\Fusion] [HKLM\SOFTWARE\Microsoft\FuzzyDS] [HKLM\SOFTWARE\Microsoft\GameOverlay] [HKLM\SOFTWARE\Microsoft\GPUPipeline] [HKLM\SOFTWARE\Microsoft\HostMIB] [HKLM\SOFTWARE\Microsoft\HTMLHelp] [HKLM\SOFTWARE\Microsoft\Hub] [HKLM\SOFTWARE\Microsoft\IdentityCRL] [HKLM\SOFTWARE\Microsoft\IdentityStore] [HKLM\SOFTWARE\Microsoft\IHDS] [HKLM\SOFTWARE\Microsoft\IMAPI] [HKLM\SOFTWARE\Microsoft\IME] [HKLM\SOFTWARE\Microsoft\IMEJP] [HKLM\SOFTWARE\Microsoft\IMEKR] [HKLM\SOFTWARE\Microsoft\IMETC] [HKLM\SOFTWARE\Microsoft\InetStp] [HKLM\SOFTWARE\Microsoft\InProcLogger] [HKLM\SOFTWARE\Microsoft\Input] [HKLM\SOFTWARE\Microsoft\InputMethod] [HKLM\SOFTWARE\Microsoft\InputPersonalization] [HKLM\SOFTWARE\Microsoft\IntelliPoint] [HKLM\SOFTWARE\Microsoft\IntelliPoint IntelliType Pro Bluetooth] [HKLM\SOFTWARE\Microsoft\IntelliType Pro] [HKLM\SOFTWARE\Microsoft\Internet Account Manager] [HKLM\SOFTWARE\Microsoft\Internet Domains] [HKLM\SOFTWARE\Microsoft\Internet Explorer] [HKLM\SOFTWARE\Microsoft\IsoBurn] [HKLM\SOFTWARE\Microsoft\LanguageOverlay] [HKLM\SOFTWARE\Microsoft\LANManagerMIB2Agent] [HKLM\SOFTWARE\Microsoft\LexiconUpdate] [HKLM\SOFTWARE\Microsoft\Live Mesh] [HKLM\SOFTWARE\Microsoft\LPKSetup] [HKLM\SOFTWARE\Microsoft\MdmCommon] [HKLM\SOFTWARE\Microsoft\MdmDiagnostics] [HKLM\SOFTWARE\Microsoft\MediaEngine] [HKLM\SOFTWARE\Microsoft\MediaPlayer] [HKLM\SOFTWARE\Microsoft\MemoryDiagnostic] [HKLM\SOFTWARE\Microsoft\Messaging] [HKLM\SOFTWARE\Microsoft\MessengerService] [HKLM\SOFTWARE\Microsoft\Microsoft Camera Codec Pack] [HKLM\SOFTWARE\Microsoft\Microsoft Games] [HKLM\SOFTWARE\Microsoft\Microsoft SQL Server Compact Edition] [HKLM\SOFTWARE\Microsoft\MiracastReceiver] [HKLM\SOFTWARE\Microsoft\MMC] [HKLM\SOFTWARE\Microsoft\Mobile] [HKLM\SOFTWARE\Microsoft\MpEngine] [HKLM\SOFTWARE\Microsoft\MpSigStub] [HKLM\SOFTWARE\Microsoft\MSBuild] [HKLM\SOFTWARE\Microsoft\MSDE] [HKLM\SOFTWARE\Microsoft\MSDRM] [HKLM\SOFTWARE\Microsoft\MSDTC] [HKLM\SOFTWARE\Microsoft\MSF] [HKLM\SOFTWARE\Microsoft\MSIME] [HKLM\SOFTWARE\Microsoft\MSLicensing] [HKLM\SOFTWARE\Microsoft\MSMQ] [HKLM\SOFTWARE\Microsoft\MSN Apps] [HKLM\SOFTWARE\Microsoft\MSSQLServer] [HKLM\SOFTWARE\Microsoft\MTF] [HKLM\SOFTWARE\Microsoft\MTFFuzzyFactors] [HKLM\SOFTWARE\Microsoft\MTFInputType] [HKLM\SOFTWARE\Microsoft\MTFKeyboardMappings] [HKLM\SOFTWARE\Microsoft\Multimedia] [HKLM\SOFTWARE\Microsoft\Multivariant] [HKLM\SOFTWARE\Microsoft\NET Framework Setup] [HKLM\SOFTWARE\Microsoft\NetSh] [HKLM\SOFTWARE\Microsoft\Network] [HKLM\SOFTWARE\Microsoft\NetworkAccessProtection] [HKLM\SOFTWARE\Microsoft\Non-Driver Signing] [HKLM\SOFTWARE\Microsoft\Notepad] [HKLM\SOFTWARE\Microsoft\ODBC] [HKLM\SOFTWARE\Microsoft\OEM] [HKLM\SOFTWARE\Microsoft\Office] [HKLM\SOFTWARE\Microsoft\OfficeCSP] [HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform] [HKLM\SOFTWARE\Microsoft\Ole] [HKLM\SOFTWARE\Microsoft\OnlineProviders] [HKLM\SOFTWARE\Microsoft\Outlook Express] [HKLM\SOFTWARE\Microsoft\Palm] [HKLM\SOFTWARE\Microsoft\PCHealth] [HKLM\SOFTWARE\Microsoft\Personalization] [HKLM\SOFTWARE\Microsoft\Phone] [HKLM\SOFTWARE\Microsoft\Photos] [HKLM\SOFTWARE\Microsoft\PIM] [HKLM\SOFTWARE\Microsoft\PLA] [HKLM\SOFTWARE\Microsoft\PlayReady] [HKLM\SOFTWARE\Microsoft\PlayToReceiver] [HKLM\SOFTWARE\Microsoft\PointOfService] [HKLM\SOFTWARE\Microsoft\Policies] [HKLM\SOFTWARE\Microsoft\PolicyManager] [HKLM\SOFTWARE\Microsoft\Poom] [HKLM\SOFTWARE\Microsoft\PowerShell] [HKLM\SOFTWARE\Microsoft\Print] [HKLM\SOFTWARE\Microsoft\Provisioning] [HKLM\SOFTWARE\Microsoft\PushRouter] [HKLM\SOFTWARE\Microsoft\RADAR] [HKLM\SOFTWARE\Microsoft\Ras] [HKLM\SOFTWARE\Microsoft\RcsPresence] [HKLM\SOFTWARE\Microsoft\Reliability Analysis] [HKLM\SOFTWARE\Microsoft\Remediation] [HKLM\SOFTWARE\Microsoft\RemovalTools] [HKLM\SOFTWARE\Microsoft\rempl] [HKLM\SOFTWARE\Microsoft\RendezvousApps] [HKLM\SOFTWARE\Microsoft\RFC1156Agent] [HKLM\SOFTWARE\Microsoft\Router] [HKLM\SOFTWARE\Microsoft\Rpc] [HKLM\SOFTWARE\Microsoft\SchedulingAgent] [HKLM\SOFTWARE\Microsoft\SDDS] [HKLM\SOFTWARE\Microsoft\Security Center] [HKLM\SOFTWARE\Microsoft\SecurityManager] [HKLM\SOFTWARE\Microsoft\SEMgr] [HKLM\SOFTWARE\Microsoft\Sensors] [HKLM\SOFTWARE\Microsoft\ServerManager] [HKLM\SOFTWARE\Microsoft\Settings] [HKLM\SOFTWARE\Microsoft\Shared Tools] [HKLM\SOFTWARE\Microsoft\Shared Tools Location] [HKLM\SOFTWARE\Microsoft\Shell] [HKLM\SOFTWARE\Microsoft\SideShow] [HKLM\SOFTWARE\Microsoft\sih] [HKLM\SOFTWARE\Microsoft\Silverlight] [HKLM\SOFTWARE\Microsoft\Siuf] [HKLM\SOFTWARE\Microsoft\SMB1Uninstall] [HKLM\SOFTWARE\Microsoft\SNMPMIB] [HKLM\SOFTWARE\Microsoft\SNMP_EVENTS] [HKLM\SOFTWARE\Microsoft\Software] [HKLM\SOFTWARE\Microsoft\Speech] [HKLM\SOFTWARE\Microsoft\Speech_OneCore] [HKLM\SOFTWARE\Microsoft\SQMClient] [HKLM\SOFTWARE\Microsoft\StrongName] [HKLM\SOFTWARE\Microsoft\Sync Framework] [HKLM\SOFTWARE\Microsoft\Sysprep] [HKLM\SOFTWARE\Microsoft\SystemCertificates] [HKLM\SOFTWARE\Microsoft\SystemSettings] [HKLM\SOFTWARE\Microsoft\TableTextService] [HKLM\SOFTWARE\Microsoft\TabletTip] [HKLM\SOFTWARE\Microsoft\TaskFlowDataEngine] [HKLM\SOFTWARE\Microsoft\Tcpip] [HKLM\SOFTWARE\Microsoft\TelemetryClient] [HKLM\SOFTWARE\Microsoft\Terminal Server Client] [HKLM\SOFTWARE\Microsoft\TermServLicensing] [HKLM\SOFTWARE\Microsoft\Thumbnail] [HKLM\SOFTWARE\Microsoft\TIP Shared] [HKLM\SOFTWARE\Microsoft\TMM] [HKLM\SOFTWARE\Microsoft\TouchPrediction] [HKLM\SOFTWARE\Microsoft\TPG] [HKLM\SOFTWARE\Microsoft\Tpm] [HKLM\SOFTWARE\Microsoft\Tracing] [HKLM\SOFTWARE\Microsoft\Transaction Server] [HKLM\SOFTWARE\Microsoft\TV System Services] [HKLM\SOFTWARE\Microsoft\uDRM] [HKLM\SOFTWARE\Microsoft\Uev] [HKLM\SOFTWARE\Microsoft\Unified Store] [HKLM\SOFTWARE\Microsoft\Unistore] [HKLM\SOFTWARE\Microsoft\UNP] [HKLM\SOFTWARE\Microsoft\UPnP Control Point] [HKLM\SOFTWARE\Microsoft\UPnP Device Host] [HKLM\SOFTWARE\Microsoft\UserData] [HKLM\SOFTWARE\Microsoft\UserManager] [HKLM\SOFTWARE\Microsoft\Virtual Machine] [HKLM\SOFTWARE\Microsoft\VisualStudio] [HKLM\SOFTWARE\Microsoft\W3SVC] [HKLM\SOFTWARE\Microsoft\WAB] [HKLM\SOFTWARE\Microsoft\Wallet] [HKLM\SOFTWARE\Microsoft\Wbem] [HKLM\SOFTWARE\Microsoft\WcmSvc] [HKLM\SOFTWARE\Microsoft\WIMMount] [HKLM\SOFTWARE\Microsoft\Windows] [HKLM\SOFTWARE\Microsoft\Windows Defender] [HKLM\SOFTWARE\Microsoft\Windows Defender Security Center] [HKLM\SOFTWARE\Microsoft\Windows Desktop Search] [HKLM\SOFTWARE\Microsoft\Windows Live] [HKLM\SOFTWARE\Microsoft\Windows Mail] [HKLM\SOFTWARE\Microsoft\Windows Media Device Manager] [HKLM\SOFTWARE\Microsoft\Windows Media Foundation] [HKLM\SOFTWARE\Microsoft\Windows Media Player NSS] [HKLM\SOFTWARE\Microsoft\Windows Messaging Subsystem] [HKLM\SOFTWARE\Microsoft\Windows NT] [HKLM\SOFTWARE\Microsoft\Windows Performance Toolkit] [HKLM\SOFTWARE\Microsoft\Windows Phone] [HKLM\SOFTWARE\Microsoft\Windows Photo Viewer] [HKLM\SOFTWARE\Microsoft\Windows Portable Devices] [HKLM\SOFTWARE\Microsoft\Windows Script Host] [HKLM\SOFTWARE\Microsoft\Windows Search] [HKLM\SOFTWARE\Microsoft\Windows Security Health] [HKLM\SOFTWARE\Microsoft\Windows10Upgrader] [HKLM\SOFTWARE\Microsoft\WindowsRuntime] [HKLM\SOFTWARE\Microsoft\WindowsSelfHost] [HKLM\SOFTWARE\Microsoft\WindowsStore] [HKLM\SOFTWARE\Microsoft\WindowsUpdate] [HKLM\SOFTWARE\Microsoft\Wisp] [HKLM\SOFTWARE\Microsoft\WlanSvc] [HKLM\SOFTWARE\Microsoft\Wlpasvc] [HKLM\SOFTWARE\Microsoft\Workspaces] [HKLM\SOFTWARE\Microsoft\Wow64] [HKLM\SOFTWARE\Microsoft\Wow64ProxyAgent] [HKLM\SOFTWARE\Microsoft\WSDAPI] [HKLM\SOFTWARE\Microsoft\WwanSvc] [HKLM\SOFTWARE\Microsoft\XAML] [HKLM\SOFTWARE\Microsoft\XboxGameSaveStorage] [HKLM\Software\Microsoft\Windows\ClickNote] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\Dwm] [HKLM\Software\Microsoft\Windows\DynamicManagement] [HKLM\Software\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\Microsoft\Windows\Heat] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\PrivacySettingsBeforeCreatorsUpdate] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\UpdateApi] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\apphost] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\BcastDVRUserService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\btagservice] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\BthAppGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ClipboardSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DevicesFlow] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\diagnostics] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\GraphicsPerfSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\iissvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\PrintWorkflow] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\rdxgroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\RmSvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wusvcs] [HKLM\Software\WOW6432Node\Activision] [HKLM\Software\WOW6432Node\Adobe] [HKLM\Software\WOW6432Node\AdwCleaner] [HKLM\Software\WOW6432Node\AGEIA Technologies] [HKLM\Software\WOW6432Node\Altiris] [HKLM\Software\WOW6432Node\AppDataLow] [HKLM\Software\WOW6432Node\AVAST Software] [HKLM\Software\WOW6432Node\Battlelog Web Plugins] [HKLM\Software\WOW6432Node\Bethesda Softworks] [HKLM\Software\WOW6432Node\BlueRippleSound] [HKLM\Software\WOW6432Node\Bunndle] [HKLM\Software\WOW6432Node\C07ft5Y] [HKLM\Software\WOW6432Node\CAPCOM] [HKLM\Software\WOW6432Node\CAPCOM U.S.A., INC] [HKLM\Software\WOW6432Node\CDDB] [HKLM\Software\WOW6432Node\Combined-Community-Codec-Pack] [HKLM\Software\WOW6432Node\Crytek] [HKLM\Software\WOW6432Node\Cyanide] [HKLM\Software\WOW6432Node\CyberLink] [HKLM\Software\WOW6432Node\DamienBT] [HKLM\Software\WOW6432Node\Danger Close Games] [HKLM\Software\WOW6432Node\Disc Soft] [HKLM\Software\WOW6432Node\DivXNetworks] [HKLM\Software\WOW6432Node\DT Soft] [HKLM\Software\WOW6432Node\EA Games] [HKLM\Software\WOW6432Node\EA SPORTS] [HKLM\Software\WOW6432Node\ej-technologies] [HKLM\Software\WOW6432Node\Electronic Arts] [HKLM\Software\WOW6432Node\ESN Launcher] [HKLM\Software\WOW6432Node\ESN Sonar-0.70.4] [HKLM\Software\WOW6432Node\GNU] [HKLM\Software\WOW6432Node\GOG.com] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\Hewlett-Packard] [HKLM\Software\WOW6432Node\Hewlett-Packard Company] [HKLM\Software\WOW6432Node\HP] [HKLM\Software\WOW6432Node\illiminable] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\IObit] [HKLM\Software\WOW6432Node\JavaSoft] [HKLM\Software\WOW6432Node\JreMetrics] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\KLCodecPack] [HKLM\Software\WOW6432Node\KONAMI] [HKLM\Software\WOW6432Node\LAV] [HKLM\Software\WOW6432Node\Lavasoft] [HKLM\Software\WOW6432Node\Lenovo] [HKLM\Software\WOW6432Node\Lexmark] [HKLM\Software\WOW6432Node\Licenses] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware (Trial)] [HKLM\Software\WOW6432Node\MDNF] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\MimarSinan] [HKLM\Software\WOW6432Node\Morgan] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\mozilla.org] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\mpDRM] [HKLM\Software\WOW6432Node\MusicNet] [HKLM\Software\WOW6432Node\Namco] [HKLM\Software\WOW6432Node\NCH Software] [HKLM\Software\WOW6432Node\nd] [HKLM\Software\WOW6432Node\ND Games] [HKLM\Software\WOW6432Node\Neogie Software] [HKLM\Software\WOW6432Node\Notepad++] [HKLM\Software\WOW6432Node\Nuance] [HKLM\Software\WOW6432Node\NVIDIA Corporation] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\OpenAL] [HKLM\Software\WOW6432Node\OpenOffice] [HKLM\Software\WOW6432Node\Origin] [HKLM\Software\WOW6432Node\Origin Games] [HKLM\Software\WOW6432Node\PDFCreator] [HKLM\Software\WOW6432Node\Piriform] [HKLM\Software\WOW6432Node\Protexis] [HKLM\Software\WOW6432Node\RealNetworks] [HKLM\Software\WOW6432Node\Realtek] [HKLM\Software\WOW6432Node\Realtek Semiconductor Corp.] [HKLM\Software\WOW6432Node\Rebellion] [HKLM\Software\WOW6432Node\Rockstar Games] [HKLM\Software\WOW6432Node\Skype] [HKLM\Software\WOW6432Node\Software] [HKLM\Software\WOW6432Node\Sony Corporation] [HKLM\Software\WOW6432Node\Sony Creative Software] [HKLM\Software\WOW6432Node\Sony Media Software] [HKLM\Software\WOW6432Node\SRS Labs] [HKLM\Software\WOW6432Node\Stellar information Systems ltd.] [HKLM\Software\WOW6432Node\Symantec] [HKLM\Software\WOW6432Node\Telltale Games] [HKLM\Software\WOW6432Node\TeRMiNaToR] [HKLM\Software\WOW6432Node\THQ] [HKLM\Software\WOW6432Node\Thrustmaster] [HKLM\Software\WOW6432Node\TuneUp] [HKLM\Software\WOW6432Node\Ubisoft] [HKLM\Software\WOW6432Node\Valve] [HKLM\Software\WOW6432Node\VobSub] [HKLM\Software\WOW6432Node\Volatile] [HKLM\Software\WOW6432Node\Windows] [HKLM\Software\WOW6432Node\WOW6432Node] [HKLM\Software\WOW6432Node\Xilisoft] [HKLM\Software\WOW6432Node\Xing Technology Corp.] [HKLM\Software\WOW6432Node\Yahoo] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Even Balance] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\.NETFramework] [HKLM\Software\WOW6432Node\Microsoft\Active Setup] [HKLM\Software\WOW6432Node\Microsoft\ADs] [HKLM\Software\WOW6432Node\Microsoft\Advanced INF Setup] [HKLM\Software\WOW6432Node\Microsoft\AMSI] [HKLM\Software\WOW6432Node\Microsoft\AppServiceProtocols] [HKLM\Software\WOW6432Node\Microsoft\ASP.NET] [HKLM\Software\WOW6432Node\Microsoft\ASP.NET MVC 4] [HKLM\Software\WOW6432Node\Microsoft\Assistance] [HKLM\Software\WOW6432Node\Microsoft\AuthHost] [HKLM\Software\WOW6432Node\Microsoft\BidInterface] [HKLM\Software\WOW6432Node\Microsoft\BitLockerCsp] [HKLM\Software\WOW6432Node\Microsoft\ClipboardServer] [HKLM\Software\WOW6432Node\Microsoft\Code Store Database] [HKLM\Software\WOW6432Node\Microsoft\Command Processor] [HKLM\Software\WOW6432Node\Microsoft\Cryptography] [HKLM\Software\WOW6432Node\Microsoft\CTF] [HKLM\Software\WOW6432Node\Microsoft\DataAccess] [HKLM\Software\WOW6432Node\Microsoft\DevDiv] [HKLM\Software\WOW6432Node\Microsoft\Device Association Framework] [HKLM\Software\WOW6432Node\Microsoft\Direct3D] [HKLM\Software\WOW6432Node\Microsoft\DirectDraw] [HKLM\Software\WOW6432Node\Microsoft\DirectInput] [HKLM\Software\WOW6432Node\Microsoft\DirectMusic] [HKLM\Software\WOW6432Node\Microsoft\DirectPlay] [HKLM\Software\WOW6432Node\Microsoft\DirectPlay8] [HKLM\Software\WOW6432Node\Microsoft\DirectPlayNATHelp] [HKLM\Software\WOW6432Node\Microsoft\DirectShow] [HKLM\Software\WOW6432Node\Microsoft\DirectX] [HKLM\Software\WOW6432Node\Microsoft\DownloadManager] [HKLM\Software\WOW6432Node\Microsoft\DRM] [HKLM\Software\WOW6432Node\Microsoft\DVDNavigator] [HKLM\Software\WOW6432Node\Microsoft\DVR] [HKLM\Software\WOW6432Node\Microsoft\EAPSIMMethods] [HKLM\Software\WOW6432Node\Microsoft\ENROLLMENTS] [HKLM\Software\WOW6432Node\Microsoft\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Exchange] [HKLM\Software\WOW6432Node\Microsoft\F12] [HKLM\Software\WOW6432Node\Microsoft\Fax] [HKLM\Software\WOW6432Node\Microsoft\Feeds] [HKLM\Software\WOW6432Node\Microsoft\FilePicker] [HKLM\Software\WOW6432Node\Microsoft\FlashConfig] [HKLM\Software\WOW6432Node\Microsoft\FTH] [HKLM\Software\WOW6432Node\Microsoft\Function Discovery] [HKLM\Software\WOW6432Node\Microsoft\Fusion] [HKLM\Software\WOW6432Node\Microsoft\GameOverlay] [HKLM\Software\WOW6432Node\Microsoft\HTMLHelp] [HKLM\Software\WOW6432Node\Microsoft\IdentityCRL] [HKLM\Software\WOW6432Node\Microsoft\IdentityStore] [HKLM\Software\WOW6432Node\Microsoft\IMAPI] [HKLM\Software\WOW6432Node\Microsoft\IME] [HKLM\Software\WOW6432Node\Microsoft\IMEJP] [HKLM\Software\WOW6432Node\Microsoft\IMEKR] [HKLM\Software\WOW6432Node\Microsoft\IMETC] [HKLM\Software\WOW6432Node\Microsoft\InetStp] [HKLM\Software\WOW6432Node\Microsoft\InputMethod] [HKLM\Software\WOW6432Node\Microsoft\Internet Account Manager] [HKLM\Software\WOW6432Node\Microsoft\Internet Domains] [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer] [HKLM\Software\WOW6432Node\Microsoft\IsoBurn] [HKLM\Software\WOW6432Node\Microsoft\Jet] [HKLM\Software\WOW6432Node\Microsoft\Learning Essentials] [HKLM\Software\WOW6432Node\Microsoft\Live Mesh] [HKLM\Software\WOW6432Node\Microsoft\MediaEngine] [HKLM\Software\WOW6432Node\Microsoft\MediaPlayer] [HKLM\Software\WOW6432Node\Microsoft\MessengerService] [HKLM\Software\WOW6432Node\Microsoft\Microsoft Camera Codec Pack] [HKLM\Software\WOW6432Node\Microsoft\Microsoft SQL Server Compact Edition] [HKLM\Software\WOW6432Node\Microsoft\Migwiz] [HKLM\Software\WOW6432Node\Microsoft\MiracastReceiver] [HKLM\Software\WOW6432Node\Microsoft\MMC] [HKLM\Software\WOW6432Node\Microsoft\MSBuild] [HKLM\Software\WOW6432Node\Microsoft\MSDE] [HKLM\Software\WOW6432Node\Microsoft\MSDRM] [HKLM\Software\WOW6432Node\Microsoft\MSDTC] [HKLM\Software\WOW6432Node\Microsoft\MSF] [HKLM\Software\WOW6432Node\Microsoft\MSLicensing] [HKLM\Software\WOW6432Node\Microsoft\MSN Apps] [HKLM\Software\WOW6432Node\Microsoft\MTF] [HKLM\Software\WOW6432Node\Microsoft\Multimedia] [HKLM\Software\WOW6432Node\Microsoft\NET Framework Setup] [HKLM\Software\WOW6432Node\Microsoft\NetSh] [HKLM\Software\WOW6432Node\Microsoft\Network] [HKLM\Software\WOW6432Node\Microsoft\NetworkAccessProtection] [HKLM\Software\WOW6432Node\Microsoft\Notepad] [HKLM\Software\WOW6432Node\Microsoft\ODBC] [HKLM\Software\WOW6432Node\Microsoft\OEM] [HKLM\Software\WOW6432Node\Microsoft\Office] [HKLM\Software\WOW6432Node\Microsoft\Office Server] [HKLM\Software\WOW6432Node\Microsoft\OfficeSoftwareProtectionPlatform] [HKLM\Software\WOW6432Node\Microsoft\OnlineProviders] [HKLM\Software\WOW6432Node\Microsoft\Outlook Express] [HKLM\Software\WOW6432Node\Microsoft\Palm] [HKLM\Software\WOW6432Node\Microsoft\Photos] [HKLM\Software\WOW6432Node\Microsoft\PLA] [HKLM\Software\WOW6432Node\Microsoft\Policies] [HKLM\Software\WOW6432Node\Microsoft\PowerPoint Viewer] [HKLM\Software\WOW6432Node\Microsoft\PowerShell] [HKLM\Software\WOW6432Node\Microsoft\Print] [HKLM\Software\WOW6432Node\Microsoft\Provisioning] [HKLM\Software\WOW6432Node\Microsoft\RADAR] [HKLM\Software\WOW6432Node\Microsoft\RendezvousApps] [HKLM\Software\WOW6432Node\Microsoft\SchedulingAgent] [HKLM\Software\WOW6432Node\Microsoft\Security Center] [HKLM\Software\WOW6432Node\Microsoft\Sensors] [HKLM\Software\WOW6432Node\Microsoft\ServerManager] [HKLM\Software\WOW6432Node\Microsoft\Shared] [HKLM\Software\WOW6432Node\Microsoft\Shared Tools] [HKLM\Software\WOW6432Node\Microsoft\Shared Tools Location] [HKLM\Software\WOW6432Node\Microsoft\SideShow] [HKLM\Software\WOW6432Node\Microsoft\Silverlight] [HKLM\Software\WOW6432Node\Microsoft\SoftGrid] [HKLM\Software\WOW6432Node\Microsoft\Software] [HKLM\Software\WOW6432Node\Microsoft\SPEECH] [HKLM\Software\WOW6432Node\Microsoft\Speech_OneCore] [HKLM\Software\WOW6432Node\Microsoft\SQMClient] [HKLM\Software\WOW6432Node\Microsoft\Sync Framework] [HKLM\Software\WOW6432Node\Microsoft\SystemSettings] [HKLM\Software\WOW6432Node\Microsoft\TableTextService] [HKLM\Software\WOW6432Node\Microsoft\TabletTip] [HKLM\Software\WOW6432Node\Microsoft\Tcpip] [HKLM\Software\WOW6432Node\Microsoft\Terminal Server Client] [HKLM\Software\WOW6432Node\Microsoft\TIP Shared] [HKLM\Software\WOW6432Node\Microsoft\TouchPrediction] [HKLM\Software\WOW6432Node\Microsoft\TPG] [HKLM\Software\WOW6432Node\Microsoft\Tpm] [HKLM\Software\WOW6432Node\Microsoft\Tracing] [HKLM\Software\WOW6432Node\Microsoft\TV System Services] [HKLM\Software\WOW6432Node\Microsoft\UCCPlatform] [HKLM\Software\WOW6432Node\Microsoft\uDRM] [HKLM\Software\WOW6432Node\Microsoft\Updates] [HKLM\Software\WOW6432Node\Microsoft\UPnP Control Point] [HKLM\Software\WOW6432Node\Microsoft\UPnP Device Host] [HKLM\Software\WOW6432Node\Microsoft\VisualStudio] [HKLM\Software\WOW6432Node\Microsoft\W3SVC] [HKLM\Software\WOW6432Node\Microsoft\WAB] [HKLM\Software\WOW6432Node\Microsoft\WBEM] [HKLM\Software\WOW6432Node\Microsoft\WIMMount] [HKLM\Software\WOW6432Node\Microsoft\Windows] [HKLM\Software\WOW6432Node\Microsoft\Windows Desktop Search] [HKLM\Software\WOW6432Node\Microsoft\Windows Live] [HKLM\Software\WOW6432Node\Microsoft\Windows Live Mail] [HKLM\Software\WOW6432Node\Microsoft\Windows Live Writer] [HKLM\Software\WOW6432Node\Microsoft\Windows Mail] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Device Manager] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Foundation] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Player NSS] [HKLM\Software\WOW6432Node\Microsoft\Windows Messaging Subsystem] [HKLM\Software\WOW6432Node\Microsoft\Windows NT] [HKLM\Software\WOW6432Node\Microsoft\Windows Phone] [HKLM\Software\WOW6432Node\Microsoft\Windows Photo Viewer] [HKLM\Software\WOW6432Node\Microsoft\Windows Portable Devices] [HKLM\Software\WOW6432Node\Microsoft\Windows Script Host] [HKLM\Software\WOW6432Node\Microsoft\WindowsRuntime] [HKLM\Software\WOW6432Node\Microsoft\WindowsUpdate] [HKLM\Software\WOW6432Node\Microsoft\Wisp] [HKLM\Software\WOW6432Node\Microsoft\WlanSvc] [HKLM\Software\WOW6432Node\Microsoft\Workspaces] [HKLM\Software\WOW6432Node\Microsoft\WSDAPI] [HKLM\Software\WOW6432Node\Microsoft\Cellular] [HKLM\Software\WOW6432Node\Microsoft\COM3] [HKLM\Software\WOW6432Node\Microsoft\DeviceReg] [HKLM\Software\WOW6432Node\Microsoft\DFS] [HKLM\Software\WOW6432Node\Microsoft\Driver Signing] [HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates] [HKLM\Software\WOW6432Node\Microsoft\EventSystem] [HKLM\Software\WOW6432Node\Microsoft\FingerKB] [HKLM\Software\WOW6432Node\Microsoft\FuzzyDS] [HKLM\Software\WOW6432Node\Microsoft\Input] [HKLM\Software\WOW6432Node\Microsoft\LanguageOverlay] [HKLM\Software\WOW6432Node\Microsoft\Messaging] [HKLM\Software\WOW6432Node\Microsoft\MSMQ] [HKLM\Software\WOW6432Node\Microsoft\MTFFuzzyFactors] [HKLM\Software\WOW6432Node\Microsoft\MTFInputType] [HKLM\Software\WOW6432Node\Microsoft\MTFKeyboardMappings] [HKLM\Software\WOW6432Node\Microsoft\Non-Driver Signing] [HKLM\Software\WOW6432Node\Microsoft\Ole] [HKLM\Software\WOW6432Node\Microsoft\Phone] [HKLM\Software\WOW6432Node\Microsoft\Pim] [HKLM\Software\WOW6432Node\Microsoft\Poom] [HKLM\Software\WOW6432Node\Microsoft\Ras] [HKLM\Software\WOW6432Node\Microsoft\Rpc] [HKLM\Software\WOW6432Node\Microsoft\SecurityManager] [HKLM\Software\WOW6432Node\Microsoft\Semgr] [HKLM\Software\WOW6432Node\Microsoft\Shell] [HKLM\Software\WOW6432Node\Microsoft\SystemCertificates] [HKLM\Software\WOW6432Node\Microsoft\TermServLicensing] [HKLM\Software\WOW6432Node\Microsoft\Transaction Server] [HKLM\Software\WOW6432Node\Microsoft\Unified Store] [HKLM\Software\WOW6432Node\Microsoft\UserData] [HKLM\Software\WOW6432Node\Microsoft\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\XAML] [HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\Dwm] [HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Windows\Heat] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\UpdateApi] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\iissvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\PrintWorkflow] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wusvcs] ---------- | Drives E: ---------- | C: [03/12/2018 10:27:30] - |SHD| - [52813220831] - C:\$RECYCLE.BIN [MD5.D41D8CD98F00B204E9800998ECF8427E] - [25/12/2018 00:25:45] - |AH| - (.-.) - [0] - (0.0.0.0) - C:\$WINRE_BACKUP_PARTITION.MARKER [26/12/2019 14:10:19] - |D| - [7016] - C:\AdwCleaner [14/07/2009 04:20:08] - |D| - [6971537270] - C:\Backup My Data [14/03/2018 21:18:43] - |SHD| - [1172984] - C:\Config.Msi [10/07/2015 13:21:38] - |SHD| - [0] - C:\Documents and Settings [28/04/2014 10:17:18] - |D| - [914754] - C:\DriveKey [05/05/2019 17:22:30] - |D| - [0] - C:\ESD [26/12/2019 14:17:22] - |D| - [191324024] - C:\FRST [30/03/2012 22:14:51] - |D| - [155637529806] - C:\Games [MD5.D41D8CD98F00B204E9800998ECF8427E] - [27/06/2019 14:13:01] - |ASH| - (.-.) - [6428000256] - (0.0.0.0) - C:\hiberfil.sys [27/06/2019 14:28:28] - |D| - [1011815] - C:\inetpub [03/01/2016 21:46:10] - |D| - [1876736] - C:\Intel [23/01/2013 20:04:53] - |D| - [242806272] - C:\Medion [05/04/2012 21:00:32] - |RHD| - [51376] - C:\MSOCache [MD5.D41D8CD98F00B204E9800998ECF8427E] - [15/01/2017 12:07:11] - |ASH| - (.-.) - [8589934592] - (0.0.0.0) - C:\pagefile.sys [15/09/2018 08:33:50] - |D| - [0] - C:\PerfLogs [15/09/2018 08:33:50] - |RD| - [44497841413] - C:\Program Files [15/09/2018 08:33:50] - |RD| - [635555113069] - C:\Program Files (x86) [15/09/2018 08:33:50] - |HD| - [5433558822] - C:\ProgramData [26/12/2019 16:28:05] - |D| - [68685] - C:\QuickDiag [MD5.0FC42D9C19AAF61F475CFD6AB5B4E6D3] - [26/12/2019 16:28:27] - |A| - (.-.) - [390868] - (0.0.0.0) - C:\QuickDiag.txt [11/08/2015 23:51:26] - |SHD| - [424456536] - C:\Recovery [20/01/2014 11:21:32] - |D| - [26774] - C:\Saves [MD5.D41D8CD98F00B204E9800998ECF8427E] - [11/08/2015 22:54:22] - |ASH| - (.-.) - [268435456] - (0.0.0.0) - C:\swapfile.sys [18/07/2011 11:22:31] - |SHD| - [0] - C:\System Volume Information [15/09/2018 07:09:26] - |RD| - [183649370367] - C:\Users [15/09/2018 07:09:26] - |D| - [40332696404] - C:\Windows [27/06/2019 14:55:26] - |D| - [3082] - C:\Windows.old [06/03/2018 21:43:49] - |D| - [1127899132] - C:\Windows10Upgrade ---------- | C:\WINDOWS [27/01/2014 08:49:00] - |D| - [1710091] - C:\WINDOWS\ACF5FE1B377240688B872D2A6EFD0A05.TMP [15/09/2018 08:33:50] - |D| - [802] - C:\WINDOWS\addins [15/09/2018 08:33:50] - |D| - [17611388] - C:\WINDOWS\appcompat [15/09/2018 08:33:50] - |D| - [8455356] - C:\WINDOWS\apppatch [15/09/2018 08:33:50] - |D| - [0] - C:\WINDOWS\AppReadiness [15/09/2018 08:33:50] - |RD| - [798897078] - C:\WINDOWS\assembly [MD5.12EBDA58437CD1EA7066FCB6455241D2] - [03/01/2017 18:34:45] - |A| - (.Copyright (c) 2014 AVAST Software - avast! Screen Saver stub.) - [53208] - (12.3.3154.0) - C:\WINDOWS\avastSS.scr [06/01/2013 22:20:45] - |D| - [200704] - C:\WINDOWS\B9DB4C7601A446D58910F7AA6376DBAF.TMP [15/09/2018 08:33:50] - |D| - [740161] - C:\WINDOWS\bcastdvr [MD5.49D0AD393AE0B1EE7F3A3DD81B54BFBF] - [15/09/2018 08:28:22] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [78848] - (10.0.17763.1) - C:\WINDOWS\bfsvc.exe [15/09/2018 08:33:50] - |D| - [39076699] - C:\WINDOWS\Boot [MD5.0138C08CBA63A80D0D6B6BF46BECE07C] - [27/06/2019 14:43:18] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [15/09/2018 08:33:50] - |D| - [2449912] - C:\WINDOWS\Branding [15/09/2018 08:23:35] - |D| - [0] - C:\WINDOWS\CbsTemp [MD5.D45FA1C1B94487D50DD06AC4628235D3] - [26/11/2013 22:13:31] - |A| - (.Copyright © 1995 - CKCONFIG MFC Application.) - [165888] - (1.0.0.1) - C:\WINDOWS\Ckconfig.exe [MD5.7A1A627BA8AC85A3C1E863664037008F] - [26/11/2013 22:13:31] - |A| - (.-.) - [11776] - (0.0.0.0) - C:\WINDOWS\Ckrfresh.exe [15/09/2018 08:33:50] - |D| - [29108996] - C:\WINDOWS\Containers [MD5.1F334AC7713E228137147CBFBB7BC9AA] - [15/09/2018 17:41:43] - |A| - (.-.) - [33951] - (0.0.0.0) - C:\WINDOWS\Core.xml [MD5.15E739D75A3ADF100894531DCD1BEF4C] - [26/11/2013 22:13:36] - |A| - (.-.) - [145] - (0.0.0.0) - C:\WINDOWS\Crypkey.ini [MD5.70D88E0F99CD71A8CCFD8012C205DBCC] - [10/02/2011 13:18:35] - |A| - (.-.) - [12] - (0.0.0.0) - C:\WINDOWS\csup.txt [15/09/2018 08:33:50] - |D| - [11482410] - C:\WINDOWS\Cursors [10/02/2011 20:25:14] - |D| - [0] - C:\WINDOWS\de-DE [15/09/2018 08:33:50] - |D| - [22928261] - C:\WINDOWS\debug [MD5.DB84926836ADB9F42D07781864185ABC] - [06/06/2013 22:03:40] - |A| - (.-.) - [288] - (0.0.0.0) - C:\WINDOWS\DeleteOnReboot.bat [MD5.A16E07E6536DF19AE4EA8BDAAEA2C356] - [27/06/2019 14:32:14] - |A| - (.-.) - [15243] - (0.0.0.0) - C:\WINDOWS\diagerr.xml [15/09/2018 08:33:50] - |D| - [4241520] - C:\WINDOWS\diagnostics [MD5.A16E07E6536DF19AE4EA8BDAAEA2C356] - [27/06/2019 14:32:14] - |A| - (.-.) - [15243] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml [15/09/2018 17:39:05] - |D| - [0] - C:\WINDOWS\DigitalLocker [04/06/2015 21:08:03] - |D| - [2145792] - C:\WINDOWS\Downloaded Installations [15/09/2018 08:33:50] - |SD| - [652] - C:\WINDOWS\Downloaded Program Files [02/05/2015 13:40:19] - |D| - [0] - C:\WINDOWS\ehome [15/09/2018 08:33:50] - |HD| - [83824] - C:\WINDOWS\ELAMBKUP [15/09/2018 17:39:05] - |D| - [0] - C:\WINDOWS\en-US [MD5.E185BDA84E5F03F4E1D8DCA30E209277] - [31/12/2012 19:35:11] - |A| - (.-.) - [1912] - (0.0.0.0) - C:\WINDOWS\epplauncher.mif [MD5.E3E2FB5A4D9370E4A9025D53FE752486] - [14/11/2019 12:39:04] - |A| - (.-.) - [2171] - (0.0.0.0) - C:\WINDOWS\error.log [MD5.76A7F77EA749D2F1681C54D28F68EAE3] - [14/11/2019 12:37:28] - |A| - (.-.) - [504] - (0.0.0.0) - C:\WINDOWS\errord.log [10/02/2011 20:33:55] - |D| - [0] - C:\WINDOWS\es-ES [MD5.C25CF941EE6C7927C0A2AB0CB7FABE0B] - [13/11/2019 20:43:52] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4413936] - (10.0.17763.831) - C:\WINDOWS\explorer.exe [15/09/2018 08:33:50] - |RSD| - [377933476] - C:\WINDOWS\Fonts [02/07/2012 21:24:42] - |D| - [107376] - C:\WINDOWS\fr [15/09/2018 17:39:05] - |D| - [110080] - C:\WINDOWS\fr-FR [04/02/2014 12:37:21] - |SHD| - [0] - C:\WINDOWS\ftpcache [15/09/2018 08:33:50] - |D| - [0] - C:\WINDOWS\GameBarPresenceWriter [15/09/2018 08:33:50] - |D| - [53417547] - C:\WINDOWS\Globalization [15/09/2018 08:33:50] - |D| - [78758835] - C:\WINDOWS\Help [MD5.6CAA2887418899D8AA5D4FB06E8DB043] - [11/09/2019 17:28:37] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [1071616] - (10.0.17763.719) - C:\WINDOWS\HelpPane.exe [MD5.1CECEE8D02A8E9B19D3A1A65C7A2B249] - [15/09/2018 08:29:18] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.17763.1) - C:\WINDOWS\hh.exe [MD5.0C79C04EA0F6D5AEB2D03CB5452CA86C] - [20/02/2013 22:08:10] - |A| - (.-.) - [245724] - (0.0.0.0) - C:\WINDOWS\hpoins19.dat [MD5.E366573E4AB73F3EBE169B62ABCF77FC] - [20/02/2013 22:08:10] - |A| - (.-.) - [13898] - (0.0.0.0) - C:\WINDOWS\hpomdl19.dat [MD5.E366573E4AB73F3EBE169B62ABCF77FC] - [20/02/2013 22:17:49] - |A| - (.-.) - [13898] - (0.0.0.0) - C:\WINDOWS\hpomdl19.dat.temp [15/09/2018 08:33:50] - |D| - [29869] - C:\WINDOWS\IdentityCRL [15/09/2018 08:33:50] - |D| - [28822422] - C:\WINDOWS\IME [15/09/2018 08:33:50] - |RD| - [8781665] - C:\WINDOWS\ImmersiveControlPanel [15/09/2018 08:31:55] - |D| - [192740059] - C:\WINDOWS\INF [12/04/2018 00:38:21] - |D| - [0] - C:\WINDOWS\InfusedApps [15/09/2018 08:33:50] - |D| - [38126462] - C:\WINDOWS\InputMethod [15/09/2018 08:33:50] - |SHDC| - [5452569889] - C:\WINDOWS\Installer [10/02/2011 20:49:25] - |D| - [0] - C:\WINDOWS\it-IT [15/09/2018 08:33:50] - |D| - [94163] - C:\WINDOWS\L2Schemas [15/09/2018 08:33:50] - |HD| - [0] - C:\WINDOWS\LanguageOverlayCache [15/09/2018 08:33:50] - |D| - [0] - C:\WINDOWS\LiveKernelReports [15/09/2018 07:09:30] - |D| - [69387985] - C:\WINDOWS\Logs [15/09/2018 08:33:50] - |RSD| - [27977771] - C:\WINDOWS\media [MD5.23AF90D2355D8C83AA4567EF1763B467] - [15/09/2018 08:28:57] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [15/09/2018 08:33:50] - |RD| - [842166386] - C:\WINDOWS\Microsoft.NET [15/09/2018 08:33:50] - |D| - [3323] - C:\WINDOWS\Migration [15/09/2018 08:33:50] - |D| - [0] - C:\WINDOWS\ModemLogs [MD5.B9FB94A8DA62711C6955825DEFB25C5A] - [14/07/2009 03:35:42] - |A| - (.-.) - [1405] - (0.0.0.0) - C:\WINDOWS\msdfmap.ini [19/12/2012 12:32:18] - |HD| - [0] - C:\WINDOWS\msdownld.tmp [10/02/2011 20:54:52] - |D| - [0] - C:\WINDOWS\nl-NL [MD5.0E61079D3283687D2E279272966AE99D] - [29/06/2019 12:49:13] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [254464] - (10.0.17763.475) - C:\WINDOWS\notepad.exe [MD5.74F28574BB8F61FFC7DD419FE6B6E0D5] - [03/12/2018 15:21:24] - |A| - (.-.) - [1951] - (0.0.0.0) - C:\WINDOWS\NvContainerRecovery.bat [15/09/2018 17:40:22] - |D| - [199472] - C:\WINDOWS\OCR [MD5.B38CAED9318BB488C226DFB8A802AE5B] - [28/06/2011 12:21:43] - |A| - (.-.) - [28728] - (0.0.0.0) - C:\WINDOWS\ocsetup_cbs_install_OEMHelpCustomization.txt [MD5.ECB5C579C5959A9F1D29E7579634009C] - [28/06/2011 12:18:43] - |A| - (.-.) - [28739] - (0.0.0.0) - C:\WINDOWS\ocsetup_cbs_uninstall_OEMHelpCustomization.txt [MD5.826A227CAA6C8ABF9289EE0A572E984E] - [28/06/2011 12:21:43] - |A| - (.-.) - [196608] - (0.0.0.0) - C:\WINDOWS\ocsetup_install_OEMHelpCustomization.etl [MD5.E1B3C77AC32CA44EAC023F069985E8BC] - [28/06/2011 12:18:43] - |A| - (.-.) - [131072] - (0.0.0.0) - C:\WINDOWS\ocsetup_uninstall_OEMHelpCustomization.etl [15/09/2018 08:33:50] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [24/06/2019 08:44:40] - |DC| - [402700955] - C:\WINDOWS\Panther [15/09/2018 08:33:50] - |D| - [3648393] - C:\WINDOWS\Performance [MD5.5B4B5AC62BC75F13433E499215FD303E] - [10/10/2016 03:40:01] - |A| - (.-.) - [3081730] - (0.0.0.0) - C:\WINDOWS\PFRO.log [15/09/2018 08:33:50] - |D| - [1136442] - C:\WINDOWS\PLA [15/09/2018 08:33:50] - |D| - [2915239] - C:\WINDOWS\PolicyDefinitions [27/06/2019 13:57:50] - |D| - [23822800] - C:\WINDOWS\Prefetch [15/09/2018 08:33:50] - |RD| - [1910255] - C:\WINDOWS\PrintDialog [MD5.09394999ADB19901C665454EE964B13C] - [20/03/2018 23:29:56] - |A| - (.-.) - [36] - (0.0.0.0) - C:\WINDOWS\progress.ini [15/09/2018 08:33:50] - |D| - [5659611] - C:\WINDOWS\Provisioning [01/01/2013 22:31:46] - |D| - [0] - C:\WINDOWS\pss [10/02/2011 21:05:16] - |D| - [107888] - C:\WINDOWS\pt-PT [MD5.EA0E338038E9651DCD32AC964E4DF0D2] - [20/09/2014 06:11:57] - |A| - (.-.) - [103] - (0.0.0.0) - C:\WINDOWS\Re - Copy.vbs [MD5.12BF1AED617C6E9E8D3427413BDF5E5B] - [20/09/2014 06:11:12] - |A| - (.-.) - [201] - (0.0.0.0) - C:\WINDOWS\Re.vbs [MD5.A3668018735B59050AD123A5A8CDC184] - [27/06/2019 14:37:09] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [358400] - (10.0.17763.168) - C:\WINDOWS\regedit.exe [15/09/2018 08:33:50] - |D| - [1117876] - C:\WINDOWS\Registration [15/09/2018 08:33:50] - |D| - [9782000] - C:\WINDOWS\rescache [15/09/2018 08:33:50] - |D| - [5173578] - C:\WINDOWS\Resources [MD5.12D992C04EE8278FDEBFEFB8B261DAAA] - [15/07/2011 20:57:47] - |A| - (.Copyright (C) 2011 Realtek Semiconductor Corp. - RtlExUpd DLL for setup utility function.) - [1284712] - (1.0.2.7) - C:\WINDOWS\RtlExUpd.dll [15/09/2018 08:33:50] - |D| - [0] - C:\WINDOWS\SchCache [15/09/2018 08:33:50] - |D| - [122082] - C:\WINDOWS\schemas [15/09/2018 08:33:50] - |D| - [8544498] - C:\WINDOWS\security [27/06/2019 14:42:02] - |D| - [108474514] - C:\WINDOWS\ServiceProfiles [15/09/2018 08:33:50] - |D| - [4096] - C:\WINDOWS\ServiceState [15/09/2018 07:09:26] - |D| - [1226721934] - C:\WINDOWS\servicing [15/09/2018 08:36:53] - |D| - [42] - C:\WINDOWS\Setup [MD5.6396BF29EF7260856D9537D6E05BC0A1] - [09/12/2019 18:11:40] - |A| - (.-.) - [1851] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [09/12/2019 18:11:40] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log [MD5.1DC81022E7605CE5FC7BF08ACFE5FD9C] - [26/11/2013 22:13:31] - |A| - (.-.) - [18432] - (0.0.0.0) - C:\WINDOWS\Setup_ck.dll [MD5.178A4F6A92760DD8927B4B8C51E760DB] - [26/11/2013 22:13:31] - |A| - (.-.) - [27648] - (0.0.0.0) - C:\WINDOWS\Setup_ck.exe [15/09/2018 08:33:50] - |D| - [6752256] - C:\WINDOWS\ShellComponents [15/09/2018 08:33:50] - |D| - [52921344] - C:\WINDOWS\ShellExperiences [15/09/2018 08:33:50] - |D| - [3070736] - C:\WINDOWS\SKB [05/03/2012 11:59:27] - |D| - [591046131] - C:\WINDOWS\SoftwareDistribution [15/09/2018 08:33:50] - |D| - [86038209] - C:\WINDOWS\Speech [15/09/2018 08:33:50] - |D| - [63949381] - C:\WINDOWS\Speech_OneCore [MD5.AF0AB44828A9A120DE50814E5806C9DD] - [13/11/2019 20:43:51] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [132608] - (10.0.17763.864) - C:\WINDOWS\splwow64.exe [MD5.4BADBB38E1AF93FC1D9DC939F890E47D] - [03/03/2016 20:20:29] - |A| - (.-.) - [81] - (0.0.0.0) - C:\WINDOWS\spwdrt.INI [15/09/2018 08:33:50] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [14/07/2009 03:34:57] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [15/09/2018 07:09:26] - |D| - [15702762206] - C:\WINDOWS\System32 [15/09/2018 08:33:50] - |D| - [203735693] - C:\WINDOWS\SystemApps [15/09/2018 08:33:51] - |D| - [26533955] - C:\WINDOWS\SystemResources [15/09/2018 07:09:31] - |D| - [1636447228] - C:\WINDOWS\SysWOW64 [15/09/2018 08:33:51] - |D| - [0] - C:\WINDOWS\TAPI [14/07/2009 04:20:14] - |D| - [6] - C:\WINDOWS\Tasks [15/09/2018 08:33:51] - |D| - [146126031] - C:\WINDOWS\Temp [15/09/2018 08:33:51] - |D| - [14425088] - C:\WINDOWS\TextInput [15/09/2018 08:33:51] - |D| - [0] - C:\WINDOWS\tracing [15/09/2018 08:33:51] - |D| - [7680] - C:\WINDOWS\twain_32 [MD5.4B8ED4EF819DC87A2DC108EF60504FE9] - [15/09/2018 08:29:28] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [64512] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [14/09/2018 19:54:25] - |D| - [6780876] - C:\WINDOWS\UpdateAssistant [15/09/2018 08:33:51] - |D| - [12420] - C:\WINDOWS\Vss [15/09/2018 07:09:29] - |D| - [28930] - C:\WINDOWS\WaaS [15/09/2018 08:33:51] - |D| - [17749296] - C:\WINDOWS\Web [MD5.162904DAA5412143F5403233E77F787E] - [14/07/2009 03:34:57] - |A| - (.-.) - [403] - (0.0.0.0) - C:\WINDOWS\win.ini [04/01/2016 09:55:27] - |D| - [45948703] - C:\WINDOWS\WindowsMobile [MD5.C844CA459F3B209329984772269B6E56] - [15/09/2018 08:28:58] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.2CC83D93DD1DDE691158CF5E9882420B] - [31/10/2019 21:04:36] - |A| - (.-.) - [276] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.351FDCE5B7CDE5009C768FFDA64B5E57] - [15/09/2018 08:29:27] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [11776] - (10.0.17763.1) - C:\WINDOWS\winhlp32.exe [15/09/2018 07:09:26] - |D| - [11803604355] - C:\WINDOWS\WinSxS [MD5.4860944ABF2F8EAB74039A3A132B9995] - [08/03/2012 17:37:20] - |A| - (.© 2010 Microsoft Corporation. Tous droits réservés. - Écran de veille photos Windows Live.) - [302448] - (15.4.3555.308) - C:\WINDOWS\WLXPGSS.SCR [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [15/09/2018 08:38:26] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.10F2BC4209233AB34BDA602967D0F798] - [15/09/2018 08:29:24] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.17763.1) - C:\WINDOWS\write.exe [MD5.F9F4905664C5B42B49E78EFA12D1A6B6] - [02/07/2012 19:02:32] - |A| - (.-.) - [20] - (0.0.0.0) - C:\WINDOWS\øôº ---------- | C:\WINDOWS\System32\GroupPolicy ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [09/11/2014 12:03:12] - C:\WINDOWS\Installer\102e8ece.msi : (Gadwin PrintScreenPro (64-Bit) - Gadwin Systems) [Header ok : D0CF11E0A1B11AE10000000000000000] [13/08/2012 19:01:39] - C:\WINDOWS\Installer\14276d30.msi : ( - Konami Digital Entertainment Co., Ltd.) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/12/2015 18:15:29] - C:\WINDOWS\Installer\153228.msi : (NVIDIA System Monitor - NVIDIA Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/12/2015 18:16:27] - C:\WINDOWS\Installer\15322c.msi : (NVIDIA System Update - NVIDIA Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [23/05/2015 21:05:36] - C:\WINDOWS\Installer\1579638.msi : (TcpService - Lavasoft) [Header ok : D0CF11E0A1B11AE10000000000000000] [15/04/2011 10:15:12] - C:\WINDOWS\Installer\15aa6.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [26/04/2011 18:19:22] - C:\WINDOWS\Installer\15aab.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [26/04/2011 18:22:12] - C:\WINDOWS\Installer\15ab9.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [15/04/2011 10:35:32] - C:\WINDOWS\Installer\15abe.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [26/04/2011 18:42:36] - C:\WINDOWS\Installer\15acb.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [26/04/2011 18:31:42] - C:\WINDOWS\Installer\15ad9.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [20/09/2012 11:40:40] - C:\WINDOWS\Installer\162f02.msi : (iMesh - iMesh Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [19/10/2019 08:18:44] - C:\WINDOWS\Installer\17efb99f.msi : (Adobe ARM Installer - Adobe Systems Incorporated) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/12/2015 18:22:14] - C:\WINDOWS\Installer\1b77a0.msi : (NVIDIA Performance - NVIDIA Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [19/06/2012 10:18:50] - C:\WINDOWS\Installer\1f431f8.msi : (Intel(R) Trusted Connect Service Client - Intel Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [05/04/2010 13:08:22] - C:\WINDOWS\Installer\21c4b2.msi : (Grand Theft Auto: Episodes from Liberty City - Rockstar Games Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [12/03/2017 10:05:20] - C:\WINDOWS\Installer\22ecd17e.msi : (LibreOffice 5.3 - The Document Foundation) [Header ok : D0CF11E0A1B11AE10000000000000000] [13/04/2012 08:02:27] - C:\WINDOWS\Installer\2480bd.msi : (Software Update Helper - Boxore OU.) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/03/2015 09:41:29] - C:\WINDOWS\Installer\2501cd.msi : ( - Adobe Systems Incorporated) [Header ok : D0CF11E0A1B11AE10000000000000000] [04/06/2015 21:08:02] - C:\WINDOWS\Installer\268ff6.msi : (Metric Collection SDK Redistributable - Lenovo Group Limited) [Header ok : D0CF11E0A1B11AE10000000000000000] [07/07/2011 16:11:24] - C:\WINDOWS\Installer\29f5b4d.msi : (MSVCRT Redists - Sony Creative Software Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [19/04/2012 07:06:31] - C:\WINDOWS\Installer\29f5b92.msi : (Sound Forge Audio Studio 10.0 - Sony) [Header ok : D0CF11E0A1B11AE10000000000000000] [26/05/2011 17:20:48] - C:\WINDOWS\Installer\309d3.msi : (Blank Project Template - CyberLink Corp.) [Header ok : D0CF11E0A1B11AE10000000000000000] [14/12/2019 15:44:18] - C:\WINDOWS\Installer\36ff7e.msi : (Google Update Helper - Google LLC) [Header ok : D0CF11E0A1B11AE10000000000000000] [27/11/2012 21:23:30] - C:\WINDOWS\Installer\3a49c47.msi : (PMB Installer - Sony Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/11/2014 13:59:20] - C:\WINDOWS\Installer\3b74bb.msi : (Google Update Helper - Google Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [27/08/2017 10:17:58] - C:\WINDOWS\Installer\402bfad.msi : (Java SE Runtime Environment 8 Update 144 - Oracle Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [27/08/2017 10:17:55] - C:\WINDOWS\Installer\402bfba.msi : (Java Auto Updater - Oracle Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [22/11/2010 07:58:56] - C:\WINDOWS\Installer\42fe5.msi : (Spelling Dictionaries for Adobe Reader X - Adobe Systems Incorporated) [Header ok : D0CF11E0A1B11AE10000000000000000] [04/09/2019 02:09:54] - C:\WINDOWS\Installer\555cecc.msi : (OpenOffice 4.1.7 - OpenOffice) [Header ok : D0CF11E0A1B11AE10000000000000000] [10/02/2012 19:13:35] - C:\WINDOWS\Installer\5b78431.msi : (MSVCRT Redists - Sony Creative Software Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [19/04/2012 21:30:09] - C:\WINDOWS\Installer\5b78454.msi : (Vegas Movie Studio HD Platinum 11.0 - Sony) [Header ok : D0CF11E0A1B11AE10000000000000000] [19/04/2012 21:30:09] - C:\WINDOWS\Installer\5b78520.msi : (DVD Architect Studio 5.0 - Sony) [Header ok : D0CF11E0A1B11AE10000000000000000] [21/04/2011 01:53:50] - C:\WINDOWS\Installer\5deafcd.msi : (DiRT 3 - Codemasters) [Header ok : D0CF11E0A1B11AE10000000000000000] [22/10/2012 11:55:05] - C:\WINDOWS\Installer\5fc7b78.msi : (UE3Redist - Epic Games) [Header ok : D0CF11E0A1B11AE10000000000000000] [05/04/2019 20:15:16] - C:\WINDOWS\Installer\61d97932.msi : (Google Earth Pro - Google) [Header ok : D0CF11E0A1B11AE10000000000000000] [03/12/2013 18:08:59] - C:\WINDOWS\Installer\728a6f5.msi : (myphotobook.fr - myphotobook GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [15/01/2015 20:00:49] - C:\WINDOWS\Installer\96b508.msi : (USB 3.0 Host Controller Driver - Renesas Electronics Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [15/01/2015 20:00:49] - C:\WINDOWS\Installer\96b50c.msi : (USB 3.0 Host Controller Driver - Renesas Electronics Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [08/06/2015 18:16:51] - C:\WINDOWS\Installer\b1e9e.msi : (WebCompanion - Lavasoft) [Header ok : D0CF11E0A1B11AE10000000000000000] [10/04/2017 08:49:40] - C:\WINDOWS\Installer\b7ff84c1.msi : (7-Zip Package - Igor Pavlov) [Header ok : D0CF11E0A1B11AE10000000000000000] [10/04/2017 08:50:13] - C:\WINDOWS\Installer\b7ff84dd.msi : (Adobe AIR Installer - Adobe Systems Incorporated) [Header ok : D0CF11E0A1B11AE10000000000000000] [27/11/2017 12:31:22] - C:\WINDOWS\Installer\be457b.msi : (Hardware Detection DriversCloud.com - Cybelsoft) [Header ok : D0CF11E0A1B11AE10000000000000000] [27/09/2006 15:29:28] - C:\WINDOWS\Installer\bfa39.msi : (Company of Heroes - THQ Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [08/07/2009 11:51:17] - C:\WINDOWS\Installer\c4fed1.msi : (64 Bit HP CIO Components Installer Package - Hewlett-Packard) [Header ok : D0CF11E0A1B11AE10000000000000000] [09/12/2019 09:07:55] - [30273536] - (.().-. - ()) - C:\WINDOWS\Installer\102a66a2.msp [24/01/2011 17:16:02] - [14336] - (.().-. - ()) - C:\WINDOWS\Installer\105bc78.msp [12/01/2012 02:01:16] - [21030912] - (.().-. - ()) - C:\WINDOWS\Installer\105bcbc.msp [02/07/2012 21:20:57] - [39936] - (.().-. - ()) - C:\WINDOWS\Installer\106fbd.msp [02/07/2012 21:18:14] - [4426240] - (.().-. - ()) - C:\WINDOWS\Installer\106fe0.msp [02/07/2012 21:18:16] - [2932224] - (.().-. - ()) - C:\WINDOWS\Installer\106ff8.msp [02/07/2012 21:22:45] - [136704] - (.().-. - ()) - C:\WINDOWS\Installer\10700d.msp [02/07/2012 21:22:46] - [1139712] - (.().-. - ()) - C:\WINDOWS\Installer\10701d.msp [02/07/2012 21:22:46] - [715264] - (.().-. - ()) - C:\WINDOWS\Installer\107029.msp [02/07/2012 21:22:48] - [3312128] - (.().-. - ()) - C:\WINDOWS\Installer\107049.msp [02/07/2012 21:22:50] - [5535744] - (.().-. - ()) - C:\WINDOWS\Installer\107062.msp [02/07/2012 21:23:26] - [5868544] - (.().-. - ()) - C:\WINDOWS\Installer\107086.msp [02/07/2012 21:23:27] - [2957312] - (.().-. - ()) - C:\WINDOWS\Installer\1070a4.msp [02/07/2012 21:23:37] - [14624256] - (.().-. - ()) - C:\WINDOWS\Installer\1070d8.msp [02/07/2012 21:23:41] - [3734016] - (.().-. - ()) - C:\WINDOWS\Installer\1070e6.msp [02/07/2012 21:23:42] - [205824] - (.().-. - ()) - C:\WINDOWS\Installer\1070f4.msp [02/07/2012 21:23:44] - [276480] - (.().-. - ()) - C:\WINDOWS\Installer\107135.msp [02/07/2012 21:23:48] - [3105792] - (.().-. - ()) - C:\WINDOWS\Installer\107144.msp [02/07/2012 21:24:31] - [1829376] - (.().-. - ()) - C:\WINDOWS\Installer\107151.msp [02/07/2012 21:18:15] - [29184] - (.().-. - ()) - C:\WINDOWS\Installer\10715b.msp [02/07/2012 21:18:17] - [631296] - (.().-. - ()) - C:\WINDOWS\Installer\107168.msp [02/07/2012 21:24:06] - [469504] - (.().-. - ()) - C:\WINDOWS\Installer\107176.msp [02/07/2012 21:24:07] - [5127680] - (.().-. - ()) - C:\WINDOWS\Installer\107189.msp [02/07/2012 21:24:09] - [665600] - (.().-. - ()) - C:\WINDOWS\Installer\107194.msp [02/07/2012 21:24:11] - [515584] - (.().-. - ()) - C:\WINDOWS\Installer\10719d.msp [02/07/2012 21:24:12] - [2149888] - (.().-. - ()) - C:\WINDOWS\Installer\1071ad.msp [02/07/2012 21:24:13] - [61440] - (.().-. - ()) - C:\WINDOWS\Installer\1071b7.msp [02/07/2012 21:24:13] - [23552] - (.().-. - ()) - C:\WINDOWS\Installer\1071c1.msp [02/07/2012 21:24:13] - [31232] - (.().-. - ()) - C:\WINDOWS\Installer\1071ca.msp [02/07/2012 21:24:46] - [25088] - (.().-. - ()) - C:\WINDOWS\Installer\1071d8.msp [10/02/2016 14:18:20] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\109aa5fd.msp [19/01/2017 11:28:55] - [1937408] - (.().-. - ()) - C:\WINDOWS\Installer\114c12.msp [17/02/2015 17:37:22] - [746496] - (.().-. - ()) - C:\WINDOWS\Installer\1200857.msp [06/02/2015 14:55:06] - [3752960] - (.().-. - ()) - C:\WINDOWS\Installer\1200862.msp [17/02/2015 17:43:42] - [8855552] - (.().-. - ()) - C:\WINDOWS\Installer\120086e.msp [17/02/2015 17:43:02] - [1053696] - (.().-. - ()) - C:\WINDOWS\Installer\120086f.msp [10/02/2015 22:16:22] - [8412160] - (.().-. - ()) - C:\WINDOWS\Installer\1200879.msp [12/07/2013 02:01:12] - [53242368] - (.().-. - ()) - C:\WINDOWS\Installer\12a4751.msp [09/11/2013 14:20:28] - [7577600] - (.().-. - ()) - C:\WINDOWS\Installer\1356446.msp [31/10/2013 11:35:20] - [26079232] - (.().-. - ()) - C:\WINDOWS\Installer\136d573.msp [12/11/2015 02:23:01] - [9075200] - (.().-. - ()) - C:\WINDOWS\Installer\137c050.msp [12/11/2015 02:23:13] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\137c05a.msp [22/10/2014 12:42:50] - [3754496] - (.().-. - ()) - C:\WINDOWS\Installer\13a13fc.msp [05/09/2014 19:54:56] - [397312] - (.().-. - ()) - C:\WINDOWS\Installer\13a1407.msp [01/07/2016 10:17:40] - [3743744] - (.().-. - ()) - C:\WINDOWS\Installer\13f036fc.msp [28/06/2016 09:30:42] - [10895360] - (.().-. - ()) - C:\WINDOWS\Installer\140ac265.msp [10/05/2016 04:20:29] - [58986496] - (.().-. - ()) - C:\WINDOWS\Installer\144e4ae4.msp [06/02/2019 21:40:19] - [53014528] - (.().-. - ()) - C:\WINDOWS\Installer\14bfa373.msp [16/01/2019 21:22:30] - [9031680] - (.().-. - ()) - C:\WINDOWS\Installer\14bfa37b.msp [13/11/2018 05:24:12] - [3485696] - (.().-. - ()) - C:\WINDOWS\Installer\14f1ef.msp [16/02/2016 13:48:12] - [9687040] - (.().-. - ()) - C:\WINDOWS\Installer\154e07b8.msp [23/06/2016 18:42:05] - [53339648] - (.().-. - ()) - C:\WINDOWS\Installer\1553bf4e.msp [08/03/2016 04:45:31] - [2719744] - (.().-. - ()) - C:\WINDOWS\Installer\1597890e.msp [24/07/2013 07:12:50] - [6168064] - (.().-. - ()) - C:\WINDOWS\Installer\15bafa3.msp [24/07/2013 07:08:20] - [28968448] - (.().-. - ()) - C:\WINDOWS\Installer\15bafd4.msp [12/01/2016 04:19:17] - [46080000] - (.().-. - ()) - C:\WINDOWS\Installer\17591c.msp [19/05/2016 04:30:11] - [1429504] - (.().-. - ()) - C:\WINDOWS\Installer\19ff57bd.msp [03/11/2016 08:25:06] - [1642496] - (.().-. - ()) - C:\WINDOWS\Installer\1be9a4.msp [26/11/2014 11:41:36] - [3754496] - (.().-. - ()) - C:\WINDOWS\Installer\1ccb858.msp [12/11/2014 00:00:14] - [1543168] - (.().-. - ()) - C:\WINDOWS\Installer\1ccb862.msp [29/11/2017 11:42:28] - [1355776] - (.().-. - ()) - C:\WINDOWS\Installer\1dec3331.msp [10/10/2016 08:29:03] - [36499456] - (.().-. - ()) - C:\WINDOWS\Installer\207224.msp [11/12/2015 15:06:40] - [8866816] - (.().-. - ()) - C:\WINDOWS\Installer\22c82093.msp [18/12/2015 16:20:42] - [10895360] - (.().-. - ()) - C:\WINDOWS\Installer\22c8209e.msp [13/01/2016 18:47:46] - [53338112] - (.().-. - ()) - C:\WINDOWS\Installer\22c820af.msp [16/08/2019 09:08:46] - [9048064] - (.().-. - ()) - C:\WINDOWS\Installer\23ed6da7.msp [13/05/2019 07:57:34] - [59400192] - (.().-. - ()) - C:\WINDOWS\Installer\257a8857.msp [19/12/2019 09:53:18] - [1863680] - (.().-. - ()) - C:\WINDOWS\Installer\287673b9.msp [02/06/2016 05:48:41] - [2772992] - (.().-. - ()) - C:\WINDOWS\Installer\28f14545.msp [03/01/2019 10:17:04] - [1720320] - (.().-. - ()) - C:\WINDOWS\Installer\29187a8f.msp [22/08/2019 12:14:18] - [2002944] - (.().-. - ()) - C:\WINDOWS\Installer\29a08427.msp [10/12/2018 07:52:51] - [44044288] - (.().-. - ()) - C:\WINDOWS\Installer\29af9be3.msp [29/10/2015 08:48:45] - [1208320] - (.().-. - ()) - C:\WINDOWS\Installer\29aff59f.msp [30/11/2018 13:32:46] - [2023424] - (.().-. - ()) - C:\WINDOWS\Installer\2d347aff.msp [09/07/2015 12:46:23] - [49188864] - (.().-. - ()) - C:\WINDOWS\Installer\3130f1.msp [18/06/2019 13:52:28] - [5652480] - (.().-. - ()) - C:\WINDOWS\Installer\335c7390.msp [27/10/2016 10:49:10] - [3719168] - (.().-. - ()) - C:\WINDOWS\Installer\369d37e.msp [12/10/2016 02:59:04] - [5893120] - (.().-. - ()) - C:\WINDOWS\Installer\3762089.msp [21/03/2016 08:51:40] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\37dcfe.msp [16/03/2016 16:08:48] - [6668288] - (.().-. - ()) - C:\WINDOWS\Installer\37dd08.msp [08/04/2019 07:22:42] - [7155712] - (.().-. - ()) - C:\WINDOWS\Installer\3a5ea0.msp [12/08/2019 07:29:03] - [50438144] - (.().-. - ()) - C:\WINDOWS\Installer\3fa0313a.msp [13/05/2016 09:41:30] - [3747840] - (.().-. - ()) - C:\WINDOWS\Installer\41535b.msp [17/05/2016 16:56:42] - [2978304] - (.().-. - ()) - C:\WINDOWS\Installer\415364.msp [13/06/2019 13:38:00] - [2260992] - (.().-. - ()) - C:\WINDOWS\Installer\41e3c45.msp [12/08/2015 18:32:40] - [1110528] - (.().-. - ()) - C:\WINDOWS\Installer\41f8faf.msp [12/08/2015 18:32:49] - [7955456] - (.().-. - ()) - C:\WINDOWS\Installer\41f8fb8.msp [12/08/2015 18:34:04] - [53332992] - (.().-. - ()) - C:\WINDOWS\Installer\41f8fc8.msp [10/02/2011 21:30:54] - [468992] - (.().-. - ()) - C:\WINDOWS\Installer\42b1f.msp [10/02/2011 21:30:55] - [5126656] - (.().-. - ()) - C:\WINDOWS\Installer\42b33.msp [10/02/2011 21:31:28] - [665088] - (.().-. - ()) - C:\WINDOWS\Installer\42c90.msp [10/02/2011 21:31:29] - [515072] - (.().-. - ()) - C:\WINDOWS\Installer\42c99.msp [10/02/2011 21:31:57] - [2148864] - (.().-. - ()) - C:\WINDOWS\Installer\42dfc.msp [10/02/2011 21:31:57] - [61440] - (.().-. - ()) - C:\WINDOWS\Installer\42e06.msp [10/02/2011 21:32:07] - [23552] - (.().-. - ()) - C:\WINDOWS\Installer\42ea2.msp [12/08/2015 18:49:08] - [758784] - (.().-. - ()) - C:\WINDOWS\Installer\4324f57.msp [12/08/2015 18:49:59] - [3751936] - (.().-. - ()) - C:\WINDOWS\Installer\4324f61.msp [12/08/2015 18:50:32] - [10952192] - (.().-. - ()) - C:\WINDOWS\Installer\4324f6b.msp [14/03/2019 10:49:28] - [8896512] - (.().-. - ()) - C:\WINDOWS\Installer\4462ae.msp [24/10/2019 13:03:06] - [4616192] - (.().-. - ()) - C:\WINDOWS\Installer\4deca62d.msp [25/08/2017 11:21:18] - [5895168] - (.().-. - ()) - C:\WINDOWS\Installer\51aecb.msp [27/08/2017 10:25:28] - [638976] - (.().-. - ()) - C:\WINDOWS\Installer\51aed4.msp [04/09/2017 14:43:06] - [6676480] - (.().-. - ()) - C:\WINDOWS\Installer\51aede.msp [28/08/2017 22:44:32] - [6455296] - (.().-. - ()) - C:\WINDOWS\Installer\51aee8.msp [04/09/2017 13:07:34] - [9108480] - (.().-. - ()) - C:\WINDOWS\Installer\51aef1.msp [28/08/2017 17:40:46] - [2424832] - (.().-. - ()) - C:\WINDOWS\Installer\544128e.msp [18/12/2016 20:55:38] - [3743744] - (.().-. - ()) - C:\WINDOWS\Installer\579aa018.msp [20/11/2013 18:35:18] - [6696448] - (.().-. - ()) - C:\WINDOWS\Installer\57ec7c.msp [25/08/2010 16:06:30] - [6479360] - (.().-. - ()) - C:\WINDOWS\Installer\57ec88.msp [12/09/2007 15:37:22] - [344064] - (.().-. - ()) - C:\WINDOWS\Installer\57ec93.msp [17/05/2011 17:28:52] - [6862848] - (.().-. - ()) - C:\WINDOWS\Installer\57ec9f.msp [12/12/2012 09:40:24] - [6141440] - (.().-. - ()) - C:\WINDOWS\Installer\57ecaa.msp [06/08/2013 08:55:42] - [10988032] - (.().-. - ()) - C:\WINDOWS\Installer\57ecb6.msp [27/03/2014 14:19:08] - [3748864] - (.().-. - ()) - C:\WINDOWS\Installer\57ecc3.msp [24/05/2011 15:27:26] - [60928] - (.().-. - ()) - C:\WINDOWS\Installer\57ecce.msp [27/01/2016 18:03:14] - [8910848] - (.().-. - ()) - C:\WINDOWS\Installer\58051c1.msp [15/01/2016 16:21:20] - [3743744] - (.().-. - ()) - C:\WINDOWS\Installer\58051cc.msp [13/01/2016 10:19:54] - [5639168] - (.().-. - ()) - C:\WINDOWS\Installer\58051d5.msp [05/07/2017 14:37:52] - [9083904] - (.().-. - ()) - C:\WINDOWS\Installer\58b47023.msp [13/11/2017 05:26:16] - [23506944] - (.().-. - ()) - C:\WINDOWS\Installer\5977385a.msp [02/06/2017 23:35:02] - [6668288] - (.().-. - ()) - C:\WINDOWS\Installer\5ac01dd8.msp [05/06/2017 14:00:54] - [637952] - (.().-. - ()) - C:\WINDOWS\Installer\5ac01de1.msp [05/06/2017 13:53:32] - [8860672] - (.().-. - ()) - C:\WINDOWS\Installer\5ac01dea.msp [05/05/2017 22:26:12] - [6455296] - (.().-. - ()) - C:\WINDOWS\Installer\5ac01df4.msp [26/06/2017 10:06:15] - [53350400] - (.().-. - ()) - C:\WINDOWS\Installer\5ac01e04.msp [02/08/2016 12:49:06] - [1511424] - (.().-. - ()) - C:\WINDOWS\Installer\679420d1.msp [24/07/2014 21:48:48] - [53303296] - (.().-. - ()) - C:\WINDOWS\Installer\694126.msp [14/02/2013 09:58:46] - [5850624] - (.().-. - ()) - C:\WINDOWS\Installer\6a0772f.msp [14/03/2013 03:00:57] - [53209600] - (.().-. - ()) - C:\WINDOWS\Installer\6a07741.msp [30/11/2016 12:21:48] - [10891264] - (.().-. - ()) - C:\WINDOWS\Installer\6aac80.msp [16/11/2016 09:17:48] - [638464] - (.().-. - ()) - C:\WINDOWS\Installer\6aac89.msp [13/05/2012 00:02:55] - [53217792] - (.().-. - ()) - C:\WINDOWS\Installer\6ae46.msp [28/06/2011 21:21:32] - [4637184] - (.().-. - ()) - C:\WINDOWS\Installer\6c2c7c.msp [28/06/2011 21:27:28] - [4028928] - (.().-. - ()) - C:\WINDOWS\Installer\6c2c88.msp [26/10/2011 23:23:32] - [8821760] - (.().-. - ()) - C:\WINDOWS\Installer\7033d3e.msp [26/10/2011 23:22:30] - [1071616] - (.().-. - ()) - C:\WINDOWS\Installer\7033d3f.msp [27/06/2013 22:13:14] - [40314880] - (.().-. - ()) - C:\WINDOWS\Installer\7033d58.msp [16/06/2015 16:24:48] - [3755520] - (.().-. - ()) - C:\WINDOWS\Installer\759f08.msp [17/06/2015 14:23:24] - [8835072] - (.().-. - ()) - C:\WINDOWS\Installer\759f12.msp [17/06/2015 14:23:30] - [432128] - (.().-. - ()) - C:\WINDOWS\Installer\759f1a.msp [17/04/2018 18:53:56] - [9064448] - (.().-. - ()) - C:\WINDOWS\Installer\7bc424f2.msp [17/04/2018 18:54:56] - [1417216] - (.().-. - ()) - C:\WINDOWS\Installer\7bc424fb.msp [12/05/2018 07:05:37] - [7094272] - (.().-. - ()) - C:\WINDOWS\Installer\7bc4256d.msp [21/10/2013 22:12:21] - [53242880] - (.().-. - ()) - C:\WINDOWS\Installer\7f5f0f.msp [13/01/2015 15:16:20] - [8894464] - (.().-. - ()) - C:\WINDOWS\Installer\8045c2.msp [06/09/2013 23:07:02] - [11534336] - (.().-. - ()) - C:\WINDOWS\Installer\8045cd.msp [05/11/2014 19:55:34] - [745984] - (.().-. - ()) - C:\WINDOWS\Installer\8045d8.msp [05/12/2014 05:42:54] - [5876736] - (.().-. - ()) - C:\WINDOWS\Installer\8045e3.msp [08/01/2015 15:16:32] - [3752960] - (.().-. - ()) - C:\WINDOWS\Installer\8045ef.msp [16/09/2013 14:15:32] - [8407552] - (.().-. - ()) - C:\WINDOWS\Installer\8045fa.msp [18/07/2014 05:01:00] - [1012736] - (.().-. - ()) - C:\WINDOWS\Installer\804605.msp [11/06/2014 17:25:04] - [8407552] - (.().-. - ()) - C:\WINDOWS\Installer\804610.msp [06/09/2013 23:07:14] - [2347008] - (.().-. - ()) - C:\WINDOWS\Installer\80461b.msp [02/04/2014 02:54:52] - [3246592] - (.().-. - ()) - C:\WINDOWS\Installer\804625.msp [12/11/2014 05:23:48] - [1054720] - (.().-. - ()) - C:\WINDOWS\Installer\804630.msp [15/10/2014 20:12:06] - [5946880] - (.().-. - ()) - C:\WINDOWS\Installer\804673.msp [29/11/2016 10:46:42] - [6455296] - (.().-. - ()) - C:\WINDOWS\Installer\816efa.msp [30/11/2016 17:05:40] - [3719168] - (.().-. - ()) - C:\WINDOWS\Installer\816f04.msp [16/11/2016 09:18:22] - [9089024] - (.().-. - ()) - C:\WINDOWS\Installer\816f0d.msp [26/07/2016 20:41:46] - [6668288] - (.().-. - ()) - C:\WINDOWS\Installer\8663b016.msp [05/08/2016 13:25:54] - [10895360] - (.().-. - ()) - C:\WINDOWS\Installer\8670e909.msp [04/08/2016 15:43:50] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\867ed5bb.msp [12/07/2016 20:22:26] - [8464384] - (.().-. - ()) - C:\WINDOWS\Installer\867ed5c4.msp [20/10/2018 14:18:40] - [774144] - (.().-. - ()) - C:\WINDOWS\Installer\89021f.msp [09/01/2017 04:41:00] - [25853952] - (.().-. - ()) - C:\WINDOWS\Installer\8b4037b2.msp [18/08/2016 06:26:02] - [8467968] - (.().-. - ()) - C:\WINDOWS\Installer\8bd4bfad.msp [15/09/2016 20:20:10] - [53339648] - (.().-. - ()) - C:\WINDOWS\Installer\8bde4776.msp [18/08/2016 06:26:32] - [5889536] - (.().-. - ()) - C:\WINDOWS\Installer\8bde477e.msp [15/08/2016 14:21:08] - [10891264] - (.().-. - ()) - C:\WINDOWS\Installer\8bde4788.msp [13/09/2018 19:25:16] - [9035776] - (.().-. - ()) - C:\WINDOWS\Installer\9387e812.msp [13/09/2018 19:24:58] - [5918720] - (.().-. - ()) - C:\WINDOWS\Installer\9387e81b.msp [22/01/2019 16:38:42] - [8855552] - (.().-. - ()) - C:\WINDOWS\Installer\94bbf74a.msp [22/01/2019 16:39:00] - [7778304] - (.().-. - ()) - C:\WINDOWS\Installer\9560c427.msp [04/03/2014 22:24:38] - [327680] - (.().-. - ()) - C:\WINDOWS\Installer\970145.msp [20/04/2016 05:41:02] - [8040960] - (.().-. - ()) - C:\WINDOWS\Installer\9916b3d.msp [04/05/2016 17:24:46] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\9916b48.msp [21/02/2017 13:33:51] - [12845056] - (.().-. - ()) - C:\WINDOWS\Installer\9959cf59.msp [17/04/2014 15:09:20] - [1133568] - (.().-. - ()) - C:\WINDOWS\Installer\996534.msp [22/04/2014 15:00:46] - [6168064] - (.().-. - ()) - C:\WINDOWS\Installer\99653d.msp [13/11/2019 12:16:36] - [1527808] - (.().-. - ()) - C:\WINDOWS\Installer\9a3aa6c2.msp [12/07/2016 04:25:29] - [39538688] - (.().-. - ()) - C:\WINDOWS\Installer\9f7e884.msp [08/12/2015 20:39:05] - [53336064] - (.().-. - ()) - C:\WINDOWS\Installer\a186f96.msp [08/12/2015 20:40:49] - [6668288] - (.().-. - ()) - C:\WINDOWS\Installer\a186fa0.msp [08/12/2015 20:41:17] - [8869376] - (.().-. - ()) - C:\WINDOWS\Installer\a186faa.msp [08/12/2015 20:41:59] - [758784] - (.().-. - ()) - C:\WINDOWS\Installer\a186fb4.msp [08/12/2015 20:42:22] - [3743744] - (.().-. - ()) - C:\WINDOWS\Installer\a186fbf.msp [12/05/2015 22:22:32] - [53332992] - (.().-. - ()) - C:\WINDOWS\Installer\a1d4ce.msp [17/02/2015 04:40:06] - [3084288] - (.().-. - ()) - C:\WINDOWS\Installer\a1d4d8.msp [15/04/2015 11:18:14] - [9088512] - (.().-. - ()) - C:\WINDOWS\Installer\a39354.msp [01/04/2015 11:30:34] - [5764096] - (.().-. - ()) - C:\WINDOWS\Installer\a3935e.msp [18/02/2015 00:17:08] - [421888] - (.().-. - ()) - C:\WINDOWS\Installer\a39369.msp [15/04/2015 11:18:14] - [8030208] - (.().-. - ()) - C:\WINDOWS\Installer\a4b63f.msp [15/04/2015 11:18:52] - [5877248] - (.().-. - ()) - C:\WINDOWS\Installer\a4b649.msp [21/04/2015 12:17:56] - [30257152] - (.().-. - ()) - C:\WINDOWS\Installer\a4b66f.msp [14/11/2015 19:57:25] - [7851008] - (.().-. - ()) - C:\WINDOWS\Installer\a567b.msp [25/07/2014 17:08:26] - [10416128] - (.().-. - ()) - C:\WINDOWS\Installer\a5957b.msp [23/07/2014 19:30:10] - [10473472] - (.().-. - ()) - C:\WINDOWS\Installer\a7e3bb.msp [26/03/2018 18:16:24] - [5918720] - (.().-. - ()) - C:\WINDOWS\Installer\a9d2a211.msp [26/03/2018 18:15:46] - [761856] - (.().-. - ()) - C:\WINDOWS\Installer\a9d2a21a.msp [26/03/2018 18:15:06] - [9060352] - (.().-. - ()) - C:\WINDOWS\Installer\a9d2a223.msp [22/10/2018 14:33:19] - [2584576] - (.().-. - ()) - C:\WINDOWS\Installer\b062c.msp [04/09/2014 21:29:54] - [856064] - (.().-. - ()) - C:\WINDOWS\Installer\b0a95e.msp [22/03/2015 22:16:26] - [30203392] - (.().-. - ()) - C:\WINDOWS\Installer\b49385.msp [22/03/2015 22:17:58] - [5605888] - (.().-. - ()) - C:\WINDOWS\Installer\b4938d.msp [17/03/2015 08:10:52] - [3751424] - (.().-. - ()) - C:\WINDOWS\Installer\b49397.msp [22/03/2015 22:15:56] - [8028672] - (.().-. - ()) - C:\WINDOWS\Installer\b493a1.msp [25/03/2015 07:24:06] - [8896512] - (.().-. - ()) - C:\WINDOWS\Installer\b493ab.msp [06/02/2015 02:34:26] - [10502144] - (.().-. - ()) - C:\WINDOWS\Installer\b493ca.msp [08/08/2014 17:41:08] - [2473984] - (.().-. - ()) - C:\WINDOWS\Installer\b4dfc0.msp [13/10/2015 04:26:31] - [21102592] - (.().-. - ()) - C:\WINDOWS\Installer\b5851b51.msp [16/10/2015 22:05:01] - [5976064] - (.().-. - ()) - C:\WINDOWS\Installer\b659720a.msp [16/10/2015 22:05:49] - [8987648] - (.().-. - ()) - C:\WINDOWS\Installer\b6597213.msp [10/04/2017 09:38:07] - [53348864] - (.().-. - ()) - C:\WINDOWS\Installer\b82be571.msp [02/02/2017 18:09:36] - [6455296] - (.().-. - ()) - C:\WINDOWS\Installer\b82be57a.msp [04/03/2017 10:25:00] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\b82be584.msp [03/03/2017 15:59:24] - [6668288] - (.().-. - ()) - C:\WINDOWS\Installer\b82be58e.msp [16/02/2017 16:11:28] - [638976] - (.().-. - ()) - C:\WINDOWS\Installer\b82be597.msp [22/05/2015 11:58:06] - [8036352] - (.().-. - ()) - C:\WINDOWS\Installer\b95bf0.msp [22/05/2015 11:57:58] - [9068032] - (.().-. - ()) - C:\WINDOWS\Installer\b95bfa.msp [22/05/2015 11:58:38] - [5877248] - (.().-. - ()) - C:\WINDOWS\Installer\b95c04.msp [13/03/2014 23:43:21] - [53303296] - (.().-. - ()) - C:\WINDOWS\Installer\bd2455.msp [31/01/2014 16:19:26] - [6185472] - (.().-. - ()) - C:\WINDOWS\Installer\bd245e.msp [18/04/2017 15:29:56] - [3743744] - (.().-. - ()) - C:\WINDOWS\Installer\c4476846.msp [12/04/2017 11:25:28] - [9121280] - (.().-. - ()) - C:\WINDOWS\Installer\c447684f.msp [14/10/2015 10:40:18] - [1224704] - (.().-. - ()) - C:\WINDOWS\Installer\c5d34f66.msp [31/07/2007 13:29:20] - [12880896] - (.().-. - ()) - C:\WINDOWS\Installer\caa3e.msp [17/05/2018 11:40:20] - [7991296] - (.().-. - ()) - C:\WINDOWS\Installer\d0558d23.msp [26/06/2018 11:38:18] - [761856] - (.().-. - ()) - C:\WINDOWS\Installer\d0558d2d.msp [27/06/2018 07:11:14] - [1417216] - (.().-. - ()) - C:\WINDOWS\Installer\d0558d37.msp [30/07/2018 15:13:26] - [9052160] - (.().-. - ()) - C:\WINDOWS\Installer\d0558d40.msp [10/04/2017 06:34:32] - [57815040] - (.().-. - ()) - C:\WINDOWS\Installer\d2504528.msp [02/04/2017 00:41:10] - [8898048] - (.().-. - ()) - C:\WINDOWS\Installer\d33a05ac.msp [15/04/2017 15:43:30] - [53348864] - (.().-. - ()) - C:\WINDOWS\Installer\d33a05bc.msp [25/11/2015 10:42:23] - [212992] - (.().-. - ()) - C:\WINDOWS\Installer\d670d1.msp [03/10/2016 15:23:16] - [6668288] - (.().-. - ()) - C:\WINDOWS\Installer\d99187e.msp [12/10/2016 19:05:47] - [53345280] - (.().-. - ()) - C:\WINDOWS\Installer\d99188e.msp [05/10/2016 09:46:48] - [3739648] - (.().-. - ()) - C:\WINDOWS\Installer\da46a13.msp [23/02/2018 14:25:19] - [1343488] - (.().-. - ()) - C:\WINDOWS\Installer\ec68169a.msp [14/09/2017 02:40:08] - [1410560] - (.().-. - ()) - C:\WINDOWS\Installer\ee94e8cf.msp [27/10/2017 09:20:04] - [3747840] - (.().-. - ()) - C:\WINDOWS\Installer\ee94e8d8.msp [19/01/2018 14:22:44] - [5892608] - (.().-. - ()) - C:\WINDOWS\Installer\ee94e8e1.msp [19/01/2018 14:18:12] - [9095168] - (.().-. - ()) - C:\WINDOWS\Installer\ee94e8ea.msp ---------- | %System%\*.in* [15/09/2018 08:29:16] - [3329] - C:\WINDOWS\System32\ieuinit.inf [27/06/2019 14:20:26] - [2008672] - C:\WINDOWS\System32\PerfStringBackup.INI [15/09/2018 08:28:56] - [60124] - C:\WINDOWS\System32\tcpmon.ini [15/09/2018 08:28:42] - [2404] - C:\WINDOWS\System32\WimBootCompress.ini [15/09/2018 08:29:28] - [3329] - C:\WINDOWS\Syswow64\ieuinit.inf [19/09/2012 22:46:43] - [866] - C:\WINDOWS\Syswow64\InstallUtil.InstallLog [17/04/2017 21:38:05] - [2049916] - C:\WINDOWS\Syswow64\PerfStringBackup.INI [15/09/2018 08:29:07] - [2404] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\AppPatch\Custom\Custom64 [MD5.EF6254A58776FB0C09999406501C5CB2] - |A| - [22/12/2019 11:25:24] - (.-.) - [1.88 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\AdobeARM.log [MD5.864C22FB9A1C0670EDF01C6ED3E4FBE4] - |A| - [22/12/2019 11:25:55] - (.-.) - [251.88 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\ArmUI.ini [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:12:58] - [0 Ko] - C:\WINDOWS\Temp\as_A90C.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:32:43] - [139238.4 Ko] - C:\WINDOWS\Temp\avast_ash2 [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 21:38:08] - [0 Ko] - C:\WINDOWS\Temp\BB633262-0884-4D1D-91DF-F65C04147839-Sigs [MD5.A5EA0AD9260B1550A14CC58D2C39B03D] - |AH| - [30/11/2018 22:24:50] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\BITA005.tmp [MD5.6AF2D23BB95C64E3A37A80BD1F128A8F] - |A| - [18/12/2019 17:55:18] - (.-.) - [29.62 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\chrome_installer.log [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:18:24] - [0.04 Ko] - C:\WINDOWS\Temp\Crashpad [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 19:49:54] - [2190.91 Ko] - C:\WINDOWS\Temp\CR_921AA.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:08:26] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_alternativeTrace [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:08:26] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_aot [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:08:26] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_diag [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:08:26] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_miniTrace [MD5.207EBA2BB0D6BAFA22904114063FCB9C] - |A| - [22/12/2019 15:21:10] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191222-152110-0.log [MD5.EFAD7406596DE51B9ABB8223FD1AA831] - |A| - [23/12/2019 18:39:17] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191223-183917-0.log [MD5.A0567DF4E04137B5E4402C713852A5CF] - |A| - [25/12/2019 11:51:26] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191225-115125-0.log [MD5.BA14189B1D8AFD3FEA9B3300BB61D002] - |A| - [26/12/2019 11:37:19] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191226-113719-0.log [MD5.5D49F1044FE352B04DD8C37969B31DC2] - |A| - [26/12/2019 14:41:37] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191226-144137-0.log [MD5.14F38207E940538D3EB70A6B2AB6AE95] - |A| - [26/12/2019 15:08:19] - (.-.) - [2.59 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191226-150819-0.log [MD5.70EC9FA4D730607802EF3B24BBF83F0E] - |A| - [27/06/2019 14:51:39] - (.-.) - [359.2 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\mavcperf-setup.log [MD5.87825FA7B4C11556247AF1CD6EAF3B4E] - |A| - [27/06/2019 14:34:32] - (.-.) - [482.11 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpCmdRun.log [MD5.1A2884238408661F72EB305C10D4F9A9] - |A| - [08/12/2019 21:38:08] - (.-.) - [110.63 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpSigStub.log [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:23:06] - [0 Ko] - C:\WINDOWS\Temp\MPTelemetrySubmit [MD5.6B01C32C20E80663325BD33F2FFAB2E1] - |A| - [19/12/2019 09:36:31] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI16805.LOG [MD5.022F4FB342AF2FF88D446F21997E1D07] - |A| - [19/12/2019 11:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI18963.LOG [MD5.16BFEE1CAF42DEF15DFFEF84EBB148E1] - |A| - [21/12/2019 19:34:34] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI1a81c.LOG [MD5.DF04639BB1A1E7AF93DDD863D978CB2D] - |A| - [25/12/2019 15:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI1d5f0.LOG [MD5.E47754271A8ACAEF4AAEE3F7F645CC62] - |A| - [19/12/2019 11:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI1f4f2.LOG [MD5.732601266EBED1A09104C352230822DC] - |A| - [20/12/2019 20:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI23618.LOG [MD5.40D6671D47783D75352954700BAC3F06] - |A| - [25/12/2019 22:04:03] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI26062.LOG [MD5.E24AE2462EFA2B6AE4556EE1B9202ADE] - |A| - [22/12/2019 13:04:04] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI27f45.LOG [MD5.3E9F2E9D03442CB1F09C4CA69E4E4885] - |A| - [19/12/2019 15:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI2da9c.LOG [MD5.38F4AE99D73609C7903CCAD0DFD1F6E6] - |A| - [23/12/2019 18:28:25] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI305c8.LOG [MD5.EB68EAE44BA1435EE9878ACB8FD4D51A] - |A| - [22/12/2019 12:12:18] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI31cd6.LOG [MD5.F0558B7B26407D579DA2214D4BFCEB6B] - |A| - [21/12/2019 20:11:07] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI31d9a.LOG [MD5.2F9B24A9B309B357B8A015CDDB00098A] - |A| - [19/12/2019 10:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI320c.LOG [MD5.68B26A369E4E9676EED6E3538A9347DA] - |A| - [26/12/2019 16:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI382b4.LOG [MD5.683CBF1BE16D7AEE750609FB1B690E37] - |A| - [21/12/2019 21:04:05] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI39b4c.LOG [MD5.7B070B9CB3A4939CA9E128E8384828D0] - |A| - [24/12/2019 20:19:35] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI3b21a.LOG [MD5.A09134E28FAF0E213D4934FA1FF4A5C0] - |A| - [25/12/2019 13:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI3f92f.LOG [MD5.9EA2980BE1D10CC6342BEDFA765E2508] - |A| - [19/12/2019 09:39:28] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI417e3.LOG [MD5.61BCE995D5021453208B757025343D8E] - |A| - [19/12/2019 16:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI42dad.LOG [MD5.2C8C7702A213A4D10D5CB2A22BC038D1] - |A| - [22/12/2019 20:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI43680.LOG [MD5.4E5F8E6CDD26B7345121AE948B066CCB] - |A| - [25/12/2019 20:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI48268.LOG [MD5.392EDE19533ADF2759866891CCF86AE3] - |A| - [24/12/2019 18:18:23] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI4bc67.LOG [MD5.C6B17FD3380EE28C542BBB1723CEB5F3] - |A| - [19/12/2019 13:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI4fd8c.LOG [MD5.F488A1E15F09A867589376C7BCD9EA92] - |A| - [22/12/2019 15:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI5550.LOG [MD5.E32005A0CF9F6B04FFE148FBAECDCBD0] - |A| - [22/12/2019 14:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI556f9.LOG [MD5.99B2E29F325E4C76400355B017F9B531] - |A| - [26/12/2019 15:04:03] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI58ac5.LOG [MD5.8069388B7D131ABCDAA05243A3E7AC83] - |A| - [21/12/2019 19:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI5b459.LOG [MD5.4B7A437F44B0117CB91851F87EA84B58] - |A| - [24/12/2019 18:19:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI5cea2.LOG [MD5.EF3BEBBDB604CDC38B80088424DAD317] - |A| - [18/12/2019 21:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI61463.LOG [MD5.CC5B054F2CACA7A4220E45F207C7CBCE] - |A| - [21/12/2019 19:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI620b4.LOG [MD5.FF9D8A0C97D824F4F083BD88C17186F6] - |A| - [23/12/2019 21:04:14] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6376f.LOG [MD5.39158CB1D16B84BFD39915224F686780] - |A| - [20/12/2019 20:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6467b.LOG [MD5.467E92A0D64D6484180B0E5723453295] - |A| - [19/12/2019 14:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI654c4.LOG [MD5.7F65A840BC92E0EA1932BA4DFD6EA460] - |A| - [22/12/2019 18:04:03] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI65d0a.LOG [MD5.84AF8F7AD670AB0F9AFF10945E1870EB] - |A| - [21/12/2019 22:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI67022.LOG [MD5.1B7D469851A139729BA2EC3725BF8506] - |A| - [22/12/2019 11:23:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI67a82.LOG [MD5.801952B5FFEF7C7BC154026E38A7AB04] - |A| - [25/12/2019 18:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6a549.LOG [MD5.563578CD9A6B3FCC1DA7E05E0E0CB4CC] - |A| - [24/12/2019 20:05:22] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6b025.LOG [MD5.12E8DC1FE1D7AD45E9555CA1F3209B7A] - |A| - [20/12/2019 20:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6b324.LOG [MD5.68E5829A5B03EADFED9AF41A11C12FE8] - |A| - [19/12/2019 14:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6c092.LOG [MD5.C8EA98CD90185035AD52AE2102A28D78] - |A| - [22/12/2019 15:11:07] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6d129.LOG [MD5.88B46CDF755470E5B960D598310A815A] - |A| - [19/12/2019 21:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6d8fb.LOG [MD5.1B9A00D0FCDE35F00F464E5DD84765F9] - |A| - [19/12/2019 19:36:41] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI6e1ea.LOG [MD5.E8AACDC377EFE0640C275F55F2789BDD] - |A| - [19/12/2019 11:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI7208c.LOG [MD5.E526EDC366DDC19328E75357DD4F5124] - |A| - [19/12/2019 20:39:34] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI7338.LOG [MD5.8989471C0111CBD52B16421117183CE3] - |A| - [18/12/2019 22:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI76b2d.LOG [MD5.46DBD126E96F65AC6F4C74A614947449] - |A| - [22/12/2019 12:34:47] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI7b377.LOG [MD5.3D9FC2936677FD876079F9247CFEFFF0] - |A| - [18/12/2019 21:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI7d0b.LOG [MD5.1E2CDD906FB2B7285341C6160E407F1E] - |A| - [26/12/2019 14:04:21] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI80eee.LOG [MD5.4EFD0C7D55127487D8840A83E84FD002] - |A| - [23/12/2019 19:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI82c4b.LOG [MD5.9C2E8DF920EDA87459E6A1EBA2B07B69] - |A| - [19/12/2019 12:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI877e3.LOG [MD5.7015AB4E8FD9E4182E74DB1F99269E8F] - |A| - [22/12/2019 16:04:06] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI88b16.LOG [MD5.DCAB88D33BB41BB4EC78DE96890319A9] - |A| - [25/12/2019 10:41:14] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI89108.LOG [MD5.8ED1C834576648376DD57F10BFBA1FBA] - |A| - [21/12/2019 20:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI89218.LOG [MD5.F8DE95E99F5F0FBF156DF30755034738] - |A| - [25/12/2019 16:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI8c4af.LOG [MD5.6C8D84DF4ED73F5469EDD6261D04411B] - |A| - [22/12/2019 11:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI8d0f.LOG [MD5.83EB7163839428992DDEE408177D573C] - |A| - [19/12/2019 12:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI8e392.LOG [MD5.3C7B23D750D131B419405A2399D6661F] - |A| - [22/12/2019 13:11:07] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI8f40a.LOG [MD5.AD37B989790C62A34AA094F9DC3D1358] - |A| - [20/12/2019 21:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI92488.LOG [MD5.895F5197E769ADE3E28E0EE34A5B806C] - |A| - [22/12/2019 14:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI966fe.LOG [MD5.77C67DF8D36D0BB3866DBE7719A741E2] - |A| - [19/12/2019 19:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI96902.LOG [MD5.298DA531B8CD71465B4E01889752EDFD] - |A| - [26/12/2019 13:31:19] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI9c564.LOG [MD5.BE0089681F507CA0A941638205CDEE48] - |A| - [19/12/2019 16:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI9c90c.LOG [MD5.DDCFE62A47CA5395FF5378CE78C0FE8E] - |A| - [20/12/2019 18:40:35] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI9d16c.LOG [MD5.D67A59D4C30893FB41C3AE302117C0C6] - |A| - [18/12/2019 20:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSI9fba1.LOG [MD5.ED5F632FC2C58565657EC8F49062344F] - |A| - [21/12/2019 21:11:07] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIa0c0a.LOG [MD5.80480032E3C1BA924CAB747C3A02D291] - |A| - [21/12/2019 22:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIa7eef.LOG [MD5.6E29395DE8777FF6CE3067793C390FBB] - |A| - [19/12/2019 10:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIa9ad3.LOG [MD5.5AD6ADAF1BC47A1093A1D0A4CBB89266] - |A| - [24/12/2019 21:19:34] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIa9ea6.LOG [MD5.3500998318D1F8832F241DDE626E4800] - |A| - [21/12/2019 18:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIab670.LOG [MD5.3D2480FB45ADD7C839132F6567E902B9] - |A| - [25/12/2019 14:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIae770.LOG [MD5.1A897E89DF39E1575964897D783255F9] - |A| - [19/12/2019 10:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIb071e.LOG [MD5.043D1389E976210722F609CBA5741A05] - |A| - [21/12/2019 18:17:28] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIb11cc.LOG [MD5.96048812F9D67ED34A0FB6C2DB9F3508] - |A| - [22/12/2019 21:04:06] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIb3423.LOG [MD5.3EFD6614EA993741E9D2D1E36D6676FF] - |A| - [20/12/2019 19:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIb4a57.LOG [MD5.C1FB94C196B9A5487E024522BEA345D7] - |A| - [25/12/2019 21:04:05] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIb79a2.LOG [MD5.8A9878AC064EC830B7B2D71338591A5E] - |A| - [25/12/2019 11:19:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIba5ed.LOG [MD5.8FAE8F0DDC8400CCD7905B3AFC18E587] - |A| - [19/12/2019 14:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIbeca8.LOG [MD5.C245EF7C7742E78C9CDDF625BCBF8C8E] - |A| - [21/12/2019 19:11:08] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIc3340.LOG [MD5.E1F4E6FE74981B3A3058370A82DE8785] - |A| - [24/12/2019 21:04:03] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIc6933.LOG [MD5.1C42FF4AD1FB3FFCA903F7EBC156AFF5] - |A| - [22/12/2019 12:05:04] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIc7d09.LOG [MD5.BAAA48E2C2FE18251AFD3210CDF7A200] - |A| - [21/12/2019 20:04:05] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIcacad.LOG [MD5.983C481803A735C06D5CBCAC8A9FB63A] - |A| - [26/12/2019 11:04:19] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIcbb71.LOG [MD5.3EC3C564D8803FFF45A74755BD3D9427] - |A| - [24/12/2019 19:19:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIcbded.LOG [MD5.64EE8BA78812BFB2AB0C05FE66F89ED3] - |A| - [23/12/2019 22:04:06] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId05d4.LOG [MD5.F1FBC38ED3ED31D0D57FDCC495BDE303] - |A| - [21/12/2019 20:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId0f34.LOG [MD5.FA431A6169F24B23E178E0077B19393D] - |A| - [25/12/2019 12:04:04] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId133a.LOG [MD5.8088B4145F7D0ECD7F1801400CD7BAD6] - |A| - [20/12/2019 21:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId3653.LOG [MD5.C7AC2DC515BE226838608B79A0AD4BFD] - |A| - [19/12/2019 15:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId4344.LOG [MD5.1356FAD500FF0A2EDACAB5E1E5532285] - |A| - [22/12/2019 19:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId48fa.LOG [MD5.8EE949FBE62491251F9895E195A2503D] - |A| - [25/12/2019 11:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId6e18.LOG [MD5.E29CEEB5E76ADA0E168439126B67DEAD] - |A| - [25/12/2019 19:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSId93a9.LOG [MD5.5B831D8350354951558AE9C01FE6AF35] - |A| - [20/12/2019 21:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIda1e3.LOG [MD5.97CFEA64256803415B1CD79A579DD4E5] - |A| - [19/12/2019 15:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIdaf12.LOG [MD5.93946D560E07F8151E3DB664A2E52F50] - |A| - [19/12/2019 12:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIe0efc.LOG [MD5.A74E200760DE82AFE038706DBCF435B7] - |A| - [22/12/2019 13:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIe6b28.LOG [MD5.90AD226146ED669B4BC573B86F5DE527] - |A| - [26/12/2019 10:51:24] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIe80a.LOG [MD5.5CD3C2AA40924629CBCBBCAA49A9299F] - |A| - [24/12/2019 19:04:01] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIe8637.LOG [MD5.1F01AA14CFFBDC232AD8CC32165269F3] - |A| - [18/12/2019 21:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIea21.LOG [MD5.3F85ACDB7955F79DFC24A59B1F546D29] - |A| - [23/12/2019 20:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf1b48.LOG [MD5.F825D57F5CA634B140BBB510D9FBE23F] - |A| - [18/12/2019 20:27:37] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf271c.LOG [MD5.103783C68B3687BBB351A20D3FF63425] - |A| - [21/12/2019 18:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf3282.LOG [MD5.6E4ACA84F01BE590E8EF286E84716244] - |A| - [20/12/2019 19:04:03] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf5d2c.LOG [MD5.48C68446843399DC89F60F692FE76D57] - |A| - [19/12/2019 13:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf6672.LOG [MD5.74607725E1CB9C325A772EC583D3DBA5] - |A| - [22/12/2019 17:04:04] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf73e9.LOG [MD5.7D37609420D381009794DD8D35568F95] - |A| - [21/12/2019 21:34:33] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIf822e.LOG [MD5.C4D3CED75E404959B52748C7CE04A690] - |A| - [21/12/2019 22:11:07] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIfaa9.LOG [MD5.22EEE15E03ACC68E5A461F8259D2ABDA] - |A| - [25/12/2019 17:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIfb37d.LOG [MD5.0A22DC0D4A68DB4CA9DFD21BD9B62021] - |A| - [20/12/2019 19:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIfc4b4.LOG [MD5.3C342BF6ABC1FC2B369D1AC69037F106] - |A| - [19/12/2019 13:39:27] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIfd202.LOG [MD5.B64B78024520BDAC00F586790BFBE854] - |A| - [22/12/2019 14:11:07] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIfe26b.LOG [MD5.3761AFDEAFC55FD5F67730408875BAA6] - |A| - [19/12/2019 20:04:02] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MSIfe9fe.LOG [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461206.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461208.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46121a.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46122b.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46122d.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46122f.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461241.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461243.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461245.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461247.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461259.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46125b.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46125d.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-46126e.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461270.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461272.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461274.tmp [MD5.00000000000000000000000000000000] - |D| - [22/12/2019 16:36:21] - [0 Ko] - C:\WINDOWS\Temp\tw-1190-1ba8-461286.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:38] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d851.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d8d0.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d8f1.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d912.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d943.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d955.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d976.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d987.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d9b8.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654d9da.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654da0a.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654da3b.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654da4d.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654da7e.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654da9f.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654dad0.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654db01.tmp [MD5.00000000000000000000000000000000] - |D| - [15/11/2019 18:07:39] - [0 Ko] - C:\WINDOWS\Temp\tw-11c8-2e04-654db12.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:29] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444723.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:29] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444744.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:29] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444775.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:29] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-94447c5.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-94447f6.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444827.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444858.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444889.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-94448b9.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-94448ea.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-944490c.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-944492d.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-944496d.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-944499e.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-94449df.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-94449f0.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444a40.tmp [MD5.00000000000000000000000000000000] - |D| - [16/12/2019 10:00:30] - [0 Ko] - C:\WINDOWS\Temp\tw-1280-3b2c-9444a62.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218054.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218066.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218068.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-21806a.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-21807c.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-21807e.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218080.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218082.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218093.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218095.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218097.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-218099.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-21809b.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-2180ad.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-2180af.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-2180b1.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-2180b3.tmp [MD5.00000000000000000000000000000000] - |D| - [23/12/2019 19:14:13] - [0 Ko] - C:\WINDOWS\Temp\tw-12ec-2e04-2180c4.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:31] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cc84e.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:31] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccaa2.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccb12.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccb33.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccbd1.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cccfc.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccd4c.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccdbb.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccdfc.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cce2d.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cce8d.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:32] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccecd.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:33] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cceee.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:33] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccf4e.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:33] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1ccf6f.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:33] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cd02d.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:33] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cd0db.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 21:10:33] - [0 Ko] - C:\WINDOWS\Temp\tw-138c-2df8-1b1cd10c.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e61.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e73.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e84.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e86.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e88.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e9a.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e9c.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6e9e.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6ebf.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6ec1.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6ed3.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6ed5.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6ed7.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6ee9.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6eeb.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6eed.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6f1d.tmp [MD5.00000000000000000000000000000000] - |D| - [20/12/2019 19:17:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1390-b14-1fdb6f1f.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b146f.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b1471.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b1473.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b1475.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b1487.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b1489.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b148b.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b148d.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b148f.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14a0.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14a2.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14a4.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14a6.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14b8.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14ba.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14bc.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14be.tmp [MD5.00000000000000000000000000000000] - |D| - [30/11/2019 11:38:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1424-3c70-469b14c0.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:51] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7dfc8.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:52] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e17f.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:52] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e1c0.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:52] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e23f.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:52] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e2cd.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:52] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e408.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:52] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e419.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e544.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e5b4.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e5c5.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e635.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e6e3.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e752.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e82f.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e87f.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:53] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e92d.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:54] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e95e.tmp [MD5.00000000000000000000000000000000] - |D| - [04/12/2019 19:16:54] - [0 Ko] - C:\WINDOWS\Temp\tw-17ec-2098-5cd7e98e.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42879.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b4289a.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b428cb.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b428ec.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b428ee.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b428f0.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42902.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42904.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42915.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42917.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42919.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b4292b.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b4292d.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b4292f.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42941.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42943.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42945.tmp [MD5.00000000000000000000000000000000] - |D| - [19/12/2019 09:57:00] - [0 Ko] - C:\WINDOWS\Temp\tw-19c0-33a8-18b42956.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba40.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba52.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba63.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba65.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba67.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba69.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba7b.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba7d.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1ba8e.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1baa0.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1baa2.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1baa4.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1bab6.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1bbd1.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1bbf2.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1bbf4.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1bc06.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 20:52:23] - [0 Ko] - C:\WINDOWS\Temp\tw-1a00-30d0-5a1bc08.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:17] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5b40.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:17] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5b61.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5b82.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5b84.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5b96.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5ba8.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5baa.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5bda.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5db1.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5e01.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e5eaf.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e6019.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e6078.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e6165.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e6196.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e61c6.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e61f7.tmp [MD5.00000000000000000000000000000000] - |D| - [23/11/2019 15:08:19] - [0 Ko] - C:\WINDOWS\Temp\tw-1d44-bc4-234e6209.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199602c.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199602e.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996030.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996042.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996044.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996055.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996067.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996069.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199606b.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199607d.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199607f.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996081.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996083.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996085.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996096.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-31996098.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199609a.tmp [MD5.00000000000000000000000000000000] - |D| - [26/11/2019 09:44:55] - [0 Ko] - C:\WINDOWS\Temp\tw-1d70-2e8-3199609c.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-1764fd.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-17651e.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176530.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176541.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176563.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176584.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-1765c4.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176643.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176684.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-1766a5.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176715.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176755.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:49] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176786.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:49] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-1767c6.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:49] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-1767f7.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:49] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176828.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:49] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-176849.tmp [MD5.00000000000000000000000000000000] - |D| - [14/11/2019 13:02:49] - [0 Ko] - C:\WINDOWS\Temp\tw-1df8-2710-17686b.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:47] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9a00.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:47] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9a41.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9ac0.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9af1.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9b02.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9b14.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9b25.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9b76.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9b87.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9b99.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9baa.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9beb.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9c0c.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9c3d.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9c5e.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9c70.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9ca1.tmp [MD5.00000000000000000000000000000000] - |D| - [20/11/2019 18:19:48] - [0 Ko] - C:\WINDOWS\Temp\tw-1e6c-1ff4-148a9cc2.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb6ac.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb6cd.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb6cf.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb6e0.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb702.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb704.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb706.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb717.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb719.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb72b.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb73d.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb74e.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb750.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb762.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb764.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb766.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb777.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 16:32:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ea8-29b0-4eb779.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:02] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56713f9f.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:03] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714137.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:03] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-567141f5.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:03] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-567142a3.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:03] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-5671437f.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:03] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-567143c0.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:04] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714597.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:04] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-567146a2.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:04] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-567147bd.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:04] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-5671486b.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714938.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-567149e6.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714a75.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714a96.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714b63.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714c30.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:05] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714cbf.tmp [MD5.00000000000000000000000000000000] - |D| - [03/12/2019 13:27:06] - [0 Ko] - C:\WINDOWS\Temp\tw-1ec0-810-56714d2e.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181461.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181463.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181475.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181477.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181479.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-4218147b.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-4218148c.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-4218148e.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181490.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-42181492.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814a4.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814a6.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814a8.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814aa.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814ac.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814be.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814c0.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 14:37:14] - [0 Ko] - C:\WINDOWS\Temp\tw-1fdc-ea0-421814c2.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f11c.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f13d.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f14f.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f151.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f172.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f184.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f186.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f197.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1a9.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1ab.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1ad.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1bf.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1c1.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1d2.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1e4.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1f6.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f1f8.tmp [MD5.00000000000000000000000000000000] - |D| - [17/11/2019 11:38:18] - [0 Ko] - C:\WINDOWS\Temp\tw-1ff0-35fc-3a7f209.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:12] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-5874439d.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:13] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744536.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:13] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-587446ed.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:13] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-5874478b.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:13] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-587447fb.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:14] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744916.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:14] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744a41.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:14] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744a72.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:14] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744beb.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:15] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744d54.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:15] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58744e7f.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:15] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58745037.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58745181.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-587451c1.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-587451f2.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-5874537b.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:17] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-58745590.tmp [MD5.00000000000000000000000000000000] - |D| - [31/10/2019 20:59:17] - [0 Ko] - C:\WINDOWS\Temp\tw-2250-16ac-587455b1.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a045.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a170.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a1a1.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a220.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a260.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a2c0.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a310.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a38f.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:29] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a3ff.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a48d.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a4be.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a53d.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a57e.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a5dd.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a65c.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a71a.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:30] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a7b8.tmp [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 12:59:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2678-1ac-918a8a5.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-286577cf.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-286577d1.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-286577d3.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-286577e4.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-286577f6.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-286577f8.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-28657819.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-2865781b.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-2865781d.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-2865781f.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-28657831.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-28657833.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-28657844.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-28657856.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-28657868.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-2865786a.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-2865786c.tmp [MD5.00000000000000000000000000000000] - |D| - [24/11/2019 14:51:38] - [0 Ko] - C:\WINDOWS\Temp\tw-2810-2c04-2865786e.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:35] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb197dc.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:35] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb199a3.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19a41.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19ab1.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19b20.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19b60.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19bdf.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19c10.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19c32.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19cd0.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:36] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19d4f.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19e1c.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19e8b.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb19efb.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb1a0c2.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb1a112.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb1a1c0.tmp [MD5.00000000000000000000000000000000] - |D| - [22/11/2019 17:38:37] - [0 Ko] - C:\WINDOWS\Temp\tw-29c4-18b0-1eb1a1d1.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bfe32.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bfeb1.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bfee2.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bff13.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bff44.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bff84.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bff86.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bffa8.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bffaa.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bfffa.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156bfffc.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c003c.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c004e.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c0050.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c0071.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c0073.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c0094.tmp [MD5.00000000000000000000000000000000] - |D| - [18/12/2019 18:39:19] - [0 Ko] - C:\WINDOWS\Temp\tw-2ac8-352c-156c00a6.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c62013e.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c620140.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c620152.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c620163.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c620165.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c620167.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c620188.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c62018a.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c62018c.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201ae.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201cf.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201e1.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201e3.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201e5.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201e7.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201e9.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c6201fa.tmp [MD5.00000000000000000000000000000000] - |D| - [28/11/2019 12:00:16] - [0 Ko] - C:\WINDOWS\Temp\tw-2ae8-3454-3c62022b.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a226a.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a227c.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22ac.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22ae.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22b0.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22b2.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22c4.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22c6.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22c8.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22ca.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22cc.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22de.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22e0.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22e2.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22e4.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22f5.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22f7.tmp [MD5.00000000000000000000000000000000] - |D| - [05/12/2019 17:27:31] - [0 Ko] - C:\WINDOWS\Temp\tw-2c0c-3af4-619a22f9.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70f70.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70f72.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70f84.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70f96.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70f98.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70f9a.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70fab.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70fbd.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70fcf.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70fe0.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70fe2.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70ff4.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef70ff6.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef71007.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef71009.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef7101b.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef7103c.tmp [MD5.00000000000000000000000000000000] - |D| - [19/11/2019 16:20:32] - [0 Ko] - C:\WINDOWS\Temp\tw-2cb0-4d8-ef7103e.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:43] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fc358.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:44] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fc723.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:44] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fc764.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:44] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fc86f.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:45] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fc90e.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:45] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fc94e.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:45] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fcaa8.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:45] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fcc21.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:46] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fce17.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:46] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fcf13.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:47] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd2ed.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:47] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd36c.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:47] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd3bc.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:47] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd42c.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:47] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd45d.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:48] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd4cc.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:48] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd51c.tmp [MD5.00000000000000000000000000000000] - |D| - [08/11/2019 19:58:49] - [0 Ko] - C:\WINDOWS\Temp\tw-2f48-2e9c-816fd8d7.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259ade.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259aef.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b11.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b22.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b34.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b46.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b57.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b69.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b7a.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b8c.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259b9e.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259baf.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259bd1.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259bd3.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259bf4.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259c05.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259c07.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 15:48:50] - [0 Ko] - C:\WINDOWS\Temp\tw-2f60-2f48-259c19.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba084a.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba089a.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba08cb.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba08fb.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba090d.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba091f.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0950.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0980.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba09a2.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba09c3.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba09e4.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:29] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0a15.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:30] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0ae2.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:30] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0b03.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:30] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0b34.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:30] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0be2.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:30] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0c61.tmp [MD5.00000000000000000000000000000000] - |D| - [25/11/2019 11:02:30] - [0 Ko] - C:\WINDOWS\Temp\tw-30ac-2de4-2cba0c92.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:01:59] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d32f.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:01:59] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d479.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:01:59] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d4c9.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:01:59] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d51a.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:01:59] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d5a8.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d637.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d6c5.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d6f6.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d775.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d7f4.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d893.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d912.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d933.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3d964.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:01] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3da9e.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:01] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3db9a.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:02] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3de3c.tmp [MD5.00000000000000000000000000000000] - |D| - [21/12/2019 19:02:02] - [0 Ko] - C:\WINDOWS\Temp\tw-3248-3af8-24f3de9c.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:32] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c3859e1.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:32] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385afc.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:32] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385b5c.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:33] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385c29.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:33] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385d83.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:33] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385e50.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:33] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385eee.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:33] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c385f4e.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:34] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c38604a.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:34] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c38605b.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:34] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c3861e4.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c386428.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c386449.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c38647a.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c386622.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c386663.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c386684.tmp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 18:56:35] - [0 Ko] - C:\WINDOWS\Temp\tw-340-3480-6c386703.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1800b0.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-180120.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-18019f.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1801c0.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1801c2.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1801d4.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1801f5.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1802a3.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1802b4.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1802e5.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-180316.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-180337.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:33] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-180397.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:34] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1803b8.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:34] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1803da.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:34] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-1803eb.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:34] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-18040c.tmp [MD5.00000000000000000000000000000000] - |D| - [14/12/2019 15:15:34] - [0 Ko] - C:\WINDOWS\Temp\tw-3404-2eec-18043d.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:28] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dfed50.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:29] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dfee7b.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:29] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dfef29.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:29] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff025.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:29] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff0f2.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:30] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff20d.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:30] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff3b5.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:30] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff473.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:30] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff4b3.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:30] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff523.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff62e.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff66f.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff6bf.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff70f.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff74f.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff7ee.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff8ea.tmp [MD5.00000000000000000000000000000000] - |D| - [09/12/2019 11:16:31] - [0 Ko] - C:\WINDOWS\Temp\tw-354-1458-2dff92a.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:12] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b241905.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:14] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24201b.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:15] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b2425cb.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:18] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b2430aa.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:19] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b243455.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:24] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b2449d3.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:28] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24589b.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:32] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b2466b6.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:35] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b2471e3.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:38] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b247d7e.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:41] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b248c65.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:45] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b249bf7.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:48] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24a62a.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:54] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24bd1f.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:56] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24c724.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:58] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24ce5a.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:46:59] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24d09e.tmp [MD5.00000000000000000000000000000000] - |D| - [13/11/2019 19:47:01] - [0 Ko] - C:\WINDOWS\Temp\tw-357c-fbc-9b24d747.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8ba.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8bc.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8ce.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8d0.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8d2.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8e4.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8f5.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a8f7.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a918.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a91a.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a92c.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a92e.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a930.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a932.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a944.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a946.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a948.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 10:53:21] - [0 Ko] - C:\WINDOWS\Temp\tw-371c-adc-8a3a94a.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c2627b.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c2628c.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c2628e.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c26290.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262a2.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262a4.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262a6.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262b8.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262ba.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262bc.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262cd.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262df.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262e1.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c262f2.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c26304.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c26306.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c26308.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 17:39:45] - [0 Ko] - C:\WINDOWS\Temp\tw-373c-2868-5c26329.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:37] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1ac1.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:37] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1b9e.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:37] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1bbf.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:37] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1be0.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:37] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1bf2.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:38] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1e46.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:38] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e1f9f.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:38] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e200f.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:38] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2011.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:38] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2032.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:38] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e217c.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2259.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2307.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2347.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e23b7.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2445.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2503.tmp [MD5.00000000000000000000000000000000] - |D| - [24/12/2019 18:28:39] - [0 Ko] - C:\WINDOWS\Temp\tw-38b0-33f8-51e2524.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-11480c.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-11480e.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-114810.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-114812.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-114814.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-114826.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-114828.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-11482a.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-11482c.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-11483d.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-11483f.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-114841.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-1148c0.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-1148c2.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-1148c4.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-1148d6.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-1148d8.tmp [MD5.00000000000000000000000000000000] - |D| - [25/12/2019 12:08:39] - [0 Ko] - C:\WINDOWS\Temp\tw-39a8-39b8-1148da.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b56.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b68.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b6a.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b6c.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b6e.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b7f.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b81.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b83.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b85.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b97.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b99.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b9b.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b9d.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488b9f.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488bb1.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488bb3.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488bb5.tmp [MD5.00000000000000000000000000000000] - |D| - [01/12/2019 09:26:45] - [0 Ko] - C:\WINDOWS\Temp\tw-39fc-2950-4b488bb7.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e7dd.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e7ee.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e800.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e802.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e814.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e816.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e818.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e81a.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e81c.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e82d.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e82f.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e831.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e833.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e835.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e847.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e849.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e84b.tmp [MD5.00000000000000000000000000000000] - |D| - [27/11/2019 11:04:50] - [0 Ko] - C:\WINDOWS\Temp\tw-3aa0-39f4-3708e84d.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:39:52] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea1003.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:39:53] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea111e.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:39:53] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea1239.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:39:53] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea1299.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:39:53] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea1357.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:00] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea2ed0.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:01] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea3143.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:01] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea31d1.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:01] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea32dd.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:03] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea3948.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:03] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea3a05.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:03] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea3a75.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:06] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea44d7.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:08] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea4d07.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:10] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea53b0.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:10] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea5538.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:11] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea57ea.tmp [MD5.00000000000000000000000000000000] - |D| - [10/12/2019 18:40:11] - [0 Ko] - C:\WINDOWS\Temp\tw-4f0-790-5ea58f5.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5cd1.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5ce3.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5ce5.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5ce7.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5ce9.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5ceb.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5cfc.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5cfe.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d00.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d02.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d04.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d16.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d18.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d1a.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d1c.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d1e.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d30.tmp [MD5.00000000000000000000000000000000] - |D| - [29/11/2019 18:13:49] - [0 Ko] - C:\WINDOWS\Temp\tw-520-272c-42de5d32.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b01.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b23.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b25.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b27.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b38.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b3a.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b3c.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b3e.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b40.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b52.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b64.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b66.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b68.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b79.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b7b.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b7d.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:57] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7b9e.tmp [MD5.00000000000000000000000000000000] - |D| - [08/12/2019 11:57:58] - [0 Ko] - C:\WINDOWS\Temp\tw-734-3da0-6fdf7e6f.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b07793.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b07795.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077a6.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077a8.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077aa.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077bc.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077dd.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077df.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077f1.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077f3.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b077f5.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b07806.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b07808.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b0780a.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b0781c.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b0781e.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b07820.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 20:39:46] - [0 Ko] - C:\WINDOWS\Temp\tw-82c-3224-b07832.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d21da.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d21ec.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d21fd.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d221f.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2230.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2242.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2244.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2246.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2248.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2259.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d225b.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d225d.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d225f.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2261.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2273.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2275.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2277.tmp [MD5.00000000000000000000000000000000] - |D| - [26/12/2019 11:50:04] - [0 Ko] - C:\WINDOWS\Temp\tw-9bc-b30-d2279.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d247.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d2e5.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d364.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d412.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d443.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d464.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d4a5.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:00] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d4e5.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d516.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d537.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d568.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d5b8.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d5d9.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d6d5.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d6f7.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d718.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d7a7.tmp [MD5.00000000000000000000000000000000] - |D| - [06/12/2019 17:53:01] - [0 Ko] - C:\WINDOWS\Temp\tw-a98-3a4c-66d7d7e7.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:03] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117323.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:03] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117354.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:04] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117421.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:04] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117442.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:04] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-11754e.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:04] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117669.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:04] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117785.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:05] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117ab3.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:06] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-117ecc.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:07] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-11819d.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:07] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-1181fc.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:08] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-11851b.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:08] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-118646.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:08] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-118713.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:08] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-118754.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:08] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-118785.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:09] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-1187d5.tmp [MD5.00000000000000000000000000000000] - |D| - [16/11/2019 18:55:09] - [0 Ko] - C:\WINDOWS\Temp\tw-ee8-bb8-118806.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e9419.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e9489.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e94ba.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e94fa.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e951b.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e956c.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e957d.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e95be.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e95ef.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e9610.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e968f.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e96c0.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:25] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e96d1.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:26] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e9760.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:26] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e9781.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:26] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e97f1.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:26] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e989e.tmp [MD5.00000000000000000000000000000000] - |D| - [13/12/2019 18:00:26] - [0 Ko] - C:\WINDOWS\Temp\tw-f74-39f4-1e98ef.tmp [MD5.1696A4487030B0B6B5CDD521A9C3D238] - |A| - [03/12/2019 13:10:13] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WERD9F0.tmp.WERDataCollectionStatus.txt [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:14:07] - [0 Ko] - C:\WINDOWS\Temp\_avast_ [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:05] - [0 Ko] - C:\WINDOWS\System32\0409 [MD5.00000000000000000000000000000000] - |D| - [10/02/2011 20:39:07] - [0 Ko] - C:\WINDOWS\System32\040C [MD5.8C70365AA61543ABEB675E8ACC21C78E] - |A| - [14/07/2009 05:45:49] - (.-.) - [27.69 Ko] - (0.0.0.0) - C:\WINDOWS\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [MD5.8C70365AA61543ABEB675E8ACC21C78E] - |A| - [14/07/2009 05:45:49] - (.-.) - [27.69 Ko] - (0.0.0.0) - C:\WINDOWS\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [MD5.D6F8DD9F561B8A67FFAC2BAD7E989770] - |A| - [15/09/2018 08:28:43] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AppHelpToast.png [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [15/09/2018 08:28:42] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AudioToastIcon.png [MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |A| - [15/09/2018 08:28:30] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@BackgroundAccessToastIcon.png [MD5.3937359E324E15F6A7A7092D4DAEBD64] - |A| - [15/09/2018 08:28:50] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@bitlockertoastimage.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [15/09/2018 08:28:51] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@EnrollmentToastIcon.png [MD5.C2A332DE50FE519DA21AFB8BD6E134F4] - |A| - [15/09/2018 08:28:53] - (.-.) - [0.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@language_notification_icon.png [MD5.A119D69B4C29845D3F8CE2E5638C8E65] - |A| - [15/09/2018 08:29:21] - (.-.) - [0.47 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@optionalfeatures.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [15/09/2018 08:28:56] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@VpnToastIcon.png [MD5.7AC3EA1A5175106ED6467FF0C5315541] - |A| - [15/09/2018 08:28:26] - (.-.) - [14.75 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WiFiNotificationIcon.png [MD5.79166EAF65485F1432DD72B72870026B] - |A| - [15/09/2018 08:29:13] - (.-.) - [190.86 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@windows-hello-V4.1.gif [MD5.13EF2C8D799F7B6E9D8E3D6BACB9C779] - |A| - [15/09/2018 08:29:13] - (.-.) - [0.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsHelloFaceToastIcon.png [MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.contrast-black.png [MD5.DAD405CBDE259DE527EBF71BCC28099C] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.contrast-white.png [MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.png [MD5.DB71001FC261F6685BE410527DAE3942] - |A| - [15/09/2018 08:29:14] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WirelessDisplayToast.png [MD5.D0FCF781D0801ABF5F74B54E98076A5B] - |A| - [15/09/2018 08:28:36] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WwanNotificationIcon.png [MD5.85D91E478AF18125007C531227FF6E59] - |A| - [15/09/2018 08:28:36] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WwanSimLockIcon.png [MD5.10B27174D46094984E7A05F3C36ACD2A] - |A| - [20/09/2012 07:31:20] - (.Copyright © 2002 by Vigovsky Alexander - ac3filter.) - [176 Ko] - (0.7.0.0) - C:\WINDOWS\System32\ac3filter.cpl [MD5.2783B7A76C5D58279CB99CDFBFCC7EBD] - |A| - [27/06/2019 14:27:35] - (.-.) - [13.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\accserv.mib [MD5.D061DE4A3C974790E0AA7B264DE5EBF1] - |A| - [24/06/2015 21:56:58] - (.-.) - [115.81 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AcpiServiceVnA64.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:30] - [2819.03 Ko] - C:\WINDOWS\System32\AdvancedInstallers [MD5.0EA24F0FCE29E818F1DD8F7B37256683] - |A| - [21/02/2014 21:33:15] - (.(c) Protection Technology - Application Driver Auto Removal Service (01).) - [538.89 Ko] - (5.70.6.2) - C:\WINDOWS\System32\appdrvrem01.exe [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\System32\AppLocker [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [2728.29 Ko] - C:\WINDOWS\System32\appraiser [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [354.5 Ko] - C:\WINDOWS\System32\ar-SA [MD5.FE6D792232F609743EABF2C089033651] - |A| - [15/09/2018 08:29:14] - (.Copyright (c) libarchive authors - Windows-internal libarchive library.) - [607.5 Ko] - (3.3.2.0) - C:\WINDOWS\System32\archiveint.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\as-IN [MD5.62E10C57672EAF4750D6322E9ECF5212] - |A| - [23/08/2014 13:14:38] - (.-.) - [3.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ASOROSet.bin [MD5.42FE37B90A47609B7A362660BCA5F3C4] - |A| - [11/10/2019 09:21:11] - (.Copyright (c) 2019 AVAST Software - Avast Antivirus start-up scanner.) - [347.38 Ko] - (19.8.4793.0) - C:\WINDOWS\System32\aswBoot.exe [MD5.BADDD429C04946F0F562105A430B54F6] - |A| - [24/06/2015 21:57:00] - (.-.) - [102.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\audioLibVc.dll [MD5.36D0E24AEF1A9947F2A2E9332ACCC23F] - |A| - [27/06/2019 14:27:35] - (.-.) - [14.68 Ko] - (0.0.0.0) - C:\WINDOWS\System32\authserv.mib [MD5.C03F0062C0749CDB59A4D60862C3E83E] - |A| - [15/09/2018 08:28:22] - (.-.) - [134.86 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AverageRoom.bin [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\az-Latn-AZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\be-BY [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:28:28] - [84.19 Ko] - C:\WINDOWS\System32\BestPractices [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [347.5 Ko] - C:\WINDOWS\System32\bg-BG [MD5.705628497C0012302212A46ADD463E6E] - |A| - [15/09/2018 08:28:22] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-black.png [MD5.F63C615733A3337BF2BEA96C6EE9B568] - |A| - [15/09/2018 08:28:22] - (.-.) - [8.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-high.png [MD5.705628497C0012302212A46ADD463E6E] - |A| - [15/09/2018 08:28:22] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-white.png [MD5.DAF1DCB4AEE839A1965F4CC160C49A53] - |A| - [15/09/2018 08:28:22] - (.-.) - [8.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.png [MD5.28ECA83D7F9D10D69E969675D1FF6725] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothSystemToastIcon.contrast-white.png [MD5.A620186FF1CDE4EE117FC4CAD648B9CC] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.2 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\bn-BD [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\bn-IN [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [5678.48 Ko] - C:\WINDOWS\System32\Boot [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\bs-Latn-BA [MD5.FF8455531929A7067F8A6267B34D2DB8] - |A| - [15/09/2018 08:28:42] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [181.5 Ko] - (1.0.0.1) - C:\WINDOWS\System32\BthpanContextHandler.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0.1 Ko] - C:\WINDOWS\System32\Bthprops [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ca-ES [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ca-ES-valencia [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:26] - [106436.74 Ko] - C:\WINDOWS\System32\CatRoot [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [48488.08 Ko] - C:\WINDOWS\System32\catroot2 [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\chr-CHER-US [MD5.2263727032E9B19231A706046B8C82D3] - |A| - [26/11/2013 22:13:31] - (.-.) - [27.99 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Ckldrv.sys [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [11.19 Ko] - C:\WINDOWS\System32\CodeIntegrity [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [369.5 Ko] - C:\WINDOWS\System32\com [MD5.535884123FABC2C15AA7DEC9834B55D4] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ComputerToastIcon.contrast-white.png [MD5.89F92266DFC6F93961DFFBB2D6C61A15] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ComputerToastIcon.png [MD5.FC2C602B6CEDD85FDF0D6C5CBEE45EA3] - |A| - [24/06/2015 21:57:00] - (.2013 © Real Sound Lab SIA, iSoft Solutions - CONEQ™ Media Suite APO GUI Library.) - [119.46 Ko] - (1.0.0.4) - C:\WINDOWS\System32\CONEQMSAPOGUILibrary.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:26] - [321843.97 Ko] - C:\WINDOWS\System32\config [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:50] - [53.11 Ko] - C:\WINDOWS\System32\Configuration [MD5.133F82B6391F3390BECFA429C23FB2BE] - |A| - [26/11/2013 22:13:31] - (.Copyright © 2000 - CrypKey License Service.) - [120 Ko] - (1.1.0.2) - C:\WINDOWS\System32\Crypserv.exe [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [405 Ko] - C:\WINDOWS\System32\cs-CZ [MD5.2419907A0BB9A14F1871F0BDA7F65578] - |A| - [11/09/2019 17:27:39] - (.© 1996 - 2017 Daniel Stenberg, . - The curl executable.) - [411.5 Ko] - (7.55.1.0) - C:\WINDOWS\System32\curl.exe [MD5.E9F9F758CE28B922871A6AFD505B0558] - |A| - [24/06/2015 21:59:08] - (.©Conexant Systems Inc. - Conexant APO.) - [1562.3 Ko] - (1.28.0.0) - C:\WINDOWS\System32\CX64APO.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\cy-GB [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [400.5 Ko] - C:\WINDOWS\System32\da-DK [MD5.44C688E0013097CF8594C9145BF37631] - |A| - [27/06/2019 14:36:05] - (.-.) - [145 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DataStoreCacheDumpTool.exe [MD5.00000000000000000000000000000000] - |D| - [17/04/2017 21:36:10] - [4022.57 Ko] - C:\WINDOWS\System32\DAX2 [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [240.31 Ko] - C:\WINDOWS\System32\DDFs [MD5.357F4F0C7A3F94066F48D80115CF8AEC] - |A| - [24/06/2015 21:59:08] - (.©2014 Dolby Laboratories. - Dolby Digital Plus API x86.) - [266.33 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPA64.dll [MD5.7319EAD10DD0640147F3F13E1430862B] - |A| - [24/06/2015 21:59:08] - (.©2014 Dolby Laboratories. - Dolby Digital Plus API x86.) - [289.55 Ko] - (7.6.7.1) - C:\WINDOWS\System32\DDPA64F3.dll [MD5.C84E72FF5409A423C06C5146466EA7FB] - |A| - [24/06/2015 21:59:08] - (.©2014 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1919.74 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPD64A.dll [MD5.EAC2CDBDFBFF5D3E2083E77E6437D571] - |A| - [24/06/2015 21:59:08] - (.©2014 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1913.68 Ko] - (7.6.7.1) - C:\WINDOWS\System32\DDPD64AF3.dll [MD5.4D6EA60C8A01AC6D2CBAF1CF5CD156D4] - |A| - [24/06/2015 21:59:08] - (.©2014 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [319.78 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPO64A.dll [MD5.A8735674D1A327ED0FA5125DD084EFD9] - |A| - [24/06/2015 21:59:08] - (.©2014 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [339.93 Ko] - (7.6.7.1) - C:\WINDOWS\System32\DDPO64AF3.dll [MD5.D9ED946E612914C67F530F469C582AB4] - |A| - [24/06/2015 21:57:00] - (.©2014 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6929.88 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPP64A.dll [MD5.704B9243673AD64719FE6FEF40896E13] - |A| - [24/06/2015 21:57:00] - (.©2014 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6104.81 Ko] - (7.6.7.1) - C:\WINDOWS\System32\DDPP64AF3.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [455.5 Ko] - C:\WINDOWS\System32\de-DE [MD5.C04ED7B2794D40E8E777FD44ED44FC50] - |A| - [15/09/2018 08:28:30] - (.-.) - [0.36 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultAccountTile.png [MD5.618BA9E529EAB7E11DBA43469481835F] - |A| - [15/09/2018 08:28:22] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultHrtfs.bin [MD5.664AA698FC0106A2B075A641E8DC6302] - |A| - [15/09/2018 08:31:36] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultQuestions.json [MD5.34AF361B9CAD6077279ADD5F88C0DB0A] - |A| - [10/02/2011 21:50:42] - (.Copyright © 2013 - Java(TM) Platform SE binary.) - [513.92 Ko] - (6.0.390.4) - C:\WINDOWS\System32\deployJava1.dll [MD5.74CBFD8DD24538D3E5E24305905841F1] - |A| - [10/07/2015 13:22:52] - (.-.) - [15.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DESKTOP-M7P1NB6_Administrator_HistoryPrediction.bin [MD5.851A9305E14B348CA0D9C7FB75391FDB] - |A| - [15/09/2018 08:28:39] - (.-.) - [272.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DesktopKeepOnToastImg.gif [MD5.4A6FA3C0EFD237F104E09A22883D9388] - |A| - [15/09/2018 08:28:44] - (.-.) - [3.85 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DetailedReading-Default.xml [MD5.36E64F088106836C321CF2ED03D81235] - |A| - [27/06/2019 14:27:35] - (.-.) - [4.49 Ko] - (0.0.0.0) - C:\WINDOWS\System32\dhcp.mib [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:50] - [907 Ko] - C:\WINDOWS\System32\DiagSvcs [MD5.BE6BCD1A0D8F8F8072996900200D4CF8] - |A| - [15/09/2018 08:28:38] - (.-.) - [82.01 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DiskSnapshot.conf [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:28] - [9696.42 Ko] - C:\WINDOWS\System32\Dism [MD5.6AB2B935BF38EB13CFCB9506223FD6E7] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplaySystemToastIcon.contrast-white.png [MD5.FF004E0B30E5E4EC747B3D8EF6E3B89E] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplaySystemToastIcon.png [MD5.E812FA00C13155C1359CCA86E8256591] - |A| - [24/06/2015 21:59:08] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 APO Property Page.) - [939.63 Ko] - (0.4.0.18) - C:\WINDOWS\System32\DolbyDAX2APOProp.dll [MD5.FCBF71E4CB6CDFDD6156080FDD9470D1] - |A| - [24/06/2015 21:59:08] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [2366.68 Ko] - (0.4.0.18) - C:\WINDOWS\System32\DolbyDAX2APOv201.dll [MD5.411F13239359434B5518FB01DC6670BA] - |A| - [24/06/2015 21:59:08] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [2433.24 Ko] - (0.4.0.18) - C:\WINDOWS\System32\DolbyDAX2APOv211.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:28] - [2418.7 Ko] - C:\WINDOWS\System32\downlevel [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:12] - [121036.15 Ko] - C:\WINDOWS\System32\drivers [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\System32\DriverState [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:26] - [10777208.65 Ko] - C:\WINDOWS\System32\DriverStore [MD5.9DAB079879FA9894A93D3A3F69B43890] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth1.bin [MD5.A660973F4FED3F5B326E70E183E753DC] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth2.bin [MD5.4D8D4A4C736AE31F63D3FEA9E65EDDDF] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth3.bin [MD5.850AFB79B42691FFB6A93E0E4D5E6E01] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth4.bin [MD5.DD183F38F601477ECA9BF87A4F096F8D] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth5.bin [MD5.983E5EB5972596E3ED661AD757476704] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth6.bin [MD5.E19D995E8F337788ED44371AA7582C43] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth7.bin [MD5.F58008C41D104FF9E21340F323ECE184] - |A| - [12/12/2019 18:41:43] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth8.bin [MD5.00000000000000000000000000000000] - |DC| - [02/07/2012 21:22:19] - [48.58 Ko] - C:\WINDOWS\System32\DRVSTORE [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:50] - [161.5 Ko] - C:\WINDOWS\System32\dsc [MD5.F74D1D989528A9D2F8B62300375A665F] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Bass Enhancement COM DLL.) - [726.53 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBassEnhancementDLL64.dll [MD5.17E12A73A758FD6C164B559E661E86A9] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Boost COM DLL.) - [1473.57 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBoostDLL64.dll [MD5.AA425753D4AED461D0531256E0E927E0] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Gain Compensator COM DLL.) - [430.93 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSGainCompensatorDLL64.dll [MD5.74B2540D82452F121FC632A1A5E76852] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS GFX APO.) - [247.95 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPO64.dll [MD5.26ED45050D54C30F84CFB4EBA14F0F61] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS GFX APO.) - [246.95 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPONS64.dll [MD5.7886E418D4D59F77182518D461EE3551] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS LFX APO.) - [247.91 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSLFXAPO64.dll [MD5.60BD7F70E54CACFDDE5E0F2890C2B3C5] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Limiter COM DLL.) - [434.96 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSLimiterDLL64.dll [MD5.AA1B3E531D519E5E777ED75834148BBC] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS NEO:PC COM DLL.) - [492.49 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSNeoPCDLL64.dll [MD5.8673B3A05AF693A96FE53DE9AFFB2656] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Surround Sensation Headphone COM DLL.) - [1553.77 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2HeadphoneDLL64.dll [MD5.14E673E0E22A2407A439B55113F4C042] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Surround Sensation Speaker COM DLL.) - [1738.89 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2SpeakerDLL64.dll [MD5.1B6AAB5812DAD434859DAC7824322C35] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Symmetry COM DLL.) - [710.39 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSSymmetryDLL64.dll [MD5.B1FD42916D28F6574AE118359B44D262] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS GFX APO.) - [488.83 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PGFX64.dll [MD5.896F6EB4F41AB2FFBEB62AF453AC3621] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS LFX APO.) - [502.47 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PLFX64.dll [MD5.02D91B05D7889F6744CE167C6604CE28] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS LFX APO.) - [418.2 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PREC64.dll [MD5.5450995EA8F0F4C6FCCFD2E6AF4B30A0] - |A| - [24/06/2015 21:59:08] - (.(c) DTS. - DTS Voice Clarity COM DLL.) - [691.71 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSVoiceClarityDLL64.dll [MD5.DF84EB7B44D1414284BA384F0061D1DC] - |A| - [15/09/2018 08:28:22] - (.-.) - [728.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicLong.bin [MD5.346870077DFD18867A9693C7A59AA3E6] - |A| - [15/09/2018 08:28:22] - (.-.) - [503.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicMedium.bin [MD5.2BEC13D68312ADE8C0065D8BCC146D2F] - |A| - [15/09/2018 08:28:22] - (.-.) - [315.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicShort.bin [MD5.10C38E1CA0D664F58E8B9F3645885E1D] - |A| - [27/06/2019 14:35:41] - (.-.) - [0.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\edgehtmlpluginpolicy.bin [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [460 Ko] - C:\WINDOWS\System32\el-GR [MD5.ACCEDD542C4C4F3697978DD398887CEB] - |A| - [11/08/2015 23:27:11] - (.-.) - [22.66 Ko] - (0.0.0.0) - C:\WINDOWS\System32\emptyregdb.dat [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:05] - [0 Ko] - C:\WINDOWS\System32\en [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [325.5 Ko] - C:\WINDOWS\System32\en-GB [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [1714.53 Ko] - C:\WINDOWS\System32\en-US [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [435 Ko] - C:\WINDOWS\System32\es-ES [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [360.5 Ko] - C:\WINDOWS\System32\es-MX [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [319.5 Ko] - C:\WINDOWS\System32\et-EE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\eu-ES [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:50] - [16905.14 Ko] - C:\WINDOWS\System32\F12 [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\fa-IR [MD5.4DED57BD7ACB9B0EBBE82034EC44645A] - |A| - [15/09/2018 08:28:26] - (.-.) - [43.22 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FeatureToastBulldogImg.png [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [405.5 Ko] - C:\WINDOWS\System32\fi-FI [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\fil-PH [MD5.EE1AF6B7BD714E73603439C64490A9A8] - |A| - [27/06/2019 13:56:46] - (.-.) - [350.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FNTCACHE.DAT [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:05] - [3403.5 Ko] - C:\WINDOWS\System32\fr [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [370.5 Ko] - C:\WINDOWS\System32\fr-CA [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [47018.1 Ko] - C:\WINDOWS\System32\fr-FR [MD5.43E2703978F8DCE0DC0F824AA3EE03E2] - |A| - [27/06/2019 14:27:35] - (.-.) - [6.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ftp.mib [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\System32\FxsTmp [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ga-IE [MD5.41FD64AE28A0C932CA7B2A250993D675] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GameSystemToastIcon.contrast-white.png [MD5.6DC77FD8B062264AF1C6DA325ABB7010] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GameSystemToastIcon.png [MD5.2E6AF4D5BF6E31E728F409984C3045D4] - |A| - [15/09/2018 08:29:23] - (.-.) - [86.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\gatherNetworkInfo.vbs [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\gd-GB [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\gl-ES [MD5.00000000000000000000000000000000] - |D| - [14/07/2009 04:20:11] - [0 Ko] - C:\WINDOWS\System32\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [14/07/2009 04:20:11] - [0 Ko] - C:\WINDOWS\System32\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\gu-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ha-Latn-NG [MD5.EA99A87E98D995DE6E280CF85CEAD413] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HandwritingSystemToastIcon.contrast-white.png [MD5.B8E586ED92DB703FFA480E254996160E] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.89 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HandwritingSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [329 Ko] - C:\WINDOWS\System32\he-IL [MD5.6E9E9D56B192B2995493E529CFF2BBFE] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadphoneSystemToastIcon.contrast-white.png [MD5.7F1E9502267F778F3A8139C35A352190] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadphoneSystemToastIcon.png [MD5.202A07E4526B050E22624328E64E0470] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadsetSystemToastIcon.contrast-white.png [MD5.1892ACC10CAC009BCAC146AD650ABA58] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.17 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadsetSystemToastIcon.png [MD5.031713BFD5F30E63336D3CA5D2767BE9] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.79 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HealthSystemToastIcon.contrast-white.png [MD5.C1BD7976C99830E33A713D02374054EC] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.62 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HealthSystemToastIcon.png [MD5.9270BD94661CE72F98F5B0BB9D184D15] - |A| - [15/09/2018 08:28:34] - (.-.) - [256.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeatCore.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\hi-IN [MD5.944C9F5B31273D4B36D45244294740BD] - |A| - [24/06/2015 21:57:00] - (.© 2015 Dolby Laboratories, Inc. - Dolby DAX2 HiFi API.) - [349.88 Ko] - (0.4.0.20) - C:\WINDOWS\System32\HiFiDAX2API.dll [MD5.B4B555BA69CBE894EA8CF47DD7518261] - |A| - [27/06/2019 14:27:35] - (.-.) - [47.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\hostmib.mib [MD5.7AA40BB4EBC7E92492D748D5B106557D] - |A| - [24/04/2007 10:32:56] - (.Copyright © 2005 - bidichan.) - [128 Ko] - (1.3.9.1) - C:\WINDOWS\System32\hplbdchn.dll [MD5.BAF66C8C8DF00E1181EDE3A2EB56AEBC] - |A| - [14/10/2016 00:52:34] - (.© 2016 HPDC LP - HPScanTRDrv Module.) - [4687.66 Ko] - (43.0.3621.0) - C:\WINDOWS\System32\HPScanTEDrv_DJ2600_x64.dll [MD5.1422B7219F7842D03DA15E09188E12D9] - |A| - [14/10/2016 00:52:32] - (.© 2016 HPDC LP - DiscoveryLibDyn Module.) - [765.16 Ko] - (43.0.3621.0) - C:\WINDOWS\System32\HPScanTEDrv_DJ2600_x64_DiscoveryLibDyn.dll [MD5.FF9EE97AB17D9E51BB87D1C63B26A234] - |A| - [14/10/2016 00:54:54] - (.© Copyright 2015 HP Development Company, L.P. - HP WIA 2.0 scanner driver.) - [599.16 Ko] - (43.0.6000.26483) - C:\WINDOWS\System32\HPWia2_DJ2600.dll [MD5.53D8BBB236513133915E8206CC8E419F] - |A| - [07/05/2008 20:59:34] - (.Copyright (C) 1999 - LanguageMonitor.) - [34 Ko] - (61.53.25.9) - C:\WINDOWS\System32\HPZ3LLHN.DLL [MD5.C835670705596AE67EE7E0AE92A12071] - |A| - [07/05/2008 20:59:34] - (.Copyright (C) 1999 - LanguageMonitor.) - [47.5 Ko] - (61.53.25.9) - C:\WINDOWS\System32\HPZLLLHN.DLL [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [336.5 Ko] - C:\WINDOWS\System32\hr-HR [MD5.8FCC09B868D074AA553433554AA7FB56] - |A| - [27/06/2019 14:27:35] - (.-.) - [20.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\http.mib [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [412.5 Ko] - C:\WINDOWS\System32\hu-HU [MD5.E092D70A1D2D6E2CE75071A0A12EC06C] - |A| - [15/09/2018 08:29:24] - (.-.) - [37.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HvSocket.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\hy-AM [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:40:58] - [160.64 Ko] - C:\WINDOWS\System32\hydrogen [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [5.36 Ko] - C:\WINDOWS\System32\ias [MD5.8ADEC7B594221FAA1B4565BF46DE25EA] - |A| - [24/06/2015 21:59:08] - (.Copyright (c) 2015, ICEpower a/s - ICEpower ICEsound audio effects.) - [332.66 Ko] - (1.0.0.15) - C:\WINDOWS\System32\ICEsoundAPO64.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [36.27 Ko] - C:\WINDOWS\System32\icsxml [MD5.2FF8EEFAAEC9FAE611A587BD6D3C56C7] - |RA| - [29/06/2019 12:48:19] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU I18N DLL.) - [1816.5 Ko] - (61.1.0.0) - C:\WINDOWS\System32\icuin.dll [MD5.18FDD8D8C5BFA9B1767C2BFE97E74090] - |RA| - [15/09/2018 08:28:36] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Common DLL.) - [1315.5 Ko] - (61.1.0.0) - C:\WINDOWS\System32\icuuc.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\id-ID [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ig-NG [MD5.093C86CD529A3932C9E58C3387DA4AAC] - |A| - [13/07/2009 22:59:35] - (.-.) - [407.56 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igcompkrng500.bin [MD5.87031985145FE4FC13E8DABF387E78A4] - |A| - [13/07/2009 22:59:36] - (.-.) - [136.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igfcg500.bin [MD5.44E5EA6A6AB4D6343B8FBC1DE19B5005] - |A| - [13/07/2009 22:59:36] - (.-.) - [95.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igfcg500m.bin [MD5.71E96C791D10CAACF4867C5AD65FA19B] - |A| - [13/07/2009 22:59:36] - (.-.) - [959.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\igkrng500.bin [MD5.5C75F3B35EB158BF27B87A5920B77A3E] - |A| - [15/09/2018 08:28:22] - (.-.) - [195 Ko] - (0.0.0.0) - C:\WINDOWS\System32\IHDS.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [25900.42 Ko] - C:\WINDOWS\System32\IME [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [6177.08 Ko] - C:\WINDOWS\System32\inetsrv [MD5.8FDA485946897BFD248D5452628CC231] - |A| - [27/06/2019 14:27:35] - (.-.) - [0.68 Ko] - (0.0.0.0) - C:\WINDOWS\System32\inetsrv.mib [MD5.ADDF24D54BB454BF9FC38C9CA8FBDAA5] - |A| - [27/06/2019 14:36:16] - (.-.) - [813.54 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputHost.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [6841.5 Ko] - C:\WINDOWS\System32\InputMethod [MD5.8DE9AE82152650C178BF1E24014E8503] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputSystemToastIcon.contrast-white.png [MD5.0B9FBD6F3ED617CD36D042D3422F1C2B] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputSystemToastIcon.png [MD5.AAA0C03BF54FC8A4E895B576861A9848] - |A| - [21/11/2010 04:07:41] - (.-.) - [29.12 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InstallPackage_ETW.Log [MD5.4CFB45E07E81160CD374CC745ACCB962] - |A| - [27/06/2019 14:27:35] - (.-.) - [15.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ipforwd.mib [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\System32\Ipmi [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\is-IS [MD5.DB43DAB8E9B14DFBBF7E0B44F03A8A90] - |A| - [12/11/2016 21:59:47] - (.Copyright (c) 2015 Flexera Software LLC. - InstallShield (R) RunTime DLL.) - [421.23 Ko] - (22.0.0.330) - C:\WINDOWS\System32\isrt.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [434 Ko] - C:\WINDOWS\System32\it-IT [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [324.59 Ko] - C:\WINDOWS\System32\ja-jp [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ka-GE [MD5.B45E646F5D8B7ECD4F022FCC79B549D0] - |A| - [24/06/2015 21:59:08] - (.© Knowles Electronics. - Knowles HD Audio APO.) - [603.7 Ko] - (4.1105.6000.53) - C:\WINDOWS\System32\KAAPORT64.dll [MD5.23AC7515B6D8A794BCC01B582F044078] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardSystemToastIcon.contrast-white.png [MD5.3DF873E16CCEA9B42857FB5FA085CB00] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\kk-KZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\km-KH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\kn-IN [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [297.5 Ko] - C:\WINDOWS\System32\ko-KR [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\kok-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ku-Arab-IQ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ky-KG [MD5.9451D4436E2EA67EB33FCC764E4AABED] - |A| - [15/09/2018 08:28:39] - (.-.) - [186.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LaptopPlugInToastImg.gif [MD5.F0CC83E1BA7E24F9B3292160C28AECD7] - |A| - [15/09/2018 08:28:22] - (.-.) - [145.56 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LargeRoom.bin [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [23/12/2019 18:50:50] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\System32\last.dump [MD5.AE3B39538706AFF8952E7D06EF2D3E2C] - |A| - [23/05/2015 21:05:49] - (.Copyright © 2010 -.) - [419.33 Ko] - (2.3.4.2) - C:\WINDOWS\System32\LavasoftTcpService64.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\lb-LU [MD5.5C600FFFBDA69877A36D8FBF08B1F5D6] - |A| - [18/11/2015 22:27:28] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LexFiles.ulf [MD5.157FB82D7141B18624FF2D42190C97E1] - |A| - [15/09/2018 17:39:53] - (.-.) - [1572 Ko] - (2.6.5.1) - C:\WINDOWS\System32\libcrypto.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [625.17 Ko] - C:\WINDOWS\System32\Licenses [MD5.6DF4D76190C55D6E67D1F8D2496C1421] - |A| - [27/06/2019 14:27:35] - (.-.) - [25.49 Ko] - (0.0.0.0) - C:\WINDOWS\System32\lmmib2.mib [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\lo-LA [MD5.E89C001FB4D9E08CC7072CE774CDB999] - |A| - [21/11/2010 03:52:07] - (.-.) - [0.01 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LocalGroupAdminAdd.log [MD5.563C3703A9B57CC9B370A76D6173D09C] - |A| - [21/11/2010 03:52:08] - (.-.) - [0.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Local_LLU.log [MD5.00000000000000000000000000000000] - |D| - [26/01/2014 23:55:36] - [0 Ko] - C:\WINDOWS\System32\log [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [5081.16 Ko] - C:\WINDOWS\System32\LogFiles [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [334.5 Ko] - C:\WINDOWS\System32\lt-LT [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [333 Ko] - C:\WINDOWS\System32\lv-LV [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [58424.58 Ko] - C:\WINDOWS\System32\Macromed [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:40:28] - [32.68 Ko] - C:\WINDOWS\System32\MailContactsCalendarSync [MD5.00000000000000000000000000000000] - |D| - [14/07/2009 04:20:11] - [0 Ko] - C:\WINDOWS\System32\manifeststore [MD5.98BA4461E962C9E8F00C5ABBC5867C79] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [322.82 Ko] - (2.2.9.0) - C:\WINDOWS\System32\MaxxAudioAPO20.dll [MD5.7B6B17826474CEF2E432A4BFBC809C4E] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [662.29 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxAudioAPO30.dll [MD5.DD938E2E590839F3FDED71E8C11EB0C9] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1137.05 Ko] - (4.5.8.0) - C:\WINDOWS\System32\MaxxAudioAPO4064.dll [MD5.BF75DDB2797625659436262911BC5D9E] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1183.43 Ko] - (5.6.5.0) - C:\WINDOWS\System32\MaxxAudioAPO5064.dll [MD5.079B1093A2711B8DC61B98CDAD747E22] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1363.05 Ko] - (6.1.12.0) - C:\WINDOWS\System32\MaxxAudioAPO6064.dll [MD5.E57FC2B3237B09CE002EA60196E6D801] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [2757.11 Ko] - (7.0.10.0) - C:\WINDOWS\System32\MaxxAudioAPO7064.dll [MD5.809BBFAB0EF479CCFDA4C38DB0ADDB1E] - |A| - [24/06/2015 21:57:00] - (.Copyright (C) 2010-2013 - MaxxAudio APO Shell.) - [909.79 Ko] - (4.10.8.0) - C:\WINDOWS\System32\MaxxAudioAPOShell64.dll [MD5.1053E6C17DBD059422FEB4F967C9C297] - |A| - [24/06/2015 21:57:00] - (.Copyright © 1996-2014 -.) - [2002.13 Ko] - (4.1.1.0) - C:\WINDOWS\System32\MaxxAudioEQ64.dll [MD5.60D2CE36F34F000F796B4C54EF4D43BA] - |A| - [24/06/2015 21:57:02] - (.Copyright © 1996-2013 -.) - [13727.79 Ko] - (4.4.10.0) - C:\WINDOWS\System32\MaxxAudioRealtek64.dll [MD5.9B5746030DC8747E495ADB47EB7CF413] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxSpeech APO.) - [1303.11 Ko] - (1.1.4.0) - C:\WINDOWS\System32\MaxxSpeechAPO64.dll [MD5.C4A627009E0BF51E99C9EBB86269F616] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [974.64 Ko] - (2.6.2.0) - C:\WINDOWS\System32\MaxxVoiceAPO2064.dll [MD5.42916F05A5DC5601D38A9E0A391A883D] - |A| - [24/06/2015 21:59:10] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [12812.24 Ko] - (3.1.13.0) - C:\WINDOWS\System32\MaxxVoiceAPO3064.dll [MD5.C85979F68BF316DBA8586095DB7B3BA3] - |A| - [24/06/2015 21:59:10] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [12652.91 Ko] - (4.0.8.0) - C:\WINDOWS\System32\MaxxVoiceAPO4064.dll [MD5.04234879F4A8F8B768A8D4DC0F444E0D] - |A| - [24/06/2015 21:59:08] - (.© Waves Audio Ltd. - MaxxVolumeSD APO.) - [661.79 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxVolumeSDAPO.dll [MD5.D1F2D436257CAC94B69109EEE75E9B1C] - |A| - [11/10/2019 10:36:16] - (.-.) - [840 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MBR2GPT.EXE [MD5.2D11C2F06E6652DF17D0B4ADE75B6177] - |A| - [27/06/2019 14:27:35] - (.-.) - [29.73 Ko] - (0.0.0.0) - C:\WINDOWS\System32\mcastmib.mib [MD5.F23EB28468FC8B62AF941308EC30387F] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediaSystemToastIcon.contrast-white.png [MD5.6E27512E38D598E0A60F8E5ADCF032CD] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.83 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediaSystemToastIcon.png [MD5.69D04DE701CF1E8CE69C65D1671D2B3F] - |A| - [15/09/2018 08:28:22] - (.-.) - [107.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediumRoom.bin [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mi-NZ [MD5.6F4DC972EAD256A2C6407CDBC6ECA8E7] - |A| - [27/06/2019 14:27:35] - (.-.) - [105.35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\mib_ii.mib [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:42:02] - [1155.28 Ko] - C:\WINDOWS\System32\Microsoft [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [6213.32 Ko] - C:\WINDOWS\System32\migration [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [47536.93 Ko] - C:\WINDOWS\System32\migwiz [MD5.EBA55B66CDE9E19762EC6377FC74B4F0] - |A| - [20/09/2012 07:31:25] - (.-.) - [40 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MMAVILNG.exe [MD5.C8BF077B236ED2803347BD95DE29BF68] - |A| - [15/09/2018 08:31:36] - (.-.) - [3.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\mmc.exe.config [MD5.4A83FFDB59D6B757C5639FFD4DC360FB] - |A| - [20/09/2012 07:31:25] - (.Copyright (C) 1990-2001 Morgan Multimedia. - MM Switcher.) - [61 Ko] - (0.9.9.0) - C:\WINDOWS\System32\MMSwitch.ax [MD5.C29A96A349B926CED5229965AE3F8310] - |A| - [20/09/2012 07:31:25] - (.-.) - [76 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MMSwitch.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mn-MN [MD5.B43E43FFFDD0F06A6925C7C89594042B] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MouseSystemToastIcon.contrast-white.png [MD5.5D2F0D3E50BF1129D260AC1405FF2A18] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MouseSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mr-IN [MD5.00000000000000000000000000000000] - |D| - [31/07/2013 23:03:47] - [0 Ko] - C:\WINDOWS\System32\MRT [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ms-MY [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [45.5 Ko] - C:\WINDOWS\System32\MSDRM [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [35300.28 Ko] - C:\WINDOWS\System32\MsDtc [MD5.CBE91B00B3E6CC8EBFE758756B185A8A] - |A| - [27/06/2019 14:27:35] - (.-.) - [0.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\msft.mib [MD5.733D0CDA17A99209BC8926B8A0F7773B] - |A| - [27/06/2019 14:27:35] - (.-.) - [13.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\msipbtp.mib [MD5.11309DE7CE6F8DD566EF9629B2E4F4A0] - |A| - [27/06/2019 14:27:35] - (.-.) - [33.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\msiprip2.mib [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:28:28] - [12319.14 Ko] - C:\WINDOWS\System32\msmq [MD5.18403DE4979A328F21279DECB2E4298F] - |A| - [15/09/2018 08:29:36] - (.-.) - [3.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\msmqpub.mof [MD5.E0640DE5407EEE4C6E16D839243B71F9] - |A| - [15/09/2018 08:38:55] - (.-.) - [8.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\msmqtrc.mof [MD5.3ED9AC3EE11EE2C16E2E41F0DC4BAD42] - |A| - [15/09/2018 08:29:36] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\System32\msmqtrcRemove.mof [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mt-MT [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [20.55 Ko] - C:\WINDOWS\System32\MUI [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [34.35 Ko] - C:\WINDOWS\System32\my-mm [MD5.14EDB1743C929A31AC0F11927F80E7F0] - |A| - [24/06/2015 21:59:10] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [5165.96 Ko] - (6.3.9600.17231) - C:\WINDOWS\System32\NAHIMICAPOlfx.dll [MD5.10AD7AB1FC06A5874F03B34F064CB09D] - |A| - [24/06/2015 21:57:00] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO Settings Communication Dll.) - [980.34 Ko] - (1.0.0.14866) - C:\WINDOWS\System32\NahimicAPONSControl.dll [MD5.A3FD74081973B31A2FD04EF8B199C553] - |A| - [24/06/2015 21:59:10] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [5632.72 Ko] - (6.3.9600.16384) - C:\WINDOWS\System32\NAHIMICV2apo.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [396 Ko] - C:\WINDOWS\System32\nb-NO [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [896 Ko] - C:\WINDOWS\System32\NDF [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ne-NP [MD5.8C8630325515FAD04311765D5AE3FA0D] - |A| - [17/04/2017 21:34:27] - (.-.) - [91.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetSetupMig.log [MD5.C146E873B22C3B300B21A859FE66C27A] - |A| - [15/09/2018 08:29:23] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetTrace.PLA.Diagnostics.xml [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [102 Ko] - C:\WINDOWS\System32\networklist [MD5.8E24A7BCAEF2045DA1FF29217622843E] - |A| - [21/11/2010 03:52:07] - (.-.) - [0.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Network_LLU.log [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [431 Ko] - C:\WINDOWS\System32\nl-NL [MD5.5A2FD63B162FBD1E8C293135BDA27132] - |A| - [17/08/2011 09:59:22] - (.Copyright (c) 2002,2003,2004,2005. Nokia. - Wireless Communication Device Class Installer.) - [56.5 Ko] - (7.1.32.69) - C:\WINDOWS\System32\nmwcdclsx64.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\nn-NO [MD5.7E44DA154E5CDBB2946225C9EB4386AB] - |A| - [04/04/2013 22:11:05] - (.Copyright © 2013 - NPRuntime Script Plug-in Library for Java(TM) Deploy.) - [531.92 Ko] - (6.0.390.4) - C:\WINDOWS\System32\npdeployJava1.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\nso-ZA [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:50] - [3781.5 Ko] - C:\WINDOWS\System32\Nui [MD5.BED94E70C10EFF09AEF94D18CA7FF7F7] - |A| - [17/04/2017 21:37:27] - (.-.) - [7924.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvcoproc.bin [MD5.D2715E724478FAE559968916BD7DCADA] - |A| - [03/12/2018 11:46:13] - (.-.) - [47.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvinfo.pb [MD5.B6A772E360C09E009CC7FA0105E6319B] - |A| - [04/10/2019 17:25:57] - (.-.) - [17.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OEMDefaultAssociations.xml [MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.contrast-black.png [MD5.BFE1CCA08FEFC8A3422F7DA615567D75] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.contrast-white.png [MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.png [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [23802.06 Ko] - C:\WINDOWS\System32\oobe [MD5.2AD7B4F3C8D2BB686D231EDFF404B7A4] - |A| - [07/11/2013 12:48:33] - (.Copyright (C) 2000-2006 - Standard OpenAL(TM) Implementation.) - [120.02 Ko] - (6.14.357.24) - C:\WINDOWS\System32\OpenAL32.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:53] - [3554.5 Ko] - C:\WINDOWS\System32\OpenSSH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\or-IN [MD5.459FB33AA2114A28C5932FEAA115B072] - |A| - [15/09/2018 08:28:22] - (.-.) - [45.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OutdoorAudioEnvironment.bin [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\pa-Arab-PK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\pa-IN [MD5.26B172DB42D20F58D08A1AAED9C1B7D8] - |A| - [25/11/2012 17:22:24] - (.Copyright (C) 2011, 2012 - pdfcmon.) - [98.5 Ko] - (0.2.1.0) - C:\WINDOWS\System32\pdfcmon.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [1123.97 Ko] - C:\WINDOWS\System32\PerceptionSimulation [MD5.345616AE393704DA2275B44286C6E754] - |A| - [15/09/2018 08:35:59] - (.-.) - [164.23 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc009.dat [MD5.51EEA7ACF5D7AA1CAB7DDB7C7AF19EA8] - |A| - [15/09/2018 17:39:07] - (.-.) - [173.75 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc00C.dat [MD5.1E60BC5E525063B96078DF17FBD3C4E1] - |A| - [15/09/2018 08:35:59] - (.-.) - [32.64 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd009.dat [MD5.9F9AF8517189B0D61B2615007E071084] - |A| - [15/09/2018 17:39:07] - (.-.) - [39.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd00C.dat [MD5.95DAD5D164132D21864B97EB0C1E29F1] - |A| - [15/09/2018 08:35:59] - (.-.) - [778.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh009.dat [MD5.9D0D73A5612C7D4AEBA72679E024A12D] - |A| - [15/09/2018 17:39:07] - (.-.) - [845.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh00C.dat [MD5.2D54B332E2350B6FC5808DFD0E264E7A] - |A| - [27/06/2019 14:20:26] - (.-.) - [1961.59 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PerfStringBackup.INI [MD5.79D34E3B62076D4C875C748F5BE71ECA] - |A| - [15/09/2018 08:28:22] - (.-.) - [2.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PhoneSystemToastIcon.contrast-white.png [MD5.4D9495349D00D9AD907F227FF51F289F] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PhoneSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [429 Ko] - C:\WINDOWS\System32\pl-PL [MD5.CD421DDB5C6E5458CE52EDC36DE7DC5B] - |A| - [25/10/2016 17:15:58] - (.-.) - [74.37 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PnkBstrA.exe [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [437 Ko] - C:\WINDOWS\System32\PointOfService [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [420.74 Ko] - C:\WINDOWS\System32\Printing_Admin_Scripts [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [15/02/2016 10:09:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Programme [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [15/02/2016 10:09:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\System32\programmes [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\System32\ProximityToast [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\prs-AF [MD5.007893E8374C766471239EB291BA8C17] - |A| - [15/09/2018 08:28:29] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\psmodulediscoveryprovider.mof [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [423.5 Ko] - C:\WINDOWS\System32\pt-BR [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [426 Ko] - C:\WINDOWS\System32\pt-PT [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\quc-Latn-GT [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\quz-PE [MD5.52FB52A981FE6F375160491C972712B7] - |A| - [24/06/2015 21:59:10] - (.©2012 Dolby Laboratories. - Dolby PCEE4 ASL Analog x64.) - [131.05 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEA64A.dll [MD5.C6F4FFC449F0E530310986ED903D7DEF] - |A| - [24/06/2015 21:59:10] - (.©2012 Dolby Laboratories. - Dolby PCEE4 COM DLL x64.) - [437.23 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EED64A.dll [MD5.62560EB3B05AA687E4EAE3E4CEFEF019] - |A| - [24/06/2015 21:59:10] - (.©2012 Dolby Laboratories. - Dolby PCEE4 GFX APO x64.) - [82.63 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEG64A.dll [MD5.5578A467119491F95BC4AC7297959631] - |A| - [24/06/2015 21:59:10] - (.©2012 Dolby Laboratories. - Dolby PCEE4 LFX APO x64.) - [148.23 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEL64A.dll [MD5.C1A124D4C8FDE04A5BB51277FC4EF6CB] - |A| - [24/06/2015 21:57:00] - (.©2012 Dolby Laboratories. - Dolby PCEE4 Control Panel x64.) - [7004.8 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEP64A.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [23.75 Ko] - C:\WINDOWS\System32\ras [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0 Ko] - C:\WINDOWS\System32\RasToast [MD5.2210F24EDC6E80B1D311B2C3641DE9FA] - |A| - [14/08/2019 16:31:49] - (.-.) - [1983.5 Ko] - (1.0.1907.17001) - C:\WINDOWS\System32\rdpnano.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [2.18 Ko] - C:\WINDOWS\System32\Recovery [MD5.826549DF7B1333179BA8CA939B12DAD3] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RemoteSystemToastIcon.contrast-white.png [MD5.B4DEEC96F9DF6961D5DE054F11BF9C2B] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.1 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RemoteSystemToastIcon.png [MD5.93915F385A4EED6C0FBEE364EA90CE56] - |A| - [15/09/2018 08:29:25] - (.-.) - [9.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageList [MD5.93915F385A4EED6C0FBEE364EA90CE56] - |A| - [15/09/2018 08:29:25] - (.-.) - [9.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageListLowCost [MD5.39A2449AFF6ABAD80B97EA7C7CEB3F8E] - |A| - [15/09/2018 08:29:25] - (.-.) - [8.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageList [MD5.39A2449AFF6ABAD80B97EA7C7CEB3F8E] - |A| - [15/09/2018 08:29:25] - (.-.) - [8.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageListLowCost [MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.contrast-black.png [MD5.DF286186041C6BF73C5DC21CEEEFFED5] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.contrast-white.png [MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.png [MD5.AE9FE55FED83149715734CB83339055A] - |A| - [14/08/2019 16:31:56] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80.png [MD5.AE9FE55FED83149715734CB83339055A] - |A| - [14/08/2019 16:31:56] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80_contrast-black.png [MD5.891AD355AB777A95695FC8A8A623A614] - |A| - [14/08/2019 16:31:56] - (.-.) - [0.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80_contrast-white.png [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [0.07 Ko] - C:\WINDOWS\System32\restore [MD5.1845A234B834FF5772D494F09B910E50] - |A| - [27/06/2019 14:27:35] - (.-.) - [21.94 Ko] - (0.0.0.0) - C:\WINDOWS\System32\rfc2571.mib [MD5.DEC8F124829E17CA3C05107D6DFF69FA] - |A| - [24/06/2015 21:59:10] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x64.) - [314.18 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DAA64.dll [MD5.A7B225BB9EB8B346BECA1B3B23775D33] - |A| - [24/06/2015 21:59:10] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x64.) - [314.18 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DHT64.dll [MD5.20EAD89E5044DE5A2941537DE359A7C7] - |A| - [24/06/2015 21:59:10] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x64.) - [209.8 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEED64A.dll [MD5.E31F9FCB2537658F5ED1BE68D810B37F] - |A| - [24/06/2015 21:59:10] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x64.) - [86.28 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEG64A.dll [MD5.207E597220E4E54D5E7B8A06F1607600] - |A| - [24/06/2015 21:59:10] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x64.) - [108.38 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEL64A.dll [MD5.0C22251BF39C141EB580A3D7E0486779] - |A| - [24/06/2015 21:59:10] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x64.) - [378.24 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEP64A.dll [MD5.8AA05F502FCF586AFEA8E5C4AFB19AEB] - |A| - [15/09/2018 08:28:46] - (.-.) - [56.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\runexehelper.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\rw-RW [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [15/09/2018 08:29:46] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScavengeSpace.xml [MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.contrast-black.png [MD5.E72B1B6800DE45AA9AE7E10F899E5999] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.54 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.contrast-white.png [MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sd-Arab-PK [MD5.0E953E040B975849254BBFE63E9AFA07] - |A| - [01/12/2012 18:49:17] - (.-.) - [0.01 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SearchEngine.dat [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |A| - [15/09/2018 08:28:26] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\settings.dat [MD5.2C3DCF25D5FE14B3B429F7888B8D5E21] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFAPO.DLL.) - [86.26 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFAPO64.dll [MD5.78FED04B040A101EB02CBA370CBDA14C] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFCOM.DLL.) - [88.79 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFCOM64.dll [MD5.3D47D6EDBA872DF058AEBC33AA61AA64] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFNHK.DLL.) - [226.48 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFNHK64.dll [MD5.0DAA165140F5422B52BDC6653E2FC5B7] - |A| - [24/06/2015 21:59:10] - (.Copyright (C) 2013 DTS, Inc. - DTS Studio Sound.) - [938.49 Ko] - (3.1.38.0) - C:\WINDOWS\System32\sl3apo64.dll [MD5.8154D43E0A42695FEA8FF9E8BB65FECE] - |A| - [24/06/2015 21:59:10] - (.Copyright (C) 2011 SRS Labs, Inc. - SRS Labs.) - [1096.33 Ko] - (3.1.38.0) - C:\WINDOWS\System32\slcnt64.dll [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 13:56:52] - [34608.79 Ko] - C:\WINDOWS\System32\SleepStudy [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [52.14 Ko] - C:\WINDOWS\System32\slmgr [MD5.7F294BF080D7EF9A720D790AF07816D0] - |A| - [24/06/2015 21:57:02] - (.TODO: (c) . - TODO: .) - [253.21 Ko] - (1.0.0.1) - C:\WINDOWS\System32\slprp64.dll [MD5.53C2DA9FA84736DECC32A511A258AADB] - |A| - [24/06/2015 21:59:10] - (.Copyright (C) 2013 DTS, Inc. - DTS Studio Sound.) - [732.2 Ko] - (3.1.38.0) - C:\WINDOWS\System32\sltech64.dll [MD5.DAC275ABAAD2B689D7BB3685E4032072] - |A| - [15/09/2018 08:28:22] - (.-.) - [68.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SmallRoom.bin [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:26] - [14513.02 Ko] - C:\WINDOWS\System32\SMI [MD5.7B02BD84347AFF7F9A9B820DA304CB34] - |A| - [27/06/2019 14:27:35] - (.-.) - [4.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\smi.mib [MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.contrast-black.png [MD5.E30B7D226E7B5B0EC2B9FC2316694ECC] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.contrast-white.png [MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [15/09/2018 08:28:39] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.png [MD5.DE3EAAF17BC934C77C4FC0C626EEA03B] - |A| - [15/09/2018 08:28:22] - (.-.) - [1.48 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpeakersSystemToastIcon.contrast-white.png [MD5.3308374DB8D20CFDA4D4204E2B5E559E] - |A| - [15/09/2018 08:28:22] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpeakersSystemToastIcon.png [MD5.D7C806511EE5CD3E3F9FB0D26957EBED] - |A| - [15/09/2018 08:29:24] - (.-.) - [37.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpectrumSyncClient.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [7564.02 Ko] - C:\WINDOWS\System32\Speech [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [12402.73 Ko] - C:\WINDOWS\System32\Speech_OneCore [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [183247.12 Ko] - C:\WINDOWS\System32\spool [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [6586.38 Ko] - C:\WINDOWS\System32\spp [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [23.61 Ko] - C:\WINDOWS\System32\sppui [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sq-AL [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sr-Cyrl-BA [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sr-Cyrl-RS [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [0 Ko] - C:\WINDOWS\System32\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [338.5 Ko] - C:\WINDOWS\System32\sr-Latn-RS [MD5.54E616B36E41E45BA1606F65AAD51DE2] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRAPO.DLL.) - [456.21 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRAPO64.dll [MD5.7E252669211FCAE12E39E87672570583] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [333.16 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM.dll [MD5.A1FB4F87A71D87D96D29EB278D60D71C] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [372.48 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM64.dll [MD5.2E00E08420875FAE0B173C6A34C2A575] - |A| - [15/09/2018 08:29:25] - (.-.) - [18.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms-apr.dat [MD5.EA8B12C5A67ADC1FE689FF886BD4CB7E] - |A| - [14/08/2019 16:32:43] - (.-.) - [57.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms.dat [MD5.22FDF7A2E890C26F4C1E92207AD42C8B] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRRPTR.DLL.) - [1401.51 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRRPTR64.dll [MD5.D132E8F870919C8A4E6930866FD75C88] - |A| - [24/06/2015 21:59:10] - (.(c) 2007 SRS Labs, Inc. - COM object implementing SRS Headphone 360.) - [204.63 Ko] - (1.1.0.0) - C:\WINDOWS\System32\SRSHP64.dll [MD5.CB57496B1AF096B42D95B61632DD859D] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006 SRS Labs, Inc.. - TruSurround HD and HD4 COM object for Windows.) - [216.77 Ko] - (1.1.4.0) - C:\WINDOWS\System32\SRSTSH64.dll [MD5.E6E4DA1464EC036AD110B7B6A2A54883] - |A| - [24/06/2015 21:59:10] - (.Copyright 2002 SRS Labs, Inc. - TruSurroundXT Module.) - [519.91 Ko] - (3.2.0.0) - C:\WINDOWS\System32\SRSTSX64.dll [MD5.5C9047C159EE21D63893DC77EEB20F8E] - |A| - [24/06/2015 21:59:10] - (.(c) 2006 SRS Labs, Inc. - WOW HD COM object for Windows.) - [162.31 Ko] - (1.1.3.0) - C:\WINDOWS\System32\SRSWOW64.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [44312 Ko] - C:\WINDOWS\System32\sru [MD5.3624B418DE33BB31E40C04F844ECBC33] - |A| - [13/12/2019 07:10:48] - (.-.) - [9.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SSASCurrent.log [MD5.DE63BBC4AF740A7D0C379A9D758FBCE9] - |A| - [15/09/2018 08:28:22] - (.-.) - [439 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ssdm.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [403 Ko] - C:\WINDOWS\System32\sv-SE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sw-KE [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:28] - [1391.43 Ko] - C:\WINDOWS\System32\Sysprep [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [955.28 Ko] - C:\WINDOWS\System32\SystemResetPlatform [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [10.73 Ko] - C:\WINDOWS\System32\ta-in [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [10.73 Ko] - C:\WINDOWS\System32\ta-lk [MD5.0B8821B257EEE9C01CD29C62AE9D3EF9] - |A| - [15/09/2018 08:29:16] - (.Copyright (c) libarchive authors - bsdtar archive tool.) - [49.5 Ko] - (3.3.2.0) - C:\WINDOWS\System32\tar.exe [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [910.96 Ko] - C:\WINDOWS\System32\Tasks [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 00:38:21] - [904.46 Ko] - C:\WINDOWS\System32\Tasks_Migrated [MD5.D602CA245CC6774A0981B607F0675609] - |A| - [15/09/2018 08:28:56] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\tcpmon.ini [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\te-IN [MD5.4BC04FD0E6237621AB3301AF949ABB54] - |A| - [12/11/2016 21:59:47] - (.Copyright (C) 2005-2015 - Thrustmaster Shock-Force Feedback Control Panel.) - [258 Ko] - (2.5.6.0) - C:\WINDOWS\System32\tmffbcpl.dll [MD5.4576F99E8DEBEFDDF09D386419B2CD0E] - |A| - [12/11/2016 21:59:47] - (.Copyright (C) 2004-2015 - Thrustmaster Force Feedback Library.) - [40.5 Ko] - (2.5.2.0) - C:\WINDOWS\System32\tmffbdrv.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\tn-ZA [MD5.B88B8D017386A00D7724519F475317A0] - |A| - [15/09/2018 08:28:26] - (.-.) - [10.33 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlan.xslt [MD5.2F05390B798363D51EBE65D6320CD45E] - |A| - [15/09/2018 08:28:26] - (.-.) - [1.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlanCredentials.xslt [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\tt-RU [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ug-CN [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [336.5 Ko] - C:\WINDOWS\System32\uk-UA [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:50] - [2133.08 Ko] - C:\WINDOWS\System32\UNP [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ur-PK [MD5.F729741D514ED13EF6AFCB1B568987A9] - |A| - [15/09/2018 08:28:38] - (.-.) - [44.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\UsbPmApi.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\uz-Latn-UZ [MD5.00000000000000000000000000000000] - |D| - [25/05/2015 20:00:20] - [10684.92 Ko] - C:\WINDOWS\System32\vbox [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\vi-VN [MD5.D70BEDB9436DBCA77D3E470C1BAB373E] - |A| - [04/05/2016 03:22:42] - (.-.) - [127.78 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkan-1-1-0-11-1.dll [MD5.B0ECA1A7A27554613D52FF60328D75DA] - |A| - [14/02/2016 02:46:26] - (.-.) - [123.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkan-1-1-0-3-0.dll [MD5.5450A69087D2F6955A253CB2BF86503C] - |A| - [08/12/2017 23:24:44] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [906.8 Ko] - (1.0.65.1) - C:\WINDOWS\System32\vulkan-1-1-0-65-1.dll [MD5.5450A69087D2F6955A253CB2BF86503C] - |A| - [27/06/2019 14:03:12] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [906.8 Ko] - (1.0.65.1) - C:\WINDOWS\System32\vulkan-1.dll [MD5.0597F21B1DCADAB5F28806671670CDE4] - |A| - [04/05/2016 03:22:10] - (.-.) - [44.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo-1-1-0-11-1.exe [MD5.8B3FD814D7DD1D35540C8C8883E83FF2] - |A| - [14/02/2016 02:45:26] - (.-.) - [44.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo-1-1-0-3-0.exe [MD5.95253BF8F996BEA19BFA974F61277E87] - |A| - [08/12/2017 23:24:32] - (.-.) - [577.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo-1-1-0-65-1.exe [MD5.95253BF8F996BEA19BFA974F61277E87] - |A| - [27/06/2019 14:03:12] - (.-.) - [577.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [05/03/2012 20:13:41] - [0 Ko] - C:\WINDOWS\System32\Wat [MD5.7B29768C8B59ECA9FCFCEAF6229BC8F8] - |A| - [24/06/2015 21:57:02] - (.Copyright © 1996-2012 - General Library for Plug-Ins.) - [2061.13 Ko] - (4.4.5.0) - C:\WINDOWS\System32\WavesGUILib64.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [171181.14 Ko] - C:\WINDOWS\System32\wbem [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [0 Ko] - C:\WINDOWS\System32\WCN [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [102328.37 Ko] - C:\WINDOWS\System32\WDI [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [15/09/2018 08:28:44] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WdsUnattendTemplate.xml [MD5.00000000000000000000000000000000] - |D| - [10/07/2015 12:04:22] - [0 Ko] - C:\WINDOWS\System32\wfp [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [1.12 Ko] - C:\WINDOWS\System32\WinBioDatabase [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [48376.75 Ko] - C:\WINDOWS\System32\WinBioPlugIns [MD5.89539DF69CB40A7D214B9EC799EF5CAA] - |A| - [15/09/2018 08:28:34] - (.-.) - [122.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsDefaultHeatProcessor.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [10719.64 Ko] - C:\WINDOWS\System32\WindowsPowerShell [MD5.28E98ED0B6B08B7F1D163FFD184B28AF] - |A| - [15/09/2018 08:28:26] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsSecurityIcon.png [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [175964 Ko] - C:\WINDOWS\System32\winevt [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [6006.72 Ko] - C:\WINDOWS\System32\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [107.53 Ko] - C:\WINDOWS\System32\winrm [MD5.BA47FD81FD97E15A391EAF72AFB774ED] - |A| - [27/06/2019 14:27:35] - (.-.) - [25.62 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wins.mib [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\wo-SN [MD5.C30C621748C66CE751B19B2788559A3E] - |A| - [15/09/2018 08:28:24] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcmon.png [MD5.69FEC1494F4C454E994D27CA6750832B] - |A| - [15/09/2018 08:28:46] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpr.config.xml [MD5.549347BCD4AACD63243D78E8F869DBB1] - |A| - [07/11/2013 12:48:33] - (.Copyright © 2008 - OpenAL32.) - [455.52 Ko] - (2.2.0.5) - C:\WINDOWS\System32\wrap_oal.dll [MD5.CD70FD75FDAF5B66A3F0FD38513DA636] - |A| - [15/09/2018 08:28:30] - (.-.) - [95 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xboxgipsynthetic.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\xh-ZA [MD5.8DCFE75827C03FE6D64F297535B596BB] - |A| - [12/11/2016 21:59:47] - (.Copyright (c) 2015 Flexera Software LLC. - InstallShield (R) Dialog Resources.) - [1459.25 Ko] - (22.0.0.330) - C:\WINDOWS\System32\_isres_0x040c.dll [MD5.41DD2D060E1172813A6EC59A7B190052] - |A| - [03/09/2015 11:15:13] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [0 Ko] - C:\WINDOWS\SysWOW64\0409 [MD5.00000000000000000000000000000000] - |D| - [10/02/2011 20:39:12] - [0 Ko] - C:\WINDOWS\SysWOW64\040C [MD5.D6F8DD9F561B8A67FFAC2BAD7E989770] - |A| - [15/09/2018 08:29:07] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AppHelpToast.png [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [15/09/2018 08:29:07] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AudioToastIcon.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [15/09/2018 08:29:08] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@EnrollmentToastIcon.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [15/09/2018 08:29:12] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@VpnToastIcon.png [MD5.DB71001FC261F6685BE410527DAE3942] - |A| - [15/09/2018 08:29:27] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@WirelessDisplayToast.png [MD5.0A97961897B2FEAA4AD1037F8F7C6564] - |A| - [22/07/2008 18:33:26] - (.Copyright © 2002 Abale.com - Abale Zip ActiveX.) - [280.52 Ko] - (5.0.3.0) - C:\WINDOWS\SysWOW64\AbaleZip.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 07:09:31] - [1963.8 Ko] - C:\WINDOWS\SysWOW64\AdvancedInstallers [MD5.A04A9EA5A1FC96CD21D7558DE56ECBDC] - |A| - [23/01/2017 20:02:10] - (.-.) - [1.95 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\AeXSetup.log [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\af-ZA [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\am-ET [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\AppLocker [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [228.5 Ko] - C:\WINDOWS\SysWOW64\ar-SA [MD5.30196C11BFB7FC2F4DD2A289AFFD8A84] - |A| - [15/09/2018 08:29:27] - (.Copyright (c) libarchive authors - Windows-internal libarchive library.) - [521 Ko] - (3.3.2.0) - C:\WINDOWS\SysWOW64\archiveint.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\as-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\az-Latn-AZ [MD5.52B3A8FABCE2F2CE0AB0FB769C774FB5] - |A| - [20/09/2012 07:30:56] - (.-.) - [0.05 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\B01B6011F1.sys [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\be-BY [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:28:28] - [12.63 Ko] - C:\WINDOWS\SysWOW64\BestPractices [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [206.5 Ko] - C:\WINDOWS\SysWOW64\bg-BG [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\bn-BD [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\bn-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\bs-Latn-BA [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0.1 Ko] - C:\WINDOWS\SysWOW64\Bthprops [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ca-ES [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ca-ES-valencia [MD5.66B6D67B9F47F6475500114AFF588EDE] - |A| - [05/05/2012 22:42:13] - (.-.) - [0.09 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\cache.00 [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot [MD5.00000000000000000000000000000000] - |D| - [14/07/2009 04:20:14] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot2 [MD5.57741342CB514072D26EF56B9EF95C86] - |A| - [24/08/2011 09:56:12] - (.Copyright 1999 - 2007 - CDDBControl Core Module.) - [777.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CDDBControl.dll [MD5.99A44759C589DF319376B29724DFBAEB] - |A| - [17/02/2011 15:39:22] - (.Copyright © 2003-2007 - CddbLangDE.) - [101.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CddbLangDE.dll [MD5.889293D30D3F7A459EA4C00FAF006B1B] - |A| - [17/02/2011 15:39:22] - (.Copyright © 2003-2007 - CddbLangES.) - [101.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CddbLangES.dll [MD5.C69B5427BCCA7BD1ABEE933B9CD41989] - |A| - [17/02/2011 15:39:22] - (.Copyright © 2003-2007 - CddbLangFR.) - [101.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CddbLangFR.dll [MD5.51E65BD6C3E4EB6F80F89E90647BC7DB] - |A| - [28/09/2006 19:52:18] - (.Copyright © 2003-2005 - CddbLangIT.) - [100 Ko] - (2.4.0.5) - C:\WINDOWS\SysWOW64\CddbLangIT.dll [MD5.1E4ADA579CF04AAE901F14970604078E] - |A| - [17/02/2011 15:39:22] - (.Copyright © 2003-2007 - CddbLangJA.) - [81.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CddbLangJA.dll [MD5.7E2EC1C9221CD17E96B61AA8BF6F38EF] - |A| - [28/09/2006 19:52:18] - (.Copyright © 2003-2005 - CddbLangNL.) - [96 Ko] - (2.4.0.5) - C:\WINDOWS\SysWOW64\CddbLangNL.dll [MD5.CDF4D8D1717F22F9BD5DFA9E44842757] - |A| - [17/02/2011 15:39:22] - (.Copyright © 2003-2007 - CddbLangRU.) - [165.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CddbLangRU.dll [MD5.F525176D64D23A4C4B27DD6BCCD96F4E] - |A| - [24/08/2011 09:56:12] - (.Copyright 2001 - 2007 - CDDBUIControl Module.) - [789.49 Ko] - (2.5.0.104) - C:\WINDOWS\SysWOW64\CDDBUI.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\chr-CHER-US [MD5.209FDF5096AFD1312B98527B8B7B852E] - |A| - [18/05/2016 13:49:10] - (.-.) - [952 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\cis-2.4.dll [MD5.38718C4E864DC8F8E1DB0EF3B5566FA7] - |A| - [02/06/2016 17:21:31] - (.Copyright (C) 2004/05 Sony DADC Austria AG - SecuROM Context-Menu for Explorer..) - [174.61 Ko] - (1.1.221.0) - C:\WINDOWS\SysWOW64\CmdLineExt_x64.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [317.5 Ko] - C:\WINDOWS\SysWOW64\com [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [73.66 Ko] - C:\WINDOWS\SysWOW64\config [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [05/03/2012 18:48:46] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\config.nt [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:51] - [53.11 Ko] - C:\WINDOWS\SysWOW64\Configuration [MD5.527266292FD297AED6394BE2B71ACC93] - |A| - [20/09/2012 07:31:33] - (.-.) - [32.75 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\CoreVorbis-uninstall.exe [MD5.442A37CA4D124A8CC2F89A27EB6E6BD1] - |A| - [23/08/2004 20:35:08] - (.Copyright © 2004 - CoreVorbis.) - [240 Ko] - (1.0.0.2) - C:\WINDOWS\SysWOW64\CoreVorbis.ax [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [263 Ko] - C:\WINDOWS\SysWOW64\cs-CZ [MD5.FDEF330575C8C8EAD815F58BB7A93ED3] - |A| - [15/07/2011 20:52:01] - (.Copyright 2011 - CSVer.) - [52 Ko] - (9.4.0.1026) - C:\WINDOWS\SysWOW64\CSVer.dll [MD5.1E02A122FE09272058FC1EF0B1B6265E] - |A| - [11/09/2019 17:28:40] - (.© 1996 - 2017 Daniel Stenberg, . - The curl executable.) - [377 Ko] - (7.55.1.0) - C:\WINDOWS\SysWOW64\curl.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\cy-GB [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [263.5 Ko] - C:\WINDOWS\SysWOW64\da-DK [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [290.5 Ko] - C:\WINDOWS\SysWOW64\de-DE [MD5.1E2E11549364F217A612D5445EA7D4D4] - |A| - [20/06/2016 17:54:35] - (.-.) - [42.18 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\debug.log [MD5.1230DAA8564721CA78F3165D7F0ECD36] - |A| - [28/12/2012 18:27:59] - (.-.) - [0.06 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\debug_error.txt [MD5.C04ED7B2794D40E8E777FD44ED44FC50] - |A| - [15/09/2018 08:29:03] - (.-.) - [0.36 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\DefaultAccountTile.png [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:51] - [202.5 Ko] - C:\WINDOWS\SysWOW64\DiagSvcs [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [7676.42 Ko] - C:\WINDOWS\SysWOW64\Dism [MD5.5DEF23316384C68ACFE42256F6156B4C] - |A| - [27/11/2001 01:19:54] - (.- DivX;-) Audio Codec.) - [284.58 Ko] - (4.1.0.3920) - C:\WINDOWS\SysWOW64\DivXa32.acm [MD5.ED1A2EE6F012880CB011BE729AA25B8B] - |A| - [11/12/2001 13:17:12] - (.- DivX ;-) MPEG-4 Video Codec.) - [404.56 Ko] - (4.1.0.3920) - C:\WINDOWS\SysWOW64\DivXc32.dll [MD5.B21C0CAA07E0FEBC980AB44568AD12FA] - |A| - [27/11/2001 01:19:54] - (.- DivX ;-) MPEG-4 Video Codec.) - [404.56 Ko] - (4.1.0.3917) - C:\WINDOWS\SysWOW64\DivXc32f.dll [MD5.C6F52507D29D894720A5549B97934275] - |A| - [04/09/2004 00:34:08] - (.Copyright © DivXNetworks, 2001-2004 - DivX® Decoder-Filter.) - [92 Ko] - (5.2.1.1328) - C:\WINDOWS\SysWOW64\divxdec_0407.dll [MD5.899303493A6E143B1CE41066590A7775] - |A| - [04/09/2004 00:34:08] - (.Copyright © DivXNetworks, 2001-2004 - Filtre décodeur DivX®.) - [92 Ko] - (5.2.1.1328) - C:\WINDOWS\SysWOW64\divxdec_040c.dll [MD5.E631B38894D975303CB7B98E8318EC02] - |A| - [04/09/2004 00:25:12] - (.Copyright ? DivXNetworks, 2001-2004 - DivX? Decoder ?????.) - [92 Ko] - (5.2.1.1328) - C:\WINDOWS\SysWOW64\divxdec_0411.dll [MD5.321AC6CDC7F4167241D3BD78C09EA0B4] - |A| - [27/11/2001 01:19:54] - (.No More Money ! - DivX MPEG-4 DVD Video Decompressor.) - [234.77 Ko] - (4.1.0.3917) - C:\WINDOWS\SysWOW64\DivX_c32.ax [MD5.9B8413CAD2279F7D2C92506270FD820E] - |A| - [11/12/2002 09:19:59] - (.Copyright (C) 2001-2002 Gabest - DirectVobSub.) - [244 Ko] - (2.0.23.0) - C:\WINDOWS\SysWOW64\DVobSub.ax [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [294 Ko] - C:\WINDOWS\SysWOW64\el-GR [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [0 Ko] - C:\WINDOWS\SysWOW64\en [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [191 Ko] - C:\WINDOWS\SysWOW64\en-GB [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [709.53 Ko] - C:\WINDOWS\SysWOW64\en-US [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [278 Ko] - C:\WINDOWS\SysWOW64\es-ES [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [209 Ko] - C:\WINDOWS\SysWOW64\es-MX [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [191.5 Ko] - C:\WINDOWS\SysWOW64\et-EE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\eu-ES [MD5.00000000000000000000000000000000] - |D| - [14/08/2012 18:18:55] - [0 Ko] - C:\WINDOWS\SysWOW64\Extensions [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:51] - [12990.15 Ko] - C:\WINDOWS\SysWOW64\F12 [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\fa-IR [MD5.95EE9AA23605B12C90666E595B42D313] - |A| - [30/01/2013 20:03:42] - (.-.) - [83.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ff_vfw.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [265 Ko] - C:\WINDOWS\SysWOW64\fi-FI [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\fil-PH [MD5.B873A5ABCFBC42B1BAC9EBE8741C6162] - |A| - [13/11/2019 20:45:58] - (.Copyright (C) 2019 - Gracenote SDK component.) - [244 Ko] - (3.9.511.0) - C:\WINDOWS\SysWOW64\gnsdk_fp.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\gu-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ha-Latn-NG [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [217.5 Ko] - C:\WINDOWS\SysWOW64\he-IL [MD5.2E2FE36B09077A3EEBF713F3257514FC] - |A| - [15/09/2018 08:29:03] - (.-.) - [200.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\HeatCore.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\hi-IN [MD5.7350B30327E6188E69B2C131F007D5C0] - |A| - [14/10/2016 00:54:32] - (.© 2016 HPDC LP - HPScanTRDrv Module.) - [3319.66 Ko] - (43.0.3621.0) - C:\WINDOWS\SysWOW64\HPScanTEDrv_DJ2600.dll [MD5.D53DA3D5702122A514691066A38EAAEF] - |A| - [14/10/2016 00:52:32] - (.© 2016 HPDC LP - DiscoveryLibDyn Module.) - [574.66 Ko] - (43.0.3621.0) - C:\WINDOWS\SysWOW64\HPScanTEDrv_DJ2600_DiscoveryLibDyn.dll [MD5.8EE880B7C1D295DF650FC9F177739E18] - |A| - [08/12/2001 21:20:20] - (.Copyright © 2000 Ben Rudiak-Gould. - Huffyuv lossless video codec.) - [38 Ko] - (2.1.1.1) - C:\WINDOWS\SysWOW64\HUFFYUV.DLL [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\hy-AM [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [36.27 Ko] - C:\WINDOWS\SysWOW64\icsxml [MD5.93214B768B4306824547485C4F8D43DC] - |RA| - [29/06/2019 12:49:47] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU I18N DLL.) - [1581 Ko] - (61.1.0.0) - C:\WINDOWS\SysWOW64\icuin.dll [MD5.7A55602EDBB1ECC335AA0E3FE75C2890] - |RA| - [29/06/2019 12:49:47] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Common DLL.) - [1128 Ko] - (61.1.0.0) - C:\WINDOWS\SysWOW64\icuuc.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\id-ID [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ig-NG [MD5.093C86CD529A3932C9E58C3387DA4AAC] - |A| - [13/07/2009 22:59:35] - (.-.) - [407.56 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\igcompkrng500.bin [MD5.87031985145FE4FC13E8DABF387E78A4] - |A| - [13/07/2009 22:59:36] - (.-.) - [136.55 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\igfcg500.bin [MD5.44E5EA6A6AB4D6343B8FBC1DE19B5005] - |A| - [13/07/2009 22:59:36] - (.-.) - [95.16 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\igfcg500m.bin [MD5.71E96C791D10CAACF4867C5AD65FA19B] - |A| - [13/07/2009 22:59:36] - (.-.) - [959.18 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\igkrng500.bin [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [21854.52 Ko] - C:\WINDOWS\SysWOW64\IME [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [8552.44 Ko] - C:\WINDOWS\SysWOW64\inetsrv [MD5.DC0E693807A529CCC10D1AB9126FB753] - |A| - [27/06/2019 14:36:53] - (.-.) - [577.96 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\InputHost.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [219 Ko] - C:\WINDOWS\SysWOW64\InputMethod [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [1160 Ko] - C:\WINDOWS\SysWOW64\InstallShield [MD5.882EA53A3565FF4D5A81B44650C7096F] - |A| - [19/09/2012 22:46:43] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\InstallUtil.InstallLog [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\Ipmi [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\is-IS [MD5.D8D6FA22135619B3C3B32441571B3C4F] - |A| - [18/05/2016 13:49:10] - (.-.) - [80 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\issacapi_bs-2.3.dll [MD5.18DB794E8C223A248671D4A9409AED23] - |A| - [18/05/2016 13:49:10] - (.-.) - [64 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\issacapi_pe-2.3.dll [MD5.F7D4D358EE74ADF1ECDEEFBA35765D22] - |A| - [18/05/2016 13:49:10] - (.-.) - [56 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\issacapi_se-2.3.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [275.5 Ko] - C:\WINDOWS\SysWOW64\it-IT [MD5.2CB7EF22466AC884915D854E0F7889C0] - |A| - [19/06/2012 18:52:42] - (.-.) - [1.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\IusEventLog.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [201.5 Ko] - C:\WINDOWS\SysWOW64\ja-JP [MD5.2211C51BABE577798343D69F818E25AB] - |A| - [09/02/2016 20:15:40] - (.Copyright © 2016 - Java(TM) Web Start Launcher.) - [272.09 Ko] - (11.73.2.2) - C:\WINDOWS\SysWOW64\javaws.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ka-GE [MD5.E4FF28ED8315304BAE3A5E3EFCE8179F] - |A| - [20/09/2012 07:30:56] - (.-.) - [1.64 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\KGyGaAvL.sys [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\kk-KZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\km-KH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\kn-IN [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [201 Ko] - C:\WINDOWS\SysWOW64\ko-KR [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\kok-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ku-Arab-IQ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ky-KG [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [19/08/2016 14:56:01] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\last.dump [MD5.8DB7967838109BE33CAE414F324D8F42] - |A| - [23/05/2015 21:05:45] - (.Copyright © 2010 -.) - [339.82 Ko] - (2.3.4.2) - C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\lb-LU [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [625.17 Ko] - C:\WINDOWS\SysWOW64\Licenses [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\lo-LA [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [15/07/2011 20:53:32] - (.-.) - [0.02 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\log.txt [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\LogFiles [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [203 Ko] - C:\WINDOWS\SysWOW64\lt-LT [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [200 Ko] - C:\WINDOWS\SysWOW64\lv-LV [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [50638.4 Ko] - C:\WINDOWS\SysWOW64\Macromed [MD5.8901A0803B5601DC1DF5ECC99339C09B] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2003-2004, (?) ???? - ????? ???? ?????.) - [44 Ko] - (1.2.2005.128) - C:\WINDOWS\SysWOW64\MACXMLProto.dll [MD5.C2CDFD61447D278C96B441C13F8F71BE] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2003 - MaDRM DLL.) - [116 Ko] - (3.0.2004.1011) - C:\WINDOWS\SysWOW64\MaDRM.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:40:28] - [32.68 Ko] - C:\WINDOWS\SysWOW64\MailContactsCalendarSync [MD5.B5B76E18B10724CF0D88CCC9B1F4FB37] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2003, (?) ???? - MaJGUILib DLL.) - [48 Ko] - (1.0.2004.301) - C:\WINDOWS\SysWOW64\MaJGUILib.dll [MD5.9B2F9CC5BD4D266A2E76DBFECDDB0122] - |A| - [18/05/2016 13:49:10] - (.Copyright ? 2004 MarkAny Inc. - ???? MAC ?? ?? DLL.) - [44.26 Ko] - (1.0.2009.930) - C:\WINDOWS\SysWOW64\MAMACExtract.dll [MD5.00000000000000000000000000000000] - |D| - [14/07/2009 04:20:14] - [0 Ko] - C:\WINDOWS\SysWOW64\manifeststore [MD5.2C16CF611C87FAB86B287CFFBA91B647] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2004 - (?)???? ContentSAFER Cleaner.) - [24 Ko] - (3.0.2006.925) - C:\WINDOWS\SysWOW64\MASetupCleaner.exe [MD5.642C11D988A14D3A441B5040AE0DA5C6] - |A| - [16/08/2004 16:41:08] - (.Copyright (C) 2003-2004 Gabest - Matroska Muxer.) - [232 Ko] - (1.0.0.9) - C:\WINDOWS\SysWOW64\MatroskaMuxer.ax [MD5.A9CD14749A956990435FBC2E5911504A] - |A| - [06/09/2004 18:30:52] - (.Copyright (C) 2003-2004 Gabest - Matroska Splitter.) - [336 Ko] - (1.0.2.4) - C:\WINDOWS\SysWOW64\MatroskaSplitter.ax [MD5.AD2454F9D19FDCA0FF26F48E809F5361] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2003-2004, (?) ???? - MaXMLProto DLL.) - [44 Ko] - (1.0.2004.602) - C:\WINDOWS\SysWOW64\MaXMLProto.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mi-NZ [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [3692.78 Ko] - C:\WINDOWS\SysWOW64\migration [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [815.3 Ko] - C:\WINDOWS\SysWOW64\migwiz [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mk-MK [MD5.01FB39AD6F00AEF968372027259E8F13] - |A| - [18/05/2016 13:49:10] - (.Copyright ? 2004 - MK_Lyric.) - [56 Ko] - (1.0.1124.1) - C:\WINDOWS\SysWOW64\MK_Lyric.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ml-IN [MD5.C8BF077B236ED2803347BD95DE29BF68] - |A| - [15/09/2018 08:31:37] - (.-.) - [3.03 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\mmc.exe.config [MD5.DEF6EC43802634D22781DB253E7C2CEE] - |A| - [30/01/2013 20:43:22] - (.Copyright Damien Bain-Thouverez 2007 - MMShellHook DLL for Win32.) - [10 Ko] - (1.0.0.0) - C:\WINDOWS\SysWOW64\MMShellHook.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mn-MN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mr-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ms-MY [MD5.422D36A4743BF9CC2A787A68D9C9A988] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2005 Teruten Inc. - MSCLib DLL.) - [240 Ko] - (1.0.0.8) - C:\WINDOWS\SysWOW64\MSCLib.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [45.5 Ko] - C:\WINDOWS\SysWOW64\MSDRM [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [52.28 Ko] - C:\WINDOWS\SysWOW64\Msdtc [MD5.99089A2B318765568F2745BBF1A4F870] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2005 Teruten Inc. - MSFLib DLL.) - [152 Ko] - (1.0.0.7) - C:\WINDOWS\SysWOW64\MSFLib.dll [MD5.18403DE4979A328F21279DECB2E4298F] - |A| - [15/09/2018 08:29:54] - (.-.) - [3.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\msmqpub.mof [MD5.E0640DE5407EEE4C6E16D839243B71F9] - |A| - [15/09/2018 08:41:19] - (.-.) - [8.88 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\msmqtrc.mof [MD5.3ED9AC3EE11EE2C16E2E41F0DC4BAD42] - |A| - [15/09/2018 08:29:54] - (.-.) - [0.87 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\msmqtrcRemove.mof [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mt-MT [MD5.CF25249C36368124E0FF9E6B68194460] - |A| - [18/05/2016 13:49:10] - (.Copyright (C) 2001 Telechips Inc., - USB Dynamic Link Library for TCC730.) - [40 Ko] - (1.9.4.2) - C:\WINDOWS\SysWOW64\MTTELECHIP.dll [MD5.E8558EFAD97B3D10A73E8DC9426E4DCA] - |A| - [18/05/2016 13:49:10] - (.Copyright 2004 Marktek Inc. - MTXSYNCICON Module.) - [56 Ko] - (1.0.0.1) - C:\WINDOWS\SysWOW64\MTXSYNCICON.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [20.55 Ko] - C:\WINDOWS\SysWOW64\MUI [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [262 Ko] - C:\WINDOWS\SysWOW64\nb-NO [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\NDF [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ne-NP [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [51 Ko] - C:\WINDOWS\SysWOW64\networklist [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [275.5 Ko] - C:\WINDOWS\SysWOW64\nl-NL [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\nn-NO [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\nso-ZA [MD5.00000000000000000000000000000000] - |SD| - [15/09/2018 08:33:51] - [3781.5 Ko] - C:\WINDOWS\SysWOW64\Nui [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [08/06/2015 10:37:33] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\Number of results [MD5.A6C9A92E579AD93306F702140F1E6840] - |A| - [05/10/2002 00:04:17] - (.-.) - [44 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ogg.dll [MD5.AC39539F25C253BBFDCC73AB0A771B51] - |A| - [06/10/2002 19:42:57] - (.Copyright (C) 2002 Tobias Waldvogel - Ogg DirectShow(tm) Filter Collection.) - [232 Ko] - (0.9.9.5) - C:\WINDOWS\SysWOW64\OggDS.dll [MD5.C51F878B37C7E66D3782BED018F4F515] - |A| - [20/09/2012 07:31:30] - (.-.) - [35.87 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\OggDSuninst.exe [MD5.B3B9C8925432FDA674ACCA908FE3CFDE] - |A| - [15/09/2018 08:40:49] - (.-.) - [36.79 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\OneDrive.ico [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [8308.61 Ko] - C:\WINDOWS\SysWOW64\oobe [MD5.235355A8DD26903E75D5E812ECF50E53] - |A| - [07/11/2013 12:48:33] - (.Copyright (C) 2000-2006 - Standard OpenAL(TM) Implementation.) - [106.52 Ko] - (6.14.357.24) - C:\WINDOWS\SysWOW64\OpenAL32.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\or-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\pa-Arab-PK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\pa-IN [MD5.577C2FC077203F646C43F61B1796A9CF] - |A| - [21/06/2012 09:37:14] - (.-.) - [2197.29 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\pbsvc.exe [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [68 Ko] - C:\WINDOWS\SysWOW64\PerceptionSimulation [MD5.64C7A2FDF5C725F2DBC064AAD36F6B26] - |A| - [17/04/2017 21:38:05] - (.-.) - [2001.87 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PerfStringBackup.INI [MD5.C857721980B36F7018327FA795648CFF] - |A| - [26/11/2013 22:13:25] - (.Copyright (c) 2000 - 2012 Advanced Messaging Systems LLC - Outlook Redemption COM library.) - [5987.5 Ko] - (5.4.0.3044) - C:\WINDOWS\SysWOW64\PhoenixDll.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [275 Ko] - C:\WINDOWS\SysWOW64\pl-PL [MD5.13001EB0A58B4DE96126B16AB15FD8CC] - |A| - [20/03/2014 12:54:06] - (.Copyright (C) Real Networks 1999 - Real Networks C/C++ Runtime Library.) - [272 Ko] - (6.0.0.0) - C:\WINDOWS\SysWOW64\pncrt.dll [MD5.3A2E85F7D90D15460C337CE80C2E3B29] - |A| - [09/05/2015 16:29:39] - (.-.) - [75.09 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PnkBstrA.exe [MD5.FC72546EA23DD8144D4FF44152378729] - |A| - [26/10/2016 21:05:27] - (.-.) - [209.37 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PnkBstrB.ex0 [MD5.7216827676AE6B40F7873C481B9E9446] - |A| - [26/10/2016 21:05:53] - (.-.) - [220.87 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PnkBstrB.exe [MD5.8B3FCD4D5F2D4211E38DCADD3A096004] - |A| - [26/10/2012 22:47:48] - (.-.) - [276.07 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PnkBstrB.xtr [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [420.74 Ko] - C:\WINDOWS\SysWOW64\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\prs-AF [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [273 Ko] - C:\WINDOWS\SysWOW64\pt-BR [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [275.5 Ko] - C:\WINDOWS\SysWOW64\pt-PT [MD5.CE931021E18F385F519E945A8A10548E] - |A| - [30/01/2013 20:03:42] - (.Copyright (C) Project contributors 1998-2004 - POSIX Threads for Windows32 Library.) - [58.86 Ko] - (2.8.0.0) - C:\WINDOWS\SysWOW64\pthreadGC2.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\quc-Latn-GT [MD5.5148AC4AD8FA35D06FDBDE24CF9D8A0B] - |A| - [07/07/2012 21:33:42] - (.-.) - [0.18 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\queries-02.cache [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\quz-PE [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [23.75 Ko] - C:\WINDOWS\SysWOW64\ras [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\RasToast [MD5.96D1780365241CF98A56165FC04CFD55] - |A| - [20/03/2014 12:54:06] - (.Copyright (C) 2003-2005 - RealMedia Splitter.) - [412 Ko] - (1.0.1.1) - C:\WINDOWS\SysWOW64\RealMediaSplitter.ax [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0.82 Ko] - C:\WINDOWS\SysWOW64\Recovery [MD5.A64711C9CF690718EADA750370EC5EB2] - |A| - [26/08/2017 18:52:11] - (.Copyright (c) 2000 - 2010 Dmitry Streblechenko - Outlook Redemption COM library.) - [4550.5 Ko] - (4.8.0.1184) - C:\WINDOWS\SysWOW64\Redemption.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\restore [MD5.E4CA91DBFAC20D5080FBEA70F7C87E3F] - |A| - [20/03/2014 12:54:32] - (.Copyright © RealNetworks, Inc. 1998-2004 - Real Player(tm) ActiveX Control.) - [177.48 Ko] - (6.0.9.2533) - C:\WINDOWS\SysWOW64\rmoc3260.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [207 Ko] - C:\WINDOWS\SysWOW64\ro-RO [MD5.00000000000000000000000000000000] - |D| - [17/04/2017 21:35:59] - [6935.32 Ko] - C:\WINDOWS\SysWOW64\RTCOM [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [272 Ko] - C:\WINDOWS\SysWOW64\ru-RU [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\rw-RW [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sd-Arab-PK [MD5.00000000000000000000000000000000] - |D| - [14/08/2012 18:18:55] - [0 Ko] - C:\WINDOWS\SysWOW64\searchplugins [MD5.7753FC56F9CAC4B5AFDA3196DB654F21] - |A| - [26/08/2017 17:54:23] - (.Copyright © 2004-2010 MAPILab Ltd. & Add-in Express Ltd. - Security Manager Component for Microsoft Outlook allows to turn off and on Outlook Object Model Security Guard.) - [141.27 Ko] - (3.0.0.0) - C:\WINDOWS\SysWOW64\secman.dll [MD5.6E42331397DD354DD6D162FDDEFEEC23] - |A| - [31/03/2000 21:47:38] - (.Copyright © 1996,1997 Fraunhofer Institut Integrierte Schaltungen IIS - MPEG Layer-3 Audio Codec for DivX.) - [294.5 Ko] - (1.2.0.63) - C:\WINDOWS\SysWOW64\SET9F97.tmp [MD5.793FE87864DF96B611F3481CCA66A801] - |A| - [13/11/2016 18:33:58] - (.-.) - [0.02 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\shortcut_ex.dat [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\si-LK [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [201 Ko] - C:\WINDOWS\SysWOW64\sk-SK [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [200 Ko] - C:\WINDOWS\SysWOW64\sl-SI [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [52.14 Ko] - C:\WINDOWS\SysWOW64\slmgr [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\SMI [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [4051.8 Ko] - C:\WINDOWS\SysWOW64\Speech [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [9041.62 Ko] - C:\WINDOWS\SysWOW64\Speech_OneCore [MD5.00000000000000000000000000000000] - |D| - [19/04/2012 07:07:03] - [7.53 Ko] - C:\WINDOWS\SysWOW64\spool [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [1304.29 Ko] - C:\WINDOWS\SysWOW64\spp [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [23.61 Ko] - C:\WINDOWS\SysWOW64\sppui [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sq-AL [MD5.0DC5AF80D059DEC792B665ED598C6567] - |A| - [28/04/2014 10:36:23] - (.2000-2010 Public Domain - SQLite Dynamic Link Library (No TCL).) - [524 Ko] - (3.7.2.0) - C:\WINDOWS\SysWOW64\sqlite3.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Cyrl-BA [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Cyrl-RS [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [200.5 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-RS [MD5.7E252669211FCAE12E39E87672570583] - |A| - [24/06/2015 21:59:10] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [333.16 Ko] - (4.0.0.59) - C:\WINDOWS\SysWOW64\SRCOM.dll [MD5.2E00E08420875FAE0B173C6A34C2A575] - |A| - [15/09/2018 08:29:33] - (.-.) - [18.28 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\srms-apr.dat [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\sru [MD5.2A9EB39951763761E55D46BFEB595AEB] - |A| - [15/09/2018 08:29:00] - (.-.) - [319.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ssdm.dll [MD5.D1953334ED302B2BE3C509336E5C53B3] - |A| - [19/12/2012 12:50:37] - (.Copyright (C) 2007 - Steam Client API.) - [119.13 Ko] - (7.9.87.40) - C:\WINDOWS\SysWOW64\steam_api.dll [MD5.9827540AD8A26F15F0CB56B6121BE143] - |A| - [26/11/2013 22:13:25] - (.Copyright (c) 2000 - 2012 Advanced Messaging Systems LLC - Outlook Redemption COM library.) - [773.13 Ko] - (5.4.0.3044) - C:\WINDOWS\SysWOW64\StellarProfile.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [264.5 Ko] - C:\WINDOWS\SysWOW64\sv-SE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sw-KE [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [0 Ko] - C:\WINDOWS\SysWOW64\sysprep [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ta-IN [MD5.8E49D76E21295D010FF0803D65928F5A] - |A| - [15/09/2018 08:29:28] - (.Copyright (c) libarchive authors - bsdtar archive tool.) - [42.5 Ko] - (3.3.2.0) - C:\WINDOWS\SysWOW64\tar.exe [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [0 Ko] - C:\WINDOWS\SysWOW64\Tasks [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\te-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tg-Cyrl-TJ [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [185 Ko] - C:\WINDOWS\SysWOW64\th-TH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ti-ET [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tk-TM [MD5.D7C4A881A58A37B8153AA15FD1581C8F] - |A| - [12/11/2016 21:59:39] - (.Copyright (C) 2005-2015 - Thrustmaster Shock-Force Feedback Control Panel.) - [234 Ko] - (2.5.6.0) - C:\WINDOWS\SysWOW64\tmffbcpl.dll [MD5.0AB0812747217687BDEE9C465879114B] - |A| - [12/11/2016 21:59:39] - (.Copyright (C) 2004-2015 - Thrustmaster Force Feedback Library.) - [35 Ko] - (2.5.2.0) - C:\WINDOWS\SysWOW64\tmffbdrv.dll [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [21/04/2012 18:06:12] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp1758.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [16/04/2011 00:40:18] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp386D.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [21/04/2012 18:06:11] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp38AD.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [16/04/2011 00:40:18] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp54E3.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [07/11/2013 12:48:33] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp5522.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [21/04/2012 18:06:12] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp783D.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [16/04/2011 00:40:18] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp99B5.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [01/07/2012 19:13:50] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmp99F4.tmp [MD5.75CA10B6D41ED18FC653461E63D247CF] - |A| - [03/11/2010 15:35:01] - (.Copyright © 2007 - OpenAL Installer.) - [764 Ko] - (2.0.3.0) - C:\WINDOWS\SysWOW64\tmp9A7B.tmp [MD5.75CA10B6D41ED18FC653461E63D247CF] - |A| - [22/03/2012 13:19:04] - (.Copyright © 2007 - OpenAL Installer.) - [764 Ko] - (2.0.3.0) - C:\WINDOWS\SysWOW64\tmp9A8C.tmp [MD5.694F54BD227916B89FC3EB1DB53F0685] - |A| - [21/04/2012 18:06:12] - (.Copyright © 2009 - OpenAL Installer.) - [790.52 Ko] - (2.0.7.0) - C:\WINDOWS\SysWOW64\tmpBCEE.tmp [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tn-ZA [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [257.5 Ko] - C:\WINDOWS\SysWOW64\tr-TR [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tt-RU [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ug-CN [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [202.5 Ko] - C:\WINDOWS\SysWOW64\uk-UA [MD5.60FEE6F524865950EF0A40D49F969320] - |A| - [15/10/2002 23:54:04] - (.-.) - [174.5 Ko] - (4.20.100.526) - C:\WINDOWS\SysWOW64\unrar.dll [MD5.00000000000000000000000000000000] - |D| - [01/12/2012 18:49:17] - [2409.5 Ko] - C:\WINDOWS\SysWOW64\update [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ur-PK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\uz-Latn-UZ [MD5.00000000000000000000000000000000] - |D| - [25/05/2015 20:00:20] - [7975.76 Ko] - C:\WINDOWS\SysWOW64\vbox [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\vi-VN [MD5.C4F97E10038EDC4E772480B0DA11B9D8] - |A| - [11/12/2002 09:19:32] - (.Copyright (C) 2000-2002 Gabest - vobsub.) - [360 Ko] - (2.0.23.0) - C:\WINDOWS\SysWOW64\vobsub.dll [MD5.DD783AAD2FAB1CD4764D1B3733FCA5A0] - |A| - [05/10/2002 00:04:24] - (.-.) - [184 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vorbis.dll [MD5.DCA492C3D3019A689E85F3FF0AFB3D3D] - |A| - [05/10/2002 00:04:25] - (.-.) - [900 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vorbisenc.dll [MD5.AB1C2F8AC516844B8B04FB36970A0109] - |A| - [08/03/2004 00:07:06] - (.Copyright (C) 2001-2004 Gabest - VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth.) - [756 Ko] - (1.0.0.9) - C:\WINDOWS\SysWOW64\VSFilter.dll [MD5.23EEB7034F3F7AA8554D9093B7EB319A] - |A| - [04/05/2016 03:23:30] - (.-.) - [126.78 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkan-1-1-0-11-1.dll [MD5.7B3AAC6D2DB9AAB0D1BD0CB753E4AF4D] - |A| - [14/02/2016 02:47:02] - (.-.) - [122.77 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkan-1-1-0-3-0.dll [MD5.ECAD282D3035068CFB021D159C91B514] - |A| - [08/12/2017 23:25:12] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [779.8 Ko] - (1.0.65.1) - C:\WINDOWS\SysWOW64\vulkan-1-1-0-65-1.dll [MD5.ECAD282D3035068CFB021D159C91B514] - |A| - [27/06/2019 14:03:12] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [779.8 Ko] - (1.0.65.1) - C:\WINDOWS\SysWOW64\vulkan-1.dll [MD5.B1F9C56E5F3C20FEF261E2510221F6E4] - |A| - [04/05/2016 03:22:58] - (.-.) - [39.28 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-11-1.exe [MD5.9D33E598C94B522D780B8023F9F5A207] - |A| - [14/02/2016 02:45:46] - (.-.) - [41.27 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-3-0.exe [MD5.35065D5FFEFB6886F77AA6A7E5DF901B] - |A| - [08/12/2017 23:25:00] - (.-.) - [479.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-65-1.exe [MD5.35065D5FFEFB6886F77AA6A7E5DF901B] - |A| - [27/06/2019 14:03:12] - (.-.) - [479.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [05/03/2012 20:13:41] - [0 Ko] - C:\WINDOWS\SysWOW64\Wat [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [15748.35 Ko] - C:\WINDOWS\SysWOW64\wbem [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [0 Ko] - C:\WINDOWS\SysWOW64\WCN [MD5.F884B2B3047C6A61B21540CEAACC53BC] - |A| - [15/09/2018 08:29:03] - (.-.) - [104.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [9481.89 Ko] - C:\WINDOWS\SysWOW64\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [6004.44 Ko] - C:\WINDOWS\SysWOW64\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 17:39:06] - [107.53 Ko] - C:\WINDOWS\SysWOW64\winrm [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\wo-SN [MD5.D494267BC169604FAC5E3679B9A97FED] - |A| - [07/11/2013 12:48:33] - (.Copyright © 2008 - OpenAL32.) - [434.52 Ko] - (2.2.0.5) - C:\WINDOWS\SysWOW64\wrap_oal.dll [MD5.4CC6C2D85CE89C54905BAEFCA1A0AA95] - |A| - [15/09/2018 08:29:03] - (.-.) - [62 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\xh-ZA [MD5.00000000000000000000000000000000] - |D| - [06/11/2013 18:58:23] - [137.63 Ko] - C:\WINDOWS\SysWOW64\xlive [MD5.A96108D16C92DCC2CE5C9B8856575CA7] - |A| - [28/09/2011 17:44:14] - (.-.) - [175.07 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xlive.dll.cat [MD5.00000000000000000000000000000000] - |D| - [27/06/2019 14:27:19] - [10.14 Ko] - C:\WINDOWS\SysWOW64\XPSViewer [MD5.A3C5D48D1532428BEB9EDA3CB8C1BBE2] - |A| - [13/12/2008 21:01:14] - (.-.) - [60 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvid.ax [MD5.0B636B7D453A5FD07F2CEB7662EE40DB] - |A| - [09/01/2009 00:01:22] - (.-.) - [664 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvidcore.dll [MD5.378CEBE09BCC2CE8DD3736794099C402] - |A| - [25/01/2009 22:10:48] - (.-.) - [152 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvidvfw.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\yo-NG [MD5.9D3213D595DF8FB063B94207891EAF8C] - |A| - [14/01/2013 15:20:22] - (.-.) - [738.5 Ko] - (4.3.3.3) - C:\WINDOWS\SysWOW64\ysys.dll [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [179 Ko] - C:\WINDOWS\SysWOW64\zh-CN [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\zh-HK [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:51] - [180 Ko] - C:\WINDOWS\SysWOW64\zh-TW [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\zu-ZA [MD5.0FA2DAC440CC175150AB3B4ECBE42C83] - |A| - [06/03/2012 22:42:04] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\__iw3mp ---------- | [Admin123] [27/06/2019 14:06:55] - |HD| - [242292462] - C:\Users\Admin123\AppData [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Application Data [15/02/2016 11:04:39] - |RD| - [412] - C:\Users\Admin123\Contacts [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Cookies [15/02/2016 11:03:55] - |RD| - [282] - C:\Users\Admin123\Desktop [15/02/2016 11:03:55] - |RD| - [402] - C:\Users\Admin123\Documents [15/02/2016 11:03:55] - |RD| - [282] - C:\Users\Admin123\Downloads [15/02/2016 11:03:55] - |RD| - [999] - C:\Users\Admin123\Favorites [15/02/2016 11:03:55] - |RD| - [2051] - C:\Users\Admin123\Links [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Local Settings [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Menu Démarrer [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Mes documents [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Modèles [15/02/2016 11:03:55] - |RD| - [504] - C:\Users\Admin123\Music [27/06/2019 14:06:55] - |AH| - [786432] - C:\Users\Admin123\NTUSER.DAT [27/06/2019 14:06:56] - |ASH| - [16384] - C:\Users\Admin123\ntuser.dat.LOG1 [27/06/2019 14:06:56] - |ASH| - [0] - C:\Users\Admin123\ntuser.dat.LOG2 [27/06/2019 14:06:56] - |ASH| - [65536] - C:\Users\Admin123\NTUSER.DAT{53f832e1-98e3-11e9-9f09-8c89a5a0577d}.TM.blf [27/06/2019 14:06:56] - |ASH| - [524288] - C:\Users\Admin123\NTUSER.DAT{53f832e1-98e3-11e9-9f09-8c89a5a0577d}.TMContainer00000000000000000001.regtrans-ms [27/06/2019 14:06:56] - |ASH| - [524288] - C:\Users\Admin123\NTUSER.DAT{53f832e1-98e3-11e9-9f09-8c89a5a0577d}.TMContainer00000000000000000002.regtrans-ms [15/02/2016 11:11:12] - |RD| - [99] - C:\Users\Admin123\OneDrive [15/02/2016 11:03:55] - |RD| - [884] - C:\Users\Admin123\Pictures [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Recent [15/02/2016 11:03:55] - |RD| - [282] - C:\Users\Admin123\Saved Games [15/02/2016 11:04:39] - |RD| - [1879] - C:\Users\Admin123\Searches [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\SendTo [15/02/2016 11:03:55] - |RD| - [504] - C:\Users\Admin123\Videos [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Voisinage d'impression [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\Voisinage réseau [27/06/2019 14:06:55] - |D| - [212751471] - C:\Users\Admin123\AppData\Local [15/02/2016 11:03:56] - |D| - [32782] - C:\Users\Admin123\AppData\LocalLow [27/06/2019 14:06:55] - |D| - [29508209] - C:\Users\Admin123\AppData\Roaming [15/02/2016 11:05:59] - |D| - [0] - C:\Users\Admin123\AppData\Local\ActiveSync [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\AppData\Local\Application Data [09/04/2016 16:20:22] - |D| - [18882580] - C:\Users\Admin123\AppData\Local\Comms [15/02/2016 11:10:36] - |D| - [8671821] - C:\Users\Admin123\AppData\Local\CrashDumps [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\AppData\Local\Historique [27/06/2019 14:06:55] - |D| - [122435374] - C:\Users\Admin123\AppData\Local\Microsoft [15/02/2016 11:27:00] - |D| - [22988974] - C:\Users\Admin123\AppData\Local\Mozilla [15/02/2016 11:04:05] - |D| - [1938] - C:\Users\Admin123\AppData\Local\NVIDIA Corporation [15/02/2016 11:04:35] - |D| - [27228832] - C:\Users\Admin123\AppData\Local\Packages [09/04/2016 16:15:58] - |D| - [0] - C:\Users\Admin123\AppData\Local\Publishers [27/06/2019 14:06:55] - |D| - [0] - C:\Users\Admin123\AppData\Local\Temp [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\AppData\Local\Temporary Internet Files [15/02/2016 11:04:32] - |D| - [12541952] - C:\Users\Admin123\AppData\Local\TileDataLayer [15/02/2016 11:04:47] - |D| - [0] - C:\Users\Admin123\AppData\Local\VirtualStore [15/02/2016 11:04:00] - |SD| - [32782] - C:\Users\Admin123\AppData\LocalLow\Microsoft [15/02/2016 11:04:34] - |D| - [0] - C:\Users\Admin123\AppData\Roaming\Adobe [15/02/2016 11:10:54] - |D| - [62793] - C:\Users\Admin123\AppData\Roaming\AVAST Software [15/02/2016 11:03:55] - |D| - [313848] - C:\Users\Admin123\AppData\Roaming\Macromedia [15/02/2016 11:03:55] - |D| - [0] - C:\Users\Admin123\AppData\Roaming\Media Center Programs [27/06/2019 14:06:55] - |SD| - [82883] - C:\Users\Admin123\AppData\Roaming\Microsoft [15/02/2016 11:27:00] - |D| - [29048685] - C:\Users\Admin123\AppData\Roaming\Mozilla [15/02/2016 11:04:39] - |ASH| - [174] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [10/10/2016 03:27:44] - |D| - [22309] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [27/06/2019 14:06:55] - |RD| - [3888] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [27/06/2019 14:06:55] - |RD| - [1486] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [15/02/2016 11:04:39] - |RD| - [174] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [15/02/2016 11:03:55] - |D| - [1221] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover [27/06/2019 14:06:55] - |ASH| - [47] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [27/06/2019 14:06:55] - |D| - [170] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [27/06/2019 14:06:55] - |A| - [1105] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [15/02/2016 11:04:39] - |RD| - [174] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [27/06/2019 14:06:55] - |RD| - [4913] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [15/02/2016 11:03:55] - |D| - [1377] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WaveEditor [27/06/2019 14:06:55] - |RD| - [7754] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [15/02/2016 11:04:39] - |ASH| - [174] - C:\Users\Admin123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Ben] [09/02/2016 20:15:19] - |D| - [225] - C:\Users\Ben\.oracle_jre_usage [22/10/2016 20:42:41] - |D| - [0] - C:\Users\Ben\.Origin [22/10/2016 20:42:43] - |D| - [0] - C:\Users\Ben\.QtWebEngineProcess [29/04/2018 15:27:40] - |A| - [161957] - C:\Users\Ben\1177407747.jpg [13/08/2015 12:01:36] - |RD| - [3715873] - C:\Users\Ben\3D Objects [27/03/2018 10:46:12] - |D| - [0] - C:\Users\Ben\ansel [27/06/2019 14:06:56] - |HD| - [6768758975] - C:\Users\Ben\AppData [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Application Data [08/01/2013 22:31:18] - |D| - [8943] - C:\Users\Ben\CE [05/03/2012 12:04:27] - |RD| - [45006] - C:\Users\Ben\Contacts [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Cookies [05/03/2012 12:04:18] - |RD| - [130010048576] - C:\Users\Ben\Desktop [05/03/2012 12:04:18] - |RD| - [31509963933] - C:\Users\Ben\Documents [05/03/2012 12:04:18] - |RD| - [514851582] - C:\Users\Ben\Downloads [05/03/2012 12:04:18] - |RD| - [23156] - C:\Users\Ben\Favorites [05/03/2012 12:04:18] - |RD| - [3176] - C:\Users\Ben\Links [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Local Settings [30/03/2012 22:22:29] - |D| - [594] - C:\Users\Ben\ManiaPlanet [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Menu Démarrer [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Mes documents [03/12/2018 14:43:07] - |HD| - [5780187] - C:\Users\Ben\MicrosoftEdgeBackups [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Modèles [19/10/2012 17:46:54] - |RD| - [6911800087] - C:\Users\Ben\Music [27/06/2019 14:06:56] - |AH| - [11010048] - C:\Users\Ben\NTUSER.DAT [27/06/2019 14:06:56] - |ASH| - [2760704] - C:\Users\Ben\ntuser.dat.LOG1 [27/06/2019 14:06:56] - |ASH| - [475136] - C:\Users\Ben\ntuser.dat.LOG2 [27/06/2019 14:06:57] - |ASH| - [65536] - C:\Users\Ben\NTUSER.DAT{53f832e1-98e3-11e9-9f09-8c89a5a0577d}.TM.blf [27/06/2019 14:06:57] - |ASH| - [524288] - C:\Users\Ben\NTUSER.DAT{53f832e1-98e3-11e9-9f09-8c89a5a0577d}.TMContainer00000000000000000001.regtrans-ms [27/06/2019 14:06:57] - |ASH| - [524288] - C:\Users\Ben\NTUSER.DAT{53f832e1-98e3-11e9-9f09-8c89a5a0577d}.TMContainer00000000000000000002.regtrans-ms [27/06/2019 14:36:21] - |SH| - [20] - C:\Users\Ben\ntuser.ini [12/08/2015 18:01:30] - |RD| - [94] - C:\Users\Ben\OneDrive [12/08/2015 07:29:34] - |RD| - [384] - C:\Users\Ben\Pictures [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Recent [05/03/2012 12:04:18] - |RD| - [51041324] - C:\Users\Ben\Saved Games [05/03/2012 12:04:45] - |RD| - [2807] - C:\Users\Ben\Searches [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\SendTo [14/08/2012 18:16:29] - |D| - [33404795] - C:\Users\Ben\Start Menu [12/08/2015 07:29:34] - |RD| - [384] - C:\Users\Ben\Videos [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Voisinage d'impression [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\Voisinage réseau [27/06/2019 14:06:56] - |D| - [5291183794] - C:\Users\Ben\AppData\Local [05/03/2012 12:04:19] - |D| - [421125641] - C:\Users\Ben\AppData\LocalLow [27/06/2019 14:06:56] - |D| - [1056449540] - C:\Users\Ben\AppData\Roaming [18/12/2015 08:11:31] - |D| - [0] - C:\Users\Ben\AppData\Local\ActiveSync [08/01/2016 22:43:12] - |D| - [7281282] - C:\Users\Ben\AppData\Local\Activision [04/09/2015 22:02:21] - |D| - [11805797] - C:\Users\Ben\AppData\Local\Adobe [17/12/2017 10:20:45] - |D| - [101154816] - C:\Users\Ben\AppData\Local\Apple [17/12/2017 10:23:56] - |D| - [14558586] - C:\Users\Ben\AppData\Local\Apple Computer [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\AppData\Local\Application Data [04/08/2016 20:26:16] - |D| - [0] - C:\Users\Ben\AppData\Local\Apps [29/04/2018 14:58:44] - |D| - [492310398] - C:\Users\Ben\AppData\Local\AVAST Software [08/12/2019 21:41:48] - |D| - [41629] - C:\Users\Ben\AppData\Local\cache [04/09/2015 22:02:31] - |D| - [6431184] - C:\Users\Ben\AppData\Local\CEF [25/12/2016 09:37:31] - |D| - [40] - C:\Users\Ben\AppData\Local\Chromium [12/08/2015 07:35:14] - |D| - [52125838] - C:\Users\Ben\AppData\Local\Comms [10/10/2016 11:42:36] - |D| - [4199383] - C:\Users\Ben\AppData\Local\ConnectedDevicesPlatform [03/09/2015 20:46:54] - |D| - [378924606] - C:\Users\Ben\AppData\Local\CrashDumps [10/02/2016 19:48:34] - |D| - [0] - C:\Users\Ben\AppData\Local\CrashRpt [15/04/2019 08:11:52] - |D| - [137032] - C:\Users\Ben\AppData\Local\D3DSCache [01/05/2017 09:33:14] - |D| - [0] - C:\Users\Ben\AppData\Local\DBG [11/11/2015 20:25:58] - |D| - [0] - C:\Users\Ben\AppData\Local\Diagnostics [18/02/2016 20:12:07] - |D| - [1951] - C:\Users\Ben\AppData\Local\Disc_Soft_Ltd [26/08/2017 18:51:20] - |D| - [70340572] - C:\Users\Ben\AppData\Local\Downloaded Installations [16/12/2019 15:39:34] - |D| - [1361] - C:\Users\Ben\AppData\Local\Electronic Arts [05/09/2015 16:56:50] - |D| - [64789] - C:\Users\Ben\AppData\Local\ElevatedDiagnostics [03/09/2015 19:52:08] - |SHD| - [0] - C:\Users\Ben\AppData\Local\EmieBrowserModeList [04/01/2016 00:01:15] - |D| - [22654388] - C:\Users\Ben\AppData\Local\FishingGame [11/12/2015 21:05:16] - |D| - [100324] - C:\Users\Ben\AppData\Local\FLT [01/04/2016 17:33:40] - |D| - [0] - C:\Users\Ben\AppData\Local\Gadwin [03/12/2018 16:03:39] - |D| - [0] - C:\Users\Ben\AppData\Local\Game Updater [25/11/2015 21:48:27] - |D| - [191271382] - C:\Users\Ben\AppData\Local\Google [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\AppData\Local\Historique [27/06/2019 18:10:14] - |AH| - [23401] - C:\Users\Ben\AppData\Local\IconCache.db [04/01/2016 09:57:12] - |D| - [1331] - C:\Users\Ben\AppData\Local\IsolatedStorage [04/09/2015 21:35:01] - |D| - [0] - C:\Users\Ben\AppData\Local\Macromedia [03/12/2018 15:05:47] - |D| - [1722892] - C:\Users\Ben\AppData\Local\mbam [03/12/2018 15:05:02] - |D| - [272972] - C:\Users\Ben\AppData\Local\mbamtray [04/01/2016 09:36:42] - |D| - [1555] - C:\Users\Ben\AppData\Local\MEDION [27/06/2019 14:06:56] - |D| - [571527737] - C:\Users\Ben\AppData\Local\Microsoft [10/05/2016 18:18:11] - |D| - [274] - C:\Users\Ben\AppData\Local\Microsoft Windows [03/09/2015 19:57:51] - |D| - [67532] - C:\Users\Ben\AppData\Local\MicrosoftEdge [03/09/2015 20:08:06] - |D| - [1101714334] - C:\Users\Ben\AppData\Local\Mozilla [24/01/2016 21:30:55] - |D| - [899165] - C:\Users\Ben\AppData\Local\MSKLC [23/08/2013 20:01:20] - |D| - [908432300] - C:\Users\Ben\AppData\Local\NVIDIA [03/09/2015 19:59:40] - |D| - [42749793] - C:\Users\Ben\AppData\Local\NVIDIA Corporation [08/10/2015 17:51:06] - |D| - [445126577] - C:\Users\Ben\AppData\Local\Origin [21/03/2018 01:51:06] - |D| - [525876550] - C:\Users\Ben\AppData\Local\Packages [09/12/2018 16:17:50] - |D| - [2495] - C:\Users\Ben\AppData\Local\PlaceholderTileLogoFolder [03/09/2015 21:55:42] - |D| - [0] - C:\Users\Ben\AppData\Local\Programs [04/09/2015 08:29:27] - |D| - [1158837] - C:\Users\Ben\AppData\Local\Publishers [20/01/2016 22:31:54] - |D| - [3907875] - C:\Users\Ben\AppData\Local\PunkBuster [15/02/2016 09:43:15] - |A| - [7604] - C:\Users\Ben\AppData\Local\Resmon.ResmonCfg [26/08/2017 20:58:36] - |D| - [11842] - C:\Users\Ben\AppData\Local\samsung [23/03/2016 19:54:44] - |D| - [7440] - C:\Users\Ben\AppData\Local\SKIDROW [07/09/2015 19:46:58] - |D| - [827392] - C:\Users\Ben\AppData\Local\SoftGrid Client [08/03/2016 22:58:30] - |D| - [83873] - C:\Users\Ben\AppData\Local\Sony [25/08/2017 21:15:55] - |D| - [940] - C:\Users\Ben\AppData\Local\speech [09/03/2016 22:55:42] - |D| - [7680] - C:\Users\Ben\AppData\Local\storage [04/03/2016 21:31:25] - |D| - [98883] - C:\Users\Ben\AppData\Local\StreetFighterV [27/06/2019 14:06:56] - |D| - [314132397] - C:\Users\Ben\AppData\Local\Temp [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\AppData\Local\Temporary Internet Files [12/08/2015 07:29:17] - |D| - [17424310] - C:\Users\Ben\AppData\Local\TileDataLayer [03/11/2015 22:03:13] - |D| - [2893] - C:\Users\Ben\AppData\Local\Ubisoft Game Launcher [04/01/2016 00:01:15] - |D| - [27] - C:\Users\Ben\AppData\Local\UnrealEngine [03/09/2015 20:06:13] - |D| - [643097] - C:\Users\Ben\AppData\Local\VirtualStore [16/12/2015 19:13:04] - |D| - [49152] - C:\Users\Ben\AppData\Local\Windows Live [01/11/2015 09:30:40] - |D| - [648527] - C:\Users\Ben\AppData\Local\Windows Live Writer [22/10/2016 17:24:22] - |D| - [0] - C:\Users\Ben\AppData\Local\YSearchUtil [24/02/2016 23:58:37] - |D| - [5556] - C:\Users\Ben\AppData\Local\Yummy Interactive Inc [26/12/2019 13:43:17] - |D| - [341203] - C:\Users\Ben\AppData\Local\ZHP [21/08/2017 20:32:24] - |D| - [0] - C:\Users\Ben\AppData\Local\{108034DB-5B37-4182-964A-C827BF3F8F48} [13/10/2016 18:13:10] - |D| - [0] - C:\Users\Ben\AppData\Local\{5A72DE57-497F-4B10-90FD-20F4EBE77E8A} [19/11/2016 21:10:38] - |D| - [0] - C:\Users\Ben\AppData\Local\{91AF0EC0-C568-43CA-942F-8FB6E558FA8E} [01/08/2016 18:13:41] - |D| - [0] - C:\Users\Ben\AppData\Local\{A0118434-71CC-4398-B836-C869D6181549} [22/08/2017 21:08:02] - |D| - [0] - C:\Users\Ben\AppData\Local\{C0B08717-7AEF-4F62-B1BF-3ACDC2F499F8} [01/07/2019 17:12:20] - |D| - [0] - C:\Users\Ben\AppData\Local\{F1400532-F070-419B-A4DE-9799091249F8} [08/03/2016 23:01:41] - |D| - [0] - C:\Users\Ben\AppData\Local\{F4AFC1C3-4AEE-4953-9132-F010B512C5F7} [07/03/2012 22:38:14] - |D| - [9933662] - C:\Users\Ben\AppData\LocalLow\Adobe [16/02/2015 20:20:46] - |D| - [1428480] - C:\Users\Ben\AppData\LocalLow\Bigben Interactive [18/11/2014 22:57:54] - |SHD| - [0] - C:\Users\Ben\AppData\LocalLow\EmieBrowserModeList [22/06/2014 16:29:47] - |SHD| - [0] - C:\Users\Ben\AppData\LocalLow\EmieSiteList [22/06/2014 16:30:26] - |SHD| - [0] - C:\Users\Ben\AppData\LocalLow\EmieUserList [18/04/2013 21:22:06] - |D| - [282265913] - C:\Users\Ben\AppData\LocalLow\Google [03/12/2018 11:08:12] - |D| - [217] - C:\Users\Ben\AppData\LocalLow\IObit [05/03/2012 12:04:32] - |SD| - [4879056] - C:\Users\Ben\AppData\LocalLow\Microsoft [27/11/2016 18:26:23] - |D| - [0] - C:\Users\Ben\AppData\LocalLow\Mozilla [09/02/2016 20:13:02] - |D| - [72376320] - C:\Users\Ben\AppData\LocalLow\Oracle [07/03/2012 20:37:57] - |D| - [1029867] - C:\Users\Ben\AppData\LocalLow\Sun [23/10/2012 12:28:52] - |D| - [0] - C:\Users\Ben\AppData\LocalLow\Temp [09/02/2016 06:45:34] - |D| - [49146590] - C:\Users\Ben\AppData\LocalLow\Unity [18/10/2016 16:49:37] - |D| - [65536] - C:\Users\Ben\AppData\LocalLow\uTorrent [09/02/2016 06:37:50] - |D| - [0] - C:\Users\Ben\AppData\Roaming\.mono [14/04/2015 17:28:56] - |A| - [4387] - C:\Users\Ben\AppData\Roaming\0JCYjqIoIDkRscGx2Dt9JzXi [14/01/2013 11:57:23] - |D| - [0] - C:\Users\Ben\AppData\Roaming\2K Sports [05/03/2012 19:49:50] - |D| - [7113812] - C:\Users\Ben\AppData\Roaming\Adobe [12/11/2012 16:37:54] - |D| - [239653476] - C:\Users\Ben\AppData\Roaming\Apple Computer [03/07/2012 07:17:18] - |D| - [2394] - C:\Users\Ben\AppData\Roaming\Autodesk [27/02/2014 17:36:07] - |D| - [30627602] - C:\Users\Ben\AppData\Roaming\AVAST Software [23/03/2012 19:00:36] - |D| - [3036612] - C:\Users\Ben\AppData\Roaming\BlackBean [28/04/2014 09:09:06] - |D| - [1003] - C:\Users\Ben\AppData\Roaming\BleachBit [19/11/2014 19:37:52] - |D| - [36661] - C:\Users\Ben\AppData\Roaming\BoneTown [22/10/2014 22:39:04] - |A| - [26] - C:\Users\Ben\AppData\Roaming\ClipExtractor-UpdatePerformed.txt [29/06/2012 21:56:48] - |D| - [1433055] - C:\Users\Ben\AppData\Roaming\Corel [03/07/2012 07:00:42] - |D| - [4205] - C:\Users\Ben\AppData\Roaming\CyberLink [05/03/2012 19:51:39] - |D| - [6030937] - C:\Users\Ben\AppData\Roaming\DAEMON Tools Lite [25/11/2012 10:53:20] - |D| - [203] - C:\Users\Ben\AppData\Roaming\dvdcss [03/12/2013 18:09:53] - |D| - [0] - C:\Users\Ben\AppData\Roaming\fr.myphotobook.creator [09/11/2014 12:04:47] - |D| - [8964] - C:\Users\Ben\AppData\Roaming\Gadwin [12/11/2012 08:57:15] - |D| - [1089677] - C:\Users\Ben\AppData\Roaming\GameCenter [05/03/2012 13:09:27] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Google [27/09/2013 22:24:50] - |D| - [13018] - C:\Users\Ben\AppData\Roaming\HP [15/01/2017 10:25:32] - |D| - [0] - C:\Users\Ben\AppData\Roaming\HPPSDr [05/03/2012 12:04:33] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Identities [14/08/2012 18:15:17] - |D| - [3] - C:\Users\Ben\AppData\Roaming\IncomingFiles [29/08/2013 11:30:24] - |D| - [0] - C:\Users\Ben\AppData\Roaming\InstallShield [05/03/2012 12:05:06] - |D| - [1356] - C:\Users\Ben\AppData\Roaming\Intel Corporation [03/12/2018 11:07:08] - |D| - [7142920] - C:\Users\Ben\AppData\Roaming\IObit [14/04/2015 17:28:56] - |A| - [4387] - C:\Users\Ben\AppData\Roaming\jXonqDJAKnk [23/05/2015 21:03:59] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Lavasoft [08/12/2015 23:24:53] - |D| - [413] - C:\Users\Ben\AppData\Roaming\Leadertech [05/03/2012 12:04:18] - |D| - [59655] - C:\Users\Ben\AppData\Roaming\Macromedia [02/08/2013 20:22:35] - |D| - [0] - C:\Users\Ben\AppData\Roaming\main [04/04/2013 22:18:38] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Malwarebytes [24/05/2013 20:56:44] - |A| - [43] - C:\Users\Ben\AppData\Roaming\mbam.context.scan [05/03/2012 12:04:18] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Media Center Programs [30/01/2013 18:58:32] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Media Control [05/10/2012 07:54:14] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Media Player Classic [30/01/2013 18:58:45] - |D| - [0] - C:\Users\Ben\AppData\Roaming\MediaConfiguration [27/06/2019 14:06:56] - |SD| - [16941675] - C:\Users\Ben\AppData\Roaming\Microsoft [17/01/2014 12:23:06] - |D| - [3742136] - C:\Users\Ben\AppData\Roaming\Milestone [07/01/2014 18:03:46] - |D| - [68457] - C:\Users\Ben\AppData\Roaming\MKKE [12/11/2012 16:00:22] - |D| - [232493921] - C:\Users\Ben\AppData\Roaming\Mozilla [20/09/2012 11:59:49] - |D| - [334] - C:\Users\Ben\AppData\Roaming\MusicNet [28/04/2014 09:36:22] - |D| - [570275] - C:\Users\Ben\AppData\Roaming\Notepad++ [20/04/2012 21:44:56] - |D| - [2057168] - C:\Users\Ben\AppData\Roaming\NVIDIA [28/09/2019 16:09:47] - |D| - [23481037] - C:\Users\Ben\AppData\Roaming\OpenOffice [08/10/2014 21:03:35] - |D| - [88762] - C:\Users\Ben\AppData\Roaming\Origin [02/05/2015 07:25:42] - |D| - [1747] - C:\Users\Ben\AppData\Roaming\PopCapv100181 [10/09/2012 21:08:22] - |D| - [0] - C:\Users\Ben\AppData\Roaming\PowerISO [31/07/2014 11:34:40] - |D| - [1578137] - C:\Users\Ben\AppData\Roaming\Pro Cycling Manager 2014 [28/06/2016 17:00:54] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Pro Cycling Manager 2015 [27/06/2016 21:06:09] - |D| - [1700734] - C:\Users\Ben\AppData\Roaming\Pro Cycling Manager 2016 [22/03/2012 13:21:02] - |D| - [8134992] - C:\Users\Ben\AppData\Roaming\ProtectDISC [19/04/2012 21:33:44] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Publish Providers [23/03/2012 18:32:22] - |D| - [3123272] - C:\Users\Ben\AppData\Roaming\PunkBuster [30/04/2012 20:21:39] - |D| - [4165075] - C:\Users\Ben\AppData\Roaming\Real [26/08/2017 17:54:23] - |D| - [107099] - C:\Users\Ben\AppData\Roaming\Samsung [20/02/2013 21:34:43] - |A| - [2018] - C:\Users\Ben\AppData\Roaming\SCPSP7.DLL [10/02/2013 21:34:43] - |RAS| - [1548] - C:\Users\Ben\AppData\Roaming\SCPSS7.DLL [02/09/2013 18:45:20] - |RHD| - [17046] - C:\Users\Ben\AppData\Roaming\SecuROM [11/12/2015 12:21:25] - |D| - [159200] - C:\Users\Ben\AppData\Roaming\siw_tmp [05/08/2015 21:06:02] - |D| - [18563904] - C:\Users\Ben\AppData\Roaming\Skype [05/03/2012 22:43:11] - |D| - [1369918] - C:\Users\Ben\AppData\Roaming\SoftGrid Client [19/04/2012 07:06:31] - |D| - [96708025] - C:\Users\Ben\AppData\Roaming\Sony [20/01/2013 18:51:07] - |D| - [9500791] - C:\Users\Ben\AppData\Roaming\Sony Corporation [19/04/2012 22:17:11] - |D| - [908] - C:\Users\Ben\AppData\Roaming\Sony Creative Software Inc [03/12/2018 16:44:57] - |D| - [659542] - C:\Users\Ben\AppData\Roaming\Steam [09/02/2016 20:15:19] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Sun [27/12/2013 08:30:09] - |D| - [12246338] - C:\Users\Ben\AppData\Roaming\The Creative Assembly [27/11/2012 19:51:15] - |D| - [89592] - C:\Users\Ben\AppData\Roaming\Theta [23/08/2013 20:11:19] - |D| - [280] - C:\Users\Ben\AppData\Roaming\Thunder Wolves [05/03/2012 22:41:42] - |D| - [0] - C:\Users\Ben\AppData\Roaming\TP [26/11/2013 21:40:12] - |D| - [216427352] - C:\Users\Ben\AppData\Roaming\TuneUp Software [26/10/2012 11:23:47] - |D| - [5907875] - C:\Users\Ben\AppData\Roaming\Ubisoft [25/04/2015 15:03:49] - |D| - [3301998] - C:\Users\Ben\AppData\Roaming\uplay [09/03/2012 18:33:20] - |D| - [57869542] - C:\Users\Ben\AppData\Roaming\uTorrent [14/04/2015 17:28:56] - |A| - [4387] - C:\Users\Ben\AppData\Roaming\V9ceZZL [14/11/2012 12:56:06] - |D| - [1122271] - C:\Users\Ben\AppData\Roaming\vlc [12/11/2013 22:17:46] - |D| - [1091626] - C:\Users\Ben\AppData\Roaming\VUPlayer [15/09/2012 18:22:00] - |D| - [295] - C:\Users\Ben\AppData\Roaming\Windows Live Writer [05/03/2012 22:15:20] - |D| - [12] - C:\Users\Ben\AppData\Roaming\WinRAR [24/04/2014 21:37:25] - |D| - [13070] - C:\Users\Ben\AppData\Roaming\Xilisoft [20/02/2013 22:14:23] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Yahoo! [31/01/2016 15:27:14] - |D| - [81] - C:\Users\Ben\AppData\Roaming\Youtube Downloader HD [26/12/2019 13:43:17] - |D| - [36872291] - C:\Users\Ben\AppData\Roaming\ZHP [05/03/2012 12:04:45] - |SH| - [174] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [22/12/2019 13:00:47] - |A| - [942] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\FIFA 19.lnk [01/08/2013 21:31:39] - |D| - [5084] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Player Orange Jeux [27/06/2019 14:06:56] - |SHD| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [10/10/2016 03:27:45] - |RD| - [36795] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [19/11/2014 23:37:56] - |A| - [831] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk [20/09/2012 07:31:20] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AC3Filter [27/06/2019 14:06:56] - |RD| - [3888] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [27/06/2019 14:06:56] - |RD| - [4239] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [05/03/2012 12:04:45] - |RD| - [174] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [05/03/2012 12:04:18] - |D| - [1233] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover [27/06/2019 14:06:56] - |SH| - [264] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [12/08/2015 07:33:31] - |A| - [1055] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fonctionnalités optionnelles.lnk [23/06/2012 15:06:04] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gadwin Systems [11/10/2012 23:08:06] - |D| - [914] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [27/06/2019 14:06:56] - |D| - [170] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [13/01/2015 22:08:11] - |D| - [1016] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEDION GoPal Assistant [20/09/2012 07:31:25] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Morgan Stream Switcher [28/04/2014 09:36:23] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ [25/11/2019 10:48:40] - |A| - [2439] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [05/03/2012 12:04:45] - |RD| - [174] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [27/01/2017 19:59:06] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam [27/06/2019 14:06:56] - |RD| - [4913] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [30/07/2013 16:45:49] - |D| - [2672] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft [20/09/2012 07:28:36] - |D| - [0] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VobSub [05/03/2012 12:04:18] - |D| - [1377] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WaveEditor [27/06/2019 14:06:56] - |RD| - [7754] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [24/12/2014 17:43:41] - |D| - [4513] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [05/03/2012 12:04:45] - |SH| - [174] - C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Jeux] [05/12/2014 19:41:09] - |RD| - [2121975385] - C:\Users\Jeux\Documents ---------- | [Public] [12/08/2015 07:29:34] - |RHD| - [196] - C:\Users\Public\AccountPictures [15/07/2011 21:03:52] - |D| - [242] - C:\Users\Public\CyberLink [14/07/2009 04:20:08] - |D| - [19413] - C:\Users\Public\Desktop [15/09/2018 08:31:35] - |ASH| - [174] - C:\Users\Public\desktop.ini [14/07/2009 04:20:08] - |RD| - [478369] - C:\Users\Public\Documents [14/07/2009 04:20:08] - |RD| - [174] - C:\Users\Public\Downloads [14/07/2009 04:20:08] - |RD| - [0] - C:\Users\Public\Favorites [15/09/2018 08:33:50] - |RHD| - [1135] - C:\Users\Public\Libraries [14/07/2009 04:20:08] - |RD| - [80538] - C:\Users\Public\Music [14/07/2009 04:20:08] - |RD| - [1263209] - C:\Users\Public\Pictures [21/11/2010 08:16:41] - |RD| - [0] - C:\Users\Public\Recorded TV [21/03/2018 00:44:52] - |D| - [0] - C:\Users\Public\Recorded TV (1) [25/12/2018 01:28:43] - |D| - [0] - C:\Users\Public\Recorded TV (2) [14/07/2009 04:20:08] - |RD| - [380] - C:\Users\Public\Videos ---------- | [TEMP] [15/04/2017 17:48:44] - |HD| - [6292109] - C:\Users\TEMP\AppData [15/04/2017 17:48:44] - |D| - [6292109] - C:\Users\TEMP\AppData\Roaming [15/04/2017 17:56:57] - |D| - [6292109] - C:\Users\TEMP\AppData\Roaming\AVAST Software [15/04/2017 17:49:48] - |D| - [0] - C:\Users\TEMP\AppData\Roaming\Mozilla ---------- | [TEMP.BEN-PC] [16/04/2017 08:32:44] - |HD| - [994796] - C:\Users\TEMP.BEN-PC\AppData [16/04/2017 08:32:44] - |D| - [0] - C:\Users\TEMP.BEN-PC\AppData\Local [16/04/2017 08:32:44] - |D| - [994796] - C:\Users\TEMP.BEN-PC\AppData\Roaming [16/04/2017 08:32:45] - |D| - [0] - C:\Users\TEMP.BEN-PC\AppData\Local\Temp [16/04/2017 08:38:20] - |D| - [994796] - C:\Users\TEMP.BEN-PC\AppData\Roaming\AVAST Software ---------- | C:\ProgramData [20/09/2012 11:59:49] - |D| - [4269] - C:\ProgramData\3127A [12/11/2012 16:36:39] - |D| - [7432] - C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [10/02/2011 21:48:08] - |D| - [742743852] - C:\ProgramData\Adobe [17/12/2017 10:19:33] - |D| - [9356] - C:\ProgramData\Apple [17/12/2017 10:22:02] - |D| - [203271] - C:\ProgramData\Apple Computer [27/06/2019 14:35:09] - |SHD| - [0] - C:\ProgramData\Application Data [03/07/2012 07:17:18] - |D| - [3138] - C:\ProgramData\Autodesk [04/04/2013 17:41:04] - |D| - [920093350] - C:\ProgramData\AVAST Software [11/08/2015 23:29:09] - |SHD| - [0] - C:\ProgramData\Bureau [10/09/2012 21:06:02] - |D| - [96] - C:\ProgramData\Common Files [29/06/2012 21:51:37] - |D| - [66336853] - C:\ProgramData\Corel [15/07/2011 21:01:26] - |D| - [63915] - C:\ProgramData\CyberLink [05/03/2012 19:51:34] - |D| - [32044] - C:\ProgramData\DAEMON Tools Lite [27/06/2019 14:35:09] - |SHD| - [0] - C:\ProgramData\Documents [17/04/2017 21:36:18] - |A| - [0] - C:\ProgramData\DP45977C.lfl [03/12/2017 15:12:48] - |D| - [1969959] - C:\ProgramData\DriversCloud.com [21/04/2012 18:11:27] - |SD| - [17269] - C:\ProgramData\DSS [30/10/2012 17:40:47] - |D| - [0] - C:\ProgramData\EA Core [30/10/2012 17:40:47] - |D| - [1040] - C:\ProgramData\EA Logs [29/10/2012 22:57:58] - |D| - [77038] - C:\ProgramData\Electronic Arts [11/08/2015 23:29:09] - |SHD| - [0] - C:\ProgramData\Favoris [05/03/2012 12:01:29] - |D| - [526448] - C:\ProgramData\Google [20/02/2013 22:07:45] - |D| - [7998669] - C:\ProgramData\HP [22/01/2013 18:09:34] - |D| - [1095782] - C:\ProgramData\Intel [03/12/2018 11:07:08] - |D| - [37153] - C:\ProgramData\IObit [29/10/2013 08:35:22] - |D| - [45616] - C:\ProgramData\KONAMI [23/05/2015 21:03:59] - |D| - [0] - C:\ProgramData\Lavasoft [03/12/2018 14:36:12] - |D| - [83660012] - C:\ProgramData\Malwarebytes [04/10/2012 12:17:32] - |D| - [61149] - C:\ProgramData\Mastiff [05/03/2012 12:05:33] - |D| - [66] - C:\ProgramData\Medion Reminder [11/08/2015 23:29:09] - |SHD| - [0] - C:\ProgramData\Menu Démarrer [15/09/2018 08:33:50] - |SD| - [1751367949] - C:\ProgramData\Microsoft [06/03/2013 22:53:02] - |D| - [50144] - C:\ProgramData\Microsoft Help [27/06/2019 14:40:05] - |D| - [0] - C:\ProgramData\Microsoft OneDrive [11/08/2015 23:29:09] - |SHD| - [0] - C:\ProgramData\Modèles [05/05/2012 17:50:19] - |D| - [66719] - C:\ProgramData\Mozilla [27/02/2015 23:10:14] - |D| - [630544] - C:\ProgramData\mpDRM [17/04/2017 21:37:10] - |D| - [3410499] - C:\ProgramData\NVIDIA [17/04/2017 21:37:04] - |D| - [1200305838] - C:\ProgramData\NVIDIA Corporation [22/01/2017 10:29:43] - |A| - [5112] - C:\ProgramData\NvTelemetryContainer.log [17/01/2017 09:11:49] - |A| - [4623] - C:\ProgramData\NvTelemetryContainer.log_backup1 [09/02/2016 20:15:02] - |D| - [171] - C:\ProgramData\Oracle [20/12/2012 20:35:34] - |D| - [267748] - C:\ProgramData\Orbit [23/01/2013 10:04:58] - |D| - [454060850] - C:\ProgramData\Origin [19/11/2013 07:32:30] - |D| - [51970328] - C:\ProgramData\Package Cache [30/12/2018 13:03:22] - |D| - [536576] - C:\ProgramData\Packages [03/12/2018 11:08:10] - |D| - [512] - C:\ProgramData\ProductData [15/09/2018 08:33:50] - |D| - [999] - C:\ProgramData\regid.1991-06.com.microsoft [13/11/2012 17:24:36] - |D| - [1102] - C:\ProgramData\RELOADED [24/08/2013 20:09:40] - |D| - [16640] - C:\ProgramData\Rockstar Games [31/10/2014 19:10:58] - |D| - [92056577] - C:\ProgramData\RogueKiller [05/08/2015 21:05:47] - |D| - [36515840] - C:\ProgramData\Skype [15/09/2018 08:33:50] - |D| - [0] - C:\ProgramData\SoftwareDistribution [19/04/2012 21:32:22] - |D| - [3576] - C:\ProgramData\Sony [20/01/2013 21:34:14] - |D| - [534751] - C:\ProgramData\Sony Corporation [10/02/2011 21:50:34] - |D| - [84] - C:\ProgramData\Sun [13/11/2012 16:25:54] - |D| - [830] - C:\ProgramData\Tages [26/11/2013 21:37:46] - |D| - [685390] - C:\ProgramData\TuneUp Software [23/03/2012 18:34:30] - |D| - [1632] - C:\ProgramData\Ubisoft [15/09/2018 08:33:50] - |D| - [16033] - C:\ProgramData\USOPrivate [27/06/2019 14:02:08] - |D| - [16101376] - C:\ProgramData\USOShared [06/03/2012 19:28:49] - |D| - [0] - C:\ProgramData\VirtualizedApplications [26/01/2013 14:37:22] - |D| - [2492] - C:\ProgramData\Windows Genuine Advantage [15/09/2018 17:40:58] - |D| - [0] - C:\ProgramData\WindowsHolographicDevices [03/12/2018 16:57:02] - |D| - [0] - C:\ProgramData\{F86B0233-9A85-4589-8AAF-524CC4F8211B} ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [15/09/2018 08:31:34] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [11/08/2015 23:29:09] - |SHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [15/09/2018 08:33:50] - |RD| - [369998] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [20/09/2012 07:31:20] - |D| - [6820] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3Filter [15/09/2018 08:33:50] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [15/09/2018 08:33:50] - |RD| - [19453] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [28/08/2013 18:47:50] - |D| - [3638] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACE COMBAT ASSAULT HORIZON Enhanced Edition [22/12/2019 11:26:03] - |A| - [2487] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk [05/03/2017 13:04:22] - |A| - [2487] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk [05/03/2012 22:43:03] - |D| - [5378] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activisiion [15/09/2018 08:33:50] - |RD| - [22954] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [25/04/2015 14:11:56] - |D| - [2868] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassins Creed Chronicles China [27/11/2012 18:38:29] - |D| - [5021] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassins Creed III [06/03/2018 21:44:56] - |A| - [831] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à jour de Windows 10.lnk [05/05/2019 16:36:46] - |A| - [2098] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Antivirus Gratuit.lnk [29/04/2018 15:09:24] - |A| - [2512] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk [02/09/2015 22:31:05] - |D| - [3772] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield Hardline [24/11/2013 01:10:56] - |D| - [3778] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty - Ghosts [28/08/2017 15:12:56] - |D| - [969] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [01/09/2014 22:01:39] - |D| - [2839] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Centre Souris et Claviers Microsoft [22/08/2013 21:24:54] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codemasters [04/06/2016 21:35:05] - |D| - [1378] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Company of Heroes 2 Master Collection [27/10/2016 04:29:08] - |D| - [5681] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crysis 3 [01/07/2012 20:48:31] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyanide [15/02/2016 23:46:03] - |D| - [958] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite [11/09/2019 17:31:48] - |ASH| - [530] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [03/12/2017 15:12:48] - |D| - [2950] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriversCloud.com [19/11/2014 20:49:35] - |D| - [113] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMule [04/01/2016 10:01:50] - |D| - [2360] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Fishing [30/01/2013 20:03:42] - |D| - [5652] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow [26/08/2017 18:59:26] - |D| - [5838] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15 [23/12/2017 20:02:22] - |D| - [1706] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA18 [27/10/2016 20:01:26] - |A| - [1015] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk [27/06/2016 21:04:28] - |D| - [3132] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus Home Interactive [09/11/2014 12:03:56] - |D| - [2271] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gadwin [23/06/2012 15:06:04] - |D| - [3754] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gadwin Systems [14/07/2009 06:32:38] - |RD| - [8898] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [19/06/2016 16:34:40] - |A| - [2305] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [05/04/2019 20:15:41] - |A| - [2267] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk [21/01/2016 21:03:08] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handball 16 [28/04/2014 10:17:18] - |D| - [597] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard Company [15/07/2011 21:03:04] - |A| - [1294] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Home Cinema.lnk [08/02/2016 23:42:43] - |D| - [2076] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Homeworld Deserts of Kharak [15/09/2018 08:29:46] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [22/01/2013 18:14:24] - |RD| - [140] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel [03/12/2018 11:07:59] - |D| - [2780] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller [03/12/2018 11:08:00] - |A| - [1446] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk [09/02/2016 20:15:13] - |D| - [7132] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [16/01/2013 23:57:26] - |D| - [11865] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack [27/06/2016 19:22:39] - |D| - [4890] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Konami Digital Entertainment [15/07/2011 21:01:42] - |RD| - [1429] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LabelPrint [15/09/2018 08:33:50] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [09/07/2019 10:27:16] - |D| - [4129] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes [13/11/2012 13:54:39] - |D| - [7020] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Matroska Pack [27/08/2017 10:23:52] - |D| - [6571] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor Batailles du Pacifique™ [30/01/2013 20:43:22] - |D| - [7142] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Control [13/05/2013 20:44:58] - |D| - [2765] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Calculatrice Plus [24/01/2016 21:44:14] - |A| - [2304] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Keyboard Layout Creator 1.4.lnk [11/03/2012 22:02:46] - |D| - [16062] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Français) [20/09/2014 13:58:50] - |A| - [2775] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk [13/05/2012 00:03:32] - |D| - [2370] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [07/10/2014 07:20:37] - |D| - [2571] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Middle Earth Shadow of Mordor [20/09/2012 07:31:25] - |D| - [2382] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Morgan Stream Switcher [07/01/2014 18:01:44] - |D| - [3290] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Komplete Edition [18/02/2014 00:04:16] - |D| - [4201] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ND Games [24/11/2013 22:03:56] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed Rivals [28/04/2014 09:36:23] - |D| - [1075] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ [10/10/2012 21:58:10] - |D| - [12725] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [28/09/2019 16:05:37] - |SD| - [7392] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.7 [25/11/2012 17:22:25] - |D| - [14460] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator [21/01/2013 14:37:12] - |D| - [4702] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home [21/01/2013 14:37:12] - |A| - [1968] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home.lnk [15/07/2011 21:02:18] - |RD| - [4197] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Power2Go [15/07/2011 21:02:29] - |D| - [2162] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerDVD Copy [24/06/2015 16:13:08] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programmes de graphisme [19/12/2014 22:52:10] - |D| - [4339] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Catalyst [15/01/2015 20:02:16] - |D| - [2613] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics [24/08/2013 20:32:33] - |D| - [4304] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games [26/12/2019 11:12:53] - |D| - [927] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller [20/01/2014 18:45:57] - |D| - [2313] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shadow Warrior [18/04/2012 22:06:34] - |D| - [9426] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony [13/03/2013 21:38:25] - |D| - [3385] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX [15/09/2018 08:33:50] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [26/11/2013 22:13:25] - |D| - [4092] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Phoenix Windows Data Recovery - Technical [24/06/2015 16:13:08] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Suite NCH Software [15/09/2018 08:33:50] - |RD| - [1458] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [30/03/2015 09:28:06] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeRMiNaToR [07/06/2015 20:03:43] - |D| - [2635] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 3 Wild Hunt [10/04/2012 12:12:04] - |D| - [3522] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ [29/08/2013 11:31:10] - |D| - [4481] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster [13/01/2016 23:51:08] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tom Clancys Rainbow Six Siege [23/10/2015 11:26:47] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Top Gun - Hard Lock [20/01/2014 11:09:06] - |D| - [3845] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft [10/02/2016 21:51:52] - |D| - [5886] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [18/04/2012 23:12:13] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirginMega [07/02/2015 15:27:56] - |A| - [2587] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visionneuse Microsoft PowerPoint .lnk [20/09/2012 07:28:36] - |D| - [3920] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VobSub [10/03/2016 18:01:28] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.0 [12/11/2013 22:16:19] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VUPlayer [02/07/2012 21:22:19] - |RD| - [4663] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live [02/07/2012 21:23:34] - |A| - [1462] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk [02/07/2012 21:23:15] - |A| - [2490] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk [02/07/2012 21:24:01] - |A| - [1309] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk [02/07/2012 21:23:54] - |A| - [1378] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk [27/06/2019 14:09:33] - |A| - [1519] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [24/12/2014 17:43:41] - |D| - [4441] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [09/05/2015 15:56:19] - |D| - [2429] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein The Old Blood [14/05/2014 22:56:17] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XBCD [24/04/2014 21:37:11] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilisoft [10/11/2014 11:50:59] - |D| - [48] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiph.Org [20/09/2012 07:31:16] - |D| - [1594] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [15/09/2018 08:31:34] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | C:\Program Files (x86) [06/03/2012 22:59:36] - |D| - [78367] - C:\Program Files (x86)\7-Zip [20/09/2012 07:31:19] - |D| - [590019] - C:\Program Files (x86)\AC3Filter [28/08/2013 18:42:20] - |AD| - [12164768233] - C:\Program Files (x86)\ACE COMBAT ASSAULT HORIZON Enhanced Edition [14/11/2012 12:19:50] - |D| - [2482033711] - C:\Program Files (x86)\Activision [10/02/2011 21:48:01] - |D| - [386769319] - C:\Program Files (x86)\Adobe [25/04/2015 14:10:17] - |AD| - [3392043604] - C:\Program Files (x86)\Assassins Creed Chronicles China [29/04/2018 14:58:49] - |D| - [438756022] - C:\Program Files (x86)\AVAST Software [18/10/2016 18:41:05] - |AD| - [102831395] - C:\Program Files (x86)\Batman Arkham Knight [24/11/2013 11:06:37] - |AD| - [14964020] - C:\Program Files (x86)\Battlelog Web Plugins [02/09/2015 12:07:06] - |AD| - [51903274310] - C:\Program Files (x86)\BFH [06/11/2013 18:50:00] - |D| - [5271014782] - C:\Program Files (x86)\Capcom [19/04/2012 22:15:15] - |D| - [619630] - C:\Program Files (x86)\Codemasters [15/09/2018 08:33:50] - |D| - [724753875] - C:\Program Files (x86)\Common Files [29/01/2014 12:39:24] - |D| - [796781902] - C:\Program Files (x86)\Company of Heroes 2 [04/06/2016 21:10:41] - |AD| - [36539456321] - C:\Program Files (x86)\Company of Heroes 2 Master Collection [29/06/2012 21:50:12] - |D| - [1052511550] - C:\Program Files (x86)\Corel [28/06/2011 21:07:01] - |D| - [652486234] - C:\Program Files (x86)\CyberLink [06/03/2012 23:00:19] - |D| - [55350219] - C:\Program Files (x86)\CyberLink Power Cinema [15/09/2018 08:31:34] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [06/10/2012 16:08:12] - |D| - [0] - C:\Program Files (x86)\directx [20/09/2012 07:30:55] - |D| - [147972] - C:\Program Files (x86)\DivX [13/03/2012 13:24:58] - |D| - [797] - C:\Program Files (x86)\Electronic Arts [25/04/2016 21:06:46] - |D| - [187420357] - C:\Program Files (x86)\Engine [22/12/2019 12:00:58] - |D| - [51018133690] - C:\Program Files (x86)\FIFA 19 [27/06/2016 20:55:10] - |D| - [9889573269] - C:\Program Files (x86)\Focus Home Interactive [06/03/2012 22:57:52] - |D| - [3650842] - C:\Program Files (x86)\Gadwin Systems [05/03/2012 12:01:13] - |D| - [484084515] - C:\Program Files (x86)\Google [15/01/2017 10:24:05] - |D| - [10816062] - C:\Program Files (x86)\HP [12/11/2016 21:59:38] - |HD| - [17581119] - C:\Program Files (x86)\InstallShield Installation Information [15/07/2011 20:52:01] - |AD| - [22291114] - C:\Program Files (x86)\Intel [15/09/2018 08:33:50] - |D| - [1986331] - C:\Program Files (x86)\Internet Explorer [03/12/2018 11:07:28] - |D| - [101563499] - C:\Program Files (x86)\IObit [28/06/2011 20:29:32] - |D| - [167658621] - C:\Program Files (x86)\Java [26/11/2018 18:24:06] - |D| - [6448626016] - C:\Program Files (x86)\KONAMI [27/06/2016 19:15:43] - |D| - [8350634167] - C:\Program Files (x86)\Konami Digital Entertainment [12/03/2017 10:06:21] - |AD| - [28785812] - C:\Program Files (x86)\LibreOffice 5 [25/04/2016 21:02:41] - |D| - [4115151969] - C:\Program Files (x86)\Localization [30/01/2013 18:58:32] - |AD| - [11487039] - C:\Program Files (x86)\Media Control [05/03/2012 22:41:56] - |AD| - [13140650] - C:\Program Files (x86)\Microsoft Application Virtualization Client [15/10/2014 22:20:05] - |D| - [1670519] - C:\Program Files (x86)\Microsoft ASP.NET [13/05/2013 20:44:58] - |AD| - [979634] - C:\Program Files (x86)\Microsoft Calculatrice Plus [06/11/2013 18:58:10] - |D| - [3425102] - C:\Program Files (x86)\Microsoft Games for Windows - LIVE [24/01/2016 21:30:18] - |AD| - [26424734] - C:\Program Files (x86)\Microsoft Keyboard Layout Creator 1.4 [10/02/2011 21:39:43] - |D| - [46518433] - C:\Program Files (x86)\Microsoft Office [13/05/2012 00:02:56] - |AD| - [42894550] - C:\Program Files (x86)\Microsoft Silverlight [02/07/2012 21:23:49] - |AD| - [5072244] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition [28/11/2016 11:06:00] - |D| - [343335] - C:\Program Files (x86)\Microsoft Synchronization Services [15/09/2018 08:33:50] - |D| - [23935] - C:\Program Files (x86)\Microsoft.NET [07/10/2014 07:02:05] - |AD| - [47502841288] - C:\Program Files (x86)\Middle Earth Shadow of Mordor [21/10/2016 20:07:16] - |AD| - [133915797] - C:\Program Files (x86)\Mozilla Firefox [13/06/2013 21:57:14] - |D| - [377282] - C:\Program Files (x86)\Mozilla Maintenance Service [27/06/2019 14:27:18] - |D| - [25757] - C:\Program Files (x86)\MSBuild [05/03/2012 22:38:20] - |D| - [94790048] - C:\Program Files (x86)\MSECache [10/02/2011 21:56:31] - |AD| - [154033] - C:\Program Files (x86)\MSXML 4.0 [17/02/2014 23:58:51] - |D| - [4848077612] - C:\Program Files (x86)\ND Games [28/04/2014 09:36:22] - |D| - [15873605] - C:\Program Files (x86)\Notepad++ [17/04/2017 21:36:56] - |D| - [466230748] - C:\Program Files (x86)\NVIDIA Corporation [22/03/2012 13:19:04] - |D| - [1591832] - C:\Program Files (x86)\OpenAL [28/09/2019 16:04:11] - |D| - [331029564] - C:\Program Files (x86)\OpenOffice 4 [01/05/2015 20:39:11] - |AD| - [423653330] - C:\Program Files (x86)\Origin [01/05/2015 21:24:56] - |D| - [28352780350] - C:\Program Files (x86)\Origin Games [25/11/2012 17:22:23] - |D| - [34354638] - C:\Program Files (x86)\PDFCreator [17/09/2015 20:45:54] - |AD| - [8218429748] - C:\Program Files (x86)\Pro Evolution Soccer 2016 [19/12/2014 22:28:36] - |D| - [15951544393] - C:\Program Files (x86)\R.G. Catalyst [15/07/2011 20:57:54] - |D| - [7183680] - C:\Program Files (x86)\Realtek [27/06/2019 14:27:18] - |D| - [38462721] - C:\Program Files (x86)\Reference Assemblies [15/01/2015 20:02:13] - |D| - [1203170] - C:\Program Files (x86)\Renesas Electronics [24/08/2013 20:09:42] - |D| - [31422147379] - C:\Program Files (x86)\Rockstar Games [20/01/2014 18:41:34] - |AD| - [7286932072] - C:\Program Files (x86)\Shadow Warrior [17/04/2012 11:38:04] - |AD| - [1217703369] - C:\Program Files (x86)\Sony [13/03/2013 21:33:06] - |D| - [12361361191] - C:\Program Files (x86)\SQUARE ENIX [26/11/2013 21:40:42] - |AD| - [21203403] - C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery [25/04/2016 21:00:20] - |D| - [2572488] - C:\Program Files (x86)\Support [07/06/2015 19:20:54] - |AD| - [26577206991] - C:\Program Files (x86)\The Witcher 3 Wild Hunt [10/04/2012 12:07:51] - |D| - [12741390262] - C:\Program Files (x86)\THQ [29/08/2013 11:31:08] - |D| - [4897785] - C:\Program Files (x86)\Thrustmaster [25/02/2016 23:02:20] - |AD| - [98238512] - C:\Program Files (x86)\Tom Clancy's Splinter Cell® Blacklist™ [03/07/2014 16:47:57] - |D| - [10350619593] - C:\Program Files (x86)\Transformers Rise of the Dark Spark [23/03/2012 18:25:49] - |D| - [158450903348] - C:\Program Files (x86)\Ubisoft [08/09/2014 20:37:00] - |AD| - [11931608577] - C:\Program Files (x86)\Ultra Street Fighter IV [30/12/2018 11:48:02] - |HD| - [0] - C:\Program Files (x86)\Uninstall Information [14/11/2012 12:55:10] - |D| - [7227] - C:\Program Files (x86)\VideoLAN [04/01/2018 18:36:54] - |D| - [1735394] - C:\Program Files (x86)\VulkanRT [15/09/2018 08:33:50] - |D| - [1719928] - C:\Program Files (x86)\Windows Defender [10/02/2011 21:32:07] - |AD| - [204792630] - C:\Program Files (x86)\Windows Live [15/09/2018 08:33:50] - |D| - [625152] - C:\Program Files (x86)\Windows Mail [15/09/2018 17:40:58] - |D| - [3241325] - C:\Program Files (x86)\Windows Media Player [15/09/2018 17:40:58] - |D| - [40432] - C:\Program Files (x86)\Windows Multimedia Platform [15/09/2018 08:33:50] - |D| - [7563096] - C:\Program Files (x86)\windows nt [15/09/2018 17:40:58] - |D| - [5325328] - C:\Program Files (x86)\Windows Photo Viewer [15/09/2018 17:40:58] - |D| - [40432] - C:\Program Files (x86)\Windows Portable Devices [15/09/2018 08:33:50] - |SHD| - [619114] - C:\Program Files (x86)\Windows Sidebar [15/09/2018 08:33:50] - |D| - [3156995] - C:\Program Files (x86)\WindowsPowerShell [18/10/2012 18:41:20] - |D| - [390] - C:\Program Files (x86)\WinRAR [09/05/2015 15:28:48] - |AD| - [39358061705] - C:\Program Files (x86)\Wolfenstein The Old Blood [23/10/2015 11:33:32] - |AD| - [20099709341] - C:\Program Files (x86)\WRC 5 FIA World Rally Championship ---------- | C:\Program Files [05/03/2012 13:22:32] - |D| - [1613525467] - C:\Program Files\AVAST Software [28/08/2017 15:12:55] - |AD| - [50472088] - C:\Program Files\CCleaner [15/09/2018 08:33:50] - |D| - [61313013] - C:\Program Files\Common Files [15/02/2016 23:46:01] - |D| - [34426791] - C:\Program Files\DAEMON Tools Lite [15/09/2018 08:31:34] - |ASH| - [174] - C:\Program Files\desktop.ini [24/01/2016 21:35:42] - |AD| - [19335535] - C:\Program Files\DriversCloud.com [14/07/2009 06:32:38] - |D| - [0] - C:\Program Files\DVD Maker [30/12/2015 19:39:19] - |AD| - [3215008] - C:\Program Files\Emsisoft Anti-Malware [11/08/2015 23:29:09] - |SHD| - [0] - C:\Program Files\Fichiers communs [23/12/2017 19:27:47] - |AD| - [36712765208] - C:\Program Files\FIFA18 [09/11/2014 12:03:55] - |D| - [15991066] - C:\Program Files\Gadwin [05/03/2012 12:01:37] - |D| - [219169767] - C:\Program Files\Google [22/01/2013 18:09:27] - |D| - [11978643] - C:\Program Files\Intel [15/09/2018 08:33:50] - |D| - [2645094] - C:\Program Files\internet explorer [28/06/2011 20:29:47] - |D| - [2778881] - C:\Program Files\Java [22/01/2013 17:41:32] - |AD| - [1117] - C:\Program Files\ma-config.com [03/12/2018 14:36:12] - |D| - [213568243] - C:\Program Files\Malwarebytes [14/07/2009 06:32:38] - |D| - [184] - C:\Program Files\Microsoft Games [01/09/2014 22:00:52] - |AD| - [85565447] - C:\Program Files\Microsoft Mouse and Keyboard Center [13/05/2012 00:02:56] - |AD| - [55728894] - C:\Program Files\Microsoft Silverlight [28/11/2016 11:06:02] - |AD| - [4421503] - C:\Program Files\Microsoft SQL Server Compact Edition [28/11/2016 11:06:02] - |D| - [343335] - C:\Program Files\Microsoft Synchronization Services [31/10/2019 21:03:10] - |D| - [206898304] - C:\Program Files\Mozilla Firefox [27/06/2019 14:27:18] - |D| - [25757] - C:\Program Files\MSBuild [17/04/2017 21:36:32] - |D| - [1309453296] - C:\Program Files\NVIDIA Corporation [17/04/2017 21:35:59] - |D| - [42739992] - C:\Program Files\Realtek [27/06/2019 14:27:18] - |D| - [36867241] - C:\Program Files\Reference Assemblies [14/02/2018 20:28:17] - |AD| - [26932032] - C:\Program Files\rempl [26/10/2016 21:36:20] - |D| - [113873236] - C:\Program Files\Rockstar Games [26/12/2019 11:12:48] - |D| - [119870277] - C:\Program Files\RogueKiller [26/08/2017 18:01:29] - |D| - [0] - C:\Program Files\Samsung [01/03/2015 23:17:31] - |D| - [9216] - C:\Program Files\SmartTechnology [10/07/2015 13:21:54] - |HD| - [0] - C:\Program Files\Uninstall Information [16/04/2017 08:44:50] - |AD| - [22604381] - C:\Program Files\UNP [10/02/2016 21:51:33] - |D| - [177479800] - C:\Program Files\VideoLAN [15/09/2018 08:33:50] - |RD| - [15110670] - C:\Program Files\Windows Defender [10/02/2011 21:30:44] - |D| - [43816938] - C:\Program Files\Windows Live [15/09/2018 08:33:50] - |D| - [636416] - C:\Program Files\Windows Mail [15/09/2018 17:40:58] - |D| - [4716945] - C:\Program Files\Windows Media Player [15/09/2018 17:40:58] - |D| - [47512] - C:\Program Files\Windows Multimedia Platform [15/09/2018 08:33:50] - |D| - [7895384] - C:\Program Files\windows nt [15/09/2018 17:40:58] - |D| - [6135112] - C:\Program Files\Windows Photo Viewer [15/09/2018 17:40:58] - |D| - [47512] - C:\Program Files\Windows Portable Devices [15/09/2018 08:33:50] - |D| - [110373] - C:\Program Files\Windows Security [15/09/2018 08:33:50] - |SHD| - [390253] - C:\Program Files\Windows Sidebar [15/09/2018 08:33:50] - |HD| - [3244324543] - C:\Program Files\WindowsApps [15/09/2018 08:33:50] - |D| - [3454389] - C:\Program Files\WindowsPowerShell [05/03/2012 22:15:17] - |AD| - [7156376] - C:\Program Files\WinRAR ---------- | C:\Program Files (x86)\Common Files [28/06/2011 20:30:50] - |AD| - [23667292] - C:\Program Files (x86)\Common Files\Adobe [10/02/2011 21:48:57] - |AD| - [28784736] - C:\Program Files (x86)\Common Files\Adobe AIR [12/11/2012 16:35:33] - |D| - [0] - C:\Program Files (x86)\Common Files\Apple [20/03/2014 12:53:22] - |A| - [2174976] - C:\Program Files (x86)\Common Files\atimpenc.dll [28/01/2017 00:20:08] - |D| - [0] - C:\Program Files (x86)\Common Files\AV [14/05/2014 23:17:10] - |AD| - [99992] - C:\Program Files (x86)\Common Files\DESIGNER [23/10/2012 17:41:43] - |HD| - [8472303] - C:\Program Files (x86)\Common Files\EAInstaller [20/02/2013 22:12:07] - |D| - [172032] - C:\Program Files (x86)\Common Files\Hewlett-Packard [15/07/2011 20:57:46] - |D| - [5147148] - C:\Program Files (x86)\Common Files\InstallShield [15/07/2011 21:00:46] - |D| - [243439] - C:\Program Files (x86)\Common Files\Intel Corporation [03/12/2018 11:08:08] - |D| - [0] - C:\Program Files (x86)\Common Files\IObit [28/06/2011 20:29:42] - |D| - [1941064] - C:\Program Files (x86)\Common Files\Java [01/08/2013 21:31:15] - |D| - [3121506] - C:\Program Files (x86)\Common Files\Metaboli [15/09/2018 08:33:50] - |D| - [161010413] - C:\Program Files (x86)\Common Files\microsoft shared [27/02/2015 23:10:13] - |D| - [1207841] - C:\Program Files (x86)\Common Files\mpDRM [15/07/2011 20:53:32] - |D| - [193596] - C:\Program Files (x86)\Common Files\postureAgent [15/09/2018 08:33:50] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [27/06/2019 14:44:22] - |D| - [41095079] - C:\Program Files (x86)\Common Files\SpeechEngines [03/12/2012 16:38:24] - |D| - [3772480] - C:\Program Files (x86)\Common Files\Steam [15/09/2018 08:33:50] - |D| - [9449355] - C:\Program Files (x86)\Common Files\system [10/02/2011 21:29:49] - |D| - [287314337] - C:\Program Files (x86)\Common Files\Windows Live [22/03/2012 13:19:06] - |D| - [146883584] - C:\Program Files (x86)\Common Files\Wise Installation Wizard ---------- | C:\Program Files\Common files [28/01/2017 00:20:08] - |D| - [0] - C:\Program Files\Common files\AV [23/12/2017 19:58:16] - |D| - [1873288] - C:\Program Files\Common files\Avast Software [15/09/2018 08:33:50] - |D| - [48541780] - C:\Program Files\Common files\microsoft shared [15/09/2018 08:33:50] - |D| - [2702] - C:\Program Files\Common files\Services [27/06/2019 14:44:19] - |D| - [599040] - C:\Program Files\Common files\SpeechEngines [15/09/2018 08:33:50] - |D| - [10296203] - C:\Program Files\Common files\system ---------- | Tasks [MD5.00000000000000000000000000000000] - [03/12/2018 15:51:23] - |D| - [0] - C:\WINDOWS\Tasks\ImCleanDisabled [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [27/06/2019 14:34:32] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.76AB9A90D81D3BCC2A170F9781AF0247] - [19/10/2019 09:10:20] - |A| - [3482] - C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task : C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [MD5.1DAF9BD00CF97C774E5B29316B6FED7D] - [27/06/2019 14:34:32] - |A| - [3924] - C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier : C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_303_Plugin.exe [MD5.0CCD8DA030A9EAA56E075FD36A16570F] - [27/06/2019 14:34:32] - |A| - [3494] - C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater : C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.981C30AD961057B2BF49379CE350A2C1] - [12/10/2019 10:35:22] - |A| - [4264] - C:\WINDOWS\System32\Tasks\Avast Emergency Update : C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [MD5.9CFE9477EE19EA5B286995ABCF036F12] - [27/11/2019 20:04:57] - |A| - [3856] - C:\WINDOWS\System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) : C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [MD5.B7F45D11A051E9ED91976F4E32AB6634] - [27/11/2019 20:04:57] - |A| - [3272] - C:\WINDOWS\System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) : C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [MD5.00000000000000000000000000000000] - [27/06/2019 14:34:32] - |D| - [6962] - C:\WINDOWS\System32\Tasks\AVAST Software [MD5.030B0BACF28C1A644BEF8A1DB151D7F1] - [27/06/2019 14:34:32] - |A| - [3332] - C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineCore : C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [MD5.28A2367AE40D680EF59AE121D90B47B2] - [27/06/2019 14:34:32] - |A| - [3556] - C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineUA : C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [MD5.ABC1D5E113CAEB85E84DDEE9A14F7165] - [26/12/2019 15:43:48] - |A| - [3936] - C:\WINDOWS\System32\Tasks\CCleaner Update : C:\Program Files\CCleaner\CCUpdate.exe [MD5.A8BA0D5D78E4C2E2E5811A96C486ABE4] - [27/06/2019 14:34:32] - |A| - [2220] - C:\WINDOWS\System32\Tasks\CCleanerSkipUAC : "C:\Program Files\CCleaner\CCleaner.exe" [MD5.9C1E369BE161C4CF632F73989C312350] - [27/06/2019 14:34:32] - |A| - [2538] - C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask : C:\Windows\System32\browserchoice.exe [MD5.20E7156FF0D25B3438367D4F6FF9AC06] - [27/06/2019 14:34:32] - |A| - [3294] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.57A4A335AF293FDF68AB62C204BA27D4] - [27/06/2019 14:34:32] - |A| - [3518] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.00000000000000000000000000000000] - [27/06/2019 14:34:32] - |D| - [3390] - C:\WINDOWS\System32\Tasks\Lenovo [MD5.00000000000000000000000000000000] - [15/09/2018 08:33:50] - |D| - [707084] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.193A6086F8BEAA0305B50DD2AAAA8D48] - [27/06/2019 14:34:32] - |A| - [2394] - C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe : c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [MD5.5A542F4A78AD3D8F77A3BDE295E782F9] - [27/06/2019 14:34:32] - |A| - [2392] - C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe : c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [MD5.0E04806EB51F20A20FFF399B0E207BD6] - [27/06/2019 14:34:32] - |A| - [2420] - C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe : c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [MD5.9017583ED71AC985E1E30670F9BF1EA2] - [27/06/2019 14:34:32] - |A| - [2378] - C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe : c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [MD5.6D6A2D33377767308832E53F95D16766] - [27/06/2019 14:34:32] - |A| - [2376] - C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe : c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [MD5.00000000000000000000000000000000] - [27/06/2019 14:34:32] - |D| - [0] - C:\WINDOWS\System32\Tasks\NCH Software [MD5.CE0E61838C45A2197B7A48BA49DEC62C] - [17/11/2019 20:51:40] - |A| - [3196] - C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [MD5.EA3401791D3DEC3D40C1C77CC6AC8381] - [17/11/2019 20:51:40] - |A| - [3398] - C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [MD5.D6E7E563512D61018992A38D791ADD11] - [17/11/2019 20:52:56] - |A| - [3152] - C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" [MD5.4C16A7D7D4E05C74CF806CADB99C4205] - [17/11/2019 20:52:57] - |A| - [2914] - C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [MD5.3CD9937C1CF2C71AD55E6BBFA5089DBA] - [17/11/2019 20:51:01] - |A| - [2984] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.A416713998B405C15DF29DC980393AF6] - [17/11/2019 20:51:01] - |A| - [2744] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.ED4809B6BD2D5BEC4DC7F343CE4DD57C] - [17/11/2019 20:51:40] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.2CBF02FD1E3BF8EFA8A35D4C0C36215C] - [17/11/2019 20:51:41] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.4816E7A88DE48C956E397EA522B5F083] - [17/11/2019 20:51:41] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.97DCDB83FAE50ABBBE4DC06F04A160DE] - [17/11/2019 20:51:41] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.00000000000000000000000000000000] - [27/06/2019 14:34:32] - |D| - [0] - C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform [MD5.6377DC069B0AA09C85426ADABB684A32] - [25/11/2019 10:48:48] - |A| - [2862] - C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2392155067-2275373385-2186660377-1002 : %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MD5.A0C5CED4877F8EBAF9A548287F4A39A1] - [27/06/2019 14:34:32] - |A| - [3100] - C:\WINDOWS\System32\Tasks\Programme de mise à jour en ligne de Adobe : C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [MD5.EE7CDA750AF001ECAAE9BB850A594056] - [27/06/2019 14:34:32] - |A| - [3162] - C:\WINDOWS\System32\Tasks\Programme de mise à jour en ligne de Real Player : c:\program files (x86)\real\realplayer\Update\realsched.exe [MD5.DF310347FE4D6FE9D572AB5C9F17FC30] - [27/06/2019 14:34:32] - |A| - [2418] - C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2392155067-2275373385-2186660377-1002 : C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [MD5.3B651818A66BA09E12A0929C23799FD3] - [27/06/2019 14:34:32] - |A| - [2542] - C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2392155067-2275373385-2186660377-1002 : C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [MD5.1A887C73E783F8C40AF0C94B2183D4BF] - [27/06/2019 14:34:32] - |A| - [2418] - C:\WINDOWS\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2392155067-2275373385-2186660377-1002 : C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [MD5.F30D1A09715DD262164C105064F77D27] - [27/06/2019 14:34:32] - |A| - [2542] - C:\WINDOWS\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2392155067-2275373385-2186660377-1002 : C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [MD5.EA98029A556C9AC4C29B796FF73C915B] - [27/06/2019 14:34:32] - |A| - [2394] - C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_Ben : C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [MD5.4998529F3B30D1AE46264858DC2C1618] - [27/06/2019 14:34:32] - |A| - [4156] - C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{F62D63AA-DC6A-4080-B91B-E2A98B496DF3} : C:\WINDOWS\system32\msfeedssync.exe [MD5.00000000000000000000000000000000] - [27/06/2019 14:34:32] - |D| - [3852] - C:\WINDOWS\System32\Tasks\WPD [MD5.2882E480BD5012B477C07973B18661F4] - [27/06/2019 14:34:32] - |A| - [2118] - C:\WINDOWS\System32\Tasks\{0060CF01-458B-48D6-877E-2A0F76EA32B8} : C:\Program Files (x86)\THQ\Metro 2033\metro2033.exe [MD5.AA743DDCA1FBB84EA5C62DBBAB6383EF] - [27/06/2019 14:34:32] - |A| - [2248] - C:\WINDOWS\System32\Tasks\{0E63F5AE-60DF-4FDD-BC23-459DDD855757} : C:\Windows\system32\pcalua.exe [MD5.2AC1C9C22C334C75C96056BDDFF86EE3] - [27/06/2019 14:34:32] - |A| - [2152] - C:\WINDOWS\System32\Tasks\{122BD959-CBC5-4A49-9A5F-1DB03181C927} : C:\Program Files (x86)\Activision\Call of Duty Black Ops II\t6sp.exe [MD5.6C3CED11755E92FA887D77D67A26A2D3] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{280CEF13-C2D5-47D6-BE94-63A13B650753} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.AD5B20AB543888D085802591B0558DB4] - [27/06/2019 14:34:32] - |A| - [2414] - C:\WINDOWS\System32\Tasks\{2BF96D00-FBE4-4A3A-A187-D14D4A901C25} : C:\Windows\system32\pcalua.exe [MD5.2F63078CB5AA714EF7F53C7F20441E1E] - [27/06/2019 14:34:32] - |A| - [2354] - C:\WINDOWS\System32\Tasks\{30C6BFAD-84CD-47D6-981F-B0393D501FB6} : C:\Windows\system32\pcalua.exe [MD5.CCDA0E8AF84EF1241E387B49D4DD659D] - [27/06/2019 14:34:32] - |A| - [2118] - C:\WINDOWS\System32\Tasks\{361E0C10-EFFD-4152-ADD9-0D84E52601EC} : C:\Program Files (x86)\THQ\Metro 2033\metro2033.exe [MD5.3B727666CE9093C0A86420F3A55C2078] - [27/06/2019 14:34:32] - |A| - [2202] - C:\WINDOWS\System32\Tasks\{38FE8D0B-8DE0-455A-994B-BBCD6337BEBA} : C:\Windows\system32\pcalua.exe [MD5.CF92DBFB7D2C68B789583F686C54BC37] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{3B1E1D3E-DCD7-4DDA-96B6-E893B38AAC1B} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.C7F15263BE75551E0FF33E36827A7198] - [27/06/2019 14:34:32] - |A| - [2136] - C:\WINDOWS\System32\Tasks\{3BF4CEB5-AB8C-451D-8112-8464DD2BB071} : C:\Program Files (x86)\Activision\Modern Warfare 2\iw4sp.exe [MD5.7A8B1EBEEA5F14170923C1CA3225E772] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{3D746C14-220D-4313-B550-F9869C9B246C} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.74731EF8241211A38A96A0E3EFD6E1D9] - [27/06/2019 14:34:32] - |A| - [2152] - C:\WINDOWS\System32\Tasks\{47307A01-660C-4813-8EAD-2B72B8568751} : C:\Program Files (x86)\Activision\Call of Duty Black Ops II\t6sp.exe [MD5.F1F024F1605424454C8A5A948CEF6156] - [27/06/2019 14:34:32] - |A| - [2136] - C:\WINDOWS\System32\Tasks\{476E79E6-981D-4B4A-8150-AF36F5144AB1} : C:\Program Files (x86)\Sony\PlayMemories Home\PMBBrowser.exe [MD5.66B2A4E0118C3FE51D8305E68A9684E9] - [27/06/2019 14:34:32] - |A| - [2160] - C:\WINDOWS\System32\Tasks\{48E2B34E-BDE8-4F49-A525-D2A936C79F52} : C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe [MD5.64DE471E99FA80D25FAD04258CAA1D1D] - [27/06/2019 14:34:32] - |A| - [2384] - C:\WINDOWS\System32\Tasks\{538FA2C7-B5F1-4690-BEFC-F700CF5D0ACB} : C:\Windows\system32\pcalua.exe [MD5.CBE6EA873794D62F0E8A326518E1AC87] - [27/06/2019 14:34:32] - |A| - [2300] - C:\WINDOWS\System32\Tasks\{55C9975E-E85F-4E00-9BAB-B67196C75C11} : C:\Windows\system32\pcalua.exe [MD5.030CADEF5B3C333195CCAD347570F197] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{5BD1E956-63FE-438D-9681-8BDDA5BCCD4F} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.174B8BCC800A76E45C6CF16715769B14] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{68BF5EE7-AAC1-49F4-819D-3A2E274C2291} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRPR.exe [MD5.333DC45F881BAC0C5B8DB938F03BA942] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{6A6E7CFB-C72E-4E90-A19F-E96A8CED9255} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRPR.exe [MD5.F62DA98A57DA9AFF3ADD37131C7EBA75] - [27/06/2019 14:34:32] - |A| - [2116] - C:\WINDOWS\System32\Tasks\{6AC0402B-3CD2-4242-BFBE-27C473178239} : C:\Program Files (x86)\Codemasters\DiRT 3\play.exe [MD5.F03C0978AF89E3C3873A9E175F099CA7] - [27/06/2019 14:34:32] - |A| - [2112] - C:\WINDOWS\System32\Tasks\{6D06B9D7-84E2-4153-975E-E117D130EE8A} : C:\Program Files (x86)\Codemasters\DiRT\DiRT.exe [MD5.77DEF0F0B41ABEE6912D6C8FD5002BCF] - [27/06/2019 14:34:32] - |A| - [2160] - C:\WINDOWS\System32\Tasks\{70DBCF58-B074-43FE-87CE-33F93F92ACF2} : C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe [MD5.363941A3CD3869971F9F867E42445FFE] - [27/06/2019 14:34:32] - |A| - [2160] - C:\WINDOWS\System32\Tasks\{72E2A08B-A816-4604-ABCA-0C9215AD03AC} : C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe [MD5.6443354613462752DAABB56A90E52AEB] - [27/06/2019 14:34:32] - |A| - [2692] - C:\WINDOWS\System32\Tasks\{79283870-4C40-47F0-87B8-1A9DC658C43A} : C:\Windows\system32\pcalua.exe [MD5.41411C28449FB0E43EBCDCBCB5BD8E0B] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{80410DAF-89C3-4995-B368-94BF9687E4D2} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRPR.exe [MD5.363DC322957E51748FB21779EF6DB894] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{962DEF4A-AF10-4AA8-8F70-413A26701031} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.74D88E9085FCB165D9B2D2482EEE2A7A] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{98F7C016-4BAF-479C-9A18-EC9D88A24ACB} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.E8E3DDBEDA38CC7EAB4A00A00CD48602] - [27/06/2019 14:34:32] - |A| - [2130] - C:\WINDOWS\System32\Tasks\{9C228003-0E75-4F61-A472-172FCF168F58} : C:\Program Files (x86)\CAPCOM\ChaosLegion\ChaosLegion.exe [MD5.D805A205596D09C6BF6B820269A484B5] - [27/06/2019 14:34:32] - |A| - [2118] - C:\WINDOWS\System32\Tasks\{9EFC5413-2EA8-4578-8097-9F8FBA12986C} : C:\Program Files (x86)\THQ\Metro 2033\metro2033.exe [MD5.1E1E7833D4DC143A996D85A2C5BB53B6] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{9FBBDCEE-E1C3-41A5-A9C3-377E0ABF954B} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.F8B7E6D46F21DE35EB976938D44DB38D] - [27/06/2019 14:34:32] - |A| - [2130] - C:\WINDOWS\System32\Tasks\{A321CCB5-ABB2-4CD3-BA9E-B5CD8B24B788} : C:\Program Files (x86)\CAPCOM\ChaosLegion\ChaosLegion.exe [MD5.1A93A2481F3721D1FD93B0C55D998BBC] - [27/06/2019 14:34:32] - |A| - [2152] - C:\WINDOWS\System32\Tasks\{A59CE86E-1230-441F-942F-D8975AF6E3D1} : C:\Program Files (x86)\Activision\Call of Duty Black Ops II\t6sp.exe [MD5.2BD118D1EC203EFF75EF228E9680F900] - [27/06/2019 14:34:32] - |A| - [2152] - C:\WINDOWS\System32\Tasks\{CA707A14-78B7-4275-9983-F4AD935FEC40} : C:\Program Files (x86)\Activision\Call of Duty Black Ops II\t6sp.exe [MD5.2F09220D816909B6990664A4B5D3035E] - [27/06/2019 14:34:32] - |A| - [2130] - C:\WINDOWS\System32\Tasks\{CC04710E-F0E9-453E-A323-97164C8FE8B1} : C:\Program Files (x86)\CAPCOM\ChaosLegion\ChaosLegion.exe [MD5.C8E895AAA28D8056C4572FDF94E6773A] - [27/06/2019 14:34:32] - |A| - [2166] - C:\WINDOWS\System32\Tasks\{CF1EA5D5-C7A7-4EEE-B30C-EA19E56D8F5F} : C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe [MD5.DDE27D1318DC50335A9A236398BF5150] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{D1E469FF-2B22-4AFB-B668-13D20B61412C} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.FBBB43C75B7FDA055E2127A8A0BDE7F1] - [27/06/2019 14:34:32] - |A| - [2338] - C:\WINDOWS\System32\Tasks\{D5188470-FB6E-49C6-926F-5ECB16B4A4D4} : C:\Windows\system32\pcalua.exe [MD5.793B3075BEB7C57E8F2B50883841FE80] - [27/06/2019 14:34:32] - |A| - [2116] - C:\WINDOWS\System32\Tasks\{E40316F6-1B67-480F-A1F7-083641FB8C8B} : C:\Program Files (x86)\Mozilla Firefox\firefox.exe [MD5.DE2AB9EA407AD7D1E96F3685ECE45850] - [27/06/2019 14:34:32] - |A| - [2152] - C:\WINDOWS\System32\Tasks\{E428843A-4077-4107-B11D-50358203D2E6} : C:\Program Files (x86)\Activision\Call of Duty Black Ops II\t6sp.exe [MD5.CACE1E75CDDB380997F97FDBC421D1DA] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{EA8560A2-0927-4153-B6DE-2E90416285AA} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRPR.exe [MD5.6C8E49C07BDD85D1A908500FF23FB71B] - [27/06/2019 14:34:32] - |A| - [2092] - C:\WINDOWS\System32\Tasks\{EC5012F7-569F-490D-8B1B-5F6BC808D9EB} : C:\Program Files (x86)\eMule\emule.exe [MD5.1A7E78BA3BB4D17CAFFD809F1D0D8555] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{EE5B3511-029A-477D-9EE2-2D6EC726F865} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe [MD5.BE7E961ED74B8A6C9C494E016EE4B54F] - [27/06/2019 14:34:32] - |A| - [2092] - C:\WINDOWS\System32\Tasks\{F3004A9D-A3B5-47A5-A0C1-4F34023FEFD4} : C:\Program Files (x86)\eMule\emule.exe [MD5.EE69967E2F3EB72181B5EA5595EADA0E] - [27/06/2019 14:34:32] - |A| - [2154] - C:\WINDOWS\System32\Tasks\{F94BDF2B-DC67-4B78-8C00-EFEA60640E6F} : C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRPR.exe [MD5.00000000000000000000000000000000] - [15/09/2018 08:33:51] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "WiFiDirect-KM-Driver-In-TCP"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=System|Name=@wlansvc.dll,-37378|Desc=@wlansvc.dll,-37890|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-Out-TCP"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=System|Name=@wlansvc.dll,-37379|Desc=@wlansvc.dll,-37891|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-In-UDP"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=System|Name=@wlansvc.dll,-37380|Desc=@wlansvc.dll,-37892|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-Out-UDP"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=System|Name=@wlansvc.dll,-37381|Desc=@wlansvc.dll,-37893|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "DeliveryOptimization-TCP-In"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "DeliveryOptimization-UDP-In"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "Netlogon-NamedPipe-In"=v2.29|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "Netlogon-TCP-RPC-In"=v2.29|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010| "WirelessDisplay-In-TCP"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-UDP"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Infra-In-TCP"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100| "WCF-NetTcpActivator-In-TCP-64bit"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=808|App=%systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe|Svc=NetTcpActivator|Name=@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll,-2000|Desc=@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll,-2001|EmbedCtxt=@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll,-2002| "{DEF63E1A-AA9C-43FB-B509-8AC706D654D4}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\Bonjour\mDNSResponder.exe|Name=Bonjour| "{B7CDFA80-8643-48BD-A636-64B7EA89E004}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\Bonjour\mDNSResponder.exe|Name=Bonjour| "UDP Query User{518B18D9-79AB-48E2-A567-062A20796A43}C:\program files\fifa18\fifa18.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\fifa18\fifa18.exe|Name=FIFA 18|Desc=FIFA 18|Defer=User| "TCP Query User{FAAFAAA4-B827-45EF-BDD7-A2C8B3C5CCC1}C:\program files\fifa18\fifa18.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\fifa18\fifa18.exe|Name=FIFA 18|Desc=FIFA 18|Defer=User| "{8EF7FF8D-0B1C-4219-8D1C-CB75D4A235EE}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\DriversCloud.com\DriversCloud.exe|Name=DriversCloud| "{875D59DC-6F85-48CD-97A0-19E8337992FA}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\DriversCloud.com\DriversCloud.exe|Name=DriversCloud| "UDP Query User{069BB0CC-E3E3-491B-94BF-1D0B76F05B7E}C:\program files (x86)\thq\company of heroes\bugreport\bugreport.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\thq\company of heroes\bugreport\bugreport.exe|Name=bugreport|Desc=bugreport|Defer=User| "TCP Query User{BB16D808-E60F-4020-8777-7010CBBE3618}C:\program files (x86)\thq\company of heroes\bugreport\bugreport.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\thq\company of heroes\bugreport\bugreport.exe|Name=bugreport|Desc=bugreport|Defer=User| "{0A84BF55-A474-4F25-8F04-065BFEC1FA9E}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe|Name=Medal of Honor Batailles du Pacifique| "{BC41707E-4832-43CE-9AF1-7597CAEC0641}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe|Name=Medal of Honor Batailles du Pacifique| "{46D9C57E-D09C-4193-A079-837BD54251D5}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa_setup.exe|Name=Medal of Honor Batailles du Pacifique Configuration| "{74B45F78-C80D-480D-BF6D-EA79A2DD9F43}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa_setup.exe|Name=Medal of Honor Batailles du Pacifique Configuration| "UDP Query User{A835C2AE-FBCE-43EE-B35B-CF9B2BD95292}C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016| "TCP Query User{38657605-37D8-4191-853C-CD119BF691D9}C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016| "{981E4F04-84E9-4385-A312-3E6DEC1175CE}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Name=Deezer|Desc=Deezer|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1603163045-3571281156-695395475-2439299277-3395427646-929816475-371680158|EmbedCtxt=Deezer|Platform=2:6:2|Platform2=GTEQ| "UDP Query User{6948DDA1-129A-4806-B874-76B92110DE8D}C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe|Name=Ghost Recon Phantoms|Desc=Ghost Recon Phantoms|Defer=User| "TCP Query User{7698A4AB-3DAD-4258-87BC-2045629A3266}C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe|Name=Ghost Recon Phantoms|Desc=Ghost Recon Phantoms|Defer=User| "UDP Query User{CBFCFFAC-35D7-4EBE-A669-2556FE09A317}C:\users\ben\appdata\local\apps\2.0\med0dmdj.aaj\1y066tem.kpp\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\ben\appdata\local\apps\2.0\med0dmdj.aaj\1y066tem.kpp\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe|Name=launcher.exe|Desc=launcher.exe|Defer=User| "TCP Query User{AA7B7B1A-8544-4958-AB33-176A0EC8A707}C:\users\ben\appdata\local\apps\2.0\med0dmdj.aaj\1y066tem.kpp\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\ben\appdata\local\apps\2.0\med0dmdj.aaj\1y066tem.kpp\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe|Name=launcher.exe|Desc=launcher.exe|Defer=User| "{B9D10492-7BC6-47E0-BB20-CBBB27B8ED5A}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's The Division\TheDivision.exe|Name=Tom Clancy's The Division| "UDP Query User{8DD19571-08D8-4F43-9656-A81277481CDB}C:\program files (x86)\company of heroes 2 master collection\$rtumxsn.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\company of heroes 2 master collection\$rtumxsn.exe|Name=Company of Heroes 2|Desc=Company of Heroes 2|Defer=User| "TCP Query User{A9939AD3-7AB8-4C90-A51E-2C09C3D31F3E}C:\program files (x86)\company of heroes 2 master collection\$rtumxsn.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\company of heroes 2 master collection\$rtumxsn.exe|Name=Company of Heroes 2|Desc=Company of Heroes 2|Defer=User| "UDP Query User{90B13E95-A136-4AFA-B098-216B188707FB}C:\program files (x86)\company of heroes 2 master collection\reliccoh2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\company of heroes 2 master collection\reliccoh2.exe|Name=Company of Heroes 2|Desc=Company of Heroes 2| "TCP Query User{CB569DEE-F09F-4707-8D89-D223A6846533}C:\program files (x86)\company of heroes 2 master collection\reliccoh2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\company of heroes 2 master collection\reliccoh2.exe|Name=Company of Heroes 2|Desc=Company of Heroes 2| "UDP Query User{5692EDEF-EC10-4471-8C3D-69118015DA4F}C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016| "TCP Query User{53B92574-B86B-4EDB-AE01-5B905A671C71}C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\konami digital entertainment\uefa euro 2016 france\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016| "{E284288A-F700-4637-8B09-89E6A48796DA}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FC2Editor.exe|Name=Editeur| "{75CF1EDC-CCC8-4668-A3C8-F0F71D55F80A}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FC2Editor.exe|Name=Editeur| "{A63282FF-4A29-4EB6-889F-027C15367BAF}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FC2Launcher.exe|Name=Far Cry 2 Updater| "{AF327FBE-AA9F-4609-A158-DCCE42CE3DDB}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FC2Launcher.exe|Name=Far Cry 2 Updater| "{13293A4D-97B0-41EE-AC10-16A52667FEB1}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FarCry2.exe|Name=Far Cry 2| "{E1F28A7F-FC3D-45CB-8C52-05A17994F343}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FarCry2.exe|Name=Far Cry 2| "{6D3E0DCD-BA67-4D33-A7FF-DDF751A5412E}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Name=Sway|Desc=Microsoft Sway|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-584073948-3292409011-2882754242-2237763630-1999038865-1049037702-4080706152|EmbedCtxt=Sway|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{5A5E45FB-4634-494C-B01F-8ADEB2865DB5}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Name=Sway|Desc=Microsoft Sway|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-584073948-3292409011-2882754242-2237763630-1999038865-1049037702-4080706152|EmbedCtxt=Sway|Platform=2:6:2|Platform2=GTEQ| "{62D07C1B-01CB-4837-A697-02A719437758}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Name=Candy Crush Soda Saga|Desc=Candy Crush Soda Saga|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-3055884410-2067824683-223899546-422323478-2359388318-2114876276-1379654078|EmbedCtxt=Candy Crush Soda Saga|Platform=2:6:2|Platform2=GTEQ| "{D96F0EFB-0A10-40C9-AF60-60F1C00CC07B}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Name=Twitter|Desc=Twitter|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-1063257880-1914585122-1954150059-946145533-116938067-416079064-1690466945|EmbedCtxt=Twitter|Platform=2:6:2|Platform2=GTEQ| "{24E1D6CB-EB3F-430F-8868-B55455E2A7EF}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{C9F27B44-9F3F-4BB2-BC4C-A928038FFD04}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{8A5635DD-713C-4E56-8302-57BF0B0502BB}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{9A5F9DA5-0B82-4E82-A54C-9594A6861352}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{5CEBC621-E7E7-460F-A7FA-11478CD53740}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Name=Xbox|Desc=Xbox|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-4153522205-3718366397-1353898457-1332184198-1210887116-3116787857-2103916698|EmbedCtxt=Xbox|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{B057CCA2-FFAF-4AE5-B2E4-EF9299BF201E}"=v2.25|Action=Allow|Active=TRUE|Dir=Out|Name=Xbox|Desc=Xbox|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1275|AppPkgId=S-1-15-2-4153522205-3718366397-1353898457-1332184198-1210887116-3116787857-2103916698|EmbedCtxt=Xbox|Platform=2:6:2|Platform2=GTEQ| "{A60F7C42-5E14-4E08-A6AA-23EB1ACA16D6}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\gu.exe|Name=Tom Clancy's Splinter Cell Conviction Mise à jour| "{7D683C0D-AD05-43D0-A2E2-E4D944A7C6D4}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\gu.exe|Name=Tom Clancy's Splinter Cell Conviction Mise à jour| "{1A85A0C2-4D7C-4237-AC72-0972BC6FE883}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe|Name=Tom Clancy's Splinter Cell Conviction| "{6DCBEF7C-43E6-4919-86A6-A261E473647B}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe|Name=Tom Clancy's Splinter Cell Conviction| "{730C79AF-2BA2-4E1E-A8D8-7E664EE590F0}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ GameUpdate| "{54C4675B-5600-4E8D-A1B7-A2B12E851008}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ GameUpdate| "{BE9E2C7C-D073-46B1-95A9-4B21E91B44A2}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX11| "{8953B681-AA0B-4478-A520-ABB775CB7609}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX11| "{F1623BE2-CD46-4C25-A14D-5BE981C8355C}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX9| "{5E948201-9193-4350-B744-2CD40F80E431}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX9| "{92DAE0A0-E2AD-4D2B-8321-D3D282E70495}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ Launcher| "{4E3373EF-72BD-4EBA-86A6-392DB6DF27E3}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ Launcher| "{057886C2-07A7-4626-AA34-39B51152CB4C}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\DriversCloud.com\MCDetection.exe|Name=mcdetection| "{D6D9D825-2935-4033-8DCF-7429D288E498}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\DriversCloud.com\MCDetection.exe|Name=mcdetection| "{AB9F06D6-D685-484A-8134-D4B16D54CCC6}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe|Name=Tom Clancy's Rainbow Six Vegas 2 Update| "{7E8B98F9-BD1F-4D13-92D7-61F2FC8DB92B}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe|Name=Tom Clancy's Rainbow Six Vegas 2 Update| "{AC5A9D36-5EF6-4B9E-855D-41E5D9195EEA}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe|Name=Tom Clancy's Rainbow Six Vegas 2| "{D81F8127-6103-48CE-BA4C-AAF9E5A5B1AF}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe|Name=Tom Clancy's Rainbow Six Vegas 2| "UDP Query User{B32FDE46-FF2F-4BA4-84B9-E8DD371B33B4}C:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe|Name=SHIFT 2 UNLEASHED™|Desc=SHIFT 2 UNLEASHED™| "TCP Query User{5A6F06DB-2816-41C5-925D-D97D38A377F6}C:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe|Name=SHIFT 2 UNLEASHED™|Desc=SHIFT 2 UNLEASHED™| "{74F0BAD0-968D-43F9-8B93-B555DEA44659}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{B1C4FEF4-8045-4675-8EB5-9C72B3182EE2}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{91DB9A85-E31E-489E-9E7B-35977920D785}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{47B6DF85-CEEA-408E-A92B-4459E92EE4F7}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{6893C6B1-756A-4481-9D8A-969349C574A8}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed II\UPlayBrowser.exe|Name=Assassin's Creed II Uplay| "{A8C56FED-B69B-4434-921B-57F521522B3F}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed II\UPlayBrowser.exe|Name=Assassin's Creed II Uplay| "{67479A7B-A3F7-4B78-BE68-2C86BC5ED0F7}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe|Name=Assassin's Creed II Update| "{2970E7C1-CAC2-4327-8D0D-8C6869FE7C5A}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe|Name=Assassin's Creed II Update| "{81DE9705-EFD5-4832-916D-0D56A31541B8}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe|Name=Assassin's Creed II| "{B98B59C4-93E5-4888-AD7B-AF9A2BBB1334}"=v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe|Name=Assassin's Creed II| "UDP Query User{2B075949-C1D7-481F-B628-61358594FAA7}C:\games\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\games\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe|Name=FishingGame|Desc=FishingGame|Defer=User| "TCP Query User{ADBB7AFE-BECB-420A-BB48-DAD1A140AC8A}C:\games\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\games\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe|Name=FishingGame|Desc=FishingGame|Defer=User| "UDP Query User{27C149B4-3965-4D80-8A69-DDF54340B5CF}C:\program files (x86)\pro evolution soccer 2016\pes2016.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\pro evolution soccer 2016\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016|Defer=User| "TCP Query User{6761FBF9-71E1-4FEA-8DC1-1C8EFFCDE033}C:\program files (x86)\pro evolution soccer 2016\pes2016.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\pro evolution soccer 2016\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016|Defer=User| "UDP Query User{9C19CEF0-76D3-4728-AAFB-AADFDDF2D62B}C:\users\ben\appdata\roaming\utorrent\updates\3.4.3_40760.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\ben\appdata\roaming\utorrent\updates\3.4.3_40760.exe|Name=3.4.3_40760.exe|Desc=3.4.3_40760.exe| "TCP Query User{22B39AFF-CFB3-4E43-9700-E9B5081FC90A}C:\users\ben\appdata\roaming\utorrent\updates\3.4.3_40760.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\ben\appdata\roaming\utorrent\updates\3.4.3_40760.exe|Name=3.4.3_40760.exe|Desc=3.4.3_40760.exe| "UDP Query User{84AFFF46-3728-4E10-8DE3-B2AD1A03FC41}C:\program files (x86)\origin games\fifa 15\fifa15.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\origin games\fifa 15\fifa15.exe|Name=EA Sports™ FIFA 15|Desc=EA Sports™ FIFA 15|Defer=User| "TCP Query User{105E2F76-2271-495D-B4E9-454572AC2F5C}C:\program files (x86)\origin games\fifa 15\fifa15.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\origin games\fifa 15\fifa15.exe|Name=EA Sports™ FIFA 15|Desc=EA Sports™ FIFA 15|Defer=User| "UDP Query User{19EFAC65-8C26-4A00-B1A9-70597C300F6E}C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe|Name=WRC 4|Desc=WRC 4| "TCP Query User{7C7D9AA5-6C9B-464E-A17D-54E2DF9806C3}C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe|Name=WRC 4|Desc=WRC 4| "UDP Query User{68F1CD82-2A68-4056-80DE-46CCAA90E186}C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe|Name=MKKE|Desc=MKKE|Defer=User| "TCP Query User{E335A153-A485-421E-91DA-E6C7AF1CAC81}C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe|Name=MKKE|Desc=MKKE|Defer=User| "UDP Query User{CEA55D6B-3063-4638-B90B-3D812DAA2D60}C:\program files (x86)\tripwire interactive\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\tripwire interactive\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe|Name=ROGame|Desc=ROGame|Defer=User| "TCP Query User{C3830D07-1FF3-4267-9AA0-7CE1957B35E6}C:\program files (x86)\tripwire interactive\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\tripwire interactive\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe|Name=ROGame|Desc=ROGame|Defer=User| "UDP Query User{DE039C2C-EB68-45BC-9E85-8161FFAAA09D}C:\program files (x86)\origin games\fifa 15\fifa15.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\origin games\fifa 15\fifa15.exe|Name=EA Sports™ FIFA 15|Desc=EA Sports™ FIFA 15|Defer=User| "TCP Query User{21036EFB-5EEA-45C0-9B38-681A5D61F475}C:\program files (x86)\origin games\fifa 15\fifa15.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\origin games\fifa 15\fifa15.exe|Name=EA Sports™ FIFA 15|Desc=EA Sports™ FIFA 15|Defer=User| "UDP Query User{95CC83FE-0B41-4944-82F2-4218CC19CAA9}C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe|Name=ACCGame-Win32-Shipping|Desc=ACCGame-Win32-Shipping|Defer=User| "TCP Query User{2E4E1624-007F-417A-8186-9EA880B1485B}C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe|Name=ACCGame-Win32-Shipping|Desc=ACCGame-Win32-Shipping|Defer=User| "UDP Query User{675FDA49-FBF1-4FF8-9654-119F98E50AED}C:\program files (x86)\far cry 4\bin\farcry4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\far cry 4\bin\farcry4.exe|Name=Far Cry 4|Desc=Far Cry 4|Defer=User| "TCP Query User{E42E781B-F9B9-4EDF-A387-2B3BD4745EE6}C:\program files (x86)\far cry 4\bin\farcry4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\far cry 4\bin\farcry4.exe|Name=Far Cry 4|Desc=Far Cry 4|Defer=User| "UDP Query User{F7FA232B-FD5C-43BC-827F-F25A9CDB0CC4}C:\program files (x86)\pro evolution soccer 2015\pes2015.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\pro evolution soccer 2015\pes2015.exe|Name=Pro Evolution Soccer 2015|Desc=Pro Evolution Soccer 2015| "TCP Query User{ED736903-9C4C-4AEB-BE6D-9AD4A515B423}C:\program files (x86)\pro evolution soccer 2015\pes2015.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\pro evolution soccer 2015\pes2015.exe|Name=Pro Evolution Soccer 2015|Desc=Pro Evolution Soccer 2015| "UDP Query User{B4F0FCC8-EB3A-47F3-BC3C-DF638E48414B}C:\program files (x86)\far cry 4\bin\farcry4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\far cry 4\bin\farcry4.exe|Name=Far Cry 4|Desc=Far Cry 4|Defer=User| "TCP Query User{72DFA5D2-271E-4D5D-B28F-98D922200DF8}C:\program files (x86)\far cry 4\bin\farcry4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\far cry 4\bin\farcry4.exe|Name=Far Cry 4|Desc=Far Cry 4|Defer=User| "UDP Query User{92A09C20-0986-4EA5-9DD3-E4F9AE9758E0}C:\program files (x86)\emule\emule.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\emule\emule.exe|Name=eMule|Desc=eMule|Defer=User| "TCP Query User{AB585420-0F46-4614-9269-0776A9CE685E}C:\program files (x86)\emule\emule.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\emule\emule.exe|Name=eMule|Desc=eMule|Defer=User| "{CF8CABD2-FCF8-4101-9D48-3BB5DD8103D8}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe|Name=µTorrent (UDP-In)|Desc=Allow µTorrent network traffic with Edge Traversal|Edge=TRUE| "{07EF42F7-6F60-44B6-B3A1-F84B562ED5F4}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe|Name=µTorrent (TCP-In)|Desc=Allow µTorrent network traffic with Edge Traversal|Edge=TRUE| "UDP Query User{661AC2D3-DA2B-4E68-8C5F-44FA221F17CB}C:\program files (x86)\emule\emule.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\emule\emule.exe|Name=eMule|Desc=eMule|Defer=User| "TCP Query User{0BA4EBEA-8F8F-4359-9A3B-0578526919C3}C:\program files (x86)\emule\emule.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\emule\emule.exe|Name=eMule|Desc=eMule|Defer=User| "UDP Query User{999C749D-E503-4705-AEB5-EC80B624434A}C:\program files (x86)\pro evolution soccer 2015\pes2015.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\pro evolution soccer 2015\pes2015.exe|Name=Pro Evolution Soccer 2015|Desc=Pro Evolution Soccer 2015| "TCP Query User{979CABCE-74D6-4A25-BFCA-0267FF646991}C:\program files (x86)\pro evolution soccer 2015\pes2015.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\pro evolution soccer 2015\pes2015.exe|Name=Pro Evolution Soccer 2015|Desc=Pro Evolution Soccer 2015| "UDP Query User{45D30287-7AC3-4634-AD4A-2663E3C56863}C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe|Name=TransGame|Desc=TransGame|Defer=User| "TCP Query User{9505C992-2573-464B-8902-7375DE1D7134}C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe|Name=TransGame|Desc=TransGame|Defer=User| "UDP Query User{26F5E1CD-5756-4600-A997-B080CC04B85A}C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe|Name=ac3lhd_32|Desc=ac3lhd_32| "TCP Query User{4A30DE6C-D654-466E-BA3B-675E5CC161E7}C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe|Name=ac3lhd_32|Desc=ac3lhd_32| "UDP Query User{4CD20600-7501-4958-BE95-63A4A36671E2}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe|Name=AssassinsCreedIIGame|Desc=AssassinsCreedIIGame| "TCP Query User{235889C9-F6CB-42BB-A7B8-77D3A333B8EC}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe|Name=AssassinsCreedIIGame|Desc=AssassinsCreedIIGame| "{80B01710-2033-4D36-A66B-895FB4BE2EC9}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\Autorun\Exe\Autorun.exe|Name=Pro Cycling Manager - Saison 2014 - Autorun| "{F5DFD365-531D-4FA0-A1B1-7549A6B4887D}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\Autorun\Exe\Autorun.exe|Name=Pro Cycling Manager - Saison 2014 - Autorun| "{D729ECA4-14E2-4A28-9315-7D7BD231B5F6}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\PCM.exe|Name=Pro Cycling Manager - Saison 2014| "{042143EB-D5EA-4DA4-85F9-A705C96C176C}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\PCM.exe|Name=Pro Cycling Manager - Saison 2014| "UDP Query User{9FD87007-42DE-4859-8EC3-AA66B19E227E}C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe|Name=WolfNewOrder|Desc=WolfNewOrder| "TCP Query User{58EC8089-E764-4642-897B-87EF4F146650}C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe|Name=WolfNewOrder|Desc=WolfNewOrder| "UDP Query User{CCFF7900-4E81-4588-ABE7-9FD6C100BA26}C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe|Name=TransGame|Desc=TransGame|Defer=User| "TCP Query User{B79A3FE4-8ED2-4B35-B7FF-92C00A51FAE6}C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\transformers rise of the dark spark\binaries\transgame.exe|Name=TransGame|Desc=TransGame|Defer=User| "UDP Query User{C775420E-57BF-4808-BFB2-B02622831AB8}C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe|Name=WolfNewOrder|Desc=WolfNewOrder| "TCP Query User{3F682546-061B-456C-BFE3-63F585C8DED0}C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe|Name=WolfNewOrder|Desc=WolfNewOrder| "UDP Query User{B1874694-51B8-4A57-8EF9-30727BB0111C}C:\program files (x86)\enemy front proper\bin32\enemyfront.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\enemy front proper\bin32\enemyfront.exe|Name=EnemyFront|Desc=EnemyFront| "TCP Query User{98B8E629-2F81-448E-9C07-B639D69DD19B}C:\program files (x86)\enemy front proper\bin32\enemyfront.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\enemy front proper\bin32\enemyfront.exe|Name=EnemyFront|Desc=EnemyFront| "{D1953205-981D-4961-902C-92822D899E2F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\ma-config.com\MaConfigAgent.exe|Name=maconfigagent| "{677BB61E-228E-4948-A9E7-610D50224F8F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\ma-config.com\MaConfigAgent.exe|Name=maconfigagent| "{C86EA927-C368-4199-B842-89AE0237D7B9}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|LPort=48114|RA4=LocalSubnet|RA6=LocalSubnet|Name=maconfig_tcptls| "{734FB108-27FB-456C-8366-23DA10B2E70B}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|LPort=48113|RA4=LocalSubnet|RA6=LocalSubnet|Name=maconfig_tcp| "UDP Query User{BA8EDE60-935A-45EE-839C-785127A56511}C:\games\activision\call of duty - world at war\codwaw.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\games\activision\call of duty - world at war\codwaw.exe|Name=Call of Duty(R): World at War Campaign/Coop|Desc=Call of Duty(R): World at War Campaign/Coop| "TCP Query User{1D3FA464-7598-474F-94AE-B545DB06C935}C:\games\activision\call of duty - world at war\codwaw.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\games\activision\call of duty - world at war\codwaw.exe|Name=Call of Duty(R): World at War Campaign/Coop|Desc=Call of Duty(R): World at War Campaign/Coop| "UDP Query User{728FA56D-18C8-4866-BE34-82A273A7DABC}C:\program files (x86)\company of heroes 2\reliccoh2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\company of heroes 2\reliccoh2.exe|Name=Company Of Heroes 2|Desc=Company Of Heroes 2| "TCP Query User{263F0DA0-C5F3-42FE-93AA-0400F7EC000F}C:\program files (x86)\company of heroes 2\reliccoh2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\company of heroes 2\reliccoh2.exe|Name=Company Of Heroes 2|Desc=Company Of Heroes 2| "UDP Query User{BA80C006-A552-4617-9187-4ADF0C01462C}C:\program files (x86)\rockstar games\eflc\eflc.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\rockstar games\eflc\eflc.exe|Name=Grand Theft Auto : Episodes from Liberty City|Desc=Grand Theft Auto : Episodes from Liberty City|Defer=User| "TCP Query User{676FF6C9-AAFF-4CD9-9808-741C459229C7}C:\program files (x86)\rockstar games\eflc\eflc.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\rockstar games\eflc\eflc.exe|Name=Grand Theft Auto : Episodes from Liberty City|Desc=Grand Theft Auto : Episodes from Liberty City|Defer=User| "{971090DC-2043-4372-9645-C4A15EB51B8B}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Rockstar Games\EFLC\LaunchEFLC.exe|Name=Grand Theft Auto: Episodes From Liberty City| "{69B0D74A-07FE-4029-929D-4D4B0547691E}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Rockstar Games\EFLC\LaunchEFLC.exe|Name=Grand Theft Auto: Episodes From Liberty City| "UDP Query User{5F11457D-8923-41E4-B608-061CF1CD3D95}C:\games\activision\call of duty - world at war\codwaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\activision\call of duty - world at war\codwaw.exe|Name=Call of Duty(R): World at War Campaign/Coop|Desc=Call of Duty(R): World at War Campaign/Coop|Defer=User| "TCP Query User{77C36502-9330-49F1-ACB8-DEF854ED7BB2}C:\games\activision\call of duty - world at war\codwaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\activision\call of duty - world at war\codwaw.exe|Name=Call of Duty(R): World at War Campaign/Coop|Desc=Call of Duty(R): World at War Campaign/Coop|Defer=User| "UDP Query User{1D0BD8EB-01EC-4AF4-AFFD-EC207716B938}C:\program files (x86)\mxgp\mxgp.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\mxgp\mxgp.exe|Name=MXGP|Desc=MXGP| "TCP Query User{F493ADD1-A807-42FD-9CB8-7F92E05CE079}C:\program files (x86)\mxgp\mxgp.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\mxgp\mxgp.exe|Name=MXGP|Desc=MXGP| "{EB25E0D2-9B4E-471E-A8F5-A85697FDE777}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe|Name=Company of Heroes - Opposing Fronts| "{A6E24299-45F6-475A-B69C-01381693E4F4}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe|Name=Company of Heroes - Opposing Fronts| "UDP Query User{678FD229-837D-4D48-95EF-80085B926C46}C:\program files (x86)\company of heroes 2\reliccoh2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\company of heroes 2\reliccoh2.exe|Name=Company Of Heroes 2|Desc=Company Of Heroes 2| "TCP Query User{D8B6C997-5027-4B3A-8539-8EFFA7AD7445}C:\program files (x86)\company of heroes 2\reliccoh2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\company of heroes 2\reliccoh2.exe|Name=Company Of Heroes 2|Desc=Company Of Heroes 2| "UDP Query User{F049507A-132A-4F32-B264-7D2DBFCD2A4B}C:\Program Files (x86)\Ubisoft\assassin's creed liberation hd\ac3lhd_32.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\assassin's creed liberation hd\ac3lhd_32.exe|Name=ac3lhd_32|Desc=ac3lhd_32| "TCP Query User{B927828C-B338-42EA-B771-577E088636D3}C:\Program Files (x86)\Ubisoft\assassin's creed liberation hd\ac3lhd_32.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\assassin's creed liberation hd\ac3lhd_32.exe|Name=ac3lhd_32|Desc=ac3lhd_32| "UDP Query User{C94AE133-6719-42BA-865A-48448E444D5A}C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe|Name=WRC 4|Desc=WRC 4|Defer=User| "TCP Query User{7F01887B-3D59-4D16-9B75-9B8BADCA739B}C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe|Name=WRC 4|Desc=WRC 4|Defer=User| "UDP Query User{8EF24EA0-F258-418E-9D2A-51237FA76C5D}C:\games\dishonored_3dm\binaries\win32\dishonored.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\games\dishonored_3dm\binaries\win32\dishonored.exe|Name=Dishonored|Desc=Dishonored|Defer=User| "TCP Query User{97EFC56F-BA3E-47DB-AD92-2C1AFE27C1D5}C:\games\dishonored_3dm\binaries\win32\dishonored.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\games\dishonored_3dm\binaries\win32\dishonored.exe|Name=Dishonored|Desc=Dishonored|Defer=User| "UDP Query User{1BCA022D-8E9F-434A-8BDA-6590F9AB6EB8}C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe|Name=MKKE|Desc=MKKE|Defer=User| "TCP Query User{CE53F3ED-8A18-48F7-9567-6A1A424ABC88}C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\mortal kombat\mortal kombat komplete edition\disccontentpc\mkke.exe|Name=MKKE|Desc=MKKE|Defer=User| "UDP Query User{2969624C-3307-4F49-99E5-3560B4CC3340}C:\program files (x86)\total war rome ii\rome2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\total war rome ii\rome2.exe|Name=Total War: Rome II|Desc=Total War: Rome II| "TCP Query User{71A02F41-6525-4F34-95EE-DB71ECC8E63F}C:\program files (x86)\total war rome ii\rome2.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\total war rome ii\rome2.exe|Name=Total War: Rome II|Desc=Total War: Rome II| "{6CBD25DF-4FE6-4FCD-91CB-B793A0C81AE6}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\activision\call of duty black ops ii\t6sp.exe|Name=Call of Duty(R): Black Ops II|Desc=Call of Duty(R): Black Ops II| "{B44FD3C2-53E7-4071-887A-91CD91F6BF3A}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\activision\call of duty black ops ii\t6sp.exe|Name=Call of Duty(R): Black Ops II|Desc=Call of Duty(R): Black Ops II| "{B5BF9B7D-5A13-472F-96C2-42CD6195D034}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Battlefield 4\bf4.exe|Name=Battlefield 4™ (x64)| "{6FBB7E1B-280A-44CC-91E0-2D825BE8F8B3}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Battlefield 4\bf4.exe|Name=Battlefield 4™ (x64)| "{B0F38D13-B830-4D23-932E-BEA04E6BF146}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Battlefield 4\bf4_x86.exe|Name=Battlefield 4™| "{DA6A0EA8-63D7-469E-8451-80AA23743833}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Battlefield 4\bf4_x86.exe|Name=Battlefield 4™| "{8018D07F-78B7-44DA-9CA4-FCB1883CF7FA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe|Name=ESN Sonar Host Application| "{1123FBA1-11D5-4E22-8197-355F12521397}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe|Name=ESN Sonar Host Application| "{E463A948-6211-407A-8B6D-3E239F818530}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Games\Call of Duty - Ghosts\iw6sp64_ship.exe|Name=Call of Duty - Ghosts| "{D2B40C81-DBA7-48F3-9CDB-2E4F844E7A68}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Games\Call of Duty - Ghosts\iw6sp64_ship.exe|Name=Call of Duty - Ghosts| "{3629204E-0021-490C-B426-5BC2D206DF5B}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Codemasters\DiRT 3\dirt3_game.exe|Name=DiRT 3| "{6613022F-B512-4AEF-925B-59583713A0FA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Codemasters\DiRT 3\dirt3_game.exe|Name=DiRT 3| "{C4AC5EE4-50B1-4669-8B2D-00DBEB7150BE}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Capcom\Street Fighter X Tekken\SFTK.exe|Name=Street Fighter X Tekken| "{A082183C-29B3-47B1-B5FC-C7F95A763E60}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Capcom\Street Fighter X Tekken\SFTK.exe|Name=Street Fighter X Tekken| "{53FB0B47-3A59-43FA-8B26-B65FF9AEE61F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe|Name=µTorrent (UDP-In)|Desc=Allow µTorrent network traffic with Edge Traversal|Edge=TRUE| "{D59AB483-D4E9-4C42-A51F-35BF1C8E2D84}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Ben\AppData\Roaming\uTorrent\uTorrent.exe|Name=µTorrent (TCP-In)|Desc=Allow µTorrent network traffic with Edge Traversal|Edge=TRUE| "UDP Query User{D8F655D3-0DD9-4DCB-A892-5231C401BA9C}C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe|Name=Max Payne 3|Desc=Max Payne 3|Defer=User| "TCP Query User{82D68DD5-633E-4382-8744-B353B80A6731}C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe|Name=Max Payne 3|Desc=Max Payne 3|Defer=User| "{9BD7D16E-8855-4A07-ABD9-86F4728FDE41}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Rockstar Games\Max Payne 3\PlayMaxPayne3.exe|Name=Max Payne 3| "{278459B5-5DD6-442A-94BA-FFBBAC4FD267}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Rockstar Games\Max Payne 3\PlayMaxPayne3.exe|Name=Max Payne 3| "{4A346ECF-AF98-4FD0-BFE0-71F832DF0E45}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=808|App=C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe|Svc=NetTcpActivator|Name=@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2000|Desc=@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2001|EmbedCtxt=@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2002| "{B2874CB0-23B1-4522-8CA0-E67D6CD75550}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Far Cry 3 Blood Dragon\bin\FC3BDUpdater.exe|Name=Far Cry 3 Blood Dragon Updater| "{9F52B305-122B-4FB6-8E5C-887232E9D7AD}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Far Cry 3 Blood Dragon\bin\FC3BDUpdater.exe|Name=Far Cry 3 Blood Dragon Updater| "{5E2A3314-AE7C-4F1D-9B20-B242ED9D11B6}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe|Name=Far Cry 3 Blood Dragon D3D11| "{CA5777C0-C4C0-4499-9CFD-2E5A1E06E7EA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe|Name=Far Cry 3 Blood Dragon D3D11| "{937FF065-B5D1-4538-9299-B17A63329CF3}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe|Name=Far Cry 3 Blood Dragon D3D9| "{7A8FF51B-0CF1-46E0-AA62-75D8E563B551}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe|Name=Far Cry 3 Blood Dragon D3D9| "{7BA80CA0-4D83-4A45-8AAD-C11683E37FD9}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HP\hp software update\hpwucli.exe|Name=hpwucli.exe|Desc=C:\Program Files (x86)\HP\hp software update\hpwucli.exe| "{5ED2F2E0-23F1-40A0-8240-C3C112AC09C7}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=48113|RA4=LocalSubnet|RA6=LocalSubnet|Name=maconfig_udp| "{A4DFCD0C-5CF5-4BAD-8CC6-32461B0687DE}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|LPort=48113|RA4=LocalSubnet|RA6=LocalSubnet|Name=maconfig_tcp| "UDP Query User{E5F7F65A-C6B4-42BD-A3E3-1075A4A8ECE5}C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe|Name=AC3SP|Desc=AC3SP|Defer=User| "TCP Query User{5FB5A54C-ECDE-4D73-94A7-DCB0853D31B2}C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe|Name=AC3SP|Desc=AC3SP|Defer=User| "UDP Query User{BCA6EC18-0A83-4A4D-87B2-F9016FB1C745}C:\games\need for speed most wanted\nfs13.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\games\need for speed most wanted\nfs13.exe|Name=Need for Speed™ Most Wanted|Desc=Need for Speed™ Most Wanted| "TCP Query User{D668D0EB-F357-4792-AA41-9227EED08314}C:\games\need for speed most wanted\nfs13.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\games\need for speed most wanted\nfs13.exe|Name=Need for Speed™ Most Wanted|Desc=Need for Speed™ Most Wanted| "UDP Query User{D62E60C9-FD8F-4F0B-9668-8110D06D4728}C:\games\need for speed most wanted\nfs13.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\need for speed most wanted\nfs13.exe|Name=Need for Speed™ Most Wanted|Desc=Need for Speed™ Most Wanted|Defer=User| "TCP Query User{E061DD81-86B0-4551-A5EC-ED7CD395C08A}C:\games\need for speed most wanted\nfs13.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\need for speed most wanted\nfs13.exe|Name=Need for Speed™ Most Wanted|Desc=Need for Speed™ Most Wanted|Defer=User| "UDP Query User{E6F50A35-5F5B-43A3-B3F0-0D08BFEFDFCB}C:\games\dishonored_3dm\binaries\win32\dishonored.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\dishonored_3dm\binaries\win32\dishonored.exe|Name=Dishonored|Desc=Dishonored|Defer=User| "TCP Query User{ABDE8D39-2834-49CD-8ADE-B18144A80ABC}C:\games\dishonored_3dm\binaries\win32\dishonored.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\dishonored_3dm\binaries\win32\dishonored.exe|Name=Dishonored|Desc=Dishonored|Defer=User| "UDP Query User{D8F672FA-F08E-4BAF-A246-8CBDF531E42F}C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe|Name=AC3SP|Desc=AC3SP|Defer=User| "TCP Query User{DC669657-0C7E-40E8-A14E-A01E80DBA794}C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\ubisoft\assassins creed iii\ac3sp.exe|Name=AC3SP|Desc=AC3SP|Defer=User| "UDP Query User{50D55EAA-2600-43EF-8DE3-A3A37A5D6291}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe|Name=ACBSP|Desc=ACBSP| "TCP Query User{D48F1B50-A55E-4DBB-B570-4891963F6BD6}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe|Name=ACBSP|Desc=ACBSP| "{044C58E8-6F64-454C-8746-1F2939DE67B7}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe|Name=Assassin's Creed Brotherhood Uplay| "{AF2C6B58-19B6-4A4A-AC45-238AAF94D96A}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe|Name=Assassin's Creed Brotherhood Uplay| "{9BDD70A2-70AB-4871-AEEA-B8EA8031B51A}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe|Name=Assassin's Creed Brotherhood Update| "{8C0E836B-BA65-44E5-87AB-57822908BE3A}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe|Name=Assassin's Creed Brotherhood Update| "{9FE0E9BB-8581-4C7C-8066-908F50C8C999}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe|Name=Assassin's Creed Brotherhood Multiplayer| "{7BAE1EBA-128E-4813-8607-1B412430DE6B}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe|Name=Assassin's Creed Brotherhood Multiplayer| "{3A2B6545-2308-4894-AEA9-77C07768B1D1}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe|Name=Assassin's Creed Brotherhood| "{0851A65C-49D2-47DC-A0E6-5EC51AF933AD}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe|Name=Assassin's Creed Brotherhood| "UDP Query User{60C510DF-072F-4C88-8B7B-87B8B81BAA77}C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe|Name=Call of Duty(R): Black Ops II - Multiplayer|Desc=Call of Duty(R): Black Ops II - Multiplayer|Defer=User| "TCP Query User{BBFAA3F3-4E2D-4051-BE0F-FD92A537220A}C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe|Name=Call of Duty(R): Black Ops II - Multiplayer|Desc=Call of Duty(R): Black Ops II - Multiplayer|Defer=User| "UDP Query User{76ACC8FB-41C4-48D9-A2AE-BCEF8DF32CD8}C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe|Name=Call of Duty(R): Black Ops II - Multiplayer|Desc=Call of Duty(R): Black Ops II - Multiplayer| "TCP Query User{CE4A95DD-2CEB-494E-8DA9-4CFFEA5FD78C}C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\activision\call of duty black ops ii\t6mp.exe|Name=Call of Duty(R): Black Ops II - Multiplayer|Desc=Call of Duty(R): Black Ops II - Multiplayer| "UDP Query User{C61EA022-E50E-480F-A150-BCFD9B60F04A}C:\program files (x86)\activision\call of duty black ops ii\t6sp.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\activision\call of duty black ops ii\t6sp.exe|Name=Call of Duty(R): Black Ops II|Desc=Call of Duty(R): Black Ops II| "TCP Query User{7554CA96-F604-47EA-8D65-B5DF1FC42FCB}C:\program files (x86)\activision\call of duty black ops ii\t6sp.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\activision\call of duty black ops ii\t6sp.exe|Name=Call of Duty(R): Black Ops II|Desc=Call of Duty(R): Black Ops II| "UDP Query User{C8EC78EB-C2CE-4C36-97F0-94446ED39291}C:\games\need for speed the run\need for speed the run.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\need for speed the run\need for speed the run.exe|Name=Need For Speed The Run|Desc=Need For Speed The Run| "TCP Query User{95E3C18F-8CD9-4095-9B07-7EBE8F0BFE96}C:\games\need for speed the run\need for speed the run.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\need for speed the run\need for speed the run.exe|Name=Need For Speed The Run|Desc=Need For Speed The Run| "UDP Query User{FC0C6FB3-71A9-4B93-BE39-E7FC90FFA575}D:\crack\shift2u.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\crack\shift2u.exe|Name=SHIFT 2 UNLEASHED™|Desc=SHIFT 2 UNLEASHED™| "TCP Query User{BF1A1A42-1672-4120-8453-B12B485CBA39}D:\crack\shift2u.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\crack\shift2u.exe|Name=SHIFT 2 UNLEASHED™|Desc=SHIFT 2 UNLEASHED™| "{F21D83C2-073E-412C-865A-F1127BF87617}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{CB33C805-2EF7-4674-BA1F-CDCF4CD0748C}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{4655E5A3-EDF6-4F96-8371-25D8216A94EA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{89974630-DA46-4489-A5D3-A5E6DDB348AD}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe|Name=Tom Clancy's Ghost Recon Future Soldier| "{B1DA0597-53D2-45FB-9FC8-16A03EB9E2F9}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Mesh\MOE.exe|Name=Windows Live Mesh|Edge=TRUE| "{2E27B423-4B5E-4023-8F96-F4568CAA7F52}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe|Name=Windows Live Messenger|Edge=TRUE| "{B3F15909-B45C-49E9-B45D-05C32BBEC8CA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (SSDP)| "{0B7E69BF-021E-4668-8E67-56B81FE4D5BA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (UPnP)| "{2FA7B5EE-3FFA-41BE-85D8-B3EC9D54FEAA}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe|Name=Windows Live Communications Platform|Edge=TRUE| "UDP Query User{D5B11BD1-4612-4FE8-8382-FE926A4B28DB}C:\program files\java\jre6\bin\javaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\java\jre6\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "TCP Query User{54D6050E-CA44-4DA6-B6B7-4E3358F50B13}C:\program files\java\jre6\bin\javaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\java\jre6\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "{BA50F8F9-F750-4BD5-8BFA-FC7AB33F156C}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe|Name=Ubisoft Game Launcher| "{8EC77412-B53E-4CF2-99CB-C0EE53460307}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe|Name=Ubisoft Game Launcher| "UDP Query User{CA2A9CC5-2989-425A-907D-B2ED46174EF0}D:\program files\activision\call of duty - world at war\codwaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files\activision\call of duty - world at war\codwaw.exe|Name=Call of Duty(R): World at War Campaign/Coop|Desc=Call of Duty(R): World at War Campaign/Coop|Defer=User| "TCP Query User{BD18CA3C-EF69-4323-9D1C-B2248EA43037}D:\program files\activision\call of duty - world at war\codwaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files\activision\call of duty - world at war\codwaw.exe|Name=Call of Duty(R): World at War Campaign/Coop|Desc=Call of Duty(R): World at War Campaign/Coop|Defer=User| "UDP Query User{FBA56B87-97EB-490B-924E-FB95038CDC57}D:\program files\emule\emule.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files\emule\emule.exe|Name=eMule|Desc=eMule|Defer=User| "TCP Query User{CEF39239-0451-42CE-BCDA-F804E04BC358}D:\program files\emule\emule.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files\emule\emule.exe|Name=eMule|Desc=eMule|Defer=User| "{0CF13A5A-786D-4540-B3CB-3989AE2EF3A6}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|LPort=48113|RA4=LocalSubnet|RA6=LocalSubnet|Name=maconfig_udp| "{66F04EBF-8AF9-467A-B4B1-D7FBF2CD6288}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\ma-config.com\x64\maconfservice.exe|Name=maconfservice| "{4183D89B-0DB3-4B4B-9D3F-239B84C02170}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\ma-config.com\x64\maconfservice.exe|Name=maconfservice| "{91A30E8A-7EE9-4385-BFFB-F0A2A98ADD86}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe|Name=Titanfall™ (x64)| "{53B6B4C4-0974-4AF0-89E9-8A37F4866592}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe|Name=Titanfall™ (x64)| "{AD228FB4-94D5-40E8-99D2-19E38A74E482}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\BFH\BFHWebHelper.exe|Name=Battlefield™ Hardline (x64)| "{304F84BC-038D-428D-AF9F-B4326595248E}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\BFH\BFHWebHelper.exe|Name=Battlefield™ Hardline (x64)| "{9CFB1E2D-F80A-4ADA-9CDF-65D2008F2D99}"=v2.24|Action=Allow|Active=TRUE|Dir=Out|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{F091627C-5215-4718-B874-DB43F4FBDD62}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's H.A.W.X\HAWX.exe|Name=Tom Clancy's H.A.W.X| "{8CA4C955-FB55-4386-B9B7-97A99F495503}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's H.A.W.X\HAWX.exe|Name=Tom Clancy's H.A.W.X| "{2A8D2956-041A-440E-B311-EF8889F6BBE5}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's H.A.W.X\HAWX_dx10.exe|Name=Tom Clancy's H.A.W.X| "{B68DE7A5-0620-4301-AF85-D9C9D608BB61}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Tom Clancy's H.A.W.X\HAWX_dx10.exe|Name=Tom Clancy's H.A.W.X| "TCP Query User{32982D23-8319-45D0-A25F-4117913FF5B1}C:\program files (x86)\pro evolution soccer 2016\pes2016.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\pro evolution soccer 2016\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016|Defer=User| "UDP Query User{D27839BD-5003-4807-98A1-E6A3C6AD9D3B}C:\program files (x86)\pro evolution soccer 2016\pes2016.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\pro evolution soccer 2016\pes2016.exe|Name=Pro Evolution Soccer 2016|Desc=Pro Evolution Soccer 2016|Defer=User| "TCP Query User{61A27B4B-7ABB-4443-B078-070F42F31BF6}C:\program files (x86)\topgun - hardlock\binary\topgun.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\topgun - hardlock\binary\topgun.exe|Name=topgun|Desc=topgun|Defer=User| "UDP Query User{5B7A4BA0-777D-4BF1-8130-010D70562E1E}C:\program files (x86)\topgun - hardlock\binary\topgun.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\topgun - hardlock\binary\topgun.exe|Name=topgun|Desc=topgun|Defer=User| "{BB4237B4-BE18-4DC9-ADD8-C42BB515A6D1}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Top Gun - Hard Lock\binary\TopGun.exe|Name=Top Gun - Hard Lock| "{3C5043B0-64AB-44EC-BCB6-76B08E17A1D2}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Top Gun - Hard Lock\binary\TopGun.exe|Name=Top Gun - Hard Lock| "TCP Query User{648B99F5-249F-4D3A-860D-B55F3AD3D5FF}C:\games\need for speed the run\need for speed the run.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\games\need for speed the run\need for speed the run.exe|Name=need for speed the run|Desc=need for speed the run| "UDP Query User{B30B76FA-B1AC-47BF-B820-28CF695B4821}C:\games\need for speed the run\need for speed the run.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\games\need for speed the run\need for speed the run.exe|Name=need for speed the run|Desc=need for speed the run| "{E192CBC8-01D4-4C06-9BAE-266C4DD630AD}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Rogue\ACC.exe|Name=AC Rogue| "{042E983B-4D63-43D1-B7F2-414B6FEB019C}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Ubisoft\Assassin's Creed Rogue\ACC.exe|Name=AC Rogue| "{9676DFF8-EB82-408E-BA41-E070541F9AFE}"=v2.24|Action=Allow|Active=TRUE|Dir=In|App=C:\WINDOWS\system32\lxebcoms.exe|Name=Pro200-S500 Series Server|Desc=Pro200-S500 Series Server| "{1D3E791A-56D2-48D6-ADBB-03398F68C813}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe|Name=avast! NG front end| "{1506C54E-1ED7-477E-B891-769948FF60DB}"=v2.24|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe|Name=avast! NG front end| "TCP Query User{BA675ADB-EAD6-4564-A9A7-B1AFC706AB79}C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe|Name=FIFA 17 Demo|Desc=FIFA 17 Demo|Defer=User| "UDP Query User{C3687C88-B71E-4154-B76D-7E406B2B625C}C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe|Name=FIFA 17 Demo|Desc=FIFA 17 Demo|Defer=User| "{2530A9F1-7C5E-420E-86DC-9C31ECCB2094}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrA.exe|Name=PnkBstrA| "{9459CBC9-AEC6-4527-A50D-063EDADD4749}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrA.exe|Name=PnkBstrA| "{C6C62E55-E5D0-4C99-9853-620F4A693074}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrB.exe|Name=PnkBstrB| "{D38BBF13-C9DE-4F7F-A179-66B5A8E54B4F}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrB.exe|Name=PnkBstrB| "{17D48775-380D-4271-8B8C-6CE38BC33904}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe|Name=ESN Sonar Host Application| "{3167F676-08FF-468F-9A55-901553EAA881}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe|Name=ESN Sonar Host Application| "TCP Query User{A0C7E368-AEBE-474A-96A5-261A5E6D117C}C:\program files (x86)\origin games\battlefield 4\bf4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\origin games\battlefield 4\bf4.exe|Name=Battlefield 4™|Desc=Battlefield 4™|Defer=User| "UDP Query User{78E4B9C0-6BFF-4667-BA20-90D53E07489C}C:\program files (x86)\origin games\battlefield 4\bf4.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\origin games\battlefield 4\bf4.exe|Name=Battlefield 4™|Desc=Battlefield 4™|Defer=User| "TCP Query User{415F513B-11DB-48EB-AA48-282B952668BB}C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe|Name=Max Payne 3|Desc=Max Payne 3|Defer=User| "UDP Query User{BC817B41-C197-472D-A8A2-B8D1DD63F7A8}C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\rockstar games\max payne 3\maxpayne3.exe|Name=Max Payne 3|Desc=Max Payne 3|Defer=User| "{3D283357-246E-4683-AF36-36C440079310}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe|Name=Crysis®3| "{B873ECBE-6A46-42EC-B0B6-D2DFD4E4E784}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe|Name=Crysis®3| "{EC8E34BA-9133-403B-A666-8F6D728499D1}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe|Name=EA SPORTS™ FIFA 15| "{709AA48A-F522-46D9-9B2C-64334424D29E}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe|Name=EA SPORTS™ FIFA 15| "{E8FF2535-2DFB-478F-A169-4814E523A717}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Origin Games\FIFA 17 DEMO\FIFASetup\fifaconfig.exe|Name=Démo de FIFA 17| "{B12988DB-7F20-4CF7-B69B-D5E2300EB0B5}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Origin Games\FIFA 17 DEMO\FIFASetup\fifaconfig.exe|Name=Démo de FIFA 17| "{939A1C25-5F86-41F6-AAD5-D1F04BA4A872}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Ben\AppData\Local\Temp\7zS72B9\HPDiagnosticCoreUI.exe|Name=HPSAPS| "{7D635F15-B801-4769-B6B0-71073DBF982C}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Ben\AppData\Local\Temp\7zS72B9\HPDiagnosticCoreUI.exe|Name=HPSAPS| "{1090B478-E182-40D2-A982-FCC285888D18}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Ben\AppData\Local\Temp\7zS73CE\HPDiagnosticCoreUI.exe|Name=HPSAPS| "{4C570083-02AE-423D-8E66-7CB3ED90A127}"=v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Ben\AppData\Local\Temp\7zS73CE\HPDiagnosticCoreUI.exe|Name=HPSAPS| "TCP Query User{054A38A5-49FB-40F1-B905-06578AFE2C5C}C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe|Name=FIFA 17 Demo|Desc=FIFA 17 Demo|Defer=User| "UDP Query User{12FD6948-5619-4639-84FA-E70D9D7F9E86}C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\origin games\fifa 17 demo\fifa17_demo.exe|Name=FIFA 17 Demo|Desc=FIFA 17 Demo|Defer=User| "{2CC293AB-5FF0-43E2-8109-098377F7E08F}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files\CCleaner\CCUpdate.exe|Name=CCleaner Update| "{C4DE775E-4812-43D2-822F-59578E6386C5}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files\CCleaner\CCUpdate.exe|Name=CCleaner Update| "{DEC67950-99FE-46C3-93EC-2BEF84775313}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Name=Twitter|Desc=Twitter|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1063257880-1914585122-1954150059-946145533-116938067-416079064-1690466945|EmbedCtxt=Twitter|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{A17C4CCF-E519-45A1-BA01-6B6EF3465330}C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe|Name=Pro Evolution Soccer 2013|Desc=Pro Evolution Soccer 2013|Defer=User| "UDP Query User{1AA9A226-387E-4082-8D92-1075AAFA8E9F}C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe|Name=Pro Evolution Soccer 2013|Desc=Pro Evolution Soccer 2013|Defer=User| "TCP Query User{0C57354B-3D29-4213-A8EE-A0C9F7EFA122}C:\games\activision\call of duty - black ops\blackops.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\activision\call of duty - black ops\blackops.exe|Name=blackops|Desc=blackops| "UDP Query User{DED9F007-1C4D-45B9-A07F-F3FB2346ED0C}C:\games\activision\call of duty - black ops\blackops.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\activision\call of duty - black ops\blackops.exe|Name=blackops|Desc=blackops| "TCP Query User{E873B3DF-1769-4E42-B3BC-7117FDCB5F45}C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe|Name=accgame-win32-shipping|Desc=accgame-win32-shipping|Defer=User| "UDP Query User{E8C76ADF-B398-4FCD-8B9D-94310A40F0A0}C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe|Name=accgame-win32-shipping|Desc=accgame-win32-shipping|Defer=User| "TCP Query User{669DB455-B8A8-4268-9A6B-EB7319361572}C:\games\activision\call of duty 4 - modern warfare\iw3mp.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\games\activision\call of duty 4 - modern warfare\iw3mp.exe|Name=iw3mp|Desc=iw3mp|Defer=User| "UDP Query User{D1A33B2C-4514-42E2-905E-D8372E935F88}C:\games\activision\call of duty 4 - modern warfare\iw3mp.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\games\activision\call of duty 4 - modern warfare\iw3mp.exe|Name=iw3mp|Desc=iw3mp|Defer=User| "TCP Query User{6413FA8F-DBC1-4B7A-BE3A-0BBD53F45115}C:\program files (x86)\ubisoft\tom clancy's splinter cell conviction\src\system\conviction_game.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\ubisoft\tom clancy's splinter cell conviction\src\system\conviction_game.exe|Name=conviction_game|Desc=conviction_game|Defer=User| "UDP Query User{653B80FB-1216-41A3-9736-D239A735919C}C:\program files (x86)\ubisoft\tom clancy's splinter cell conviction\src\system\conviction_game.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\ubisoft\tom clancy's splinter cell conviction\src\system\conviction_game.exe|Name=conviction_game|Desc=conviction_game|Defer=User| "TCP Query User{91ED376B-A716-48AA-B9A6-BAE12A094484}C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_game.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_game.exe|Name=blacklist_game|Desc=blacklist_game| "UDP Query User{C00796BA-8589-4B6A-92FE-41DAC3A98563}C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_game.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_game.exe|Name=blacklist_game|Desc=blacklist_game| "{B6E16087-B035-4794-993F-1439DE702816}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Name=Xbox TCUI|Desc=Xbox TCUI|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-2603511428-3224021693-1028932517-3941269705-3349582775-2312504883-4057327947|EmbedCtxt=Xbox TCUI|Platform=2:6:2|Platform2=GTEQ| "{339765CA-E92D-40D8-90CF-E2EC861741EC}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-18|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{76265685-D19A-4ECA-8FC6-752205A35DE5}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Pay|Desc=Microsoft Pay|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-567501097-281763132-502764112-1855211022-3143306454-2372101908-561929011|EmbedCtxt=Microsoft Pay|Platform=2:6:2|Platform2=GTEQ| "{A1EC8597-AB66-43A2-8756-B6FAA4338608}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Shell Input Application|Desc=Shell Input Application|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-3945102849-3632965805-3846928828-240845225-3300287824-62672950-817265009|EmbedCtxt=Shell Input Application|Platform=2:6:2|Platform2=GTEQ| "{39DB5601-ADE3-4277-8129-23DFA7D82F6C}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Dolby Access|Desc=Dolby Access|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-864892550-682355956-3667821578-694357232-3878941086-3291980491-2900429266|EmbedCtxt=Dolby Access|Platform=2:6:2|Platform2=GTEQ| "{22129347-04F6-4480-B546-601C83C8EEDF}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Dolby Access|Desc=Dolby Access|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-864892550-682355956-3667821578-694357232-3878941086-3291980491-2900429266|EmbedCtxt=Dolby Access|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{9DD1C9A3-0A4B-40C5-A988-30E1B164D318}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=HP Smart|Desc=HP Smart|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-744533573-2444454674-265863901-3215465728-4115286053-1341080355-789689510|EmbedCtxt=HP Smart|Platform=2:6:2|Platform2=GTEQ| "{F5B624ED-3CE5-4BBE-90CF-6D6B1A9AF25D}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=HP Smart|Desc=HP Smart|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-744533573-2444454674-265863901-3215465728-4115286053-1341080355-789689510|EmbedCtxt=HP Smart|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{A2F51077-3E1F-4B48-8D50-6547FC79F522}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe|Name=Avast Secure Browser (mDNS-In)|Desc=Règle de trafic entrant pour Avast Secure Browser autorisant le trafic mDNS|EmbedCtxt=Avast Secure Browser| "{622E6C0A-88FB-4C26-91B7-D878D190F1CD}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar Plugin|Desc=Xbox Game Bar Plugin|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201|EmbedCtxt=Xbox Game Bar Plugin|Platform=2:6:2|Platform2=GTEQ| "{86368B6F-5616-4DFB-842B-1DB8FC3FE97A}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe|Name=EA SPORTS™ FIFA 15| "{FB44EEF8-988D-4B26-8E30-0B84EAFABE63}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe|Name=EA SPORTS™ FIFA 15| "{402D7DE5-5BBD-4C5B-84CD-26A29C868D26}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort2_10=4371-4379|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{E985776A-AFED-4C8C-B99E-5BCE9C95847B}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort2_10=4381-4389|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{913EB7AD-7385-481D-832E-31A4BD2D0F38}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=8088|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{EDF11FE8-B1F9-4AF5-A659-FDACB072DED3}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=8088|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{18495D8E-6982-48AD-A4A8-8A4EF547D080}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=57621|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{F61F9918-BFEB-4AA0-882D-72DC0B804E12}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort2_10=57621-57631|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{191A8698-F7EE-4890-80F1-D04F14283211}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{4DB182AD-D065-4299-94A4-EF37B01222CA}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe|Name=Spotify Music|Desc=Spotify Music|EmbedCtxt={78E1CD88-49E3-476E-B926-580E596AD309}| "{190F109A-6AB5-4565-A4DC-2DA4587C62A3}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Spotify Music|Desc=Spotify Music|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-557819504-3144503769-3460048582-2468406004-2969798954-3397036932-4166026031|EmbedCtxt=Spotify Music|Platform=2:6:2|Platform2=GTEQ| "{955F6AE3-C34A-41A8-A35E-3716FC037B1E}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe|Name=Google Chrome (mDNS-In)|Desc=Règle de trafic entrant pour Google Chrome autorisant le trafic mDNS|EmbedCtxt=Google Chrome| "{6D0B46F6-2F60-40BC-B21D-5A02214D64B6}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{aufeminin.com.Marmiton_1.1.0.49_neutral__mkpeb3b5nmday?ms-resource://aufeminin.com.Marmiton/resources/DisplayName}|Desc=@{aufeminin.com.Marmiton_1.1.0.49_neutral__mkpeb3b5nmday?ms-resource://aufeminin.com.Marmiton/resources/DisplayName}|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-2746997482-1200050250-463127341-3688427768-3675480658-3856793947-2696390589|EmbedCtxt=@{aufeminin.com.Marmiton_1.1.0.49_neutral__mkpeb3b5nmday?ms-resource://aufeminin.com.Marmiton/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{E04DB195-AF9F-4761-A231-84E471B5811C}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=@{aufeminin.com.Marmiton_1.1.0.49_neutral__mkpeb3b5nmday?ms-resource://aufeminin.com.Marmiton/resources/DisplayName}|Desc=@{aufeminin.com.Marmiton_1.1.0.49_neutral__mkpeb3b5nmday?ms-resource://aufeminin.com.Marmiton/resources/DisplayName}|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-2746997482-1200050250-463127341-3688427768-3675480658-3856793947-2696390589|EmbedCtxt=@{aufeminin.com.Marmiton_1.1.0.49_neutral__mkpeb3b5nmday?ms-resource://aufeminin.com.Marmiton/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{732AE573-D368-4128-9359-EB58384DA8BA}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar|Desc=Xbox Game Bar|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1714399563-1326177402-2048222277-143663168-2151391019-765408921-4098702777|EmbedCtxt=Xbox Game Bar|Platform=2:6:2|Platform2=GTEQ| "{7222A608-F1B0-45FB-9CA8-E148FF16A848}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar|Desc=Xbox Game Bar|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1714399563-1326177402-2048222277-143663168-2151391019-765408921-4098702777|EmbedCtxt=Xbox Game Bar|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{083FBB6A-3187-4F1F-9F1E-6B1438D2646E}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{91052200-8FEF-4D66-8F3E-8181E77A4B6A}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{E9EB9604-8CD6-45D7-8897-A9A4DF600119}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=3D Builder|Desc=3D Builder|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-3995430443-3719053022-3339397951-2895237338-2437516106-1575886070-2755610054|EmbedCtxt=3D Builder|Platform=2:6:2|Platform2=GTEQ| "{57C06777-2534-45CF-8F2E-3EFD927D0460}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=3D Builder|Desc=3D Builder|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-3995430443-3719053022-3339397951-2895237338-2437516106-1575886070-2755610054|EmbedCtxt=3D Builder|Platform=2:6:2|Platform2=GTEQ| "{5ECFCA0B-970E-4238-A9BB-E21A8497FF54}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{E2CDA95A-094A-4C6D-8942-13395B4964F4}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{F5EDD891-7E74-42EC-A748-9774C1798BDE}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Print 3D|Desc=Print 3D|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-4177018473-2823706547-3652141868-2730301309-560159678-43221128-488844051|EmbedCtxt=Print 3D|Platform=2:6:2|Platform2=GTEQ| "{A2C2E47C-11B8-4C19-AFC1-C8DC8D4C3624}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Print 3D|Desc=Print 3D|LUOwn=S-1-5-21-2392155067-2275373385-2186660377-1002|AppPkgId=S-1-15-2-4177018473-2823706547-3652141868-2730301309-560159678-43221128-488844051|EmbedCtxt=Print 3D|Platform=2:6:2|Platform2=GTEQ| [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\standardprofile\authorizedapplications\list] "C:\Program Files (x86)\Photocopier Expert\photocopierexpert.exe"=C:\Program Files (x86)\Photocopier Expert\photocopierexpert.exe:*:Enabled:Photocopier Expert "C:\Users\Ben\AppData\Roaming\cacaoweb\cacaoweb.exe"=C:\Users\Ben\AppData\Roaming\cacaoweb\cacaoweb.exe:*:Enabled:cacaoweb [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\domainprofile\authorizedapplications\list] "C:\Program Files (x86)\Photocopier Expert\photocopierexpert.exe"=C:\Program Files (x86)\Photocopier Expert\photocopierexpert.exe:*:Enabled:Photocopier Expert ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (SecurityAccelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @c_display.inf,%ClassDesc%;Display adapters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4f919108-4adf-11d5-882d-00b0d02fe381}] : (Wireless Communication Devices) [] -> @oem1.inf,%CLS%;Wireless Communication Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4fc9541c-0fe6-4480-a4f6-9495a0d17cd2}] : (HidLineDisplay) [] -> @c_linedisplay.inf,%ClassName%;POS Line Display [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53487c23-680f-4585-acc3-1f10d6777e82}] : (SmrDisk) [] -> @c_smrdisk.inf,%ClassDesc%;Shingled magnetic recording disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53b3cf03-8f5a-4788-91b6-d19ed9fcccbf}] : (SmrVolume) [] -> @c_smrvolume.inf,%ClassDesc%;Shingled magnetic recording volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs) [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5A46010E-C74B-4CB1-A041-D22759FE9F9C}] : (Sftplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5aea001d-9372-4ed7-97f3-b79bf15a53c5}] : (OposLegacyDevice) [] -> @oposdrv.inf,%ClassName%;OPOS Legacy Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{645ad99b-1344-4316-837a-08a3e73db222}] : (PerceptionSimulation) [] -> @PerceptionSimulationSixDof.inf,%ClassName%;Perception Simulation Controllers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{678dcf40-e2e6-11d5-8cd5-e960089ea00a}] : (Programming Support) [] -> @oem61.inf,%SAITEKCLASSNAME%;Programming Support [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{81C87465-DE07-4EFC-9D93-61E891D52FD2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8496e87e-c0a1-4102-9d8d-bd9a9b8b07a9}] : (WDC_SAM) [] -> @oem55.inf,%WDC_SAM_ClassName%;WD Drive Management devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87ef9ad1-8f70-49ee-b215-ab1fcadcbe3c}] : (NetDriver) [] -> @c_netdriver.inf,%ClassDesc%;Universal Network Drivers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A73C93F1-9727-4D1D-ACE1-0E333BA4E7DB}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b2728d24-ac56-42db-9e02-8edaf5db652f}] : (RDCamera) [] -> @rdcameradriver.inf,%ClassName%;Remote Desktop Camera devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ca3e7ab9-b4c3-4ae6-8251-579ef933890f}] : (Camera) [] -> @c_camera.inf,%ClassDesc%;Cameras [HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d612553d-06b1-49ca-8938-e39ef80eb16f}] : (Holographic) [] -> @c_holographic.inf,%ClassName%;Mixed Reality devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e6f1aa1c-7f3b-4473-b2e8-c97d8ac71d53}] : (UCM) [] -> @c_ucm.inf,%ClassDesc%;USB Connector Managers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [26/11/2013 22:13:31] - (0.0.0.0) - ( -) - C:\WINDOWS\system32\ckldrv.sys [21/02/2014 21:33:16] - (5.70.6.2) - (Protection Technology - Application Driver (01)) - C:\WINDOWS\System32\Drivers\appdrv01.sys [30/04/2013 11:55:32] - (7.0.27.13) - (Saitek - Smart Technology Helpers) - C:\WINDOWS\system32\drivers\SaiBus.sys [03/12/2018 11:46:13] - (23.21.13.9135) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 391.35) - C:\WINDOWS\System32\DriverStore\FileRepository\nvmoi.inf_amd64_3235b21d5787151d\nvlddmkm.sys [31/10/2019 20:49:17] - (4.13.0.0) - (NVIDIA Corporation - NVIDIA Virtual Audio Driver) - C:\WINDOWS\system32\drivers\nvvad64v.sys [31/10/2019 20:49:19] - (303.0.0.0) - (NVIDIA Corporation - Virtual USB Host Controller driver) - C:\WINDOWS\System32\drivers\nvvhci.sys [18/02/2016 17:43:56] - (3.4.0.0) - (Disc Soft Ltd - DAEMON Tools Lite Virtual USB Bus Driver) - C:\WINDOWS\System32\drivers\dtliteusbbus.sys [15/02/2016 23:46:05] - (5.28.0.0) - (Disc Soft Ltd - DAEMON Tools Lite Virtual SCSI Bus Driver) - C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30/04/2013 11:55:32] - (7.0.27.13) - (Saitek - Saitek Magic Mini Driver) - C:\WINDOWS\System32\drivers\SaiMini.sys [05/02/2018 08:30:16] - (1.3.36.6) - (NVIDIA Corporation - NVIDIA HDMI Audio Driver) - C:\WINDOWS\system32\drivers\nvhda64v.sys [13/11/2012 16:25:49] - (0.0.0.0) - ( -) - C:\WINDOWS\system32\DRIVERS\atksgt.sys [13/11/2012 16:25:49] - (0.0.0.0) - ( -) - C:\WINDOWS\system32\DRIVERS\lirsgt.sys [03/12/2018 11:07:59] - (1.0.0.20) - (IObit - IUProcessFilter) - C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [03/12/2018 11:07:59] - (1.0.0.20) - (IObit - IURegistryFilter) - C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service S0 - [Kernel Driver] - 3ware () -> System32\drivers\3ware.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ADP80XX () -> System32\drivers\ADP80XX.SYS - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsata () -> System32\drivers\amdsata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsbs () -> System32\drivers\amdsbs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdxata () -> System32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - aswArDisk (aswArDisk) -> system32\drivers\aswArDisk.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - aswbidsh (aswbidsh) -> system32\drivers\aswbidsh.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - aswbuniv (aswbuniv) -> system32\drivers\aswbuniv.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - aswElam (aswElam) -> system32\drivers\aswElam.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - aswRvrt (aswRvrt) -> system32\drivers\aswRvrt.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - aswVmm (aswVmm) -> system32\drivers\aswVmm.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD) -> System32\drivers\bxvbda.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - bttflt (@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter) -> System32\drivers\bttflt.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - cht4iscsi () -> System32\drivers\cht4sx64.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - Disk (@disk.inf,%disk_ServiceDesc%;Pilote de disque) -> System32\drivers\disk.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys - AcceptPause: False - AcceptStop: False R0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - HpSAMD () -> System32\drivers\HpSAMD.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - iaStorA () -> System32\drivers\iaStorA.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - iaStorAVC (@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller) -> System32\drivers\iaStorAVC.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - intelide () -> System32\drivers\intelide.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - iorate (@%SystemRoot%\system32\drivers\iorate.sys,-101) -> system32\drivers\iorate.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - isapnp () -> System32\drivers\isapnp.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - ItSas35i () -> System32\drivers\ItSas35i.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - LSI_SAS () -> System32\drivers\lsi_sas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SSS () -> System32\drivers\lsi_sss.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - MbamElam (MbamElam) -> system32\DRIVERS\MbamElam.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas () -> System32\drivers\megasas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas2i () -> System32\drivers\MegaSas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas35i () -> System32\drivers\megasas35i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasr () -> System32\drivers\megasr.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - msisadrv () -> System32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - mvumis () -> System32\drivers\mvumis.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - nvraid () -> System32\drivers\nvraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - nvstor () -> System32\drivers\nvstor.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pci (@pci.inf,%pci_svcdesc%;Pilote de bus PCI) -> System32\drivers\pci.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - pciide () -> System32\drivers\pciide.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - pcmcia () -> System32\drivers\pcmcia.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - percsas2i () -> System32\drivers\percsas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - percsas3i () -> System32\drivers\percsas3i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - Ramdisk (Windows RAM Disk Driver) -> system32\DRIVERS\ramdisk.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - scmbus (@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver) -> System32\drivers\scmbus.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - SgrmAgent (@%SystemRoot%\System32\Drivers\SgrmAgent.sys,-1001) -> system32\drivers\SgrmAgent.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - SiSRaid2 () -> System32\drivers\SiSRaid2.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SiSRaid4 () -> System32\drivers\sisraid4.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SmartSAMD () -> System32\drivers\SmartSAMD.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - stexstor () -> System32\drivers\stexstor.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storvsc () -> System32\drivers\storvsc.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\drivers\tcpip.sys,-10001) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volsnap (@%SystemRoot%\system32\drivers\volsnap.sys,-100) -> System32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volume (@volume.inf,%VolumeServiceDesc%;Volume driver) -> System32\drivers\volume.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vsmraid () -> System32\drivers\vsmraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - afunix (afunix) -> \SystemRoot\system32\drivers\afunix.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - appdrv01 (Application Driver (01)) -> System32\Drivers\appdrv01.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswArPot (aswArPot) -> system32\drivers\aswArPot.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswbidsdriver (aswbidsdriver) -> system32\drivers\aswbidsdriver.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswHdsKe (aswHdsKe) -> system32\drivers\aswHdsKe.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswKbd (aswKbd) -> system32\drivers\aswKbd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswRdr (aswRdr) -> system32\drivers\aswRdr2.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswSnx (aswSnx) -> system32\drivers\aswSnx.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswSP (aswSP) -> system32\drivers\aswSP.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - bam (@%SystemRoot%\system32\drivers\bam.sys,-100) -> system32\drivers\bam.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicDisplay () -> \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac179273be89\BasicDisplay.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicRender () -> \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_0b8d03c3bc0e7fd9\BasicRender.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys - AcceptPause: False - AcceptStop: True S1 - [Kernel Driver] - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys - AcceptPause: False - AcceptStop: False R1 - [File System Driver] - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - DXGKrnl (LDDM Graphics Subsystem) -> \SystemRoot\System32\drivers\dxgkrnl.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - NetworkX (NetworkX) -> \SystemRoot\system32\ckldrv.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - RDPDISPM () -> \SystemRoot\System32\drivers\rdpdispm.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - aswMonFlt (aswMonFlt) -> system32\drivers\aswMonFlt.sys - AcceptPause: False - AcceptStop: True S2 - [Kernel Driver] - aswStm (aswStm) -> system32\drivers\aswStm.sys - AcceptPause: False - AcceptStop: False R2 - [Kernel Driver] - atksgt (atksgt) -> system32\DRIVERS\atksgt.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - CldFlt (Windows Cloud Files Filter Driver) -> system32\drivers\cldflt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - lirsgt (lirsgt) -> system32\DRIVERS\lirsgt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - MBAMChameleon (MBAMChameleon) -> \SystemRoot\System32\Drivers\MbamChameleon.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MQAC (@mqutil.dll,-6101) -> system32\drivers\mqac.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - VBoxAswDrv (VBoxAsw Support Driver) -> \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - wanarp (@%systemroot%\system32\mprmsg.dll,-32011) -> System32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - wcifs (@%systemroot%\system32\drivers\wcifs.sys,-100) -> \SystemRoot\system32\drivers\wcifs.sys - AcceptPause: False - AcceptStop: True ---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted) ---------- | Uninstall (Whitelist) [HKU\S-1-5-21-2392155067-2275373385-2186660377-1002\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Google Chrome] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\c3RyZWV0ZmlnaHRlcnY_is1] : (Street Fighter V.-.) -> "C:\Program Files (x86)\Street Fighter V\unins000.exe" ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\FIFA18_is1] : (FIFA18 version 1.0.-.STEAMPUNKS) -> "C:\Program Files\FIFA18\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\V1JDNUZJQVdvcmxkUmFsbHlDaGFtcGlvbnNoaXA=_is1] : (WRC 5 FIA World Rally Championship.-.) -> "C:\Program Files\WRC 5 FIA World Rally Championship\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F86416039FF}] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{41A4E9B4-C041-42A3-8797-C49174201247}] : (Gadwin PrintScreenPro (64-Bit).-.Gadwin Systems) -> MsiExec.exe /X{41A4E9B4-C041-42A3-8797-C49174201247} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{55D55008-E5F6-47D6-B16F-B2A40D4D145F}] : (64 Bit HP CIO Components Installer.-.Hewlett-Packard) -> MsiExec.exe /I{55D55008-E5F6-47D6-B16F-B2A40D4D145F} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}] : (Google Earth Pro.-.Google) -> MsiExec.exe /I{70A0F34E-564B-4F93-ADD6-3BAEC6E44075} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{977D1ABF-4089-4CA7-BA33-CC75808B7ACE}] : (Intel® Trusted Connect Service Client.-.Intel Corporation) -> MsiExec.exe /I{977D1ABF-4089-4CA7-BA33-CC75808B7ACE} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9EA21438-935A-48F9-88D4-A0341406E12A}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel] : (NVIDIA Ansel.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel] : (Panneau de configuration NVIDIA 391.35.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update] : (Mises à jour NVIDIA 38.0.2.0.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer] : (DisplayDriverAnalyzer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv] : (NVIDIA SHIELD Streaming.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvAbHub] : (NVIDIA ABHub.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend] : (NVIDIA Backend.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer] : (NVIDIA Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper] : (NVIDIA TelemetryApi helper for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem] : (NVIDIA LocalSystem Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus] : (NVIDIA Message Bus for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService] : (NVIDIA NetworkService Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor] : (NVAPI Monitor plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session] : (NVIDIA Session Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User] : (NVIDIA User Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer] : (NVIDIA Display Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS] : (NVIDIA Display Container LS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog] : (NVIDIA Display Watchdog Plugin.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer] : (NVIDIA Display Session Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs] : (NVIDIA NodeJS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog] : (NVIDIA Watchdog Plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry] : (NVIDIA Telemetry Client.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvVHCI] : (NVIDIA Virtual Host Controller.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC] : (Nvidia Share.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay] : (NVIDIA ShadowPlay 3.20.1.57.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController] : (NVIDIA SHIELD Wireless Controller Driver.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core] : (NVIDIA Update Core.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver] : (NVIDIA Virtual Audio 4.13.0.0.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F1A25BEC-8098-475D-9F0F-DA506D41A2DC}] : (DriversCloud.com (64 bits).-.Cybelsoft) -> MsiExec.exe /X{F1A25BEC-8098-475D-9F0F-DA506D41A2DC} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ACE COMBAT ASSAULT HORIZON Enhanced Edition_is1] : (ACE COMBAT ASSAULT HORIZON Enhanced Edition.-.) -> "C:\Program Files (x86)\ACE COMBAT ASSAULT HORIZON Enhanced Edition\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Batman Arkham Knight - Patch FR 1.00] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Battlefield Hardline - Patch FR 2.00] : (Battlefield Hardline - Patch FR 2.00.-.TraductionJeux.com) -> C:\Program Files (x86)\BFH\Uninstall.exe ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Euro Fishing_is1] : (Euro Fishing.-.) -> "C:\Games\Euro Fishing\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Homeworld Deserts of Kharak_is1] : (Homeworld Deserts of Kharak.-.) -> "C:\Games\Homeworld Deserts of Kharak\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObitUninstall] : (IObit Uninstaller 8.-.IObit) -> "C:\Program Files (x86)\IObit\IObit Uninstaller\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Media Control_is1] : (Media Control 6.0.15.-.Damien Bain-Thouverez) -> "C:\Program Files (x86)\Media Control\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Middle Earth Shadow of Mordor_is1] : (Middle Earth Shadow of Mordor.-.) -> "C:\Program Files (x86)\Middle Earth Shadow of Mordor\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\mmswitch] : (Morgan Stream Switcher.-.) -> "C:\Program Files (x86)\Morgan\mmswitch\uninst.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Mortal Kombat Komplete Edition_is1] : (Mortal Kombat Komplete Edition.-.Warner Bros. Interactive Entertainment) -> "C:\Games\Mortal kombat\Mortal Kombat Komplete Edition\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MX vs ATV Reflex_is1] : (MX vs ATV Reflex.-.) -> "C:\Program Files (x86)\THQ\MX vs ATV Reflex\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\OggDS] : (Direct Show Ogg Vorbis Filter (remove only).-.) -> "C:\Windows\system32\OggDSuninst.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\RealPlayer 16.0] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Shadow Warrior_is1] : (Shadow Warrior.-.Devolver Digital) -> "C:\Program Files (x86)\Shadow Warrior\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\The Witcher 3 - Wild Hunt_is1] : (The Witcher 3 - Wild Hunt.-.) -> "C:\Program Files (x86)\The Witcher 3 Wild Hunt\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\UEFA Euro 2016 France_is1] : (UEFA Euro 2016 France.-.) -> "C:\Program Files (x86)\Konami Digital Entertainment\UEFA Euro 2016 France\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VobSub] : (VobSub v2.23 (Remove Only).-.) -> "C:\Program Files (x86)\Gabest\VobSub\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VUPlayer] : (VUPlayer.-.) -> "C:\Program Files (x86)\VUPlayer\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VWx0cmFTdHJlZXRGaWdodGVySVY=_is1] : (Ultra Street Fighter IV.-.) -> "C:\Program Files (x86)\Ultra Street Fighter IV\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WRC 5 FIA World Rally Championship - Patch FR 1.00] : (WRC 5 FIA World Rally Championship - Patch FR 1.00.-.TraductionJeux.com) -> C:\Program Files\WRC 5 FIA World Rally Championship\Uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{04BCF540-DE2A-11E0-9039-F04DA23A5C58}] : (DVD Architect Studio 5.0.-.Sony) -> MsiExec.exe /X{04BCF540-DE2A-11E0-9039-F04DA23A5C58} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{12C77A13-A31B-4565-8E60-494FD65EBB2F}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{14574B7F-75D1-4718-B7F2-EBF6E2862A35}] : (Company of Heroes.-.THQ Inc.) -> MsiExec.exe /X{14574B7F-75D1-4718-B7F2-EBF6E2862A35} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1E5C7043-09C5-4974-A69F-A5271FD82BBC}] : (PlayMemories Home.-.Sony Corporation) -> MsiExec.exe /X{1E5C7043-09C5-4974-A69F-A5271FD82BBC} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1F3EE41E-30A4-11E0-8AC3-005056C00008}] : (Sound Forge Audio Studio 10.0.-.Sony) -> MsiExec.exe /X{1F3EE41E-30A4-11E0-8AC3-005056C00008} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{23170F69-40C1-2701-1604-000001000000}] : (7-Zip 16.04.-.Igor Pavlov) -> MsiExec.exe /I{23170F69-40C1-2701-1604-000001000000} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{25A60C59-0FDC-4D73-81F4-D4A6D4E0CB92}] : (Adobe AIR.-.Adobe Systems Incorporated) -> MsiExec.exe /I{25A60C59-0FDC-4D73-81F4-D4A6D4E0CB92} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F32180144F0}] : (Java 8 Update 144.-.Oracle Corporation) -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F32180144F0} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216026FF}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218073F0}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218077F0}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218091F0}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2FB04107-7BC2-449C-915A-530B29B5E0FE}] : (UE3Redist.-.Epic Games) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}] : (Java Auto Updater.-.Oracle Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5442DAB8-7177-49E1-8B22-09A049EA5996}] : (Renesas Electronics USB 3.0 Host Controller Driver.-.Renesas Electronics Corporation) -> MsiExec.exe /X{5442DAB8-7177-49E1-8B22-09A049EA5996} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5454083B-1308-4485-BF17-111000028701}] : (Grand Theft Auto: Episodes from Liberty City.-.Rockstar Games Inc.) -> MsiExec.exe /I{5454083B-1308-4485-BF17-111000028701} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5916A24B-59A4-4FDB-9753-499CB1F65362}] : (LavasoftTcpService.-.Lavasoft) -> MsiExec.exe /I{5916A24B-59A4-4FDB-9753-499CB1F65362} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60C01570-A8AB-11E0-B591-005056C00008}] : (MSVCRT Redists.-.Sony Creative Software Inc.) -> MsiExec.exe /I{60C01570-A8AB-11E0-B591-005056C00008} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] : (Google Update Helper.-.Google LLC) -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{81F288DE-5409-11E1-813B-F04DA23A5C58}] : (Vegas Movie Studio HD Platinum 11.0.-.Sony) -> MsiExec.exe /X{81F288DE-5409-11E1-813B-F04DA23A5C58} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{95140000-0070-0000-0000-0000000FF1CE}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A9222889-1CDA-42BD-B11B-113E7C91C1C7}] : (OpenOffice 4.1.7.-.Apache Software Foundation) -> MsiExec.exe /I{A9222889-1CDA-42BD-B11B-113E7C91C1C7} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}] : (Google Update Helper.-.Google Inc.) -> MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-000182420219}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-000182435289}] : (Adobe Refresh Manager.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-0804-1033-1959-000182435289} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824161310}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824166751}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824184103}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824191728}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}] : (Adobe Acrobat Reader DC - Français.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-AC0F074E4100} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-5464-3428-A00000000004}] : (Spelling Dictionaries Support For Adobe Reader X.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-A00000000004} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BFAAFBF7-82AD-4387-B6DD-D7F49E503987}] : (LibreOffice 5.3 Help Pack (French).-.The Document Foundation) -> MsiExec.exe /I{BFAAFBF7-82AD-4387-B6DD-D7F49E503987} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C2523AE6-F335-4D0B-BC15-1C07E4ACE629}] : (Pro Evolution Soccer 2013.-.KONAMI) -> MsiExec.exe /X{C2523AE6-F335-4D0B-BC15-1C07E4ACE629} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C2B5B5B0-2545-4E94-B4BA-548D4BF0B196}] : (Metric Collection SDK 35.-.Lenovo Group Limited) -> MsiExec.exe /X{C2B5B5B0-2545-4E94-B4BA-548D4BF0B196} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EBAEEE00-5412-11E1-B144-001676AB6D60}] : (MSVCRT Redists.-.Sony Creative Software Inc.) -> MsiExec.exe /I{EBAEEE00-5412-11E1-B144-001676AB6D60} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EE467474-04A8-48D5-8DDF-0F8D3A3CCBE5}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F74345C8-C4FB-FF9F-A28A-43C5FD808E57}] : (myphotobook.fr.-.myphotobook GmbH) -> MsiExec.exe /I{F74345C8-C4FB-FF9F-A28A-43C5FD808E57} ---------- | Ports ---------- | Installer [HKCR\Installer\Products\00EEEABE21451E111B44006167BAD606] : MSVCRT Redists [HKCR\Installer\Products\045FCB40A2ED0E1109930FD42AA3C585] : DVD Architect Studio 5.0 -> C:\Windows\Installer\{04BCF540-DE2A-11E0-9039-F04DA23A5C58}\dvdarchst.ico [HKCR\Installer\Products\07510C06BA8A0E115B190005650C0080] : MSVCRT Redists [HKCR\Installer\Products\09AB59D18F4FCE748A2844C1993DC0E1] : MSXML 4.0 SP3 Parser (KB2758694) [HKCR\Installer\Products\0B5B5B2C545249E44BAB45D8B40F1B69] : Metric Collection SDK 35 [HKCR\Installer\Products\1C4235E6CF4867F4A9A36CE5708FE06E] : Complément Messenger -> C:\Windows\Installer\{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}\CompanionIcon [HKCR\Installer\Products\30DD1C25E4016CA4D96C125D5827E11D] : UpdateAssistant [HKCR\Installer\Products\3407C5E15C9047946AF95A72F18DB2CB] : PlayMemories Home [HKCR\Installer\Products\38E1FB04BE028D11795C00905C206085] : Power2Go -> C:\Windows\Installer\{40BF1E83-20EB-11D8-97C5-0009C5020658}\ARPPRODUCTICON.exe [HKCR\Installer\Products\42C6FBF1DF1C10144AB2C065F4E9E897] : PowerStarter -> C:\Windows\Installer\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4B9E4A14140C3A2478794C1947022174] : Gadwin PrintScreenPro (64-Bit) -> C:\Windows\Installer\{41A4E9B4-C041-42A3-8797-C49174201247}\ProductIcon [HKCR\Installer\Products\4EA42A62D9304AC4784BF2238110440F] : Java 8 Update 144 -> C:\Program Files (x86)\Java\jre1.8.0_144\\bin\javaws.exe [HKCR\Installer\Products\52744B0D6663D294EB6F85A741DBB99D] : MSVCRT_amd64 [HKCR\Installer\Products\6116D6C8427B0184F8D20D746E7B6DE8] : Mesh Runtime [HKCR\Installer\Products\63ACBD2914B91DD449A1EA1D94DD730F] : Windows Mobile Device Center Driver Update -> C:\WINDOWS\Installer\{92DBCA36-9B41-4DD1-941A-AED149DD37F0}\WindowsMobileDeviceCenter.ico [HKCR\Installer\Products\68AB67CA408033019195001028342598] : Adobe Refresh Manager -> C:\WINDOWS\Installer\{AC76BA86-0804-1033-1959-000182435289}\ARPPRODUCTICON.exe [HKCR\Installer\Products\68AB67CA7DA7464543820A0000000040] : Spelling Dictionaries Support For Adobe Reader X -> C:\Windows\Installer\{AC76BA86-7AD7-5464-3428-A00000000004}\ARPPRODUCTICON.exe [HKCR\Installer\Products\68AB67CA7DA76301B744CAF070E41400] : Adobe Acrobat Reader DC - Français -> C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico [HKCR\Installer\Products\6E8A266FCD4F2A1409E1C8110F44DBCE] : MSXML 4.0 SP2 (KB973688) [HKCR\Installer\Products\6EA3252C533FB0D4CB51C1704ECA6E92] : Pro Evolution Soccer 2013 -> C:\WINDOWS\Installer\{C2523AE6-F335-4D0B-BC15-1C07E4ACE629}\ARPPRODUCTICON.exe [HKCR\Installer\Products\70140BF22CB7C94419A535B0925B0EEF] : UE3Redist -> C:\Windows\Installer\{2FB04107-7BC2-449C-915A-530B29B5E0FE}\ARPPRODUCTICON.exe [HKCR\Installer\Products\7BD4C90EC03660F46A13E87A329932FA] : D3DX10 [HKCR\Installer\Products\7E0BA6F1DDC839B4A832AAE92BEFCF4E] : Junk Mail filter update [HKCR\Installer\Products\7FBFAAFBDA2878346BDD7D4FE9059378] : LibreOffice 5.3 Help Pack (French) -> C:\WINDOWS\Installer\{BFAAFBF7-82AD-4387-B6DD-D7F49E503987}\soffice.ico [HKCR\Installer\Products\80055D556F5E6D741BF62B4AD0D441F5] : 64 Bit HP CIO Components Installer [HKCR\Installer\Products\8BAD244577171E94B822900A94AE9569] : Renesas Electronics USB 3.0 Host Controller Driver -> C:\Windows\Installer\{5442DAB8-7177-49E1-8B22-09A049EA5996}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8C54347FBF4CF9FF2AA8345CDF08E875] : myphotobook.fr [HKCR\Installer\Products\92540D3EBDE68D113A270005AB3E711E] : PowerDVD Copy -> C:\Windows\Installer\{E3D04529-6EDB-11D8-A372-0050BAE317E1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E] : Google Update Helper [HKCR\Installer\Products\95C06A52CDF037D4184F4D6A4D0EBC29] : Adobe AIR [HKCR\Installer\Products\96F071321C0410726140000010000000] : 7-Zip 16.04 [HKCR\Installer\Products\9882229AADC1DB241BB111E3C7191C7C] : OpenOffice 4.1.7 -> C:\WINDOWS\Installer\{A9222889-1CDA-42BD-B11B-113E7C91C1C7}\soffice.ico [HKCR\Installer\Products\A089CE062ADB6BC44A720BA745894BAC] : Google Update Helper [HKCR\Installer\Products\A6C64DD86500CEF47BA082BB611A1FF1] : MSVCRT [HKCR\Installer\Products\A86BF41F88196304DAD00D45CBC92919] : Update for Windows 10 for x64-based Systems (KB4023057) [HKCR\Installer\Products\B380454580315844FB71110100207810] : Grand Theft Auto: Episodes from Liberty City [HKCR\Installer\Products\B3B1CDA7BC602CE4087A0F362B5CEF24] : Ad-Aware Web Companion -> C:\Windows\Installer\{7ADC1B3B-06CB-4EC2-80A7-F063B2C5FE42}\ARPPRODUCTICON.exe [HKCR\Installer\Products\BA0A2B44E214C8F40B851D8EEACCFD5F] : PowerRecover -> C:\Windows\Installer\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C971C95CD8669A946BAE1012CCCF2134] : LabelPrint -> C:\Windows\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe [HKCR\Installer\Products\CC67F423DD8D78D47BD74DFAE5A17A3B] : WaveEditor -> C:\Windows\Installer\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}\ARPPRODUCTICON.exe [HKCR\Installer\Products\CEB52A1F8908D574F9F0AD05D6142ACD] : DriversCloud.com (64 bits) -> C:\WINDOWS\Installer\{F1A25BEC-8098-475D-9F0F-DA506D41A2DC}\maconfico [HKCR\Installer\Products\D139E7FE48CDB174D86B8A3385904547] : [HKCR\Installer\Products\E14EE3F14A030E11A83C0005650C0080] : Sound Forge Audio Studio 10.0 -> C:\Windows\Installer\{1F3EE41E-30A4-11E0-8AC3-005056C00008}\forgexp10.ico [HKCR\Installer\Products\E43F0A07B46539F4DA6DB3EA6C4E0457] : Google Earth Pro -> C:\WINDOWS\Installer\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}\MainIcon.ico [HKCR\Installer\Products\ED882F1890451E1118B30FD42AA3C585] : Vegas Movie Studio HD Platinum 11.0 -> C:\Windows\Installer\{81F288DE-5409-11E1-813B-F04DA23A5C58}\vegasmoviestudioPE.ico [HKCR\Installer\Products\F60730A4A66673047777F5728467D401] : Java Auto Updater [HKCR\Installer\Products\F7B475411D5781747B2FBE6F2E68A253] : Company of Heroes -> C:\Windows\Installer\{14574B7F-75D1-4718-B7F2-EBF6E2862A35}\ARPPRODUCTICON.exe [HKCR\Installer\Products\FBA1D77998047AC4AB33CC5708B8A7EC] : Intel® Trusted Connect Service Client ---------- | ADS ---------- | Drives ---------- | MBR 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Windows ne peut pas charger la DLL de compteur extensible « C:\WINDOWS\system32\sysmain.dll » (code d'erreur Win32 Le module spécifié est introuvable.). ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Product: Avast Update Helper -- Error 1316. Le compte spécifié existe déjà. ------------ Le programme HxOutlook.exe version 16.0.12228.20276 a cessé d'interagir avec Windows et a été fermé. Pour voir si plus d'informations sur le problème sont disponibles, vérifiez l'historique des problèmes dans le Panneau de configuration Sécurité et maintenance. ID de processus : 2624 Heure de début : 01d5bb11b0edad14 Heure d'arrêt : 4294967295 Chemin d'accès à l'application : C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12228.20276.0_x64__8wekyb3d8bbwe\HxOutlook.exe ID de rapport : 09337d32-9085-48b5-8134-9f664aefd3c8 Nom complet du package défectueux : microsoft.windowscommunicationsapps_16005.12228.20276.0_x64__8wekyb3d8bbwe ID de l'application relative à un package défectueux : microsoft.windowslive.mail Type de blocage : Activation ------------ ----------( EOF)---------- - 8127 | 16:43:39